Does Microsoft 365 Back Up Your Data? What Kent Businesses Need to Know in 2026

24th August 2026

By the Gray IT team, Cyber Essentials certified IT and data protection specialists based at the Innovation Centre Medway, Chatham. Supporting Kent businesses since 1996.

Last updated: 24th August 2026

TL;DR: The short answer

No, Microsoft 365 does not back up your data in the way most business owners assume. Microsoft keeps your service running and replicates data across its own data centres for resilience, but under the Microsoft 365 shared responsibility model the customer, not Microsoft, is responsible for protecting business data against accidental deletion, ransomware, malicious insiders and departing staff. Microsoft’s own Services Agreement recommends you use a third party app to back up your content. Native retention is short and limited: deleted emails sit in the recycle bin for around 14 to 30 days and deleted OneDrive and SharePoint files for 93 days, after which they are gone for good. A dedicated Microsoft 365 backup restores any item to any point in time, often years later. For a Kent business that runs on Outlook, Teams, SharePoint and OneDrive, a separate backup is not optional. It is the difference between a five minute restore and a permanent loss.

That is the summary. The rest of this guide explains exactly what Microsoft does and does not protect, how long you really have to recover deleted data, and what a proper backup looks like.

GRAY IT

Does Microsoft 365 back up your data?

Microsoft 365 is highly available, but availability is not the same as backup. Microsoft guarantees that the service will be online and that your data is copied across multiple data centres so a hardware failure at one site does not take you offline. What Microsoft does not do is keep a separate, recoverable copy of your data that you can roll back to after a mistake or an attack.

The distinction matters because most data loss is not caused by Microsoft’s infrastructure failing. It is caused by people and software inside your own organisation. An employee empties a mailbox, a finance folder is overwritten, ransomware encrypts a SharePoint site, or a leaver’s account is deleted along with everything in it. In every one of those cases, Microsoft’s replication faithfully copies the damage. There is no undo button once the native retention window closes.

What is the Microsoft 365 shared responsibility model?

The shared responsibility model is Microsoft’s own framework for who protects what. It splits duties between Microsoft and you, the customer.

Microsoft is responsible for the physical infrastructure, the data centres, platform uptime, and security of the underlying service. It handles hardware, power, network and the built in redundancy that keeps Microsoft 365 online.

You are responsible for your data. That means protecting it against accidental and malicious deletion, retaining it for as long as your business or the regulator requires, meeting compliance obligations, and controlling who has access. Microsoft states plainly in its Services Agreement that it recommends customers regularly back up content using third party apps and services.

In short, Microsoft keeps the lights on. Keeping a recoverable copy of your business data is your job.

Does Microsoft 365 back up email?

This is one of the most common questions we hear from Kent business owners, and the honest answer surprises people. Exchange Online does not back up your email. It applies short retention rules.

When a user deletes a message it moves to Deleted Items. When that folder is emptied the message drops into the Recoverable Items area, where it is held for 14 days by default. An administrator can extend this to a maximum of 30 days. After that the message is purged and cannot be recovered through Microsoft. If a whole mailbox is deleted, for example when you remove a leaver’s account, the mailbox is soft deleted for 30 days and then permanently erased.

So if someone deletes an important email chain and nobody notices for a month, or a departing employee’s mailbox is closed and a legal query lands six weeks later, the data is simply gone. A backup, by contrast, keeps that mailbox recoverable indefinitely.

How long does Microsoft 365 keep deleted files?

Native retention differs across each Microsoft 365 app, and the windows are shorter than most people expect. Here is what the defaults actually give you.

Microsoft 365 area Default retention after deletion What happens next
Exchange email (Deleted Items emptied) 14 days, extendable to 30 Permanently purged
Deleted mailbox (leaver’s account) 30 days Permanently erased
OneDrive files 93 days in recycle bin Permanently deleted
SharePoint files 93 days in recycle bin Permanently deleted
Deleted OneDrive user 30 days, then 93 day site state Only a SharePoint admin can restore
Teams chats and files Follows Exchange and SharePoint limits Permanently deleted

The pattern is clear. Native retention buys you weeks or a few months, not the years that a growing business, an auditor, or a legal dispute can demand. Once a window closes, Microsoft cannot bring the data back.

Replication is not backup: why the difference matters

Microsoft 365 replicates your data between data centres, and this genuinely protects you against a Microsoft outage. The problem is that replication copies everything exactly as it is, including damage. If a file is deleted, the deletion replicates. If ransomware encrypts a document, the encrypted version replicates. If a record is corrupted, every copy is corrupted.

A backup works differently. It takes independent, point in time snapshots of your data and stores them separately, so you can travel back to the version that existed before the deletion, encryption or corruption happened. Replication answers the question “is the service still up”. Backup answers the question “can I get last Tuesday’s version of this file back”. A business needs both, and Microsoft only provides the first.

What are the real risks to your Microsoft 365 data?

In our experience supporting Kent SMEs, data loss almost never comes from Microsoft. It comes from five everyday scenarios that native retention does not adequately cover.

The first is accidental deletion. Someone clears out a mailbox or overwrites a shared folder, and the loss is noticed weeks later once the retention window has closed. The second is ransomware, which encrypts files across OneDrive and SharePoint faster than staff can react, and the encrypted copies replicate through the platform. The third is the malicious insider or a disgruntled leaver who deletes records on the way out. The fourth is the departing employee whose account is offboarded, taking their mailbox and files with it before anyone checks what was inside. The fifth is misconfiguration, where a well meaning change to a retention policy or a sync setting quietly destroys data.

Every one of these sits squarely in the customer’s half of the shared responsibility model. This is also where backup and security overlap. Ransomware is both a data loss event and a security incident, which is why we treat backup as part of a wider resilience plan alongside our cyber security service

Does GDPR require you to back up your data?

Yes, in effect it does. UK GDPR Article 32 requires you to keep personal data secure and, importantly, to be able to restore its availability and access in a timely manner after an incident. A business that loses customer records to ransomware or accidental deletion, with no way to recover them, has a data protection problem as well as an operational one.

Backup is therefore part of compliance, not just IT housekeeping. It supports the security and availability duties that sit at the heart of the regulation, and it helps you answer a subject access request or an audit even after something has gone wrong. 

What does a proper Microsoft 365 backup solution look like?

A dedicated third party backup fills the gaps that native retention leaves open. A good solution for a Kent business should do the following.

It should protect every workload, including Exchange email, OneDrive, SharePoint and Teams, not just mailboxes. It should back up automatically at least once a day so nothing depends on someone remembering. It should offer flexible retention, from short term recovery all the way to multi year archives that satisfy auditors and legal holds. It should allow granular restore, so you can recover a single email, a single file or a whole account without rebuilding everything. And it should store the backup in a separate, secure location so that ransomware hitting your live tenant cannot reach your recovery copies.

The result is simple in practice. When something is deleted, encrypted or lost, you restore it in minutes to the exact state it was in before, whether that was yesterday or three years ago.

Native retention versus dedicated backup

Feature Microsoft 365 native retention Dedicated third party backup
Protects against Microsoft outage Yes Yes
Recovers accidentally deleted email after 30 days No Yes
Recovers files after the 93 day window No Yes
Restores a deleted leaver’s mailbox months later No Yes
Rolls back a ransomware or corruption event No Yes
Long term and legal hold retention Limited Yes, years
Granular restore of a single item Partial Yes
Backup stored separately from the live tenant No Yes

How Gray IT protects Kent businesses

We have supported businesses across Kent and Medway since 1996, from Maidstone and Chatham to Gillingham, Rochester and Tonbridge. Our cloud backup and disaster recovery service gives you automated, independent backups of your entire Microsoft 365 environment, with fast, granular restore and retention set to match your compliance needs. If disaster strikes, we get you back up and running quickly and simply.

If you are not sure whether your Microsoft 365 data is genuinely protected, we will tell you straight. Book a free IT and security review through our managed IT services team and we will check your backup, retention and recovery position, and show you exactly where the gaps are. Call 01622 391300 or email support@grayit.co.uk.

Frequently asked questions

Does Microsoft 365 automatically back up my data? No. Microsoft 365 replicates data across its data centres for resilience and applies short retention rules, but it does not keep a separate, recoverable backup. Under the shared responsibility model the customer is responsible for backing up their own data, and Microsoft’s Services Agreement recommends using a third party backup app.

Does Office 365 back up email? Not as a true backup. Deleted emails are held in the Recoverable Items area for 14 days by default, extendable to a maximum of 30 days, after which they are permanently purged. A deleted mailbox is retained for 30 days and then erased. A dedicated backup keeps email recoverable indefinitely.

How long does Microsoft 365 keep deleted files? OneDrive and SharePoint files stay in the recycle bin for 93 days, after which they are permanently deleted. Emails are held for 14 to 30 days and deleted user accounts for 30 days. These native windows are much shorter than most businesses assume.

Is replication the same as backup? No. Replication copies your data across Microsoft’s data centres exactly as it is, including deletions, corruption and ransomware encryption. Backup takes independent point in time snapshots you can roll back to, which replication cannot do.

Do I need third party backup if I only use Microsoft 365 for email? Yes. Email is one of the most commonly lost data types, through accidental deletion, offboarded leavers and mailbox mistakes. Native retention only protects it for up to 30 days, so a backup is essential if you rely on your inbox for records or compliance.

Does GDPR require Microsoft 365 backup? UK GDPR Article 32 requires you to keep personal data secure and to restore its availability after an incident. In practice this means you need a reliable way to recover data, which native retention alone does not guarantee, so backup forms part of your compliance position.