
No, not in the way most people assume. Microsoft 365 keeps its infrastructure running and gives you short, limited windows to undelete things yourself, but it isn't a backup in the traditional sense. If a staff member permanently deletes a folder, ransomware encrypts a OneDrive library, or an admin account gets compromised and wipes a mailbox, Microsoft's own terms are clear that recovering that data is largely your responsibility, not theirs. This trips up a lot of otherwise well-run Perth businesses, because "it's in the cloud" quietly gets translated into "it's backed up."
The shared responsibility model, in plain terms
Microsoft draws a firm line around what it covers. It guarantees the platform: uptime, physical security of its data centres, patching the underlying servers, and keeping Exchange, SharePoint and OneDrive available. That's a genuinely strong guarantee, backed by a published 99.9% uptime SLA.
What it doesn't guarantee is your data staying intact and recoverable no matter what happens to it. Accidental deletion, a disgruntled employee clearing out files on the way out, a phishing-driven account takeover, or ransomware that syncs encrypted files into OneDrive: all of that falls on the customer's side of the line under Microsoft's shared responsibility model. Microsoft protects the building. You're still responsible for what's inside it.
Where the retention windows run out
Even the built-in undo tools have hard limits, and they're shorter than most people expect:
Exchange Online (email): deleted items sit in the Recoverable Items folder for 14 days by default, and an admin can extend that to a maximum of 30 days. After that, it's gone.
SharePoint and OneDrive (files): deleted items move through a two-stage recycle bin with a combined 93-day limit, then they're purged for good.
A deleted user account: by default, that person's OneDrive is kept for a set period before it moves into the site recycle bin on the same 93-day clock, after which it's unrecoverable through the admin centre.
Thirty and ninety-three days sound like plenty until you picture the actual failure modes. Ransomware that sits dormant for weeks before triggering. A departing employee's account that gets deleted during a busy month and isn't needed again until a client dispute surfaces four months later. A "quick clean-up" of an old project folder that turns out to have mattered. Once a retention window closes, Microsoft has no further copy to hand back, and neither do you unless you built one.
If any of that sounds close to home, our guide on safely offboarding an employee covers how to avoid the account-deletion version of this problem specifically.
Why this matters more with ransomware
We've written before about what actually happens when ransomware, malware and scammers target a business, and recovery almost always comes down to one question: do you have a clean, point-in-time copy of your data from before the attack started? Modern ransomware doesn't always announce itself immediately. It can sit quietly, spreading through synced files and shared drives, before it ever encrypts anything visibly. By the time you notice, the "good" version of a file may already be outside Exchange's 30-day window or SharePoint's 93-day one, especially for anything that was touched and re-saved during that dormant period.
Microsoft 365's native tools also aren't designed to isolate a backup from the tenant they're protecting. If an attacker gets hold of Global Admin credentials, which is exactly what phishing and credential-stuffing attacks are after, they can disable retention policies, purge the recycle bin, or delete mailboxes outright. A backup that lives inside the same tenant it's meant to protect isn't much of a safety net against that scenario.
What a real backup needs that Microsoft 365 doesn't provide
Independence from the tenant. Backups should sit outside Microsoft 365's own admin boundary, so a compromised admin account can't touch them.
Retention on your terms, not Microsoft's. Weeks, months or years, set by your business's needs (and, in regulated industries like legal or accounting, often by compliance requirements), not a fixed 14 to 93-day ceiling.
Point-in-time restore. The ability to roll a mailbox, site or OneDrive back to exactly how it looked at 8am yesterday, not just recover the last version of one file.
Coverage across Exchange, SharePoint, OneDrive and Teams. Teams chat and channel data in particular is easy to overlook and isn't meaningfully covered by the recycle bin approach at all.
This is standard practice for a properly run backup and disaster recovery setup, and it's a relatively small, predictable monthly cost next to the alternative of trying to reconstruct months of email and files from nothing.
What to check this week
Ask whoever manages your Microsoft 365 tenant whether a third-party backup product is running against it, separate from the built-in recycle bin and retention policies.
Check what the retention period on that backup actually is, and whether it covers Teams as well as email and files.
Confirm backups are tested, not just running. A backup nobody has ever restored from is a theory, not a plan.
If the answer to any of that is "not sure," treat it the same as a "no" until it's confirmed.
Microsoft 365 is a solid, well-run platform, and none of this is a knock on it. It just isn't a backup product, and it was never marketed as one. Knowing where Microsoft's responsibility ends and yours begins is the difference between a bad week and a genuine crisis.
If you'd like us to check what's actually protecting your Microsoft 365 data, get in touch and we'll give you a straight answer.



