Does Microsoft 365 back up your data? The gap most SMBs miss
Microsoft keeps the service running, but recovering your email and files is your responsibility. What the shared responsibility model really means, where the built-in retention runs out, and how to close the gap.
Here is a question worth sitting with for a minute: if an employee deleted a year's worth of email this morning, or a file in SharePoint was quietly encrypted by ransomware and nobody noticed for two months, could you get it back? Most business owners assume the answer is yes, because the data lives in Microsoft's cloud and Microsoft is a very large company. That assumption is where a lot of Israeli SMBs get caught out. Microsoft 365 is reliable, but reliability and backup are not the same thing, and the difference tends to become clear at the worst possible moment.
What Microsoft actually protects, and what it does not
Microsoft runs Microsoft 365 on a shared responsibility model, and it is written down plainly in their agreements. Microsoft's job is to keep the platform running: the data centres, the uptime, the physical infrastructure, and protecting the service from outages. Your data inside that service, the email in Exchange, the files in SharePoint and OneDrive, the conversations and files in Teams, is your responsibility to retain and recover. Microsoft even recommends in its service agreement that customers keep their own backup of the content they store. The replication Microsoft does run protects against a data centre failing on their side. It does not protect against your employee deleting the wrong folder, a departing staff member's mailbox being wiped, or ransomware reaching your files through a compromised account.
Where the built-in retention runs out
Microsoft 365 does have some recovery built in, and for small mistakes it is often enough. Deleted items in Exchange Online are kept for 30 days by default. The recycle bin in SharePoint and OneDrive holds deleted files for 93 days, in two stages. These are genuinely useful for the everyday 'I deleted it by accident yesterday' situation. The trouble is that they are short windows, they are not designed as a backup, and they can be emptied or bypassed. If a problem is discovered after those windows close, and data loss often is, the item is generally gone. There is no dashboard where you can roll a mailbox or a document library back to how it looked on a specific date last quarter.
The four ways SMBs actually lose Microsoft 365 data
In practice, the losses we see fall into a handful of patterns. The first is simple human error: someone deletes a folder, overwrites a shared spreadsheet, or clears out a mailbox to free space, and realises weeks later. The second is a departing employee, where an account is removed and its mailbox and OneDrive go with it, taking client history nobody thought to keep. The third is malicious or compromised activity, including ransomware that encrypts files through a hijacked account and business email compromise where an attacker deliberately deletes evidence of what they did. The fourth is misconfiguration, such as a retention or sync setting that quietly removes data that turns out to matter. None of these are covered well by a 30 or 93 day recycle bin.
Retention policies are not a backup
This is the point that trips up even technically minded people. Microsoft 365 offers retention policies and retention labels, and licences like Business Premium include real compliance tooling. Those features are valuable, but they are built for legal hold and compliance, keeping certain data for a set period so it cannot be permanently destroyed, rather than for restoring your environment to a working state. A retention policy can stop data being purged, but it does not give you a clean, point-in-time copy you can browse and restore from after an incident. Treating retention as a backup is one of the more common and more expensive misunderstandings we come across, because it feels like protection right up until you try to recover and find the tooling was never meant for that job.
What a real Microsoft 365 backup looks like
A proper backup for Microsoft 365 is an independent, scheduled copy of your Exchange, SharePoint, OneDrive, and Teams data, stored separately from the Microsoft 365 tenant itself and kept for as long as your business needs it. The important properties are the same ones that matter for any backup. It should be automatic, so it does not depend on anyone remembering. It should let you restore granularly, a single email or file, not just an all-or-nothing rollback. It should retain data long enough to cover a loss that is discovered months later. And the backup itself should be protected: kept where a compromised Microsoft 365 account cannot reach and delete it, and locked behind multi-factor authentication so an attacker who gets into your tenant cannot also wipe the safety net. Immutable copies, which cannot be altered or deleted for a set period, are what turn a backup from a target into a genuine fallback.
How long to keep it, and roughly what it costs
Two practical questions come up as soon as a business decides to back up Microsoft 365: how far back should the copies go, and what does it cost. Retention length is a business decision more than a technical one. Some Israeli SMBs are comfortable with a year, while law firms, clinics, and finance offices often want several years or indefinite retention because of how long client files and correspondence stay relevant. The point is that you choose it, rather than inheriting Microsoft's 30 and 93 day defaults by accident. Cost tends to surprise people in a good way. Microsoft 365 backup for a small team is usually a modest per-user monthly figure, far less than the cost of a single serious data-loss incident, and it is one of the few security investments where the value is easy to see the first time you use it. It also scales cleanly as you add staff, so it does not become a project to revisit every year. The mistake is not the price. It is discovering, mid-incident, that nobody had set it up.
Where backup fits alongside your other defences
Backup is the last line, not the first. It matters most precisely because the earlier lines sometimes fail, so the two belong together rather than as alternatives. Enforcing multi-factor authentication, tightening admin roles, and configuring Defender the way our Microsoft 365 security checklist lays out reduces the chance of an account being taken over in the first place. A properly managed firewall and endpoint protection cut down the paths ransomware uses to reach your data. And an independent backup means that when something does slip through, whether that is a mistaken deletion or a ransomware event, recovery does not depend on the attacker, on Microsoft's short retention windows, or on luck. The same 3-2-1 thinking that protects your on-premises server, keeping isolated and tested copies, applies to your cloud data too.
A simple way to check where you stand
You do not need a full audit to get a first answer. Ask three questions. If a mailbox were deleted today, how far back could we restore it, and who would do it? If a SharePoint library were encrypted by ransomware and we found out in three months, could we recover a clean version? And is anything currently copying our Microsoft 365 data somewhere Microsoft does not control? If the answers are unclear, there is a gap worth closing, and it is usually a straightforward and affordable one to fix. NetFortress sets up and monitors Microsoft 365 backup for Israeli SMBs, with tested restores and retention matched to how your business actually works. Ask us for a review and we will tell you plainly what today's setup would and would not get back.
Frequently asked questions
Does Microsoft back up my Microsoft 365 data?
Not in the way most people assume. Microsoft runs a shared responsibility model: it keeps the platform and service available, but retaining and recovering your actual data, the email, files, and Teams content, is your responsibility. Microsoft's own service agreement recommends that customers keep a separate backup of what they store.
Isn't the recycle bin or deleted items folder enough?
Only for small, recent mistakes. Exchange Online keeps deleted items for 30 days by default, and the SharePoint and OneDrive recycle bins hold files for 93 days. Those are short windows, they can be emptied or bypassed, and they were never designed as a backup. If a loss is discovered after them, the data is usually gone.
Aren't retention policies the same as a backup?
No, and this is a common and costly mix-up. Retention policies and labels are built for compliance and legal hold, keeping certain data so it cannot be permanently destroyed. They do not give you a clean, point-in-time copy you can browse and restore from after an incident. They stop deletion; they do not restore your environment to a working state.
How does a Microsoft 365 backup protect against ransomware?
Ransomware can reach your cloud files through a compromised account and encrypt them, and it may also delete backups it can find. A proper Microsoft 365 backup keeps an independent copy outside the tenant, protected by MFA and ideally immutable, so a compromised account cannot reach and wipe it. That is what lets you recover a clean version without depending on the attacker.
What should a Microsoft 365 backup actually cover?
Exchange (email), SharePoint and OneDrive (files), and Teams. It should run automatically, allow granular restore of a single email or file rather than all-or-nothing, retain data long enough to cover a loss found months later, and be stored separately from your Microsoft 365 tenant with its own access controls.
We have Microsoft 365 Business Premium. Do we still need backup?
Yes. Business Premium adds strong security and compliance tooling, which reduces the chance of an incident, but it still follows the shared responsibility model and does not provide a full third-party backup. The two work together: better security lowers the risk, and an independent backup means you can still recover when something slips through.
Related articles
The 3-2-1 backup rule: protecting your business from data loss and ransomware
Why most SMB backups fail exactly when they are needed most – and how the 3-2-1 rule keeps your business running after ransomware, hardware failure, or human error.
Read articleWhy ransomware hits small businesses – and what to fix first
The common weak points attackers exploit and the first protections SMBs should prioritize.
Read articleThe day an employee leaves: a secure off-boarding checklist for Israeli SMBs
Hiring gets a process. Leaving often does not, and the forgotten account is where the risk sits. A practical checklist for cutting off access cleanly when someone moves on.
Read articleRelated services
Cloud Services / Microsoft 365
Microsoft 365 setup, identity security, permissions review, and secure configuration for the cloud environment your business runs on.
Learn moreManaged Cybersecurity
Security controls, risk reduction, and practical protection against the attack paths that affect Israeli SMBs most.
Learn moreReady to secure your business without building an internal IT team?
Book a free consultation and get a practical first look at your IT and Microsoft 365 security posture.