Here is a conversation we have had more times than we can count. A client calls because someone deleted a SharePoint library, or a departing employee’s mailbox was wiped, or ransomware encrypted everything in a synced OneDrive folder. We ask what their backup situation looks like. They say, reasonably, “it’s in the cloud, so Microsoft has it.”
Microsoft does not have it. Or more precisely: Microsoft has it for a while, under conditions, and then it is gone forever.
The Shared Responsibility Model, In Plain English
Microsoft operates under what they call a shared responsibility model, and it is worth understanding because it is not hidden — it is published, it is just not what anyone reads when they buy licenses.
Microsoft’s responsibility is the service. Keeping Exchange Online running, keeping SharePoint available, replicating their infrastructure across datacenters so a hardware failure on their end never becomes your problem. They are very good at this.
Your responsibility is your data. What is in the mailboxes, what is in the libraries, who has access to it, and whether you can get it back after a mistake, a departure, or an attack.
Microsoft protects you from their failures. Nothing in that arrangement protects you from yours.
What Retention Actually Gives You
Microsoft 365 does have recovery windows, and they are genuinely useful for the ordinary case of somebody deleting an email on Tuesday and wanting it back on Wednesday. The problem is that they are short, and they are the only thing standing between you and permanent loss.
- Deleted items sit in a recoverable folder for a limited window, then they are purged
- Deleted user accounts — and the mailbox attached to them — are removed on a schedule after the license is released
- Deleted SharePoint sites go to a recycle bin, then a second-stage recycle bin, then nothing
Every one of those windows is measured in days or weeks. Data loss is frequently discovered in months. That gap is where businesses get hurt.
The Four Ways People Actually Lose Data
1. Someone deletes the wrong thing
The most common cause by a wide margin, and the least dramatic. A folder gets dragged somewhere it should not have gone. A library gets cleaned up by someone who did not realize another department was using it. Nobody notices for two months.
2. An employee leaves
Offboarding removes the license to stop the billing, which starts the clock on deleting the mailbox. Six months later somebody needs that person’s email for a dispute, a client history, or an audit, and it is not there.
3. Ransomware
This is the one people underestimate. OneDrive sync is a feature until malware encrypts the local files, at which point sync faithfully replicates the encryption to the cloud copy. Versioning helps, if it is configured and if the retention is long enough, and if the attacker did not simply exhaust the version history first.
4. A malicious insider
Rarer, but it happens, and it tends to happen on the way out the door. Someone with legitimate access deletes deliberately, and they usually know roughly how long the recycle bin holds things.
What Actually Protects You
Independent, third-party backup of your Microsoft 365 tenant. Not a different Microsoft feature — a separate system, holding separate copies, under separate retention that you control.
- Mail, OneDrive, SharePoint, and Teams all backed up, because data lives in all four and people forget about the last two
- Retention you choose, measured in years, not the vendor’s default fortnight
- Granular restore, so you can recover one mailbox or one folder without a project
- Restores that get tested, because a backup nobody has ever restored from is a belief, not a control
The Compliance Angle
If you are subject to HIPAA, PCI-DSS, or a client’s security review, this stops being a good idea and becomes a documentation problem. Auditors ask how long you retain data, how you would recover it, and when you last proved that. “Microsoft handles it” is not an answer any of them accept.
Is Your Microsoft 365 Actually Protected?
We will review your tenant — backup, security settings, licensing, and who has admin rights — and tell you what is exposed. No cost, no obligation.
