Skip to content

NIS2

What is the Microsoft 365 shared responsibility model?

Microsoft runs the platform; you own the data, the accounts and the proof that you can recover. Here is where the line sits, and what NIS2 and the GDPR expect on your side of it.

Boardroom table split by cyan light: server hardware on the far side, a laptop, security key and files nearby

The short answer

The Microsoft 365 shared responsibility model splits security duties between Microsoft and you. Microsoft secures the data centres, network, hosts and service availability. You always remain responsible for your data, user accounts, access management and devices. That includes backing up your data and proving you can restore it, which NIS2 and the GDPR both expect.

Key takeaways

  • Microsoft's documentation lists four responsibilities you always keep, in every cloud model: your data, endpoints, accounts and access management.
  • Replication is part of Microsoft's side and protects availability; it copies deletions and encryption, so it isn't a backup.
  • NIS2 Article 21(2)(c) requires backup management and disaster recovery, and Article 20 makes management bodies accountable for approving these measures.
  • GDPR Article 32(1)(c) requires the ability to restore personal data in a timely manner, and point (d) requires regular testing of that ability.
  • Covering your side means hardened identities, an independent tested backup, a leaver process and documented evidence.

What does the shared responsibility model say?

It says Microsoft is responsible for the cloud and you're responsible for what you put in it and who can reach it. Microsoft publishes this split for all its cloud services, including Microsoft 365.

According to Microsoft's page on shared responsibility in the cloud, whatever the deployment type, "you always retain" responsibility for your data (including data protection), your endpoints, your accounts and your access management. In a SaaS service such as Microsoft 365, Microsoft takes over the physical data centre, physical network, physical hosts, operating system and network controls. Applications and client devices are shared.

For organisations under NIS2, this matters because the law asks you to manage the risks on your side, not Microsoft's. We set out the full obligations on our NIS2 compliance page. This article focuses on what the model means for your Microsoft 365 data.

Who is responsible for what in Microsoft 365?

Microsoft owns the infrastructure and keeps the service available. You own configuration, identities, data and recovery.

LayerMicrosoftYou
Physical data centres, hardware and networkResponsibleNot responsible
Operating system and service availabilityResponsibleNot responsible
Application configuration (sharing, retention, security settings)Provides the controlsConfigures and maintains them
Accounts and identities, including leaversProvides Microsoft Entra IDCreates, secures and removes accounts
Access management (MFA, conditional access, admin roles)Provides the toolsDecides and enforces policy
Endpoints that access Microsoft 365Offers management toolingProtects and manages devices
Your data: email, files, sites, chatsStores and replicates itClassifies, protects, backs up and restores it
Regulatory obligations (NIS2, GDPR)Acts as a processor under contractRemains accountable as the entity or controller

The table follows Microsoft's published split. The ransomware guidance for Microsoft 365 frames it similarly, separating "tenant level controls", described as "the people in your organization and the infrastructure and services that your organization owns and controls", from Microsoft's service-level controls, as set out in Ransomware protection in Microsoft 365.

Doesn't Microsoft's replication protect my data?

It protects the service from hardware failure, not your data from changes. Replication copies deletions, overwrites and encryption to every replica.

Microsoft's Azure Storage redundancy documentation says so directly: "deletions and overwrites are applied to all copies simultaneously. Redundancy protects against hardware failure, not against data-modifying operations." Even the Microsoft Services Agreement, which covers consumer services rather than business tenants, tells users: "We recommend that you regularly backup Your Content and Data that you store on the Services."

Native recycle bins and version history are useful but short-lived. When you delete a user, for example, Microsoft's own admin documentation gives you 30 days to restore the account, after which a leaver's OneDrive spends 93 days in the recycle bin and is then permanently deleted. For the full list of native windows, see does Microsoft 365 back up my data?

How does the shared responsibility model map to NIS2 and the GDPR?

Both laws place the obligation on you, not on your cloud provider. Using Microsoft 365 doesn't move your NIS2 or GDPR duties to Microsoft; it makes Microsoft one of the suppliers whose risks you manage.

Your side of the modelLegal hookEvidence an auditor may ask for
Backup and recovery of Microsoft 365 dataNIS2 Art. 21(2)(c): business continuity, such as backup management and disaster recovery; GDPR Art. 32(1)(c)Backup policy, job reports, restore test results
Testing that recovery worksGDPR Art. 32(1)(d): regular testing, assessing and evaluatingDated test restores against RTO and RPO
Assessing Microsoft and other suppliersNIS2 Art. 21(2)(d): supply chain securitySupplier risk assessment, contracts, exit plan
Accounts, access and MFANIS2 Art. 21(2)(i) and (j): access control and multi-factor authenticationConditional access policies, admin role reviews
Management oversightNIS2 Art. 20: management bodies approve measures, oversee them and follow trainingBoard minutes, training records
Incident reportingNIS2 Art. 23: early warning in 24 hours, notification in 72 hours, final report in one monthIncident procedure and contact list

The NIS2 references are to Directive (EU) 2022/2555 and the GDPR references to Regulation (EU) 2016/679. In the Netherlands the NIS2 rules apply through the Cyberbeveiligingswet, in force since 15 August 2026, according to the Dutch government. Germany's NIS2UmsuCG has applied since 6 December 2025, as the BSI announced. See our breakdown of the ten Article 21 measures.

What goes wrong when the model is misread?

Data disappears through normal-looking actions that Microsoft's platform carries out exactly as instructed. The service stays available while the data is lost.

  • Leaver clean-ups: an account is deleted, the retention windows pass, and contracts or correspondence go with it.
  • Bulk mistakes: a sync tool, script or retention policy change deletes or overwrites a large set of files.
  • Insiders: a departing employee empties a mailbox or a SharePoint library.
  • Compromised accounts: an attacker with valid credentials encrypts synced files or, with admin rights, deletes data and shortens retention.

The last point is the one that's growing. The Microsoft Digital Defense Report 2025 found that identity-based attacks rose by 32% in the first half of 2025 and that at least 52% of attacks with a known motive were driven by extortion or ransomware. The same report says MFA can block over 99% of identity-based attacks, which is why access management sits on your side of the line.

How do you cover your side of the model?

Six steps cover most of it. Each one produces evidence you can show an auditor or insurer.

  1. Map your data. List what lives in Exchange, OneDrive, SharePoint and Teams, and which records you must keep and for how long.
  2. Harden identities. Enforce MFA for everyone, limit global admins and review admin roles regularly.
  3. Back up independently. Keep a copy outside your tenant, with separate credentials. Our Microsoft 365 backup covers Exchange, OneDrive, SharePoint and Teams, stores data immutably in our own data centres in the Netherlands and Germany and requires MFA for admin actions.
  4. Fix the leaver process. Make sure a backup exists before any account is deleted.
  5. Assess suppliers. Treat Microsoft and your backup provider as part of your supply chain. Our guide to NIS2 supply chain security explains how.
  6. Test and document. Run test restores at least quarterly and keep the results.

The same split applies in public cloud. If you also run workloads in AWS or Google Cloud, read why AWS data is not a backup yet and Google Cloud's shared responsibility model.

What to do next

The shared responsibility model is not a grey area: Microsoft keeps Microsoft 365 running, and your data, identities and recovery are yours to manage and to prove. Under NIS2 and the GDPR, that proof is part of compliance, not an optional extra.

Start with a clear view of your gaps. Read how this fits the wider obligations on our NIS2 compliance page, or ask us for a free assessment of your Microsoft 365 backup and recovery setup.

This article is information, not legal advice.

Frequently asked questions

Is Microsoft responsible for backing up my Microsoft 365 data?

No. Microsoft's shared responsibility documentation says customers always retain responsibility for their data, including data protection, in every cloud model. Microsoft replicates data to keep the service available and offers short native recovery windows, but an independent backup you can restore from a chosen point in time is your responsibility.

What is the difference between replication and backup in Microsoft 365?

Replication keeps live copies of your data in several places so a hardware failure doesn't interrupt the service. It copies every change, including deletions and encryption. A backup is a separate, point-in-time copy kept apart from production, so you can go back to the state before a mistake or an attack.

Does using Microsoft 365 make me NIS2 compliant?

No. NIS2 obligations apply to your organisation, not to your suppliers on your behalf. Microsoft 365 gives you security tools, but you still have to apply the Article 21 measures, including backup and disaster recovery, access control and supply chain security, and management must approve and oversee them under Article 20.

Who is the controller and who is the processor in Microsoft 365?

In a typical business tenant, your organisation is the controller of the personal data you store, and Microsoft acts as a processor under its data protection terms. As controller you stay accountable under the GDPR, including for Article 32 security measures such as the ability to restore personal data in a timely manner.

Does the shared responsibility model apply to Google Workspace and AWS too?

Yes. Every major cloud provider uses a version of it. The provider secures its infrastructure and keeps the service available; customers remain responsible for their data, identities and configuration. The exact split differs between SaaS services such as Google Workspace and infrastructure services such as AWS, so check each provider's documentation.

Sources

  1. Shared responsibility in the cloudMicrosoft Learn, 2026
  2. Ransomware protection in Microsoft 365Microsoft Learn (Service Assurance), 2025
  3. Data redundancy - Azure StorageMicrosoft Learn, 2026
  4. Microsoft Services Agreement (consumer), section 6(b)Microsoft, 2026
  5. Delete a user from your organizationMicrosoft Learn, 2026
  6. Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, 2022
  7. Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, 2016
  8. Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van krachtRijksoverheid, 2026
  9. Cybersicherheitsrecht: NIS-2-Umsetzungsgesetz ab morgen in KraftBSI, 2025
  10. Extortion and ransomware drive over half of cyberattacks (Microsoft Digital Defense Report 2025)Microsoft On the Issues, 2025
Part ofNIS2 Compliance