Microsoft 365 · Data protection
Does Microsoft back up your Microsoft 365 data?
Short answer: not in the way most practices assume. Microsoft keeps your data available — it does not keep a copy you can roll back to. Here is what is actually retained, for how long, and why that matters when you are obliged to hold records for six years.
We come across this in practices that are otherwise well run. The data sits in Microsoft's cloud, Microsoft is a serious company, and so the question of backup never quite gets asked. It is an entirely reasonable assumption. It is also the wrong one — though not for the reason most articles on this subject claim.
Microsoft is not careless with your data. It replicates it across data centres, it retains deleted items for a period, and it can help recover a deleted site. What it does not do is hold a point-in-time copy of your practice's data that you can roll back to. And the windows in which anything is recoverable at all are shorter than most people expect.
What Microsoft actually commits to
Microsoft publishes a shared responsibility model covering its cloud services. On the question of who owns and protects customer data, it is unambiguous: "For all cloud deployment types, you own your data and identities. You're responsible for protecting the security of your data and identities."
Responsibility for the data sits with you. Microsoft's commitment is to the platform — that the service stays available, stays replicated, and stays secure. Your content sits under a different heading entirely.
It is worth being precise here, because this is where a lot of writing on the subject overreaches. The shared responsibility model assigns you responsibility for protecting your data. It does not spell out "you must arrange your own backup". But once you look at what the built-in retention actually does, the practical conclusion is hard to avoid.
What the built-in retention actually is
These are Microsoft's documented defaults, and they surprise people:
| What | How long it survives |
|---|---|
| Deleted Items folder (Exchange Online) | No default expiry — items sit there until someone empties the folder. The widely repeated "30 days" is wrong for this folder. |
| Recoverable Items (the "dumpster", after Deleted Items is emptied) | 14 days by default, 30 days maximum. This is the real backstop for deleted email, and it is two weeks unless someone has changed it. |
| A deleted user's mailbox | 30 days, then permanently deleted and unrecoverable — unless the mailbox was placed on hold first. |
| SharePoint & OneDrive files | 93 days total. Emptying the site recycle bin moves items to the site-collection bin for the remainder of the 93 days — the two stages are cumulative, not additive. |
| A deleted user's OneDrive | 30 days by default (configurable up to 3,650), then the 93-day recycle bin clock. |
The number to hold on to is 93 days. That is the outer edge of what Microsoft retains for files by default — and fourteen days for email that someone has emptied from Deleted Items.
Retention is not the same as a backup
Practices that have looked at this sometimes conclude they are covered because they have retention policies or legal hold configured. Those are useful tools, but they solve a different problem, and Microsoft says so directly. In its own backup documentation: "Legal holds retain data, but that feature is optimized for export (for example, via eDiscovery), not for mass restore."
The distinction is worth spelling out:
- Retention keeps copies in place. It stops data being purged. It does not give you a version of your tenant as it stood last Tuesday.
- Recovery is item-level, not point-in-time. Finding and restoring one deleted invoice is workable. Reconstructing a partner's mailbox and a client folder tree after something goes wrong across both is a very different job.
- Version history thins out. On the default setting, SharePoint keeps all versions for 30 days, then hourly versions to 60 days, daily to 180, and weekly beyond that. Granular rollback degrades the further back you go.
- Files Restore covers the last 30 days only. It is a genuinely good ransomware tool within that window, and no help outside it.
The clearest evidence the gap is real
Microsoft now sells a product called Microsoft 365 Backup, and its own ransomware guidance recommends "evaluating the use of Microsoft 365 Backup or a recognized partner solution". A platform that fully backed up your data would not need to sell you a backup.
Where this collides with what a practice is required to keep
This is where it stops being an IT question. A UK limited company must keep its accounting records for six years from the end of the financial year they relate to. Failing to do so carries a £3,000 penalty from HMRC or disqualification as a director. Your self-employed clients must keep theirs for at least five years after the 31 January submission deadline.
Six years of obligation. Ninety-three days of native retention. That is the whole problem in two numbers.
There is a data protection dimension too, and it is more specific than general "GDPR risk". UK GDPR Article 32(1) requires appropriate technical measures including:
- (b) "the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services"
- (c) "the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident"
Subsection (c) is an obligation to be able to restore. A practice holding several years of client personal data, whose only recovery mechanism expires after 93 days, is in a weaker position against that requirement than it probably realises. We cover the wider compliance picture in our guide to GDPR compliance for accountancy practices.
The timing problem nobody plans for
Short windows would matter less if problems announced themselves. In a practice, they do not.
A client file that mattered in March may not be opened again until the following January. A departing staff member's mailbox gets deleted during an offboarding tidy-up, and the thing that needed to be in it surfaces at the next filing deadline — by which point the 30-day window closed months ago. Someone with entirely legitimate access clears out a SharePoint folder they believed was superseded.
In every one of those cases the clock started when the data was deleted, not when someone noticed. That asymmetry — short retention against slow discovery — is the actual risk, more than any dramatic ransomware scenario.
What good looks like
The fix is not complicated, and it is not expensive relative to the exposure:
- A separate backup of Microsoft 365 — mail, OneDrive, SharePoint and Teams — held independently of the tenant it is protecting.
- A retention period that matches your obligations, not the platform's defaults. If you are required to hold records for six years, the backup should reach six years.
- Restores that have actually been tested. An untested backup is a belief, not a control. This is the step most often skipped.
- A deliberate offboarding process, so a leaver's data is preserved before the account is deleted rather than discovered missing later.
Most practices we speak to do not have this, and are genuinely surprised to hear they need it. That is not a criticism of them — the assumption that a platform of Microsoft's size handles it is a perfectly sensible one to have made.
If you are not certain which side of this line your practice sits on, it is a short conversation with whoever runs your IT. The question worth asking is a specific one: if a mailbox were emptied today and nobody noticed for three months, what would we get back?
Frequently asked questions
Does Microsoft back up Microsoft 365 data?
Not in the sense most people mean. Microsoft replicates your data across data centres and retains deleted items for a limited period, but it does not hold a point-in-time copy you can roll back to, and it assigns responsibility for protecting your data to you. Microsoft now sells a separate Microsoft 365 Backup product, and its own ransomware guidance recommends evaluating that or a partner solution.
How long does Microsoft keep deleted emails?
Items in the Deleted Items folder have no default expiry and remain until the folder is emptied. Once emptied, they move to the Recoverable Items folder for 14 days by default, extendable to a maximum of 30 days. After that they are gone.
What happens to a member of staff's data when they leave?
A deleted user's mailbox is recoverable for 30 days and then permanently deleted, unless it was placed on hold beforehand. Their OneDrive is retained for 30 days by default, though this is configurable up to 3,650 days, after which it enters the 93-day recycle bin cycle.
Isn't a retention policy the same as a backup?
No. Retention keeps copies in place and prevents purging; it does not provide point-in-time restore. Microsoft states that legal hold is optimised for export via eDiscovery rather than for mass restore. Retention answers whether an item can still be found, not whether the practice can be put back as it was.
How long do UK accountancy practices need to keep records?
A limited company must keep accounting records for six years from the end of the financial year they relate to, with a £3,000 HMRC penalty or director disqualification for failing to do so. Self-employed clients must keep records for at least five years after the 31 January submission deadline.
Does a practice need a separate backup to meet UK GDPR?
UK GDPR Article 32(1)(c) requires the ability to restore the availability of and access to personal data in a timely manner following an incident. It does not name a specific technology, but a practice whose only recovery route expires after 93 days would find that requirement difficult to evidence for data it is obliged to hold for years.
Related reading
- Is cloud desktop GDPR compliant for accountancy practices?
- Hosted desktop vs on-premise server: the real cost comparison
- IRIS, TaxCalc and Sage on cloud desktop: what practices need to know
Not sure what your practice would actually get back?
We will look at your Microsoft 365 tenant, tell you what is currently recoverable and for how long, and set out what a backup that matches your record-keeping obligations would involve. A free 20-minute conversation — no pressure, and we will tell you honestly if you already have this covered.
Book a free consultation →
