Module 8 of StartCloud's Microsoft 365 Security Essentials learning pathway, in five short units with a knowledge check: the shared responsibility model and why 'it is in the cloud so it is backed up' is wrong, the real Microsoft retention windows (93 days for SharePoint and OneDrive, 14 days by default for email, 30 days for a deleted account), the four ways data actually disappears (deletion, departures, ransomware syncing encrypted files, sync errors), and what separates a genuine third-party backup from a recycle bin.
Backups: What Microsoft Does Not Do For You
The sentence that costs people money
There is one sentence that turns up in almost every conversation about lost data, and it is always said with complete confidence: "it is in the cloud, so it is backed up."
It sounds obviously true. Microsoft runs enormous data centres, they replicate everything, the service has not fallen over in years. All of that is real. It is just answering a different question to the one you actually care about.
Keeping the service running. Their hardware, their data centres, their uptime. If a disk dies in a Microsoft building, that is their problem and you will never hear about it. This is the part they are genuinely excellent at.
The data inside it. If someone in your business deletes the wrong folder, or an account gets taken over and wipes a mailbox, that is not a Microsoft outage. The service worked perfectly. It did exactly what it was told, by someone with permission to tell it.
Every cloud provider works this way, and Microsoft publishes it openly. They are responsible for the infrastructure. You are responsible for your data, your accounts, and your access controls. Nobody hides it. It is just that almost nobody reads it before they need it.
Here is the thing worth sitting with for a second. Microsoft does give you some safety nets, and they are genuinely useful. Recycle bins, retention windows, a grace period on deleted accounts. Plenty of businesses have been saved by them.
The trouble is that people assume those safety nets are a backup, and they are not the same thing. A backup is a separate copy you control, kept for as long as you decide, restorable on demand. What Microsoft gives you is a set of short timers. Next unit, we look at exactly how long those timers run, because the numbers surprise people.
These are the real numbers, straight from Microsoft's own documentation. Read them with one question in mind: how long would it take your business to notice that something was missing?
Delete a file and it lands in the site recycle bin. Empty that, and it drops to the second-stage recycle bin, which only admins can see. The clock does not restart, though. That 93 days spans both bins from the moment of the first delete, and then it is gone.
Emptying Deleted Items is not the end. Items sit in a hidden Recoverable Items folder that Outlook can restore from. The default window is 14 days, and an admin can raise it to 30, which is the maximum. Most businesses have never changed it from 14.
Delete someone in the admin centre and you have 30 days to restore the account and everything attached to it. Miss that window and the mailbox is permanently gone. Same 30 days applies if you simply strip their licence.
The whole site, its libraries and its version history sit recoverable for 93 days. Microsoft also holds an extra 14 days of backups beyond that, but only their support team can trigger a restore from those, and only for the whole site.
The longest of those windows is 93 days. Roughly three months. Think about the folder that only gets opened at tax time, or the project archive nobody touches between jobs, or the year-old contract someone asks for when a dispute lands. Plenty of businesses do not go looking for a file until well past three months, and by then the safety net has quietly expired.
That 14 day email window is the weakest link in the list, and it is free to double. An admin can raise it to 30 days for every mailbox in the tenant with a single command. It is not a backup and it does not replace one, but it is fifteen minutes of work for twice the breathing room. Ask your IT provider whether yours is still sitting on the default.
Notice what is missing from this list: "Microsoft lost it." That essentially does not happen, and it is not what you are protecting against. Every scenario below is your own data, deleted or changed by someone who was allowed to, in a service that worked perfectly throughout.
Someone deletes it, and nobody notices for months
The most common one by a mile, and it is almost never malicious. A tidy-up that went too far, a folder dragged into the wrong place, a departing employee clearing out what they thought was their own clutter. The deletion is legitimate, so nothing alerts anyone.
- Discovered inside 93 days: the recycle bin saves you
- Discovered after 93 days: the file is genuinely gone
- Nobody gets a warning, because the system did what it was asked
Someone leaves and their account gets cleaned up
An employee resigns, the licence gets reclaimed to save money, the account is deleted a few weeks later. Six months on, someone needs the client history that lived in that mailbox. Module 9 covers doing this properly, and this is exactly why it matters.
- The 30 day account window is shorter than most handovers
- Removing the licence starts the same 30 day clock on the mail
- The OneDrive goes too, on its own timer
Ransomware encrypts the lot, and OneDrive dutifully syncs it
This is the one people misunderstand most. Malware encrypts files on a laptop, and the sync client does precisely what it was built to do: it pushes those encrypted versions up to the cloud. Your cloud copy is now encrypted too, and it synced there legitimately.
- Version history can walk files back, one file at a time
- Across thousands of files that becomes a very long week
- Sync is a copy, not a backup, and this is the difference
A sync mistake spreads quietly across the business
Someone reorganises a shared library from their laptop, or a sync conflict resolves the wrong way, or a script does something enthusiastic. The change propagates to everyone within minutes, and it looks like normal activity all the way down.
- Fast propagation means fast damage
- The change is legitimate, so nothing flags it
- Unpicking it by hand means going file by file
Version history is brilliant for "I broke this document, give me yesterday's copy." It is a per-file tool for a per-file problem. It falls apart the moment the problem is thousands of files at once, or the file itself is gone rather than changed. Same story as the recycle bin: a genuinely good feature that people mistake for a safety net it was never built to be.
Good news first: this is a solved problem. Third-party backup for Microsoft 365 is a mature, unglamorous product category, and Microsoft now sells a first-party option too. It is not expensive relative to what it protects, and it is usually billed per user per month.
What matters is knowing what you are actually buying, because plenty of things get sold as backup that are really just retention with better marketing.
- A separate copy, held outside your tenant, so a bad day inside it cannot reach the copy
- Retention you choose: years if you want them, not a fixed 93 days
- Covers Exchange, SharePoint, OneDrive and Teams, because Teams data lives in more places than people expect
- Point-in-time restore, so you can ask for "this library as it stood on the 3rd" and get it
- Restore at any size, from one email up to an entire site, without a support ticket
- The recycle bin, however reassuring the name is
- Version history, which is a per-file undo
- OneDrive sync, which is a copy that faithfully copies the damage too
- Retention policies, which stop deletion but do not restore
- A litigation hold, which is a legal tool wearing a backup costume
An untested backup is a promise, not a protection, and the day you find out it never worked is guaranteed to be the worst possible day. Ask for a live restore once a year. Watch a real file come back. If nobody can produce one, you do not have a backup, you have an invoice.
- Show me a restore. Not a dashboard, an actual file coming back
- How long does a full restore take, realistically, with our volume of data?
- Where does the copy live, and can an attacker in our tenant reach it?
- How far back does retention go, and what does extending it cost?
- Does it cover Teams chat and channel files, not just mail and OneDrive?
One last thought before the knowledge check. Backup is the module in this pathway that protects you when every other one has already failed. MFA, admin hygiene, sharing controls and Purview all work to stop the bad day happening. Backup is what is left when it happens anyway, and that is why it belongs here rather than as an afterthought.
- learn.microsoft.com: SharePoint and OneDrive data resiliency: the 93 day recycle bin
- learn.microsoft.com: Exchange data deletion: 14 day default, 30 day maximum
- learn.microsoft.com: Change how long permanently deleted items are kept
- learn.microsoft.com: Delete or restore user mailboxes: the 30 day window
- learn.microsoft.com: SharePoint data deletion and site retention
Retention windows were current at the time of writing (August 2026). Microsoft does adjust these occasionally, so check the links above before making a decision that depends on an exact number.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. Under the shared responsibility model, who is responsible for the data inside your Microsoft 365 tenant?
2. A file was deleted from SharePoint four months ago and nobody noticed until today. Where is it?
3. Ransomware encrypts files on a laptop that syncs to OneDrive. What happens to the cloud copy?
4. By default, how long does Microsoft 365 keep email that a user has purged from Deleted Items?
5. A vendor is pitching you Microsoft 365 backup. What is the single best question to ask?