Is Your Microsoft 365 Data Actually Backed Up?
An associate leaves your consultancy on good terms. Handover done, laptop returned, no drama. Three weeks later you go looking for a client deliverable that lived in their OneDrive and a report you now need for a follow-on pitch. It’s gone. So is the account. And so, it turns out, is everything that was only ever saved there.
No ransomware. No hacker. No disaster. Just an ordinary leaver, an ordinary month passing, and a quiet assumption that Microsoft was keeping a copy of it all.
It wasn’t. And this is the single most expensive assumption in business IT.
If your working life runs on Microsoft 365 including Outlook, Teams, SharePoint, OneDrive, you’ve probably never questioned whether your data is backed up. It’s in the cloud. Microsoft are a trillion-pound company. Surely that’s handled? Here’s the honest answer, and what it means for a consultancy whose reputation rides on never losing a client’s work.
The most expensive assumption in business IT
Microsoft runs Microsoft 365 on what’s called a shared responsibility model. In plain English: Microsoft looks after the platform, and you look after your data.
Microsoft’s job is keeping the service running – the physical data centres, the network, the uptime (they guarantee 99.9%), copying your data across their sites so a hardware failure doesn’t take you offline. That part they do brilliantly.
Your data, though – protecting it, and being able to get it back after a deletion, a mistake or an attack, that is explicitly your responsibility, not theirs.
Don’t take our word for it. In 2024, Microsoft launched its own separate, paid backup product for Microsoft 365. Sit with that for a second: the company that runs the platform sells a standalone service to back it up. That’s about as clear a signal as you’ll get that the platform doesn’t do it for you.
What Microsoft actually protects (and why that isn’t backup)
It’s easy to confuse two things that sound similar: availability and recovery.
Microsoft gives you availability. They copy or “replicate” your data across multiple data centres so the service stays up. But replication isn’t backup. If a file is deleted or a folder is encrypted, that change replicates too. Every copy Microsoft holds is now the deleted, encrypted version. There’s no clean, earlier copy sitting safely to one side, because keeping one of those is your job, not theirs.
The four ordinary ways consultants lose data
You don’t need a dramatic cyber attack to lose work. Here’s how it usually happens:
- Someone deletes the wrong thing. The recycle bin buys you a window – typically around 30 days, up to 93 for some services, then it’s gone for good. Notice the gap a month later and you’re out of luck.
- An associate or contractor leaves. When a user account is closed, their mailbox and files are usually deleted after about 30 days. Everything saved only in their account goes with it.
- Ransomware strikes. Attackers know about recycle bins and retention settings – emptying them is one of the first things they do, precisely so you can’t simply restore. Microsoft 365 doesn’t offer the “immutable” (un-deletable) copies that would stop this.
- A retention policy misfires. One wrong setting quietly purges records you were relying on. Perfectly legal, perfectly permanent.
None of these are exotic. They happen in ordinary Yorkshire businesses every week.
Why this hits consultants harder than most
For a lot of businesses, losing a file is an annoyance. For a consultant, it can be the whole relationship.
Your deliverables are the product. Your engagement archives are your track record and, sometimes, your legal protection. Lose a client’s report, or a folder of work you were mid-project on, and you’re not just recreating hours you can’t bill – you’re explaining to a client why the people they trusted with their most sensitive material can’t lay hands on it. In a business built on trust, that conversation is the expensive part.
And because most consultancies have no in-house IT person watching, the gap tends to be discovered at the worst possible moment: when you go to restore something and find there’s nothing to restore from.
What proper backup actually looks like
A real backup is a separate, independent copy of your data that you can restore on your terms – not a recycle bin living inside the same account it’s meant to protect. Good practice follows the long-standing 3-2-1 rule: three copies of your data, on two types of storage, with one kept off-site.
For Microsoft 365 specifically, that means automated daily backups across Exchange, SharePoint, OneDrive and Teams; the ability to restore a single email, file or folder from a specific point in time (not just “everything or nothing”); sensible retention so you’re not limited to the last few weeks; and immutable storage, so an attacker can’t delete or encrypt the backup itself.
How we take this off your plate
This is exactly the kind of thing that should run quietly in the background and only ever matter on the day you need it. For our clients, we set up a dedicated, automated Microsoft 365 backup as standard – proper retention, granular restores, the lot, so a deleted folder, a departed associate or a bad afternoon with ransomware becomes a five-minute recovery instead of a lost month.
You shouldn’t have to think about your backups. You should just be able to trust they’re there.
Don’t wait for the day you need it
If you’re not certain what would happen to your client work in any of the four scenarios above, that uncertainty is worth resolving before it’s tested. Let’s have a chat – fifteen minutes, no jargon, no pressure. We’ll check what you’ve actually got protecting your Microsoft 365 data, and tell you honestly whether there’s a gap worth closing.
What People Always Ask Us About 365 Backup
Doesn't Microsoft back up my Microsoft 365 data automatically?
Not in the way most people assume. Microsoft keeps the platform running and copies your data across its own data centres for availability, but recovering data you’ve lost to deletion, a leaver, ransomware or a bad setting is your responsibility under their shared responsibility model. The clearest proof: in 2024 Microsoft began selling its own separate backup product for 365.
Isn't the recycle bin and version history enough?
They’re useful, but they’re not a backup – they live inside the same account they’re meant to protect, and they’re time-limited.
Once the retention window passes (often around 30 days), or if an attacker clears them, they’re no help. A real backup is a separate copy that sits outside your tenant.
What actually happens to a leaver's emails and files?
When you close a user’s account, their mailbox and files are typically deleted after about 30 days. Anything saved only in their OneDrive or mailbox (rather than a shared team location) goes with it. This is one of the most common ways consultancies lose work, and it’s completely avoidable with a backup in place.
If we got hit by ransomware, could we recover without a backup?
Often not. Ransomware typically encrypts your live files and then targets the recycle bins and retention settings so you can’t simply roll back. Because Microsoft 365 doesn’t offer immutable (un-deletable) copies natively, a separate, immutable backup is usually the only thing that lets you recover without paying a ransom.
Is setting up a Microsoft 365 backup complicated or expensive?
Not really. In general it’s a modest monthly cost, and once it’s configured it runs automatically in the background with nothing for you to do, the value only shows up on the day something goes wrong, a bit like insurance.
For our clients it’s built in: a daily backup of your emails and company documents, with 90-day retention, comes as standard with our plans, all set up and monitored for you. Need a longer safety net? We can look at extending that retention to suit how you work.

