Skip to main content Scroll Top

Microsoft 365 Is in the Cloud. That Doesn’t Mean Everything Is Backed Up.

One of the most common assumptions I hear about Microsoft 365 goes something like this:

“It’s in the cloud, so Microsoft backs everything up… right?”

Not exactly.

Microsoft 365 is an incredibly resilient platform. Microsoft protects the infrastructure behind Exchange Online, OneDrive, SharePoint and the other services businesses depend on every day.

But cloud availability and data backup aren’t the same thing.

If an employee accidentally deletes an important folder, someone overwrites a critical document, a user account is compromised, or ransomware affects synchronized files, the question isn’t simply whether Microsoft’s cloud is online.

The question is:

Can you recover the version of your data that you need, from the point in time you need it?

That’s a very different conversation.

And it’s one every business using Microsoft 365 should have.

Microsoft Protects Microsoft 365. You Still Need to Think About Your Data.

Let’s start with an important distinction.

When your business moves email and files to Microsoft 365, Microsoft assumes responsibility for operating a highly available cloud platform. Microsoft builds redundancy and resiliency into services such as SharePoint and OneDrive.

But infrastructure resiliency doesn’t eliminate every way a business can lose access to the right copy of its information.

Microsoft itself makes a distinction between disaster-recovery copies and backup. Its Microsoft 365 Backup documentation explains that disaster recovery maintains the current state of content, while backup provides the ability to return data to an earlier healthy state.

That distinction matters.

If Microsoft has your current data perfectly replicated across its infrastructure, but an employee deleted something important last month, replication isn’t necessarily what you need.

You need recovery.

Microsoft 365 app icons displayed on a smartphone

Sync Isn’t Backup Either

Here’s another common misconception.

Your files are in OneDrive.

They’re also synchronized to your computer.

So now you have two copies.

That sounds like a backup.

But consider what synchronization is designed to do.

If you make a legitimate change to a synchronized file, that change should synchronize.

If you delete a synchronized file, that deletion can synchronize too.

And if files become corrupted or maliciously altered, synchronized copies aren’t automatically equivalent to an independent historical backup.

That’s the difference.

Synchronization is designed to keep data synchronized.

Backup is designed to help you recover data when something goes wrong.

Those are related goals, but they aren’t interchangeable.

“But Microsoft Has a Recycle Bin.”

It does, and Microsoft’s built-in recovery capabilities are useful.

For example, Microsoft says deleted SharePoint items are generally retained through its recycle-bin process for 93 days. Microsoft also provides versioning and Files Restore capabilities for SharePoint and OneDrive; Files Restore can restore a document library to a previous point within the past 30 days.

That’s good protection.

But I wouldn’t confuse a recycle bin with a complete backup strategy.

Recycle bins have retention periods. Version history has its own purpose and configuration. Retention policies are designed around information lifecycle and compliance requirements. Microsoft describes retention as preserving copies in locations such as the Preservation Hold library for SharePoint and OneDrive or Recoverable Items for Exchange when configured retention settings apply.

These are valuable Microsoft 365 capabilities.

They just don’t all mean the same thing as “We have a backup.”

What Happens When an Employee Leaves?

This is an area where businesses can get caught by surprise.

An employee leaves.

Their Microsoft 365 account is removed.

Everyone assumes the employee’s OneDrive will just remain there indefinitely because the files were “in the cloud.”

That’s not a safe assumption.

Microsoft currently documents a 30-day default OneDrive retention period for a deleted user, although administrators can configure that period from 30 up to 3,650 days. After the configured retention period, the deleted OneDrive moves through additional deletion and recovery processes.

That’s why employee offboarding shouldn’t simply mean:

Delete account. Done.

Someone needs to understand what information that employee owned, where it lives, who needs continued access to it and what should be preserved.

Good IT management considers the data before the account disappears.

Accidental Deletion Happens

Not every data-loss event involves hackers.

Sometimes somebody deletes the wrong folder.

Sometimes a user cleans up a mailbox a little too aggressively.

Sometimes someone overwrites the spreadsheet that apparently contained the only copy of something important.

Sometimes you don’t realize anything is missing until weeks or months later.

This is where I like to ask businesses a simple question:

How far back would you need to go?

Yesterday?

Last week?

Three months?

A year?

The answer is different for every organization and sometimes different for different types of information.

A backup strategy should be built around the answer, not around the assumption that because something is stored online, it will always be recoverable.

Then There’s Ransomware

Moving files into Microsoft 365 doesn’t make ransomware irrelevant.

Modern ransomware incidents can involve more than encrypting a single computer. Compromised credentials, malicious activity and synchronized changes can create much larger problems.

Microsoft provides built-in recovery mechanisms that can help in ransomware scenarios, including version history, recycle bins and Files Restore.

Those capabilities are important.

But at GC Network Solutions, I prefer thinking in layers.

Endpoint security is one layer.

Email security is another.

Multi-factor authentication is another.

Patching matters.

Monitoring matters.

And recovery matters.

The goal isn’t to find one security product that magically makes every other precaution unnecessary.

The goal is to make sure that if one layer fails, the next layer is still there.

Backup belongs in that conversation.

Retention and Backup Solve Different Problems

This distinction is especially important for businesses with regulatory, legal or contractual requirements.

A retention policy answers questions such as:

What information must we preserve, and for how long?

A backup strategy answers questions such as:

Something happened to our data. How do we get the right data back?

There can be overlap between the two, but they aren’t automatically interchangeable.

Microsoft’s retention tools can preserve content subject to configured policies, including copies of changed or deleted content in protected locations.

That’s extremely useful for governance and compliance.

But a business still needs to decide what its actual recovery requirements are.

Microsoft Offers Backup Too

There’s another reason the old “Microsoft 365 doesn’t need backup” argument has become harder to defend:

Microsoft itself now offers Microsoft 365 Backup.

Microsoft 365 Backup can protect selected or all Exchange mailboxes, OneDrive accounts and SharePoint sites, with recovery capabilities designed for scenarios including accidental or malicious deletion and ransomware.

There are also third-party Microsoft 365 backup platforms.

The important question isn’t necessarily whether the word Microsoft or another vendor’s name appears on the product.

The important questions are things like:

What are we protecting?

How often?

How long are backups retained?

How quickly can we restore?

Can we recover an individual email?

An entire mailbox?

A OneDrive?

A SharePoint site?

What happens when an employee leaves?

And perhaps most importantly:

Has anyone actually verified that the backups are working?

Because a backup you’ve never tested is mostly a promise.

Backup Is About More Than Having Another Copy

This is something I’ve learned repeatedly in IT.

Having data somewhere is one thing.

Being able to recover it when the business needs it is another.

A good Microsoft 365 backup strategy should make recovery predictable.

If someone deletes an important email, we should understand how we would recover it.

If a folder disappears from OneDrive, we should understand our recovery options.

If a SharePoint site is damaged or altered, there should be a plan.

If an account is compromised, we should know what clean recovery points are available.

And if an employee leaves the company, their important business information shouldn’t disappear simply because nobody thought about it during offboarding.

That’s what backup is really about.

Not checking a box.

Being prepared to recover.

“We’re in the Cloud” Isn’t a Backup Strategy

Moving to Microsoft 365 solves a lot of problems.

It gives businesses access to enterprise-grade cloud infrastructure, collaboration, email, file sharing and security capabilities that would have been far more difficult for a small business to build on its own.

I’m a big believer in the cloud when it makes sense.

But I don’t like assumptions when it comes to data.

“Microsoft probably has it somewhere” isn’t a recovery plan.

Know what’s protected.

Know how long it’s protected.

Know what can be restored.

Know how you would restore it.

And test it before the day you actually need it.

That’s preventative IT.

Because the best time to discover a gap in your backup strategy is before you lose something important.

Protecting Your Microsoft 365 Data

GC Network Solutions helps businesses in Cobb County and throughout Metro Atlanta manage and protect Microsoft 365 environments, including email, security, user management, data protection and backup.

If your business uses Microsoft 365 but you’re not sure exactly what would happen if important email, OneDrive files or SharePoint data disappeared, that’s a question worth answering now.

Frequently Asked Questions About Microsoft 365 Backup

Microsoft 365 includes extensive built-in data protection, redundancy, retention, versioning, and recovery capabilities. Microsoft also offers a separate service called Microsoft 365 Backup. However, simply storing email and files in Microsoft 365 doesn’t automatically mean your business has the backup retention and recovery capabilities it needs.

No. OneDrive is primarily a cloud storage, synchronization, and collaboration service. When you change or delete synchronized files, those changes can be synchronized across your devices as well.

OneDrive does provide useful recovery features such as version history, recycle bins, and Files Restore, but synchronization itself should not be confused with an independent backup strategy.

It depends on the Microsoft 365 service and your organization’s configuration. For example, deleted SharePoint and OneDrive items generally remain in the recycle-bin system for up to 93 days, while other Microsoft 365 services have different retention and recovery mechanisms.

Microsoft 365 includes security and recovery capabilities that can help protect against and recover from ransomware, including version history, recycle bins, retention features, and other security controls.

But ransomware protection should be approached in layers. Endpoint security, email security, MFA, patching, monitoring, user awareness, and reliable backups all play a role. No single security feature should be expected to provide complete protection.

That depends on the business’s recovery requirements, retention needs, compliance obligations, and tolerance for data loss.

A business should determine how far back it may need to recover email and files, how quickly information needs to be restored, what happens to data when employees leave, and whether its existing Microsoft 365 protections satisfy those requirements. If they don’t, an additional Microsoft 365 backup solution may be appropriate.

Retention is primarily concerned with preserving information for a defined period, often for business, legal, regulatory, or compliance purposes.

Backup is primarily concerned with recovery—being able to restore data after accidental deletion, corruption, malicious activity, or another data-loss event.

Both can be important parts of a business’s data-protection strategy, but they solve different problems.

For many businesses, the most important Microsoft 365 data includes Exchange Online email, OneDrive files, and SharePoint data. What needs protection ultimately depends on where the organization stores critical business information and how that information is used.

A good starting point is simple: If losing it would disrupt your business, you should know exactly how you would recover it.

author avatar
Gustavo Centeio
Recent Posts