Does Microsoft 365 back up your data?
Partly, and not in the way most people assume. Microsoft is explicit that data protection is a shared responsibility: they keep the service running, you're responsible for making sure your data survives your own users, your own admins, and an attacker with valid credentials.
What Microsoft does give you
- Recycle bins in OneDrive, SharePoint and Outlook, typically holding deleted items for around 30 days.
- Version history on SharePoint and OneDrive files, though versions get pruned over time.
- Retention and legal hold policies in Purview, if someone has deliberately configured them.
- Microsoft 365 Backup, a paid add-on covering Exchange Online, OneDrive and SharePoint with up to a year of retention.
These are real protections and you should be using them. They are not, by themselves, a backup strategy.
Where the gaps are
The 30-day cliff on leavers
When someone leaves and their licence is removed, the mailbox is typically retained for 30 days before deletion, and OneDrive files for a similar window. If nobody applied a hold, recovering that data afterwards isn't possible. This is the single most common way organisations lose data in Microsoft 365, and it happens quietly.
Retention is not backup
A retention policy governs how long content is kept before deletion. A backup is an independent copy you can restore from a point in time. They solve different problems, and having the first one configured does not mean you have the second.
Teams chat
Teams data is spread across SharePoint, OneDrive and Exchange. Most organisations that back up email leave at least one of those locations out of scope. Native Microsoft 365 Backup does not cover Teams chat messages at all.
The same credentials can delete both copies
If your global admins can delete production data and also purge the soft-deleted copies, you have a single point of failure. Count how many people that is. In most tenants the answer is uncomfortable.
What to do about it
- Find out how much data you actually have, per workload, including archives.
- Work out what protecting it would cost, and what a scoped policy would cost instead.
- Decide deliberately what's in scope rather than accepting a vendor's default.
- Run a real restore test, not a single-mailbox one.