News

Does Microsoft back up my Microsoft 365 data?

Microsoft keeps Microsoft 365 running, but it doesn't keep a backup you can restore from — and its own terms say so. Here's where the built-in recycle bins and retention timers run out, and what an independent, off-tenant backup actually needs to look like.

Short answer: no. Microsoft keeps Microsoft 365 running, but it does not keep a backup of your data that you can restore from. Your mailboxes, OneDrive files, SharePoint sites and Teams chats are your responsibility, and Microsoft says so in its own service terms.

This surprises a lot of people. The service has 99.9% uptime, data is replicated across data centers, and deleted items show up in a recycle bin. That feels like a backup. It isn't. Replication protects against Microsoft losing a disk. It does nothing when a user deletes a folder, a mailbox is purged after an employee leaves, or ransomware encrypts every file in a shared library and OneDrive faithfully syncs the encrypted versions everywhere.

This article explains what Microsoft actually promises, what the built-in protections cover, where they run out, and what a real backup of Microsoft 365 looks like.

What Microsoft actually promises: the shared responsibility model

Microsoft runs the service; you own the data in it. That is the whole shared responsibility model in one sentence, and Microsoft publishes it as a matrix in its shared responsibility documentation. For a SaaS product like Microsoft 365, the split looks like this:

Responsibility area

Who is responsible

Customer data

Customer

Configurations and settings

Customer

Identities and users

Customer

Client devices

Shared

Applications

Shared

Network controls

Microsoft

Operating system

Microsoft

Physical hosts, network and datacenter

Microsoft

The same page lists the responsibilities you keep no matter which cloud model you use. The first one is data: you are responsible for your data, including how it is protected. Microsoft is responsible for the datacenter, the servers, and the platform. Nothing in that list says Microsoft will hand you back a copy of a mailbox you deleted three months ago.

Microsoft is unusually direct about this in its consumer terms as well. The Microsoft Services Agreement tells users to make regular backup copies of their content and states that Microsoft cannot be held responsible for it. Business tenants sit under different contracts, but the principle is the same: Microsoft guarantees availability of the service, not recoverability of your data.

What Microsoft's built-in protections cover (and their limits)

Microsoft 365 does ship with recovery features, and they are useful. The problem is that every one of them is short-lived, lives inside the same tenant it protects, or is aimed at compliance rather than recovery. Here are the defaults as Microsoft documents them:

Feature

What it covers

Default window

Where it stops

Exchange Recoverable Items

Emails a user permanently deleted or emptied from Deleted Items

14 days, extendable to 30

Purged after the window; nothing older can be recovered

Soft-deleted mailbox

A whole mailbox after the user account is deleted

30 days

Hard-deleted after 30 days, or immediately in some sync scenarios

OneDrive of a deleted user

The user's files after the account is deleted

30 days, then 93 days in the site recycle bin

Admin-only restore in the second stage, then gone

OneDrive and SharePoint recycle bins

Individual deleted files and folders

93 days across both stages

Emptied by the user, or expired, and the file is gone

OneDrive Files Restore

Roll a single OneDrive back to a point in time

30 days

Per-user only; cannot restore a SharePoint library or a mailbox

Retention policies and litigation hold

Keep items for compliance, even if a user deletes them

As configured

Compliance tooling, not a restore tool; needs E3/E5-class licensing and prevents deletion rather than restoring it

Three things stand out. First, the windows are measured in days, not years. A deletion nobody notices for a quarter is unrecoverable under every default above. Second, everything is stored in the same tenant, under the same admin credentials, subject to the same retention rules. If the tenant is compromised, the "backup" is compromised with it. Third, none of these give you a copy you control: you cannot download it, move it to another provider, or restore it into a different tenant.

Microsoft also sells a separate Microsoft 365 Backup product for Exchange, OneDrive and SharePoint. It is a real backup service, but it stores its copies inside Microsoft's own infrastructure and bills per gigabyte of protected data, so it still leaves you with a single-vendor dependency and no offline copy.

The gaps: scenarios where data is gone for good

These are the cases we hear about most often, and none of them are exotic.

The employee who left six months ago. An admin deletes the account to free up a license. The mailbox and OneDrive follow the retention timers above and are purged. Then a customer asks for the contract that only ever lived in that person's inbox.

The quiet deletion. Someone cleans up a SharePoint library and removes a folder they think is obsolete. Ninety-three days pass before anyone looks for it. The recycle bin is empty.

Ransomware through OneDrive sync. Malware encrypts files on a laptop. The OneDrive client sees changed files and syncs them, as designed. Version history can help for individual files, but rolling back thousands of files across several libraries by hand is not a recovery plan. If the attacker also has admin credentials, they can shorten retention or purge recycle bins first.

The compromised admin. Phishing or a stolen token gives an attacker Global Administrator. Everything the built-in protections rely on, from retention policies to recycle bins to Files Restore, is now controlled by the attacker.

The malicious insider. A departing employee deletes what they can before their last day. Recycle bins help only if someone notices within the window, and only for content the insider didn't purge.

The tenant you can't get back into. Billing disputes, a suspended subscription, or an administrative lockout mean you cannot reach data that still technically exists. Microsoft's terms also say that once an account is closed, your content is not retrievable.

Teams and other workloads. Teams chats live in hidden Exchange folders, Planner tasks and Forms responses have their own storage, and none of them have a recycle bin you can browse. Recovering them relies on compliance tooling that most tenants have not configured.

In every one of these cases, Microsoft has done exactly what it promised: the service stayed up. The data loss happened on the customer's side of the line, so recovery is the customer's job.

What a real backup of Microsoft 365 needs to look like

A backup closes the gap only if it is independent of the thing it protects. For Microsoft 365 that means five properties:

  1. Stored outside the tenant. The copy must live somewhere an M365 admin credential cannot reach: your own object storage, another cloud, or a provider's storage under a separate account. If a compromised Global Admin can delete the backup, it isn't one.

  2. Retention you set, not Microsoft. Thirty days is a grace period. A backup should keep versions for months or years, on a schedule you choose, so a deletion discovered next quarter is still recoverable.

  3. Encrypted before it leaves. Mail and files should be encrypted before they reach storage, so the storage provider never sees plaintext. Then decide who should hold the key: you, for maximum control, or the backup vendor, for a fully managed service. Know which one you have chosen, especially if you handle regulated data such as PHI or financial records.

  4. Restorable in full and in part. You need to be able to bring back a single email, a folder, a whole mailbox, or a whole user, and to restore into the same tenant or a different one. Cross-tenant restore is what saves you when the original tenant is locked or gone.

  5. Covers the workloads people actually use. At minimum Exchange mailboxes, calendars and contacts, OneDrive, SharePoint document libraries, and Teams files and chats. A backup that skips SharePoint covers the least interesting half of most tenants.

The classic 3-2-1 rule still applies: three copies, on two kinds of media, one of them off-site. For SaaS data, "off-site" means off-tenant. Microsoft's own replicas are copies one and two on the same medium in the same place. The third copy is the one you own.

How Duplicati fills the gap: managed or self-hosted

Duplicati offers two ways to keep an independent, off-tenant copy of your Microsoft 365 data. Both cover Exchange, OneDrive, SharePoint and Teams, both restore into the same tenant or a different one, and both keep versions for as long as your policy says. They differ in who runs the backup and who holds the encryption key.

Managed Microsoft 365 backup

The Duplicati Console runs the backups for you. Connect your tenant, pick the users, and Duplicati schedules and executes every job on its own infrastructure. There is nothing to install and no server to maintain.

  • Zero infrastructure. Backups run in Duplicati's cloud; your only job is choosing who to protect.

  • Storage included. Each protected user includes 100 GB of Duplicati cloud storage. You can point the backup at your own destination instead.

  • Encrypted at rest. Data is encrypted before it reaches storage. Because Duplicati runs the jobs and restores on your behalf, Duplicati Inc holds the encryption key for managed backups.

  • Best for small and mid-sized businesses, and MSPs who want one console and one policy across many client tenants with nothing to host.

Self-hosted Microsoft 365 backup

You run Duplicati on your own server, VM or workstation and add a per-user Microsoft 365 license from the Console. Backups pull from your tenant and land in a destination you choose: Duplicati Cloud Storage, S3-compatible object storage, Azure Blob, Backblaze B2, a NAS, or dozens of others.

  • You hold the key. Data is encrypted client-side on your machine with a passphrase only you know. Neither Duplicati nor the storage provider can read it.

  • Your storage, your rules. Any destination Duplicati supports, with retention and immutability configured on your side.

  • Central visibility. The Console still monitors the jobs, alerts on failures and lets you manage many machines and tenants from one place.

  • Best for organizations with data residency or key-custody requirements, regulated workloads, and MSPs who already run Duplicati for endpoint and server backup.


Managed

Self-hosted

Who runs the backup

Duplicati Console

You, on your own machine

Encryption key

Held by Duplicati Inc

Held by you

Storage

100 GB per user included, or your own

Your own destination

Setup

Connect tenant, pick users

Install Duplicati, add M365 license

Cross-tenant restore

Yes

Yes

Either way, the copy lives outside the Microsoft 365 tenant, under credentials a compromised admin does not have, with retention Microsoft's timers cannot touch.

Frequently asked questions

Isn't Microsoft's geo-redundancy a backup? No. Replication copies your data, including deletions and ransomware-encrypted files, to another datacenter within seconds. It protects Microsoft against hardware and site failure. It does not let you go back in time.

We have retention policies and litigation hold. Isn't that enough? They prevent deletion, which is valuable, but they are compliance tools. They require the right licensing, are administered from inside the tenant, and offer no way to restore to a different tenant or to export a clean copy you control.

Do I need to back up SharePoint and Teams, or just email? All of it. SharePoint libraries usually hold more business-critical files than mailboxes, and Teams files are SharePoint files. Teams chats are stored in Exchange, but not in a place users can recover from.

How much does it cost to back up Microsoft 365 with Duplicati? Both options are licensed per Microsoft 365 user. Managed backup includes 100 GB of Duplicati cloud storage per seat; self-hosted backup uses storage you already have. Current pricing is on the Duplicati pricing page.

How do I start? Sign in to the Duplicati Console. For managed backup, connect your Microsoft 365 tenant and choose the users to protect; the first backup runs from there. For self-hosted backup, install Duplicati on a machine you control, add a Microsoft 365 license, and point the job at your own storage.

Sources: Microsoft, Shared responsibility in the cloud; Microsoft Services Agreement; Change how long permanently deleted items are kept for an Exchange Online mailbox; Delete or restore user mailboxes in Exchange Online; Restore a deleted OneDrive.

Get started for free

Pick your own backend and store encrypted backups of your files anywhere online or offline. For MacOS, Windows and Linux.

Pick your own backend and store encrypted backups of your files anywhere online or offline. For MacOS, Windows and Linux.

  • Example image