Documentation7 min read

Microsoft 365 Email Continuity & Backup: What Microsoft Does Not Cover

Microsoft 365 is not a backup solution. Understanding the difference between Microsoft's built-in retention, third-party backup, and true email continuity determines whether your organization can survive an outage, ransomware attack, or accidental deletion.

Published August 11, 2026Updated August 25, 2026
Microsoft 365Email BackupEmail ContinuityExchange OnlineDattoBusiness ContinuityRansomware

The Microsoft 365 backup misconception

Most organizations assume that because their email lives in Microsoft's cloud, it is backed up. This is one of the most dangerous misconceptions in SMB IT. Microsoft's Shared Responsibility Model is explicit: Microsoft is responsible for the infrastructure and uptime of the platform. You are responsible for your data.

Microsoft's built-in retention and recycle bin features are designed for accidental deletion recovery within short windows — not for ransomware recovery, long-term archival, or continuity during an Exchange Online outage. If you need to restore a mailbox to a point-in-time state from 90 days ago, or keep sending email while Microsoft's servers are down, built-in tools will not get you there.

M365 SHARED RESPONSIBILITY — WHO OWNS WHAT Microsoft Responsibility Global infrastructure uptime (99.9% SLA) Physical data center security Platform-level replication & redundancy Deleted item recovery (30–93 days) Litigation hold & eDiscovery Your Responsibility Point-in-time backup & restore Ransomware / mass-deletion recovery Long-term archival beyond retention limits Email continuity during M365 outages Accidental / malicious deletion beyond 93 days Microsoft's SLA covers uptime — not your data. A ransomware attack that encrypts your mailboxes is your problem to recover from, not Microsoft's. Figure 1 — Microsoft 365 Shared Responsibility Model: platform vs. data ownership.

Figure 1 — Microsoft's Shared Responsibility Model. Microsoft protects the platform; your organization is responsible for data backup, continuity, and recovery.

What Microsoft's built-in tools actually provide

FeatureWhat it doesLimitation
Deleted Items folderHolds deleted emails for 30 days by defaultUser or attacker can empty it; no point-in-time restore
Recoverable Items (dumpster)Retains hard-deleted items for 14–30 daysRansomware that uses Exchange APIs can purge this too
Retention policiesPreserves content for compliance holdsNot a backup — cannot restore to a specific point in time
Litigation holdPrevents deletion for legal/eDiscovery purposesRequires E3/E5 license; not designed for operational recovery
Exchange Online geo-redundancyMicrosoft replicates data across data centersReplication copies corruption and ransomware encryption too

Three scenarios where built-in tools fail

1. Ransomware targeting Exchange Online

Modern ransomware variants use legitimate Microsoft Graph API calls to access and encrypt or exfiltrate mailbox data. Because the attack uses authenticated API calls, it bypasses Defender filters. The encryption propagates to Microsoft's replicated copies within minutes. Without a third-party backup that takes independent snapshots, there is no clean copy to restore from.

2. Accidental or malicious mass deletion

A disgruntled employee or compromised admin account deletes 500 mailboxes. Microsoft's recoverable items window is 30–93 days depending on your license and configuration — but only if the items were not purged from the recoverable items folder too. A third-party backup with immutable snapshots is the only reliable recovery path.

3. Exchange Online outage

Microsoft's 99.9% uptime SLA allows for approximately 8.7 hours of downtime per year. For organizations where email is mission-critical, that is unacceptable. Email continuity services maintain a secondary mail flow that activates automatically during an outage, allowing users to send and receive email from a web portal while Exchange Online is unavailable.

IDENETY's recommendation: Every M365 tenant should have a third-party backup solution with immutable, air-gapped snapshots. IDENETY deploys Datto SaaS Protection for M365 backup — three daily snapshots, unlimited retention, and one-click granular restore for individual emails, folders, or entire mailboxes. Included in the COMPLETE plan.

What to look for in an M365 backup solution

  • Immutable storage: Backup snapshots must be stored in a location that cannot be modified or deleted by a compromised M365 admin account or ransomware using Graph API.
  • Granular restore: Ability to restore individual emails, folders, contacts, calendar items, and SharePoint files — not just entire mailboxes.
  • Frequency: At minimum three snapshots per day. Hourly is preferred for high-volume environments.
  • Coverage: Mailboxes, SharePoint, OneDrive, and Teams data — not just email.
  • Retention: Unlimited or long-term retention for compliance requirements (HIPAA requires 6 years for covered entities).

See our Ransomware Defense for SMBs article for the broader backup and recovery strategy, and our Microsoft 365 Security Baseline for the full M365 hardening guide.

Contact our engineers to assess your current M365 backup posture and close the gaps before an incident forces the conversation.

About the Author