Why Microsoft 365 is not a backup solution for your business data

A Brisbane law firm we work with had an employee resign under difficult circumstances last year. Before IT could act, the departing staff member deleted their mailbox and cleared out a shared SharePoint folder. By the time anyone noticed, Microsoft had already replicated the deletions across its infrastructure. The data was gone.
Stories like this are common, and they come from a single misunderstanding: that storing data in Microsoft 365 means it is backed up. It is not. Microsoft keeps the platform running. Your data is your responsibility.
What Microsoft actually protects
Microsoft manages the physical infrastructure, network availability, and geo-redundant replication of its datacentres. If a server fails or a datacentre goes offline, Microsoft restores the service. That is the extent of its obligation to your data.
What Microsoft does not do is protect you from data loss caused by your own users, your own policies, or an attacker operating inside your tenant. Microsoft’s own documentation recommends that customers regularly back up content and data using third-party applications. That recommendation is also written into its service agreements. Most businesses never read it.
The gaps that catch businesses out
Microsoft 365 has some built-in recovery features: recycle bins, versioning, and retention policies. These are useful for minor, short-term mishaps. They are not a substitute for genuine backup. Here are the four scenarios we see most often.
Deleted users. When a Microsoft 365 account is removed, Microsoft replicates that deletion across its infrastructure. The user’s personal SharePoint site, OneDrive files, and mailbox data are lost. Without a third-party backup in place, there is no way to recover them.
Deleted emails outside the recovery window. Permanently deleted emails are retained for a maximum of 30 days. Australian businesses may need to keep email records for seven years or more under the Corporations Act 2001, or longer still in regulated industries such as health and financial services. Microsoft’s 30-day window does not come close to meeting that.
Malicious or accidental deletion. A disgruntled employee, a misconfigured retention policy, or a simple human error can wipe documents before anyone notices. Ransomware is another risk: modern ransomware does not only encrypt local files. It can propagate through synced OneDrive and SharePoint content, and it will target recycle bins and retention policies too, removing your native recovery options before demanding a ransom.
Legal and compliance discovery. If your business becomes involved in litigation or a regulatory audit, you may need to produce emails and documents that are several years old. Without a structured backup and archiving process, much of that data will simply not exist. Under Australia’s updated Privacy Act, enforcement is becoming more active. The OAIC launched a nationwide compliance sweep in early 2026 targeting multiple sectors, and penalties for serious breaches can now reach $50 million or 30 per cent of adjusted turnover for the relevant period.
Replication is not backup
This is the point most businesses miss. Microsoft replicates your data across multiple datacentres for availability. That means if you delete a file, the deletion is also replicated. If ransomware corrupts a SharePoint library, that corruption spreads too.
Replication keeps the service available. It does not let you roll back to a clean point in time before something went wrong. Only a dedicated backup solution with point-in-time recovery can do that.
What a proper Microsoft 365 backup looks like
A third-party backup solution stores a separate, independent copy of your Microsoft 365 data outside your tenant. It runs on a schedule, creates point-in-time restore points, and gives you granular recovery: you can restore a single email, a specific file version, or an entire mailbox without affecting anything else.
At TTA, we use Acronis Cyber Protect Cloud to back up Microsoft 365 data for our managed clients. As an authorised Acronis partner, we deploy it across Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. Backups go to secure Acronis Cloud Storage, independent of your Microsoft tenant. Key capabilities include:
- Exchange Online: emails, attachments, calendars, contacts, and full mailboxes.
- SharePoint Online: documents, libraries, and sites.
- OneDrive for Business: files, folders, and user accounts.
- Microsoft Teams: channel data and associated files.
Acronis also scans backups for malware before restore, which prevents reinfecting a clean environment with a backup that was taken after a compromise. New users and groups are automatically added to protection plans, so there are no gaps when staff join or move roles. The April 2026 Acronis platform update added a Microsoft 365 onboarding wizard and Exchange Graph API support, making it faster to set up and more reliable in ongoing operation.
What we see at TTA: the patterns that lead to data loss
Across our client base in Brisbane and South-East Queensland, data loss in Microsoft 365 almost always follows one of three patterns.
The first is a departing employee scenario, which we covered at the top of this article. Someone leaves, data disappears, and IT discovers the gap too late. The second is a ransomware or account compromise event, where an attacker empties recycle bins and disables retention policies as part of the attack, removing the easiest recovery paths. The third is a compliance request: a legal matter or an audit that needs emails from three or four years ago, which Microsoft’s native tools simply cannot provide.
All three are preventable with a straightforward third-party backup. None of them require advanced or expensive infrastructure. For most SMEs in the 10 to 100 seat range, a per-seat cloud-to-cloud backup solution adds a small, predictable cost and removes a significant, unpredictable risk.
If you are unsure whether your current Microsoft 365 setup is properly protected, an IT audit is a practical starting point. It maps what you have, identifies the gaps, and gives you a clear picture of what you actually need.
A quick check for your business
Ask yourself these questions. If any answer is “no” or “not sure”, you have a backup gap worth addressing.
- Can you restore a specific email from 18 months ago within an hour?
- If an employee’s account is deleted today, can you recover their OneDrive files next week?
- If ransomware hit your SharePoint environment on the weekend, could you restore to a clean state from Friday?
- Can you produce email correspondence from three years ago if asked by a lawyer or regulator?
- Does your backup sit outside your Microsoft tenant, in storage Microsoft cannot access or modify?
Frequently asked questions
Does Microsoft 365 back up my data automatically?
No. Microsoft replicates your data across its datacentres for service availability, but that is not backup. Deleted or corrupted data replicates in its damaged state. Microsoft’s own service agreements recommend using third-party applications to back up your Microsoft 365 data. Native recycle bins and retention policies have short time limits and can be cleared by ransomware attackers.
How long does Microsoft retain deleted emails?
Permanently deleted emails are retained for a maximum of 30 days in Microsoft 365. After that, they cannot be recovered through native tools. Australian businesses under the Corporations Act 2001 are generally required to keep financial and company records for seven years. A third-party backup solution with email archiving covers both recovery and long-term compliance retention.
What happens to a user’s data when their Microsoft 365 account is deleted?
When a Microsoft 365 user account is deleted, the deletion is replicated across Microsoft’s infrastructure. The user’s personal OneDrive and SharePoint data is removed. Without a third-party backup taken before the deletion, that data cannot be recovered. This is one of the most common data loss scenarios we see in small and mid-sized businesses.
Can ransomware affect Microsoft 365 data?
Yes. Modern ransomware can propagate through synced OneDrive and SharePoint content. Attackers often empty recycle bins and remove retention policies as part of the attack, eliminating native recovery options. A third-party backup stored outside your Microsoft tenant, with immutable storage, is the only way to guarantee a clean recovery path after a ransomware event in a Microsoft 365 environment.
Is Microsoft 365 backup a compliance requirement for Australian businesses?
Not always explicitly, but practically yes for most. The Corporations Act requires financial and company records to be kept for seven years. Regulated industries such as health and financial services have longer requirements. Australia’s updated Privacy Act, now under active enforcement by the OAIC, requires businesses to protect and be able to produce personal information on request. A Microsoft 365 backup supports all of these obligations.
Where to from here?
If your Microsoft 365 data is not being backed up independently, the fix is straightforward. TTA sets up and manages Microsoft 365 backup for businesses across Brisbane and South-East Queensland, including ongoing monitoring so you can be confident a restore will work when you need it. Get in touch and we can walk you through the options.



