What Microsoft 365 Backup means in practice
The most persistent misconception in Microsoft 365 administration is that the platform backs up customer data. Microsoft guarantees service availability and protects its infrastructure with replication. What it does not provide by default is point-in-time recovery of an organisation's own content after deletion, corruption, malicious insider action or ransomware that encrypts synchronised files.
Native protections exist and are useful within their limits. Recycle bins in SharePoint and OneDrive hold deleted items for a defined period. Versioning allows rollback of individual files. Retention policies and litigation hold preserve content beyond user deletion. Mailbox recoverable items provide a window for deleted mail. These are retention and compliance features rather than backup: recovery is item-focused, time-bounded, and awkward at scale. Restoring thousands of files to a point in time before an incident is not what they were designed for.
Third-party backup products and Microsoft's own backup offering address the gap by holding independent copies with longer retention, faster bulk restore and protection against tenant-level events. Selection criteria worth applying are workload coverage including Teams chat and channel content, restore granularity and speed, immutability, data residency, and whether the backup is in a separate security boundary with separate credentials from the production tenant.
Note also that Microsoft 365 backup and Azure Backup are different services solving different problems. Azure Backup protects Azure virtual machines, files, databases and on-premises workloads through Recovery Services vaults. Microsoft 365 backup protects SaaS content. Organisations frequently assume one covers the other; it does not.
The right starting point is the same as any other recovery decision: agree recovery time and recovery point objectives for the content that matters, then choose the mechanism that meets them and test a restore against a real scenario.
How we help with this
Related terms
- Disaster Recovery (DR)Disaster recovery is the capability to restore IT systems and data after a disruptive event such as ransomware, hardware failure, cloud region outage or physical damage.
- RTO and RPORecovery time objective is the maximum acceptable time a service can be unavailable after a disruption.
- APRA CPS 230CPS 230 is the APRA prudential standard on operational risk management.
- APRA CPS 234CPS 234 is the APRA prudential standard on information security.
