Skip to content

Backup

How do you recover Microsoft 365 after a ransomware attack?

Microsoft keeps your tenant available. Getting your mailboxes, files and Teams back to the moment before the attack is a different job, and it needs preparing in advance.

Lit, running office at night with an open amber-lit archive drawer in the foreground holding indexed folders

The short answer

Contain the attack first: reset compromised accounts, revoke sessions and remove rogue apps. Then pick a clean point in time and restore mailboxes, OneDrive, SharePoint and Teams data from an independent, immutable backup outside your tenant. Native recycle bins and version history help with small incidents but run out after 14 to 93 days.

Key takeaways

  • Availability means Microsoft 365 is running; recoverability means you can restore specific data, from a specific point in time, within a time you've agreed in advance.
  • Microsoft's own Azure Storage documentation says redundancy protects against hardware failure, not against deletions, overwrites or encryption.
  • Contain first, restore second: restoring into a tenant the attacker still controls invites a second round of encryption.
  • A recovery-grade backup is immutable, held outside the tenant behind separate credentials with MFA, and tested with timed restores.
  • Set a recovery time objective (how fast) and a recovery point objective (how much loss) per workload, and test against them at least quarterly.

What is the difference between availability and recoverability in Microsoft 365?

Availability means the service is up and your users can log in. Recoverability means you can bring back the exact data you lost, from a moment before the damage, within a timeframe the business has agreed.

Microsoft is very good at the first. It replicates your data across data centres so that hardware failures don't interrupt Exchange Online or SharePoint. But replication copies every change. Microsoft's Azure Storage redundancy documentation puts the principle plainly: "Redundancy protects against hardware failure, not against data-modifying operations." Deletions and overwrites are applied to all copies at once, and ransomware encryption is a data-modifying operation.

Recoverability is your part of the deal. It comes from an independent copy, which is what backup as a service provides. If you're still unsure who is responsible for what, start with does Microsoft 365 back up my data?

Picture a ten-person accountancy on a Monday morning. Outlook opens, Teams works, the Microsoft status page is green. Yet half the client folders in SharePoint have been replaced by encrypted copies since Friday night. The service is available. The data isn't recoverable unless someone prepared for it.

How does ransomware reach a Microsoft 365 tenant?

Usually through a stolen identity rather than a flaw in Microsoft's platform. Once an attacker has a valid account, everything they do looks like normal user or admin activity.

The Microsoft Digital Defense Report 2025 found that identity-based attacks rose by 32% in the first half of 2025, that more than 97% of identity attacks are password attacks, and that multi-factor authentication can block over 99% of them. Typical paths into Microsoft 365 are:

  • A compromised user account: a synced laptop is encrypted and OneDrive dutifully uploads the encrypted versions.
  • A compromised admin account: the attacker deletes mailboxes or sites, shortens retention or empties recycle bins.
  • A malicious or over-privileged app: an app granted broad access through consent can read, change or delete data at scale.

Attackers know backups are the way out. Microsoft's ransomware-resilient backup architecture guidance warns that "ransomware operators frequently target backup infrastructure first to eliminate recovery options before they attack production systems." That's why where your backup lives, and who can reach it, matters as much as having one.

What are the steps to recover Microsoft 365 after ransomware?

Contain, choose a clean restore point, restore in priority order, verify and report. Skipping containment is the most expensive mistake, because restored data can be encrypted again.

  1. Contain the incident. Reset passwords for affected accounts, revoke active sessions, enforce MFA, remove suspicious app consents and mailbox rules, and isolate infected endpoints. Bring in your MSP or incident responder.
  2. Preserve evidence. Export audit logs before you change too much. You'll need them for insurers, regulators and the root-cause analysis.
  3. Find the clean point in time. Work out when the first malicious change happened and choose the last backup before it.
  4. Prioritise. Restore what the business needs first: key mailboxes, finance and customer SharePoint libraries, then the rest.
  5. Restore granularly. Restore to the original location when it's clean, or to an alternative location so users can compare.
  6. Verify with users. Have owners confirm that restored folders and mailboxes are complete before you close the incident.
  7. Report and learn. If you fall under NIS2, Article 23 of Directive (EU) 2022/2555 requires an early warning within 24 hours, an incident notification within 72 hours and a final report within one month.

For realistic durations of each phase, see our ransomware recovery timeline. If you're being pressured to pay, read should you pay the ransom? first.

Which native Microsoft 365 tools help, and where do they stop?

Native tools are fine for a single deleted folder or a handful of encrypted files noticed quickly. They stop helping when the damage is large, old or done with admin rights.

Native toolWhat it recoversWhere it stops
Version history (SharePoint, OneDrive)Earlier versions of a file; 500 kept by defaultDoesn't help if files are deleted or versions purged
Recycle bins (SharePoint, OneDrive)Deleted files and folders93 days after deletion
OneDrive Files RestoreA whole OneDrive to an earlier momentLast 30 days only, per user
Exchange single item recoveryDeleted and purged mailbox items14 days by default, 30 at most
Purview retention policiesContent kept for compliance and eDiscoveryNot built for fast, bulk operational restores
Microsoft 365 Backup (paid)Exchange, OneDrive and SharePoint, up to one year backSame vendor and admin plane as the data it protects

The first five rows come from Microsoft's ransomware protection guidance for Microsoft 365, the Exchange Recoverable Items documentation and OneDrive Files Restore. Microsoft 365 Backup details are from the Microsoft 365 Backup FAQ, which lists a 10-minute recovery point objective for those workloads.

Microsoft's guidance also makes a fair point: third-party tools that only copy data to another location may not restore fast enough for a tenant-wide incident. Don't take any vendor's word for restore speed, ours included. Time a real restore.

What should a Microsoft 365 backup do to make recovery possible?

It has to survive the attack and restore what you need, at the speed you need. The UK National Cyber Security Centre's principles for ransomware-resistant cloud backups are a good yardstick.

  • Resilient to destructive actions: backups can't be deleted or altered, even by an admin, during their retention period.
  • Access can't be fully denied: an attacker who takes your tenant can't lock you out of your backups.
  • Restore from an uncorrupted version: you can go back to a point before the infection, not only to last night.
  • Keys are protected: encryption keys are managed so attackers can't use them.
  • Alerts on privileged changes: deletions and policy changes trigger notifications.

Here's how our Microsoft 365 backup maps to that. Backups of Exchange, OneDrive, SharePoint and Teams are immutable with Object Lock, with an additional air-gapped copy, following the 3-2-1-1-0 rule. Admin actions require MFA, data is AES-256 encrypted in transit to our own Tier III data centres in the Netherlands and Germany, backups are scanned for malware, and every backup job is checked automatically and monitored 24/7. Granular restore lets you bring back one mailbox folder or a whole site, and critical workloads are restored on a 4-hour SLA.

How do you set and test recovery targets for Microsoft 365?

Agree a recovery time objective (RTO, how long you can be without the data) and a recovery point objective (RPO, how much recent work you can lose) for each workload. Then prove them with timed test restores.

Testing pays off. In a Sophos study of 2,974 ransomware victims, only 26% of organisations whose backups were compromised fully recovered within a week, compared with 46% of those whose backups were intact. Testing is also in the law: Article 32(1) of the GDPR asks for "the ability to restore the availability and access to personal data in a timely manner" and "a process for regularly testing, assessing and evaluating" those measures.

A practical cadence:

  • Monthly: restore a single mailbox and a SharePoint folder from at least 30 days ago.
  • Quarterly: restore a full user (mail, OneDrive, Teams files) and record how long it took against your RTO.
  • Yearly: run a tabletop exercise of a tenant-wide incident with management, including who decides what.

Need help choosing the numbers? Our RTO and RPO explainer walks through it, and how to verify your backup works lists the metrics to track.

What to do next

Microsoft 365 recovery after ransomware is decided before the attack. If your only options are recycle bins and version history, you can recover small incidents but not a compromised tenant or damage you notice after three months. Put an independent, immutable backup in place, write down your recovery steps and test them.

See how Microsoft 365 fits into your wider protection on our backup as a service page, or book a free 15-minute demo and watch us restore a mailbox and a SharePoint library from a point in time you choose.

This article is information, not legal advice.

Frequently asked questions

Can I recover Microsoft 365 data after ransomware without a backup?

Sometimes, if you act quickly. Version history can roll back encrypted SharePoint and OneDrive files, OneDrive Files Restore covers the last 30 days and recycle bins keep deleted files for 93 days. Exchange keeps deleted items for 14 days by default. If the attacker had admin rights and purged data, or you notice the damage later, these options are usually gone.

How long does Microsoft 365 ransomware recovery take?

It depends on how much data is affected, how quickly you contain the attack and how fast your backup can restore. Restoring a few mailboxes takes hours, while a tenant-wide restore can take days. Containment and finding a clean restore point often take longer than the restore itself. Time a full-user test restore so you know your real numbers.

Should I restore Microsoft 365 before or after removing the attacker?

After. Reset compromised credentials, revoke sessions, remove malicious app consents and mailbox forwarding rules, and clean infected endpoints first. If you restore while the attacker still has access, synced devices or a compromised account can encrypt or delete the restored data again, and you lose the clean copy you depended on.

Does Microsoft help restore my data after a ransomware attack?

Microsoft provides the native tools and, for SharePoint, can restore whole site collections from backups kept for 14 days beyond the 93-day recycle bin period. It doesn't restore individual files from those backups, and attacks that start in your tenant remain your responsibility under the shared responsibility model. Plan your own recovery.

What is the difference between RTO and RPO for Microsoft 365?

RTO, the recovery time objective, is how long a workload such as Exchange can be unavailable before it seriously hurts the business. RPO, the recovery point objective, is how much recent data you can afford to lose, set by how often you back up. Set both per workload and test them with timed restores.

Sources

  1. Data redundancy - Azure StorageMicrosoft Learn, 2026
  2. Design a ransomware-resilient backup architecture by using Azure BackupMicrosoft Learn (Azure Architecture Center), 2026
  3. Extortion and ransomware drive over half of cyberattacks (Microsoft Digital Defense Report 2025)Microsoft On the Issues, 2025
  4. Ransomware protection in Microsoft 365Microsoft Learn (Service Assurance), 2025
  5. Recoverable Items folder in Exchange OnlineMicrosoft Learn, 2026
  6. Restore your OneDrive filesMicrosoft Support, 2026
  7. Frequently asked questions about Microsoft 365 BackupMicrosoft Learn, 2026
  8. Principles for ransomware-resistant cloud backupsNCSC UK, 2024
  9. The impact of compromised backups on ransomware outcomesSophos, 2024
  10. Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, 2022
  11. Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, 2016
Part ofBackup as a Service