Microsoft 365 doesn't back up your data: Why your business needs its own backup

31 Aug 2026, by Micron21

For most small-to-medium businesses (SMBs) today, Microsoft 365 (and its close cousin, Google Workspace) has quietly become the place where large parts of their business lives.  Email, documents, spreadsheets, shared drives, Teams chats, SharePoint sites, and OneDrive folders - all of it sits within a single cloud platform that staff log into every day without a second thought.  And that's rather the point - it's convenient, it's always available, and it's run by one of the largest technology companies on the planet.

However, it’s also where one of the most common - and most costly - misconceptions in  IT takes root.  Because the data lives "in the cloud" with a giant like Microsoft, many business owners assume it's automatically backed up, safe, and recoverable no matter what happens.  Unfortunately, that assumption simply isn't true.  The gap between what people think  Microsoft protects, to what Microsoft actually  protects,  is exactly where a lot of businesses end up learning a very expensive lesson.

The reality is, that Microsoft - like every major cloud provider - operates on what's known as a "shared responsibility model".   In short, Microsoft keeps the platform running, but protecting the actual data you put into it remains your  responsibility, not theirs. Microsoft's built-in recycle bins and retention settings do help, but they fall short far more often than most people realise, as they were never designed to be a backup in the first place.

That's why this month we'll be talking about what Microsoft 365 does and doesn't protect for you.  We’ll also explain how businesses actually lose data that lives in the cloud, and detail why an independent backup still matters, even when your data sits with a company as big as Microsoft.

What does Microsoft 365 actually protect?

The shared responsibility model is simply an agreement - spelled out by Microsoft themselves - about who is responsible for what. Microsoft takes care of the infrastructure: the physical data centres, the servers, the network, platform uptime, and the geo-redundant replication that keeps the service online even if one of their data centres has a bad day.  As Microsoft states in their own documentation: for all cloud deployment types, you own your data and your identities1.

That last part is the bit that catches people out.  "You own your data" sounds reassuring, but what it actually means is that you're the one on the hook for protecting it.  Microsoft's job is to make sure the service is available, whereas your job is to make sure the data within that service can be recovered when something goes wrong.

Now, to be fair, Microsoft 365 does come with some genuinely useful built-in tools: deleted item recovery, recycle bins, retention policies, litigation/retention hold, and file versioning.  These are worth using, and you should.  But it's important to understand what they are – that they are short-term retention and platform redundancy features, not a backup that you control and can restore from on demand.  They typically have time limits (measured in days or weeks), they can be misconfigured, and in many cases they can be cleared, overridden, or emptied - including by an attacker who has gained access to your account2.

The single most important distinction to take away from this article is that "redundancy" is not the same as "backup".

  • Redundancy is Microsoft protecting against their  hardware failing.  If a disk - or even an entire data centre - dies, your service keeps running because there's a live copy elsewhere.
  • Backup is protecting against your  data being lost - deleted, corrupted, encrypted, or overwritten - by keeping a separate, independent copy that you can roll back to.

The trap is that redundancy quietly does its job so well that it starts to feel  like backup.  But a redundant copy faithfully mirrors whatever is in your live environment.  If a file is deleted or encrypted, that deletion or encryption is dutifully replicated right along with everything else.  As the saying goes in the industry, a replica is not a backup  - meaning that deleted and corrupted data simply replicates itself as deleted and corrupted.

And to be clear, this isn't a "Microsoft problem".  Google Workspace works on exactly the same model, with exactly the same gap. It's simply how Software-as-a-Service (SaaS) works: the provider runs the platform, and you look after the data on it.

So how do businesses actually lose data in the cloud?

This is the part that turns an abstract "shared responsibility" diagram into a real-world problem.  Here are the most common ways we see businesses lose data that they had assumed was perfectly safe:

  • Accidental Deletion:  By far this is the most common.  A staff member deletes an email folder, a document, or even an entire mailbox, and nobody notices until weeks or months later - long after the native retention window has quietly lapsed.  At that point, it's simply gone.
  • Malicious or Intentional Deletion:  A disgruntled employee, or someone on their way out the door, deliberately wipes files, emails, or shared documents.  Without an independent backup, there's often no way to get any of it back.
  • Offboarding Gaps:  When someone leaves and you remove or reassign their licence to save on cost, the mailbox and OneDrive data tied to that account are only retained for a limited grace period - often just a matter of weeks - before being permanently deleted.  "We'll just keep their old account around"  isn't the safety net people assume it is.
  • Ransomware and Malware:  This is one of the nastiest.  Modern ransomware doesn't just encrypt the files on a local PC. Because folders like OneDrive and SharePoint sync automatically, those freshly-encrypted files sync straight up into the cloud, overwriting the good copies with encrypted ones.  When both the local machine and  the cloud copy are compromised, the "cloud backup" you were relying on, turns out to be compromised too.
  • Account Compromise:  A single successful phishing email can hand an attacker the keys to a user's mailbox and files, which they can then delete, exfiltrate, or hold to ransom.
  • Retention Misconfiguration:  Retention policies are powerful, but they're also easy to get wrong.  Assuming that a retention policy covers something, when in actual fact it doesn't, is a very common and very quiet mistake.  And unfortunately  it is at the exact moment when you actually need to restore, that you discover you have this gap in coverage.

Ransomware in particular is where a properly isolated, offsite backup earns its keep.  We've written before about how our Veeam platform helps protect against ransomware and allows for quicker recovery, and the key principle there applies just as much to your Microsoft 365 data: if your backups are stored separately, offsite, and isolated from your live environment, then even when your main environment is compromised, your backups remain untouched and recoverable.  A backup that sits in the same place as the thing it's meant to protect isn't much of a backup at all.

"But we've never lost anything" - the false sense of security

If you've been running on Microsoft 365 for years without ever losing a file, it's completely understandable to feel like you're already covered.  And to be fair, you're partly right - Microsoft's native tools will catch a great many of the small, quickly-noticed mistakes. Delete a file this morning, realise your error this afternoon, and you'll very likely fish it back out of the recycle bin without breaking a sweat.

The problem is that native retention was never designed to be a backup, and the gaps are precisely where the expensive, unrecoverable incidents live.  It's the deletion nobody notices for three months.  It's the departed employee whose mailbox was purged after their licence was reclaimed.  It's the ransomware event that sync faithfully carried up into the cloud.  These are exactly the scenarios where "we've never lost anything before" stops being reassuring and starts being a liability.

This is where a long-standing principle in data protection comes in – called the 3-2-1 rule.  In short, you should keep three copies of your data, on two different types of media, with at least one copy stored offsite. Your live Microsoft 365 environment is one copy. Microsoft's own redundancy doesn't count as your independent copy, because it isn't yours to control and it mirrors your live data - faults and all.  So to genuinely satisfy the 3-2-1 rule, you need a separate, independent backup of your Microsoft 365 data that you own and can restore from, no matter what happens to the source.

That's exactly the gap that our Backup Solutions are built to close.  We can back up your data to encrypted, offsite storage held in a secure facility that's geographically separated from where your data normally lives - so a problem in one location can't wipe out both your data and  your backup of it in one go.  And if the worst does happen, you're not left navigating a restore on your own - our support packages give you access to dedicated on-call engineers who can help you restore your data at short notice, so that you can get back to business as quickly as possible.

Have any questions about protecting your Microsoft 365 data?

If you have any questions about backing up your Microsoft 365 (or Google Workspace) data - or you're simply not sure what's actually protected in your environment right now - let us know!  We're always happy to talk it through and help you work out where your gaps are.

We can help you design, implement, and manage an independent, offsite backup for your mailboxes, files, SharePoint, and Teams data, so that whatever happens, your business-critical information stays recoverable.

You can reach us via email at sales@micron21.com or call us on 1300 769 972 (Option #1).

Sources

1, Microsoft, "Shared responsibility in the cloud", https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility
2, AvePoint, "The Shared Responsibility Model for Microsoft 365", https://www.avepoint.com/blog/backup/microsoft-365-shared-responsibility-model

See it for yourself.

Australia’s first Tier IV Data Centre
in Melbourne!

Speak to our Australian based team.

24 hours a day, 7 days a week
1300 769 972

Sign up for the Micron21 Newsletter