Is Microsoft 365 actually backed up? Shared responsibility, explained

Microsoft keeps the service running, but recovering your deleted or ransomwared data is your job. Here is what the shared-responsibility model really means.

Is Microsoft 365 actually backed up? Shared responsibility, explained

It’s one of the most reasonable assumptions a business owner can make. Your email, your files, your Teams chats all live in Microsoft 365, in Microsoft’s cloud, on Microsoft’s servers. So Microsoft is backing all of that up, right? If something goes wrong, you just call support and they restore it.

We hear this almost every week, and we understand why. You’re paying a large company every month to host your most important data. It feels safe to assume they’re also protecting it from loss. The hard part of this conversation is that the answer is mostly no, and the reason comes down to a single idea Microsoft publishes openly: the shared-responsibility model.

What the shared-responsibility model actually says

Microsoft splits the work of running a cloud service into two halves. They handle one half. You handle the other.

Their half is the platform. Keeping the data centers powered and online, replicating your data across regions so a single hardware failure does not take you down, patching the underlying systems, and defending the infrastructure itself. Microsoft is genuinely excellent at this part, and they spell it out in their shared responsibility documentation.

Your half is the data. The actual contents of your mailboxes, your SharePoint sites, your OneDrive folders, and your Teams. Protecting that content from the things that go wrong on your side of the line is your responsibility, not theirs. And Microsoft does not leave this to interpretation. Their own Services Agreement tells customers plainly: “We recommend that you regularly backup Your Content and Data that you store on the Services or store using Third-Party Apps and Services.”

When a vendor recommends in writing that you back up the data you keep with them, that is the whole story in one sentence.

The things on your side of the line

So what actually lives on your half? These are the everyday events that cause real data loss, and none of them are Microsoft’s problem to fix for you.

Someone deletes a file or an email and does not notice for a few months. Microsoft keeps deleted items for a limited window, typically measured in days, and after that retention period passes, it is gone. A departing employee’s mailbox gets removed during offboarding, and six weeks later you realize it held the only copy of a contract.

An account gets compromised through a phishing email, and the attacker deletes or alters data before you catch it. Ransomware encrypts files that then sync up into SharePoint and OneDrive, spreading the damage into the cloud copy. A well-meaning staff member overwrites a shared spreadsheet that twenty people depend on.

In every one of these cases, the Microsoft platform did exactly what it was built to do. It faithfully stored, replicated, and synced your data, including the bad changes. That is not a flaw. It is the design. Replication is not a backup, because a backup has to let you go back to a known good point in time, and replication just keeps the most recent state in more than one place.

“But there’s a recycle bin and retention policies”

There are, and they help. The recycle bin, version history, and retention policies in Microsoft 365 are useful for short-term, small-scale recovery. If someone deletes a file today and asks for it back tomorrow, those tools usually do the job.

What they are not is a substitute for real backup. Their retention windows are short and configurable, which means they can be shortened, turned off, or exhausted. They generally do not protect against a malicious admin or a compromised account that purposely clears them out. And they do not give you the kind of point-in-time recovery you need when you discover a problem weeks after it started. A genuine backup keeps independent copies of your data, on a separate system, with a retention history you control, so you can recover a specific version from a specific day even if the live environment has been tampered with.

What “backed up” should actually mean for Microsoft 365

When we set up backup for a client’s Microsoft 365 environment, we are after a few specific things. Independent copies stored outside the Microsoft tenant, so a problem inside your account cannot reach them. Coverage across the whole platform, which means Exchange mailboxes, SharePoint, OneDrive, and Teams, not just email. A retention history long enough to match how long it actually takes you to notice a problem. And the ability to restore granularly, down to a single mailbox, folder, or file, without a painful all-or-nothing recovery.

This is one piece of a bigger picture. Backing up Microsoft 365 sits alongside protecting your servers and your individual computers, and it is part of how we think about backup and disaster recovery as a whole. If you want a structured way to think through what you would do in a real outage, our Business Continuity / DR Plan Template walks through the questions worth answering before something breaks. And if your Microsoft 365 backup is handled by your IT provider rather than by you, it is worth confirming exactly what is and is not covered, which is its own conversation we cover in does your MSP already back up your data.

Where to start

You don’t need to overhaul everything at once. The most useful first step is simply finding out where you stand today. Is anything backing up your Microsoft 365 data outside of Microsoft? If so, how far back does it go, and has anyone ever tested a restore?

If you’re not sure, that’s exactly the kind of thing we’re happy to look at with you. We sit down, see what you have in place, and give you a straight answer about whether there’s a gap worth closing. As a genuinely local team in Alaska and Hawaii, we’d rather you understand the risk clearly than sell you something you don’t need.

Book a Discovery Call