Backup
Does Microsoft 365 back up my data?
Microsoft keeps the service running. What happens to your email, files and Teams data after a deletion or a ransomware attack is up to you.

The short answer
No, not as an independent backup. Microsoft keeps the Microsoft 365 service available and replicates your data, but its own documentation says your data stays your responsibility. Recycle bins and version history hold deleted items for 14 to 93 days. To recover from ransomware, mistakes or deleted accounts, you need a separate backup outside your tenant.
Key takeaways
- Microsoft's shared responsibility documentation states that customers always remain responsible for their data, accounts and access management, including in SaaS services such as Microsoft 365.
- Native recovery windows are short: Exchange Online keeps deleted items for 14 days by default (30 at most), and SharePoint and OneDrive recycle bins keep items for 93 days.
- Ransomware is common and identity-driven: the Verizon 2026 DBIR found ransomware in 48% of breaches, and Microsoft reports that more than 97% of identity attacks are password attacks.
- A backup only helps after an attack if it sits outside the compromised tenant, cannot be altered and has been tested with real restores.
- Back up all four core workloads (Exchange, OneDrive, SharePoint and Teams) and protect leavers' data before you delete their accounts.
What does Microsoft actually protect in Microsoft 365?
Microsoft protects the platform: its data centres, hardware, network and the uptime of Exchange Online, SharePoint, OneDrive and Teams. Your data, and who can change or delete it, stays with you.
That split is called the shared responsibility model. Microsoft's own page on shared responsibility in the cloud lists four things you always keep, whatever the service type: your data, your endpoints, your accounts and your access management. In a SaaS service such as Microsoft 365, Microsoft takes over the operating system, physical hosts, network and data centre. It doesn't take over responsibility for your content.
So when a user deletes a folder, an admin removes the wrong account or ransomware encrypts a SharePoint library, Microsoft's systems carry out those changes faithfully. The service stays available, which is exactly what it promises. Recovering the data is a separate job, and that's where backup as a service comes in. We cover the full model in our guide to the Microsoft 365 shared responsibility model.
Replication is not a backup
Microsoft replicates data across data centres so that a hardware failure doesn't take your mailbox offline. Replication copies every change, including deletions and encryption. It protects availability, not your ability to go back to a clean point in time.
How long does Microsoft 365 keep deleted data?
Between 14 and 93 days for most items, depending on the workload and settings. After that, data is permanently removed unless you've set up retention policies or an independent backup.
| What was deleted | Native recovery window | Source |
|---|---|---|
| Email and other mailbox items | 14 days by default, configurable up to 30 days | Microsoft Learn: Recoverable Items folder |
| A user account (with its mailbox) | 30 days to restore the account; a deleted mailbox is recoverable for 30 days by default | Microsoft Learn: delete a user |
| A leaver's OneDrive | 30 days default retention, then 93 days in the site collection recycle bin, then permanently deleted | Microsoft Learn: delete a user |
| Files in SharePoint | 93 days from deletion, across the first- and second-stage recycle bins | Microsoft Support: site collection recycle bin |
| Rolling back a whole OneDrive | Files Restore covers the last 30 days | Microsoft Support: restore your OneDrive |
Microsoft also keeps SharePoint backups for 14 days beyond the 93-day window. According to the same support page, Microsoft Support can restore entire site collections from those, but not individual files. That helps after a large accident. It doesn't help if you notice three months later that a single contract folder is missing.
Retention policies in Microsoft Purview can keep content for years. They're built for compliance and eDiscovery, though, not for fast, granular restores of a working environment.
Does Microsoft 365 protect you against ransomware?
Partly. Microsoft blocks a great deal of malware and phishing, and versioning can roll back some encrypted files. If an attacker gets into an account, though, their actions look like the user's own, and native recovery tools sit inside the same tenant they've reached.
The threat is real for organisations of every size. According to the Verizon 2026 Data Breach Investigations Report, as summarised by Help Net Security, ransomware was involved in 48% of breaches analysed, up from 44% the year before. The Microsoft Digital Defense Report 2025 found that at least 52% of attacks with a known motive were driven by extortion or ransomware, and that more than 97% of identity attacks are password attacks.
Attackers also go after recovery options. In a Sophos survey of 2,974 organisations hit by ransomware, 94% said the criminals tried to compromise their backups, and 57% of those attempts succeeded. Organisations whose backups were compromised reported median recovery costs eight times higher.
Microsoft's own ransomware protection guidance for Microsoft 365 lists what you can use natively: 500 file versions by default, a 93-day recycle bin, Files Restore for the last 30 days and single item recovery in Exchange. It's useful. But it all depends on someone noticing in time, and on the attacker not having admin rights to purge it. Read more in our article on Microsoft 365 ransomware recovery.
Is Microsoft 365 Backup enough on its own?
Microsoft 365 Backup, Microsoft's paid add-on, is a real improvement on recycle bins, but it's still a Microsoft service managed from your Microsoft 365 tenant. Whether it's enough depends on how much independence your risk assessment and your auditors expect.
According to Microsoft's Microsoft 365 Backup FAQ, it protects Exchange Online, OneDrive and SharePoint, keeps backups for one year and offers a 10-minute recovery point objective for those workloads. (The recovery point objective, or RPO, is how much recent work you could lose.) Teams isn't listed in the FAQ as a separate workload.
| Question | Native retention | Microsoft 365 Backup | Independent third-party backup |
|---|---|---|---|
| Where does the copy live? | Inside the same service | In Microsoft's cloud | Outside Microsoft, at the backup provider |
| Who controls access? | Your Microsoft 365 admins | Your Microsoft 365 admins | Separate credentials and console |
| How long can you go back? | 14 to 93 days for most items | Up to one year | Set by your backup policy |
| Supplier and jurisdiction | Microsoft | Microsoft | Your choice, for example an EU provider |
| Main limitation | Short windows, no point-in-time restore of a whole tenant | Same vendor and admin plane as the data it protects | Restore speed and scope must be tested |
Microsoft itself recommends evaluating Microsoft 365 Backup or a partner solution in its ransomware guidance. The deciding question is simple to ask: if your tenant or your global admin account were compromised tonight, would your backup still be out of the attacker's reach?
What Microsoft 365 data should you back up yourself?
All four core workloads: Exchange Online, OneDrive, SharePoint and Teams. Leaving one out is the most common gap we see, usually Teams or SharePoint.
- Exchange Online: mailboxes, calendars and contacts. Email is often your record of agreements and decisions.
- OneDrive: each user's working files, including files that only ever existed on one laptop's synced folder.
- SharePoint: team sites and document libraries, where project and customer files tend to live.
- Teams: channel conversations and the files shared in them, which are stored across SharePoint and Exchange.
Pay extra attention to leavers. When you delete a user, their mailbox and OneDrive start a countdown, as the table above shows. A backup taken before deletion means you can still restore a former colleague's files a year later.
Our Microsoft 365 backup covers Exchange, OneDrive, SharePoint and Teams. Backups are stored in our own Tier III data centres in the Netherlands and Germany, kept immutable with Object Lock plus an air-gapped copy, and every backup job is checked automatically. If you're unsure where sync ends and backup begins, see cloud storage vs cloud backup.
How do you check your Microsoft 365 data protection?
Work through five checks. You'll know within an afternoon whether you can recover a deleted mailbox, a SharePoint library or a full user from two months ago.
- List your workloads. Which of Exchange, OneDrive, SharePoint and Teams do you use, and which hold business records?
- Check your current windows. Look up your Exchange deleted item retention and any Purview retention policies. Note what happens after 30 and 93 days.
- Confirm independence. Is there a backup outside your tenant, with separate credentials and multi-factor authentication on admin actions?
- Set targets. Agree how much data you can afford to lose (RPO) and how quickly you need it back (RTO). Our RTO and RPO explainer helps you choose.
- Test a restore. Restore one mailbox and one SharePoint folder from at least 60 days ago, and time it. Our guide on how to verify your backup works covers what to measure.
What to do next
Microsoft 365 doesn't back up your data in a way that survives ransomware, admin mistakes or a deleted account beyond a few weeks. Treat its recycle bins as a convenience and put an independent, immutable and tested backup alongside them.
If you fall under NIS2, this is also a legal point. Article 21(2)(c) of the NIS2 Directive (EU) 2022/2555 lists "business continuity, such as backup management and disaster recovery, and crisis management" among the required measures. See how this fits your wider setup on our backup as a service page.
Want to see a restore of a deleted mailbox and a SharePoint library from an EU data centre? Book a free 15-minute demo. You'll talk to a person, in Dutch, German or English.
This article is information, not legal advice.
Frequently asked questions
Can Microsoft restore my Microsoft 365 data after a ransomware attack?
Only within its native windows. You can use version history, the 93-day SharePoint and OneDrive recycle bins, Files Restore for the last 30 days and Exchange single item recovery. Microsoft Support can restore whole SharePoint site collections for 14 days after the recycle bin window, but not individual files. Anything older, or anything an attacker purged with admin rights, needs an independent backup.
Does OneDrive version history protect against ransomware?
It helps, but it isn't a backup. SharePoint and OneDrive keep 500 versions of a file by default, so you can often roll back an encrypted file. Version history lives in the same service as the file, though. If an attacker deletes files, empties recycle bins or the damage goes unnoticed for months, versions won't bring the data back.
How long does Microsoft 365 keep deleted emails?
Exchange Online keeps deleted mailbox items for 14 days by default, and admins can raise that to a maximum of 30 days. A whole deleted mailbox is recoverable for 30 days by default. After that, items are removed unless a retention policy or litigation hold applies, or you have an independent backup of the mailbox.
What happens to a user's data when I delete their Microsoft 365 account?
You have 30 days to restore the account. The user's OneDrive is kept for a default 30-day retention period, then moves to the site collection recycle bin for 93 days, after which it's permanently deleted. Microsoft advises moving any email you want to keep before deleting the account. Backing up leavers first avoids racing these deadlines.
Do I need a third-party backup for Microsoft 365?
If you need to recover data older than 93 days, restore after an admin-level compromise, or show auditors a copy held outside Microsoft, yes. Microsoft 365 Backup extends retention to one year but stays within Microsoft's service and admin plane. An independent backup with separate credentials and immutable storage covers the scenarios native tools can't.
Sources
- Shared responsibility in the cloudMicrosoft Learn, 2026
- Recoverable Items folder in Exchange OnlineMicrosoft Learn, 2026
- Delete a user from your organizationMicrosoft Learn, 2026
- Restore deleted items from the site collection recycle binMicrosoft Support, 2026
- Restore your OneDrive filesMicrosoft Support, 2026
- Ransomware protection in Microsoft 365Microsoft Learn (Service Assurance), 2025
- Frequently asked questions about Microsoft 365 BackupMicrosoft Learn, 2026
- Lessons for organizations from the Verizon 2026 Data Breach Investigations ReportHelp Net Security (reporting Verizon DBIR 2026), 2026
- Extortion and ransomware drive over half of cyberattacks (Microsoft Digital Defense Report 2025)Microsoft On the Issues, 2025
- The impact of compromised backups on ransomware outcomesSophos, 2024
- Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, 2022


