Does Microsoft 365 back up your data? What Microsoft actually covers
Microsoft 365 protects your information in several ways, but they solve different problems. Microsoft operates the infrastructure and builds resilience into its services. Exchange Online has deleted-item recovery, SharePoint and OneDrive have recycle bins and version history, and Microsoft Purview can retain content under configured policies. None of those, on its own, guarantees that you can restore everything your business needs after any incident.
Service resilience keeps the platform running through infrastructure failures. It does not necessarily undo a valid but damaging action, such as an administrator deleting an account or a compromised user overwriting shared files. Synchronisation is not backup either: a deletion or corrupted file can synchronise across devices.
For an NZ business owner, the useful question is not simply whether Microsoft keeps copies. It is whether you can recover the right information, from the right date, within an acceptable time. That requires checking what is protected, how long recovery remains possible and who can perform the restore.
What the built-in recovery tools actually cover
Microsoft 365 includes useful recovery tools. For a recently deleted document or an accidentally changed spreadsheet, they may be all you need. However, each workload has its own rules; there is no single recovery window covering the whole tenant.
These are common recovery arrangements, not a guarantee of your tenant’s configuration. Have your IT provider verify the settings and demonstrate a restore.
- Exchange Online: items removed from Deleted Items normally enter Recoverable Items. The default deleted-item retention period is 14 days and can be increased to 30 days. Recovery after a user purges an item depends on settings such as single item recovery and any applicable holds or retention policies.
- SharePoint and OneDrive: deleted items generally remain recoverable through the recycle-bin stages for 93 days from the original deletion. The second-stage bin does not restart that clock. Authorised users can also empty recycle bins before the period expires.
- File versions and rollback: version history can recover earlier file content where versions remain available. OneDrive restore and shared-library restore can roll back supported changes within the previous 30 days, subject to prerequisites and limitations. These are not whole-tenant point-in-time restores.
Why retention is not the same as backup
Retention policies and labels are designed to keep or delete information according to governance requirements. A correctly configured policy can preserve content even when a user changes or deletes it. That is valuable for investigations, records management and legal obligations, but it does not automatically provide a straightforward operational restore.
For example, retaining a document for seven years does not mean you can rebuild its entire SharePoint site exactly as it looked on a particular Tuesday. Finding and exporting retained material is different from restoring folder structure, permissions and working access for staff. Capabilities vary by workload and licence.
Retention also needs deliberate management. Policies must cover the right locations and users, and some are configured to delete content when the retention period ends. Keeping everything forever is not a substitute for deciding what the business needs.
Ask for separate retention and recovery policies. The first should define what information must be kept and why. The second should define which data and working structures must be restored, how far back recovery must reach and how quickly it must happen.
Where the gaps become business problems
The largest gap is often the time between a mistake and its discovery. A team might notice missing project files months after a restructure, when ordinary recycle-bin recovery is no longer available. Another gap is scale: restoring one email is very different from recovering thousands of files while staff cannot work.
Identity and access also matter. If the same compromised administrator can damage production data and remove its recovery copies, the business has a concentration of risk. A backup should reduce that risk through separate controls, rather than simply create another console using the same unrestricted credentials.
Use specific scenarios to test your current arrangements:
- A departing employee’s account is deleted, and important correspondence is requested six months later. What preserves the mailbox, OneDrive files and ownership information?
- Ransomware encrypts synchronised files across several document libraries. Can you identify a clean recovery point and restore the affected scope?
- A staff member overwrites a critical workbook, but nobody notices until the next quarterly review. Are the necessary versions still available?
- An administrator makes a destructive change. Can another authorised person recover the data without relying entirely on the affected account?
What a separate backup should add
A third-party backup should provide recovery points and retention that are not tied to the ordinary recycle-bin lifecycle. It should also give your business a practical way to find and restore individual items or larger collections. Do not assume every product backs up every Microsoft 365 service.
Teams is a useful test. Channel files typically live in SharePoint, while files shared in chats may live in OneDrive. Messages, membership, private channels and application data involve different coverage considerations. A product labelled ‘Teams backup’ needs a detailed explanation of what it can actually restore.
Microsoft also offers Microsoft 365 Backup as a separately charged service, with partner-delivered options available. It is distinct from standard retention and recycle bins. Compare its current coverage and recovery model with third-party products; choose based on your requirements, not simply whether the supplier is Microsoft.
- Coverage: confirm support for mailboxes, shared mailboxes, archives, SharePoint, OneDrive and the Teams components you use.
- Recovery: check backup frequency, retention, search, bulk restores, alternate-location restores and preservation of metadata and permissions.
- Isolation: ask who can delete backups, whether immutable retention is available, and how administrator access is protected.
- NZ requirements: confirm storage locations, overseas processing, contractual safeguards and alignment with your Privacy Act obligations.
How to make the decision and keep it working
Start with a short recovery workshop involving the business owner, operations lead and IT provider. List the information that would stop invoicing, customer service or delivery if it disappeared. For each workload, agree how much recent work you could afford to lose and how long you could tolerate being without it. Those targets should drive backup frequency and restore planning.
Request a written coverage map showing native Microsoft recovery, configured retention and any separate backup. Include leavers, newly created sites, shared mailboxes and exclusions. Then commission a restore test using representative data. Check that files open, messages are usable and restored access is appropriate; a successful backup job alone proves none of those things.
Assign responsibility for monitoring failures, updating coverage and testing recovery regularly. If CoreTech manages your environment, make backup alerts, help desk escalation and after-hours recovery responsibilities explicit within the service scope. A 24/7 NOC or SOC can support response, but monitoring does not replace recoverable copies. The decision is complete only when someone owns the recovery process and has demonstrated that it works.
Want this handled for you?
CoreTech provides 24/7 monitoring, security operations and help desk support for businesses across Auckland and New Zealand.