Rejuvenate IT Logo
  1. Home
  2. Guides
  3. Cloud & Microsoft 365

Explainer

Does Microsoft back up your data?

No, not in the way most people mean. Microsoft keeps the service running and holds deleted items briefly - 30 days for a mailbox, 93 for files. After that it is gone, and recovering it was always your job.

By Claire Donnelly · Last reviewed 11 August 2026 · 4 min read

The short version

  • Microsoft protects the platform, but your data stays your responsibility
  • A deleted mailbox can be recovered for 30 days, then it is permanently gone
  • Deleted files sit in the recycle bin for 93 days in total, not indefinitely
  • Removing somebody's licence starts a 30-day clock on their mailbox
  • Retention is not backup: it will not save you from ransomware or a bad bulk change

The short answer

Microsoft keeps Microsoft 365 running. It replicates your data across its own data centres so that a failure at their end does not lose your email. That is resilience, and it is very good.

What it is not is a backup of your business, kept separately, that you can wind back to a chosen point. Microsoft’s own position on this is not ambiguous: in a cloud service the provider looks after the infrastructure, and the customer remains responsible for their data. Deleting something is a decision you made, and their systems replicate it faithfully.

So the honest answer is that Microsoft gives you a short grace period to undo a mistake, and nothing beyond it.

The windows you actually have

  • A deleted mailbox is retained for 30 days, then permanently deleted and unrecoverable
  • Remove a user's licence and their mailbox data is held for 30 days, then deleted
  • Files deleted from SharePoint or OneDrive get 93 days across both recycle bin stages
  • A departed user's OneDrive is kept for 30 days by default before it moves on
  • None of these windows extends because you did not notice in time

Why retention is not backup

The gap matters most in the situations that actually hurt.

Ransomware. If files on a synced machine are encrypted, the sync obediently copies the encrypted versions up. Versioning helps if you catch it quickly and the version history is deep enough. It is not designed for the job.

Someone deleting properly. A user who deletes files and then empties the recycle bin has removed both stages. There is no third one.

Discovering it late. Most data loss is noticed weeks or months after the event, when a project restarts or a client asks a question. That is precisely when the windows above have closed.

A bad bulk change. A mis-scoped script, a botched migration or a sync configured the wrong way round can remove a great deal very quickly, and correctly, as far as the system is concerned.

Retention answers “I deleted that this month, can I have it back?” Backup answers “what did this folder look like in March?” Only one of those is a recovery plan.

What people do instead

There are three sensible routes, and the right one depends on how much your data matters and how far back you need to see.

Microsoft now sells its own backup product for Microsoft 365, charged on usage rather than per user. Third-party backup tools have been doing this for years, typically per user per month with much longer retention. Some businesses use scheduled exports, which is better than nothing but slow and awkward to restore from.

Whichever you choose, three questions decide whether it is any good: how far back it lets you go, whether you can restore a single mailbox item or file rather than everything at once, and when somebody last proved a restore actually worked. The third question is the one nobody asks until the day they need it.

A reasonable position to take

If your business would survive losing everything created in the last quarter, the built-in windows may genuinely be enough, and that is a legitimate decision to make deliberately.

If it would not, you need something that keeps its own copy, holds it for longer than 93 days, and has been tested. What you should not do is assume it is already happening because the data lives in the cloud. That assumption is extremely common, and it is the reason this article exists.

Common questions

Isn't my data replicated across several data centres?

Yes, and that protects you against Microsoft losing a data centre. It does not protect you against you. Replication copies your deletions just as faithfully as it copies your files.

Does the recycle bin protect us from ransomware?

Not reliably. Encrypted files sync up as new versions of legitimate files, and the recycle bin only holds things that were deleted. Version history can sometimes rescue a small incident if it is caught fast, but it is not built for a wide attack.

What about retention policies and legal hold?

They serve compliance rather than recovery - they stop data being removed before a required date. They are useful, and they are not a backup: you cannot use one to roll a mailbox back to how it looked last spring.

How long should we keep backups?

Long enough to cover how late you would realistically notice a problem, which for most businesses is months rather than weeks. Any regulatory or contractual retention you are subject to sets a floor, not the answer.

We are a small business - is this really necessary?

It is a judgement about what losing the data would cost you, not about size. A five-person consultancy whose entire history sits in SharePoint has more to lose than a larger firm that keeps its records elsewhere.

Written by Claire Donnelly

Could you get back a file deleted six months ago?

It is a quick thing to find out, and the answer surprises people. We'll check what your tenant would actually let you recover, and how far back - no obligation either way.

Ask us to check