No. Microsoft does not back up Microsoft 365 in the way most organisations assume.

Microsoft operates the platform, keeps the service running, and replicates customer data across datacentres for resilience. It does not back up customer data with the intent of restoring it after cyber attack, administrator error or malicious insider activity — Microsoft's own Service Agreement advises customers to regularly back up their content.

See which combination you actually need
Short answer

Microsoft does not back up Microsoft 365 the way most organisations assume. It runs the platform, replicates data for resilience, and provides short-term retention — recycle bins, version history, Purview holds. None of these is the same as an independent backup designed for cyber attacks, compromised admin or long-window recovery. For a defensible position, an independent backup operated outside the Microsoft 365 tenant is what current insurance questionnaires increasingly expect. Microsoft does now offer a separate Microsoft 365 Backup capability for selected workloads; whether it alone meets your requirements depends on independence, credential separation, retention, immutability and restore evidence — not on the word "backup" in the product name.

What each actually covers

Not a vendor argument — a mapping of what each approach is designed to do.

Native features and an independent backup are designed to address different scenarios. Understanding the design intent of each is the first step in understanding which scenarios each covers.

Microsoft native retention
Short-term retention within the tenant, for routine user error
  • Recycle bins and Recoverable Items dumpsters, 14 to 93 days by workload
  • Version history on recent changes, per configured policy
  • Purview retention policies and litigation holds, for compliance
  • Geo-replication across datacentres, for platform resilience
  • Data sits inside the tenant, under administrative control
  • Credentials are the same Microsoft 365 identity an attacker would compromise
  • Large restores constrained by Microsoft Graph API throttling
Covers: user error, short-term
Independent Microsoft 365 backup
A separate recovery copy outside the tenant, for adversarial and long-window recovery
  • Retention in years rather than days, covering late discovery
  • Exchange, OneDrive, SharePoint, Teams and Entra ID objects where supported
  • Stored outside the tenant, on independent infrastructure
  • Backup admin credentials separated from Microsoft 365 identity, independent MFA
  • Immutable storage a compromised global admin cannot modify
  • Granular restore: items, mailboxes, sites or full tenant
  • Dedicated restore APIs and pre-indexed storage, not subject to Graph throttling
Covers: cyber attack, compromised admin, insider activity, long-window recovery, insurance evidence

Retention helps manage lifecycle and deletion windows. Backup is designed for independent recovery. They are not substitutes for each other.

What Microsoft provides

Useful protections against routine user error, with specific windows.

The native features are legitimate protections against routine user error. The specific windows are worth knowing, because the gap between them and a real backup is where the confusion tends to live.

Exchange Online14 days default, up to 30

The Recoverable Items dumpster retains deleted mail for 14 days by default, extendable to 30. A removed mailbox is retained around 30 days. Beyond that, native recovery is not available.

OneDrive30 days plus 93-day recycle bin

A removed user's OneDrive is retained 30 days, then placed in the Site Collection Recycle Bin for an additional 93 days. User-deleted files follow the same two-stage pattern.

SharePoint93 days across two stages

User Recycle Bin then Site Collection Recycle Bin, summing to 93 days for site-deleted items in the typical configuration.

Microsoft TeamsSharePoint-backed, complex

Teams files sit in SharePoint and follow SharePoint retention. Channel messages live in Exchange compliance storage. There is no user-facing Teams recycle bin, and team deletion is time-limited.

Microsoft Purview holdscompliance, not backup

Purview retention policies and litigation holds prevent deletion for legal discovery. Useful for compliance, but not a backup: the data sits in the tenant and is subject to administrative control.

Geo-replicationresilience, not recovery

Microsoft replicates customer data across datacentres for service resilience, protecting against hardware failure and datacentre outages. It replicates encrypted or deleted state as normal; it does not reverse customer actions.

The scenarios that expose the gap

Common loss events native retention is not designed to address.

Each scenario below is common enough that current cyber insurance questionnaires now ask about it specifically. Each is a case where native retention expires, is bypassed, or was never designed to cover the outcome.

01
Accidental deletion discovered beyond the window

A file accidentally deleted 120 days ago in OneDrive or SharePoint is gone. Discovery often lags deletion by months for files that are rarely accessed until they are needed.

02
An attacker encrypting files in OneDrive, SharePoint or Teams

A cyber attack that reaches Microsoft 365 through a compromised session encrypts files. Microsoft's replication copies the encrypted state. Version history helps only if the attack is caught quickly and the attacker has not disabled versioning.

03
Compromised global administrator with time to cause damage

A compromised global admin can delete mailboxes, sites, Teams and OneDrive contents, and modify retention policies to accelerate permanent deletion. Microsoft does not provide a tenant-wide rollback.

04
Malicious insider activity before or during departure

A departing employee with legitimate access can delete mail and files. Native retention assumes the actor is acting in error; deliberate destruction is outside its design intent.

05
Graph API throttling on large restores

Restoring large volumes through the Microsoft Graph API hits throttling limits. A month of email across a hundred mailboxes recovered through eDiscovery can take substantially longer than an incident response timeline accepts.

When each is sufficient

The question is whether the combination matches the risk being carried.

For many Australian organisations, native retention alone is no longer a comfortable recovery position. The boundaries below help locate where current posture sits.

Short-window, user-error recovery is the whole requirement
  • Risk tolerance permits short-window recovery only
  • Data volumes are small and contained to routine user activity
  • No cyber insurance is held, or no questionnaire asks about SaaS backup
  • The organisation has explicitly decided to accept cyber-attack or insider risk to Microsoft 365 data
  • No regulatory or client-driven retention obligations extend beyond native windows
  • Data loss discovered after the native window expires is considered acceptable
Adversarial or long-window coverage is part of the real requirement
  • Risk tolerance requires adversarial and long-window coverage
  • Cyber insurance is held and the questionnaire asks about Microsoft 365 backup specifically
  • Recovery readiness planning requires an evidence layer that proves recovery capability
  • Compliance or contractual obligations require retention beyond native windows
  • Client, employee or financial data is handled, where late-discovered loss is commercially material
  • Compromised admin or malicious insider scenarios are part of the realistic threat model
Where this sits commercially

The question sounds technical. The risk is commercial.

Many current cyber insurance renewal questionnaires now ask more specifically about SaaS data backup, including Microsoft 365 backup, retention period and restore testing. The question is there because the claims history made it necessary.

Questionnaire item

Do you have an independent backup of your Microsoft 365 data?

A "yes" requires a backup operated outside the tenant, under separate credentials. A "yes" that relies on Microsoft's native retention is typically scored as a gap.

Questionnaire item

What is the scope and retention period?

Which workloads, which retention (typically years rather than days), which backup cadence. Vague answers signal misalignment.

Questionnaire item

When was the last documented restore test?

A dated record of a real restore with scope and outcome — the evidence that separates a backup that would work from one that has never been tested.

Questionnaire item

Is the backup admin separate from the Microsoft 365 admin?

Separation with independent MFA. Otherwise a Microsoft 365 admin compromise reaches the backup.

The answer to "does Microsoft back up Microsoft 365?" now carries commercial consequences it did not carry a few years ago. The insurance questionnaire is the practical driver behind the technical question.

Native retention covers a short window. The recovery gap is where late deletions, ransomware and admin compromise land. A short review confirms whether an independent backup covers it.

Check your recovery gap
Inlight IT view

The Inlight IT view on whether Microsoft backs up Microsoft 365.

Whether Microsoft backs up Microsoft 365 in the sense that matters for recovery readiness, insurance renewal or audit response is a question about where the responsibility sits. Microsoft has answered it clearly in the Service Agreement: the customer is responsible. In most Australian mid-sized environments, the practical work is straightforward once the question is understood — independent backup across the relevant workloads, stored outside the tenant, under credentials separated from the Microsoft 365 administrative identity, with immutable storage and dated restore tests. None of this is exotic or disproportionately expensive relative to the cost of a loss event native retention did not cover.

A common pattern: the question was never asked internally until the insurance questionnaire forced it. By that point the renewal was weeks away, the evidence did not exist, and the remediation was compressed under commercial pressure. A structured review at renewal-minus-three-months is materially cheaper than a renewal-minus-three-weeks scramble, and the scope of the review is largely the same. Independent recovery capability is the benefit; the cost of a third-party backup service and the discipline to run it is the trade-off.

A backup that exists is not the same as a recovery path that works. The difference matters most on the day it is tested by an attacker.

Worth checking

If your retention answer is “whatever the defaults are”, your recovery window is shorter than most incidents.

Check your window →
The full Q&A

Direct answers to the questions Australian organisations ask about Microsoft 365 backup.

Does Microsoft back up Microsoft 365?
No, not in the way most organisations assume. Microsoft operates the platform, keeps the service running and replicates customer data across datacentres for resilience. It does not back up customer data with the intent of restoring it after accidental deletion, cyber attack, admin error or malicious insider activity. Microsoft's own Service Agreement directly advises customers to regularly back up their content and data stored in the service.
What does Microsoft provide natively?
Short-term retention across Exchange (14 days default, up to 30), OneDrive and SharePoint (30 days plus 93 in the Site Collection Recycle Bin), and Teams. Version history on recent changes. Litigation holds through Purview for compliance. Geo-replication across datacentres for platform resilience. These are useful protections against routine user error — not a backup in the sense insurers, auditors or recovery plans use the word.
Does Microsoft back up Exchange Online?
No. Deleted Exchange Online mail is retained in the Recoverable Items dumpster for 14 days by default, extendable to 30; a removed mailbox is retained around 30 days. Beyond those windows, native recovery is not available. Microsoft does not maintain an independent backup designed to restore from cyber attacks, compromised admin or malicious deletion. Teams channel messages also live in Exchange compliance storage and follow the same model.
Does Microsoft back up SharePoint and OneDrive?
No. Both use the same two-stage pattern: a 30-day stage then an additional 93 days in the Site Collection Recycle Bin. Version history applies to recent changes per policy. Teams files sit in SharePoint and follow the same windows. Files deleted beyond 123 days are gone from native tools; a cyber attack that encrypts files in the tenant is replicated as encrypted state, not reversed; a compromised global admin can modify retention policies before deletion.
Why is native retention not a backup?
It is designed for short-term recovery from routine user actions, such as a deleted email from yesterday — not for adversarial scenarios such as an attacker encrypting files, a compromised global admin wiping mailboxes, or malicious insider destruction. Retention windows expire, policies can be modified by privileged users, and geo-replication copies encrypted or deleted state rather than reversing it. Each of those gaps is exactly what an independent backup is designed to address.
Do I need third-party Microsoft 365 backup?
For many organisations — particularly those holding cyber insurance, handling client or financial data, or with retention obligations beyond native windows — third-party backup is usually the safer position. The decision depends on risk tolerance, insurance posture, regulatory obligations and the realistic threat model. Where any of those push toward adversarial or long-window scenarios, independent backup is the architectural answer.
Do cyber insurance questionnaires ask about it?
Increasingly, yes. Many current renewal questionnaires ask specifically about SaaS data backup, including Microsoft 365 backup, retention period and restore testing. Underwriters want to know whether an independent backup exists, its coverage scope and retention period, and whether restore testing has been performed with dated evidence. An answer relying on native retention is typically scored as a gap, because the underwriter knows Microsoft does not provide the kind of backup the question asks about.
What about Microsoft 365 Backup (the product)?
Microsoft now offers a Microsoft 365 Backup capability for selected workloads and restore scenarios, creating backups within the protected services' data boundaries. It should still be assessed against your requirements for independence, credential separation, retention, immutability, restore testing, licensing and recovery evidence. The question is not whether "backup" appears in the product name; it is whether the recovery path meets your incident, audit and insurance requirements. For some organisations it closes the immediate gap; for others it sits alongside an independent third-party backup rather than replacing it.
Can Microsoft restore deleted emails after the window?
Generally no. Once the Recoverable Items dumpster window expires (14 days default, up to 30), Microsoft does not maintain a recovery copy that can be restored on request. Litigation holds through Purview can extend retention for specific accounts, but only if the hold was in place before deletion. There is no general post-hoc restore service for routine deletions outside the configured retention windows.
What happens to data after a cyber attack or account compromise?
A cyber attack that reaches Microsoft 365 through a compromised account encrypts files in OneDrive, SharePoint and Teams. Microsoft's replication copies the encrypted state as normal activity. Version history can help if the attack is caught before versions roll over, but discovery often happens after recoverable versions are gone. A compromised global admin can also delete retention policies, modify versioning and remove items permanently. Without an independent backup outside the tenant, recovery is limited to whatever native windows still hold.
What should we check before cyber insurance renewal?
Confirm whether an independent Microsoft 365 backup exists, operated outside the tenant under credentials separated from the Microsoft 365 admin identity. Document the scope (which workloads), the retention period (typically years rather than days), the cadence, and the date and outcome of the last restore test. Underwriters score vague or native-only answers as a gap. Where evidence does not exist, it is materially cheaper to address at renewal-minus-three-months than at renewal-minus-three-weeks — the scope of work is largely the same; the commercial pressure is not.
Practical next step

Close the recovery gap before it closes a claim.

A short review maps what native retention covers against the loss scenarios you actually face, and confirms whether an independent, restore-tested backup is in place where it matters.

Review your backup posture