Service desk: 778-321-2372 Existing clients: contact@brevitytech.ca
Guide

Microsoft 365 is not a backup

What each platform actually keeps, how long for, and the four gaps that catch small businesses out.

Microsoft 365 does not back up your data, and neither does Google Workspace. Both keep multiple copies of it so that a failure in their data centre does not lose your email, which is a different problem from the one most people have in mind. Neither platform is built to return a folder somebody tidied up three months ago, or the mailbox of an employee whose account you deleted to save a licence fee.

This gets discovered at the worst possible moment. Better to understand it before then.

What the platforms give you

Both include short-term recovery features, and they are useful. They are simply not backup.

Microsoft 365 keeps deleted mail in Deleted Items, then in a recoverable folder behind it, for roughly 14 to 30 days depending on how your tenant is configured. SharePoint and OneDrive have a two-stage recycle bin totalling about 93 days. A deleted user's mailbox and OneDrive are held for around 30 days before removal.

Google Workspace keeps items in Trash for about 30 days. After that an administrator has a further three to four weeks to recover deleted Drive files, and a similar window to restore a deleted user account.

Two caveats matter here. Those numbers are defaults, they differ by licence, and both vendors change them from time to time. And retention features like Litigation Hold or Vault are built for legal discovery, not for restoring a working environment. They can hold data indefinitely while remaining awkward or impossible to restore from in a hurry.

Check your own tenant rather than trusting the paragraph above. It takes ten minutes.

The four gaps that bite

Roughly in order of how often they cause a bad afternoon.

1. The offboarding gap

Someone leaves. A month or two later, tidying up licences, their account gets deleted. Their OneDrive or Drive goes with it once the grace period expires, along with the only copy of whatever they were working on. Nobody notices until a client asks for a file that only that person ever had.

This is the most common data loss we find, and it is entirely self-inflicted. It is also why offboarding deserves a written order of operations rather than improvisation. We wrote one up in the offboarding checklist most small businesses skip.

2. Deletion nobody noticed

Retention windows only help if somebody realises inside them. A folder reorganised in April and discovered missing in September is gone. The 93-day window closed while everything looked fine.

Here is the fundamental limitation. Platform retention protects you from mistakes you catch quickly, and does nothing about mistakes you catch slowly. Slow is how most of them get caught.

3. Ransomware and the sync folder

Ransomware encrypts files on a laptop. Because that laptop syncs to OneDrive or Drive, the encrypted versions cheerfully upload as the newest version of every file.

Version history can undo this and it has saved people. But it depends on versioning being enabled, on enough versions being retained, and on somebody noticing before the useful ones roll off. A real mitigation, and a thin one.

4. A compromised account covering its tracks

When an attacker gets into a mailbox to run invoice fraud, one of the first things they do is delete the evidence: their own replies, the forwarding rule, the messages that would tip off the real owner. Then you are reconstructing what happened from a mailbox that has been deliberately pruned, inside a 14-day window, while also dealing with the fraud.

Your insurer already asks about this

Cyber-insurance applications ask whether backups are offsite, whether they sit apart from your main environment, and whether a restore has been tested. "Microsoft keeps copies" is not a yes to any of the three.

Answering loosely carries real risk, because the answers on that form are representations about your business. We went through what underwriters ask in what your cyber insurer really wants to know.

What to do about it

Cheapest first:

  1. Look up your retention settings. Not the defaults you assume. Extend deleted-item retention to the maximum your licence allows, since it costs nothing.
  2. Turn on versioning in SharePoint, OneDrive or Drive if it is off, and confirm how many versions are kept.
  3. Add a third-party backup that writes to storage outside the platform, covering mail, files, and the sites or shared drives people use. This is the part that closes the gaps above, and for a small team it runs a few dollars per user per month.
  4. Test a restore. Pick a file and a mailbox item, restore them, and time it. An untested backup is a belief rather than a control.
  5. Write down who owns this and when it gets checked. Backups fail quietly, and a job that stopped running in March is worse than no job at all, because you think you are covered.

Steps 1 and 2 you can do this week without buying anything. Step 4 is the one people skip and the only one that proves the rest worked.

Backup sits in every plan we run, restore testing included, because a backup nobody has restored from is not a backup yet. It comes bundled with managed IT and help desk and sits alongside the security work that keeps you insurable.

If you are unsure what is being backed up in your business right now, the insurance-readiness review settles it in half an hour.

Related guides

Request a readiness review