Microsoft 365 Backup
Microsoft keeps the service running. Keeping your data is your job.
This is the most consequential misunderstanding in cloud computing, and it is close to universal. Microsoft's responsibility is that the platform is available. Yours is the data inside it. Their own shared responsibility model says so, and most organizations have never read it.
What replication protects against, and what it does not
Microsoft replicates data across multiple datacentres. If hardware fails, or an entire facility is lost, your mail and files remain available. That is genuine, valuable protection and it is far better than most organizations achieved on their own.
It protects against Microsoft's infrastructure failing. It does not protect against anything originating inside your tenant, which is where essentially all real data loss comes from.
A file deleted by mistake is replicated as deleted. A mailbox emptied by a departing employee is replicated as empty. A retention policy that removed three years of content did exactly what it was configured to do, faithfully, everywhere. Replication is not a time machine; it is a copy of the current state.
The recovery windows most people assume are longer
Native recovery features exist and are useful. They are also time limited, and the limits are shorter than the situations that require them.
The pattern is consistent. Nobody discovers a missing folder the same afternoon. They discover it when a client asks about a job from two years ago, or when a dispute requires correspondence nobody has looked at since.
What actually causes loss in a tenant
- Ordinary human error
- Somebody deletes the wrong folder, or empties a mailbox while tidying up. The most common cause by a wide margin, and the most easily recovered if a backup exists.
- Departing employees
- Content removed deliberately or accidentally around a departure, frequently noticed weeks later when somebody needs it and the licence has already been reclaimed.
- Ransomware reaching synchronised files
- Encrypted local files synchronise upward. Version history helps if it is within the retention window and if the versions themselves were not exhausted by the encryption process.
- Retention policy acting as configured
- A policy applied to meet a compliance requirement removes content permanently. It is not a fault and there is nothing to appeal to; the content is gone because the organization asked for it to be.
- A compromised administrator account
- An attacker with administrative access can delete at scale and disable the native protections while doing so. An independent backup is the only thing outside their reach.
What to look for in a backup arrangement
| Requirement | Why it matters |
|---|---|
| Covers mail, files, sites and chat | Loss is not confined to one workload |
| Retention you choose | Discovery is often years later |
| Granular restore | Recovering one item, not a whole tenant |
| Stored separately from the tenant | Beyond reach of a compromised admin |
| Restores actually tested | An untested backup is an assumption |
That last row is the one most often skipped. A backup nobody has restored from is a belief rather than a control, and the moment of discovery is invariably the worst possible one.
Who needs this, which is very nearly everybody
Any organization whose mail and documents matter to its operation, which is effectively all of them. The cost per user is small, the exposure is total, and the decision is usually deferred only because the risk is invisible until it is realised.
The honest exception is an organization holding genuinely nothing of lasting value in its tenant, which is rare enough to be worth testing rather than assuming. The useful question is what would happen if the last three years of correspondence disappeared tonight.
Read the shared responsibility model once
It is short, it is published by Microsoft, and it says plainly that your data is your responsibility. Most organizations that read it arrange a backup the same week.
Review Your Tenant BackupGet in touch with Your Company
Questions about this solution? Reach us directly.