Microsoft protects
Platform uptime, network, datacenter security, software patching, geographic redundancy.
Microsoft 365 is highly available — but availability is not backup. If a user deletes a SharePoint site, an attacker encrypts a mailbox, or retention policies expire on data you actually need, Microsoft will not restore it for you. This is what real backup looks like.
Microsoft's shared-responsibility model is explicit: they guarantee the availability and security of the Microsoft 365 platform (servers, network, datacenter). You are responsible for the data inside it.
That means: if your tenant is compromised and an attacker deletes mailboxes, encrypts SharePoint files, or wipes Teams channels, Microsoft will not restore that data. The same applies to accidental deletion, departing-employee data loss, and retention-policy mistakes.
Platform uptime, network, datacenter security, software patching, geographic redundancy.
Mailbox content, SharePoint files, OneDrive files, Teams chats and channels, calendar items, contacts.
Microsoft 365 includes native data-protection features. They are useful, but they are not backup:
OneDrive sync replicates files between your laptop and the cloud. If a file changes on either side, the change syncs to the other side — including deletion and ransomware encryption.
A workstation hit with ransomware will encrypt every synced OneDrive file. Within minutes, those encrypted versions are in OneDrive and on every other device synced to that user. The Recycle Bin may catch some, but not all — and not reliably.
Mailbox deleted before contents were preserved; legitimate client communications gone.
OneDrive and SharePoint files encrypted across the tenant via a single compromised account.
A power user deletes a site collection believing it is unused. 91 days later, the data is gone forever.
A policy set to "delete after 1 year" accidentally applied to a critical library.
Attacker deletes the trace of their activity by emptying Sent Items and the Recycle Bin.
A tenant-to-tenant migration loses email headers or breaks calendar invites — restoration is impossible without backup.
A backup you have never restored is a hope, not a backup. A verified restore proves the backup is recoverable end-to-end:
A deleted file from last month, an archived mailbox, a Teams channel from a past project.
Never restore to production — restore to a recovery folder or a sandbox tenant so you do not overwrite live data.
Open the file, check the email body, confirm the calendar invites still link properly.
Note how long the restore took. That number is your real RTO (Recovery Time Objective) — not the marketing number on the backup vendor's website.
Tenants change. Restore procedures break. Quarterly verification keeps the backup honest.
A common source of confusion: Microsoft Purview retention policies preserve data for a configured period, but they are not point-in-time backup. They cannot restore a SharePoint site to a previous date. They cannot recover individual deleted files easily. They are designed for legal preservation, not operational recovery.
If your "backup strategy" is "we have retention policies on," you do not have backup — you have legal-hold infrastructure.
A 19-control Microsoft 365 hardening checklist for Canadian small businesses: MFA, Conditional Access, legacy auth, phishing defense, endpoints, backup, and incident response.
How to configure Microsoft Defender anti-phishing, Safe Links, impersonation protection, and reporting habits for small teams on Microsoft 365.
How to design, test, and enforce Conditional Access in a Microsoft 365 Business Premium tenant without locking the team out.
A practical rollout plan for Microsoft 365 MFA across staff, shared mailboxes, service accounts, BYOD devices, and admin accounts.
FAQ
No. Microsoft includes data-protection features (Recycle Bin, versioning, retention policies, litigation hold) but explicitly does not offer point-in-time backup or restore. Their shared-responsibility documentation states this clearly.
Typically $4–8 per user per month, depending on coverage, retention length, and vendor. For a 15-user SMB, that is roughly $1,000–1,500/year — a fraction of the cost of a single data-loss incident.
For unregulated SMBs, 1–3 years is typical. For regulated industries (legal, medical, financial), the retention requirement may be 7+ years — check your specific regulatory obligations.
Yes — if the backup is stored outside the tenant (air-gapped) and you can restore from a point in time before the attack. This is why backup vendor selection matters: a backup stored inside your compromised tenant is not really backup.
Yes. The most common SMB data-loss scenarios — accidental deletion, departing-employee mailbox cleanup, ransomware, retention misconfiguration — all happen at the same rates as in larger organizations. The data loss costs are proportionally larger for an SMB because there are fewer staff to absorb the disruption.