Does Microsoft 365 Back Up Your Data? What UK Businesses Need to Know

Most UK businesses assume Microsoft 365 automatically backs up their emails, files and data. It does not.

If you are asking “does Microsoft 365 back up your data?” the answer is: not in the way a true backup solution works.

Microsoft keeps its services running and provides short-term recovery tools, but it does not give you a fully independent, long-term backup that protects your business from ransomware, accidental deletion or admin errors.

This is where many organisations get caught out. Data is lost, recovery windows expire, and there is no way to restore it.

In this guide, you will learn exactly what Microsoft 365 covers, where the gaps are, and what UK businesses should do to properly protect their data.

What Microsoft is responsible for, and what you are

Microsoft works on a shared responsibility model. Microsoft is responsible for the platform: the data centres, the uptime and the security of the service itself. You are responsible for your data: who can access it, what gets deleted, and whether you can recover it when something goes wrong.

Microsoft’s own services agreement recommends that customers regularly back up the content they store in its services. That recommendation is easy to miss, and many organisations only find out how limited native recovery is after something has been lost.

Does Microsoft 365 Back Up Your Data by Default?

No. Microsoft 365 does not include full backup by default.

What it provides are built-in recovery features such as recycle bins, retention policies and short-term restore options. These tools help recover recently deleted data, but they are not designed for full backup or long-term protection.

A true backup creates a separate, secure copy of your data that can be restored at any point in time, even after ransomware attacks or major data loss events.

Without a dedicated backup solution, your organisation is relying on limited recovery windows and configurations that may not cover real-world incidents.

What Microsoft 365 recovers natively

Microsoft 365 has useful built-in recovery tools. They are designed for everyday mistakes, not for large-scale incidents. Typical default timeframes include:

Where the data lives What happens when it’s deleted Typical default window
SharePoint and OneDrive files Moves to the site recycle bin, then the site collection recycle bin 93 days in total
Exchange Online email Moves to Recoverable Items 14 days by default, extendable to 30 by an admin
A deleted user’s mailbox Soft-deleted and recoverable by an admin About 30 days
A deleted user’s OneDrive Retained after the account is removed 30 days by default, configurable by an admin

Microsoft’s documentation also describes a short window in which Microsoft Support may be able to restore SharePoint content from its own backups. Think of that as a last resort, not a service you can plan around. [Editor: check these timeframes against Microsoft’s current documentation on the day you publish and link each one to its Microsoft Learn page.]

Retention policies and holds, set up through Microsoft Purview, can keep content longer. They exist to meet legal and compliance needs, though, not to give you fast, point-in-time restore. A retention policy preserves content. A backup lets you roll back to a clean state.

Common Microsoft 365 Data Loss Scenarios UK Businesses Face

Understanding these risks explains why Microsoft 365 backup gaps matter in real business situations:

  1. Accidental deletion. Someone deletes a SharePoint site or a shared folder and nobody notices until the recovery window has passed.
  2. Ransomware and malicious encryption. Attackers can encrypt or delete files that sync from a compromised account to OneDrive and SharePoint.
  3. A rogue or compromised admin account. An administrator can delete mailboxes, sites and policies, and may also be able to remove the recovery options.
  4. Sync and migration errors. A faulty sync, bulk edit or third-party app can overwrite thousands of files before anyone spots it.
  5. Leavers. When an employee’s account and licence are removed, their mailbox and OneDrive may only be kept for a short time.

None of these is a Microsoft outage. They are all your data problems, which is why the shared responsibility model matters.

Backup, retention and archiving are not the same

Many organisations confuse Microsoft 365 retention policies with backup. They are not the same: 

 

Retention Archiving Backup
Main purpose Meet legal or policy requirements Store old data cheaply Recover after loss or attack
Restores to a point in time? Not designed to No Yes
Protects against admin or ransomware damage? Limited No Yes, if stored separately and protected from tampering
Typical owner Compliance Records or IT IT and security

This difference is critical when evaluating Microsoft 365 backup solutions or compliance readiness.

What about Microsoft’s own backup?

Microsoft now offers Microsoft 365 Backup, which became generally available in July 2024. It backs up Exchange Online mailboxes, SharePoint sites and OneDrive accounts and is bought on a pay-as-you-go basis in the admin centre. In April 2026 Microsoft announced general availability of restoring individual files and folders in SharePoint and OneDrive. Previously, restores in those services worked at site or account level.

It is a serious option. Anyone comparing choices should be aware of two things:

  • It is an optional, paid service. Turning it on is a decision you have to make. It isn’t included by default.
  • Coverage differs by service and changes over time, so check what is and isn’t protected today before you rely on it.

Many organisations still choose an independent third-party backup, mainly to keep a copy outside their own tenant and separate from the admin accounts that an attacker would target first.

What the UK GDPR expects of you

If you store personal data in Microsoft 365, you remain responsible for protecting it. Article 32 of the UK GDPR requires appropriate technical and organisational measures, including the ability to restore availability of and access to personal data in a timely manner after an incident. 

The ICO’s guidance on security explains what that means in practice. Regulated firms may also have operational resilience obligations from the FCA or PRA, so check what applies to you. This article is general information, not legal advice.

A quick self-check: could you recover from this?

Answer these honestly:

  • Can we restore one deleted SharePoint file or mailbox item without rolling back everyone’s work?
  • Do we know exactly how long deleted email and files are kept?
  • Is at least one backup copy stored outside our Microsoft 365 tenant?
  • Could a compromised admin account delete our backups?
  • Have we tested a real restore in the last 6 months?
  • How long would it take to recover after a ransomware attack, and who decides?
  • Do departing staff mailboxes and OneDrives have a defined retention process?
  • Is our backup location suitable for UK GDPR and our own contracts?

If you answered “no” or “not sure” to more than two of these, you likely have a recovery gap.

What to look for in a third-party backup

  • Granular restore. Recover a single item, not just a whole site or account.
  • Independence. Backups stored separately from your tenant and protected from deletion by a compromised admin.
  • Retention you control. Keep backups for as long as your policies and audits require.
  • Ransomware recovery. Fast restore to a clean point before the attack.
  • Data location. Know where backups are stored and whether UK or EU options exist.
  • Coverage. Check which services are protected, such as Exchange, SharePoint, OneDrive and Teams, and whether your other SaaS apps are included.
  • Testing and reporting. Evidence for auditors and for your own confidence.

How Brain Trips can help

Brain Trips is a UK partner of Spin.AI, whose SpinOne platform combines backup, ransomware detection, SaaS security posture management and data loss prevention for Microsoft 365 and other SaaS apps. If you’d like a second pair of eyes on your setup, we can run a free 20-minute risk review of your Microsoft 365 environment and send you a one-page summary of where the gaps are. There is no obligation.

Book a Quick Saas Review Now

 

Frequently asked questions

Does Microsoft 365 have a backup?
Microsoft protects its service and offers recovery tools such as recycle bins and retention. It also sells an optional, paid service called Microsoft 365 Backup. Neither is a backup you get automatically with a standard subscription.

How long are deleted emails kept in Microsoft 365?
By default, items removed from the Deleted Items folder stay recoverable for 14 days, and an administrator can extend this to 30 days. Retention policies can keep content for longer.

How long are deleted SharePoint and OneDrive files kept?
Deleted files stay in the two-stage recycle bin for 93 days in total, then are permanently removed unless a retention policy applies.

Is a retention policy the same as a backup?
No. A retention policy preserves content for legal or policy reasons. A backup lets you restore data to a chosen point in time after loss or attack.

Do I need a third-party backup if I use Microsoft 365?
Not every organisation does, but many choose one for a copy independent of their tenant, longer retention and granular restore. The self-check above will show how exposed you are.