The Microsoft 365 backup misconception
Most organizations assume that because their email lives in Microsoft's cloud, it is backed up. This is one of the most dangerous misconceptions in SMB IT. Microsoft's Shared Responsibility Model is explicit: Microsoft is responsible for the infrastructure and uptime of the platform. You are responsible for your data.
Microsoft's built-in retention and recycle bin features are designed for accidental deletion recovery within short windows — not for ransomware recovery, long-term archival, or continuity during an Exchange Online outage. If you need to restore a mailbox to a point-in-time state from 90 days ago, or keep sending email while Microsoft's servers are down, built-in tools will not get you there.
Figure 1 — Microsoft's Shared Responsibility Model. Microsoft protects the platform; your organization is responsible for data backup, continuity, and recovery.
What Microsoft's built-in tools actually provide
| Feature | What it does | Limitation |
|---|---|---|
| Deleted Items folder | Holds deleted emails for 30 days by default | User or attacker can empty it; no point-in-time restore |
| Recoverable Items (dumpster) | Retains hard-deleted items for 14–30 days | Ransomware that uses Exchange APIs can purge this too |
| Retention policies | Preserves content for compliance holds | Not a backup — cannot restore to a specific point in time |
| Litigation hold | Prevents deletion for legal/eDiscovery purposes | Requires E3/E5 license; not designed for operational recovery |
| Exchange Online geo-redundancy | Microsoft replicates data across data centers | Replication copies corruption and ransomware encryption too |
Three scenarios where built-in tools fail
1. Ransomware targeting Exchange Online
Modern ransomware variants use legitimate Microsoft Graph API calls to access and encrypt or exfiltrate mailbox data. Because the attack uses authenticated API calls, it bypasses Defender filters. The encryption propagates to Microsoft's replicated copies within minutes. Without a third-party backup that takes independent snapshots, there is no clean copy to restore from.
2. Accidental or malicious mass deletion
A disgruntled employee or compromised admin account deletes 500 mailboxes. Microsoft's recoverable items window is 30–93 days depending on your license and configuration — but only if the items were not purged from the recoverable items folder too. A third-party backup with immutable snapshots is the only reliable recovery path.
3. Exchange Online outage
Microsoft's 99.9% uptime SLA allows for approximately 8.7 hours of downtime per year. For organizations where email is mission-critical, that is unacceptable. Email continuity services maintain a secondary mail flow that activates automatically during an outage, allowing users to send and receive email from a web portal while Exchange Online is unavailable.
What to look for in an M365 backup solution
- Immutable storage: Backup snapshots must be stored in a location that cannot be modified or deleted by a compromised M365 admin account or ransomware using Graph API.
- Granular restore: Ability to restore individual emails, folders, contacts, calendar items, and SharePoint files — not just entire mailboxes.
- Frequency: At minimum three snapshots per day. Hourly is preferred for high-volume environments.
- Coverage: Mailboxes, SharePoint, OneDrive, and Teams data — not just email.
- Retention: Unlimited or long-term retention for compliance requirements (HIPAA requires 6 years for covered entities).
See our Ransomware Defense for SMBs article for the broader backup and recovery strategy, and our Microsoft 365 Security Baseline for the full M365 hardening guide.
Contact our engineers to assess your current M365 backup posture and close the gaps before an incident forces the conversation.
.png)