Why native Microsoft 365 retention is not a backup

Microsoft 365 is the operational backbone of most Australian businesses. Email runs through Exchange Online. Documents live in SharePoint and OneDrive. Conversations happen in Teams. But a persistent and costly misconception follows this dependence: that because the platform keeps data for a period of time, the business is covered if something goes wrong. It is not.
Native retention in Microsoft 365 is a governance tool. It controls how long content stays in the system before deletion. It does not create independent copies of your data, it does not give you point-in-time recovery, and it does not protect against ransomware or accidental deletion past a tight time window. These are two different things solving two different problems. Treating them as the same is where businesses get hurt.
This article explains what retention actually does, where it stops, and what genuine Microsoft 365 backup looks like. It is relevant to any business leader or IT decision-maker who uses Microsoft 365 and has not yet added a dedicated backup layer. That is most SMEs in Australia right now.
What Microsoft 365 retention actually does
Retention policies in Microsoft 365 control the lifecycle of content. They answer the question: how long should this data exist before we delete it? Or, in some cases: how long must we keep this data before we are allowed to delete it? Both directions serve compliance and governance needs, not operational recovery.
The built-in retention windows vary by workload. Exchange Online deleted items are commonly retained for 14 days by default, configurable up to 30 days in most plans. SharePoint and OneDrive items sit in the Recycle Bin for up to 93 days across both deletion stages before being permanently removed. Version history can help recover overwritten files, provided versions have not been exhausted or purged.
These tools do have value. They stop accidental deletions from becoming instant disasters. They help organisations meet basic regulatory requirements around record-keeping. They give IT teams a short window to catch a problem. But they are not designed to answer the question backup answers: if something goes badly wrong, can we restore a clean, known-good copy of data fast enough for the business to keep running?
Where native retention falls short
Native Microsoft 365 retention fails in four specific scenarios that any realistic SME threat model should include.
Ransomware attacks. When ransomware encrypts files on a device, the sync client pushes those encrypted versions to OneDrive and SharePoint, overwriting clean copies everywhere. Version history can sometimes help, but sophisticated ransomware targets version history too. OneDrive’s native rollback is an all-or-nothing restore to a single point in time, which means any changes made after that point are lost. That is a destructive recovery option, not a precision tool.
Accidental or malicious deletion past the retention window. An employee deletes a SharePoint site or wipes their OneDrive. If the deletion is not caught within 93 days for SharePoint or 30 days for Exchange, that data is gone permanently. Microsoft cannot recover it. If a disgruntled employee deliberately destroys data on their last day using valid credentials, native tools may have no way to distinguish that from normal activity.
Misconfigured retention policies. A retention policy set incorrectly can silently delete data that should have been kept. Once the retention period expires and the deletion runs, the data is purged from all backend storage including the Preservation Hold library. There is no recovery path through native tools after that point.
Account compromise. When attackers gain access using stolen credentials, they operate as a legitimate user. They can delete, export, or corrupt data in ways that bypass Data Loss Prevention rules and audit policies. Native tools cannot distinguish between a valid user and an attacker using that user’s credentials.
Microsoft’s own position on this
Microsoft is explicit about who is responsible for data protection. Their Shared Responsibility Model draws a clear line: Microsoft manages infrastructure availability, hardware reliability, and platform uptime. Customers are responsible for protecting their data within that platform.
Microsoft’s own service terms state this plainly: they recommend that customers regularly back up content and data stored on the services using third-party applications. This is not fine print. It is a direct statement in the service agreement that the geo-redundancy Microsoft provides protects against data centre failure, not against user error, ransomware, or misconfiguration.
In 2024, Microsoft also launched a separate paid product called Microsoft 365 Backup. This product creates point-in-time snapshots for Exchange Online, SharePoint, and OneDrive with a recovery point objective of around 10 minutes and restore points going back up to 52 weeks. Its existence is significant. Microsoft built and sells a dedicated backup product precisely because native retention does not do the job. The two are not the same, and Microsoft treats them as distinct offerings.
How TTA sees this play out in Brisbane SMEs
The pattern is consistent across the businesses we work with in South-East Queensland. A business migrates to Microsoft 365, gets retention policies configured, and then ticks the backup question off the list. The assumption is that retention equals backup. It does not take a breach or a disaster to create a problem. An employee who accidentally deletes a shared folder of contracts, or a ransomware event that encrypts files through the sync client, is enough to expose the gap.
We see this particularly in professional services firms: accountants, solicitors, and consultants who hold years of client records in SharePoint or Exchange. A 30-day Exchange recovery window sounds reasonable until a client asks for an email thread from eight months ago as part of a dispute. If that data was not subject to a retention policy or a litigation hold, it is gone.
The second pattern we see is over-reliance on OneDrive’s Files Restore feature as a ransomware recovery tool. Files Restore is useful for limited incidents. For a full ransomware event affecting an entire tenant, it is not a credible recovery path. The restore is not granular, it is not fast, and it does not give you a verified clean state.
Our recommendation for any Microsoft 365 customer is to treat retention and backup as separate, complementary controls. Retention for governance and compliance. A dedicated third-party backup solution for independent, off-platform, point-in-time recovery. Both have a role. Neither substitutes for the other. For businesses that want an off-platform option aligned with Australian data sovereignty considerations, our Microsoft 365 Backup service is built around exactly this separation.
What a proper Microsoft 365 backup solution provides
A genuine Microsoft 365 backup solution does things native retention cannot. Understanding those differences helps business leaders ask the right questions when reviewing their current setup.
Independent, off-platform storage. Backup data should live outside your Microsoft 365 tenant. If an attacker compromises your tenant, they cannot reach your backup. Retention data held within Microsoft’s platform is subject to the same risks as the original data.
Point-in-time recovery. A good backup solution lets you restore individual emails, files, SharePoint sites, or Teams conversations to a specific point in time. Not an all-or-nothing rollback. Granular recovery means you get the data you need without overwriting everything else.
Extended retention periods. Australian businesses in regulated industries such as financial services, healthcare, and legal often have record-keeping obligations that extend well beyond the 93-day window Microsoft provides natively. A backup solution can hold data for years, aligned to your actual regulatory obligations rather than Microsoft’s platform defaults.
Ransomware resilience through immutable storage. Immutable backup copies cannot be altered or deleted for a defined period. Even if ransomware reaches your environment, the backup remains clean. That is the recovery point you need. Tools like Acronis Cyber Protect are built around this model, with immutable backups and workload coverage across Exchange, OneDrive, SharePoint, and Teams.
Verified restore testing. A backup you have never tested is a backup you cannot trust. A good managed backup service includes scheduled restore testing so you know the data is recoverable before you need it.
Backup and the Essential Eight
For Australian businesses working toward Essential Eight compliance, the backup control sits under Maturity Level 1. The ACSC Essential Eight requires that backups of important data, software, and configuration settings are performed and retained with the ability to recover data to a known good state. “Known good state” is the operative phrase. A retention window does not guarantee a known good state. A retained encrypted file is still an encrypted file.
At Maturity Level 2, the Essential Eight also requires that backup copies are not accessible from the systems being backed up. That is the immutability requirement in practical terms. Native Microsoft 365 retention, held within the same tenant, does not satisfy this requirement. An independent, off-platform backup does.
For businesses working through IT security assessments or preparing for Essential Eight audits, the backup control is often one of the first gaps we identify when native retention has been treated as sufficient.
Frequently asked questions
Does Microsoft back up my Microsoft 365 data?
No. Microsoft manages the infrastructure that runs Microsoft 365, including uptime, hardware reliability, and platform security. Data protection is the customer’s responsibility under Microsoft’s Shared Responsibility Model. Microsoft’s own service terms recommend that customers back up their data using third-party applications. Geo-redundancy protects against data centre failure, not against user error, ransomware, or misconfiguration.
What is the difference between Microsoft 365 retention and backup?
Retention controls how long content stays in the system before deletion. It serves compliance and governance needs. Backup creates independent copies of data outside the production environment, enabling point-in-time recovery after deletion, corruption, or a ransomware attack. Retention keeps data available for a limited time. Backup ensures data is recoverable, even after the retention window closes or the data is deliberately destroyed.
How long does Microsoft keep deleted emails and files?
Exchange Online deleted items are typically retained for 14 days by default, configurable up to 30 days. SharePoint and OneDrive items sit in the Recycle Bin for up to 93 days across both deletion stages. Once these windows close, data is permanently deleted through native Microsoft tools. There is no recovery path after that point unless a separate backup or retention hold was in place before the deletion occurred.
Can OneDrive version history recover my data after a ransomware attack?
Sometimes, if the versions remain intact and have not been purged or made inaccessible. In a serious ransomware event, that is not guaranteed. Sophisticated attacks target version history. OneDrive’s Files Restore is an all-or-nothing rollback that loses any changes made after the restore point. It is a last resort, not a reliable recovery tool. Independent backup with immutable storage is the only approach that provides a verified clean state.
Is Microsoft 365 Backup the same as native retention?
No. Microsoft 365 Backup is a separate paid product Microsoft launched in 2024. It creates point-in-time snapshots with a recovery point objective of around 10 minutes and restore points going back up to 52 weeks. It is designed for recovery scenarios, not compliance governance. It is billed separately on a pay-as-you-go basis. Its existence confirms that Microsoft treats backup and retention as distinct capabilities. Native retention does not substitute for it.
Does my business need both retention policies and a backup solution?
Yes. They serve different purposes and both are necessary. Retention policies manage your compliance obligations, ensuring data is kept for the required period and deleted when it should be. Backup creates independent recovery copies for operational resilience. Use retention for policy-driven lifecycle management. Use backup for recovery from deletions, ransomware, and errors. Treating one as a substitute for the other leaves a gap that is often only discovered during an incident.
Where do I start if I want to review my Microsoft 365 backup position?
Start by confirming whether your current Microsoft 365 setup has any independent, off-platform backup in place. If the answer is only retention policies and the Recycle Bin, you have a gap. A short IT audit will confirm which workloads are covered, what your current recovery windows are, and whether your setup meets Essential Eight backup requirements. TTA can run this assessment for businesses across South-East Queensland.
How do we get started?
If you are not sure whether your Microsoft 365 environment has genuine backup coverage, we can help you find out quickly. TTA works with businesses across South-East Queensland to close the gap between retention and real recovery. Talk to us about a Microsoft 365 IT audit or our managed Microsoft 365 Backup service. Get in touch to start the conversation.



