Microsoft keeps Microsoft 365 running. It does not keep your data safe, and the difference between those two jobs is written into Microsoft's own service agreement. This guide covers what the native retention windows give you, where tenant data disappears for good, and how to choose between Microsoft's built-in backup and a third-party tool.
TL;DR
- Microsoft 365 backup is the customer's job, not Microsoft's. Microsoft runs the service and replicates it for uptime; protecting and restoring the data belongs to the tenant, per the shared responsibility model.
- Retention is short. Defaults run 14 to 93 days depending on the workload, then the data is gone.
- Microsoft now sells native backup. Microsoft 365 Backup lists at $0.15 per GB per month.
- MSPs sell recovery, not storage. Per-seat backup is a standard margin line.
What Microsoft Protects and What It Doesn't
Microsoft 365 runs on a shared responsibility model. Microsoft owns the infrastructure: datacenters, uptime backed by a financially guaranteed SLA, platform security, and replication of your data across regions so the service survives a hardware failure. The customer owns the data itself: who can touch it, how long it's retained, and how it comes back after something goes wrong.
Microsoft says this in plain text. Its Services Agreement recommends that customers regularly back up content stored on the services using third-party apps and services. The company that runs Exchange Online is telling you, in a legal document, that keeping copies of your mailboxes is not part of the deal.
The customer side of the split is wider than backup alone. Identity and access sit with the tenant: conditional access, MFA enforcement, admin role hygiene. So does retention configuration, and this is where quiet disasters start. A retention policy scoped one site too wide, or set to delete instead of retain, purges content exactly as instructed. Microsoft executed the config faithfully; the config was wrong. That's a tenant-side loss, and it lands on whoever manages the tenant.
Replication makes the split confusing, because a tenant's data does live in multiple datacenters. But replication copies everything, including mistakes. A deleted SharePoint library replicates as deleted. A mailbox encrypted by ransomware replicates as encrypted. Replication protects Microsoft's uptime promise. It does nothing for your last known good copy.
The Retention Windows That Decide What You Get Back
Every recovery conversation in Microsoft 365 ends at a retention window. These are the defaults, per Microsoft's documentation (September 2026):
| Workload | Native window | After that |
|---|---|---|
| Exchange deleted items | 14 days by default, extendable to 30 | Purged, unrecoverable |
| Deleted mailbox (user removed) | 30 days | Purged with the account |
| SharePoint recycle bin | 93 days across both stages | Purged, unrecoverable |
| OneDrive of a departed user | 30 days by default, then the recycle bin | Purged, configurable up to 10 years |
| Teams chat | Follows mailbox retention | Files ride on SharePoint and OneDrive |
The recycle bin is a grace period, not a time machine. It catches the deletion someone notices on Tuesday. It does nothing for the deletion nobody notices until the auditor asks in March.
There's one genuine rollback tool in the box: Files Restore can rewind a OneDrive account or a SharePoint document library up to 30 days, which makes it a fair first response to a ransomware hit on synced files. But it leans on version history and the recycle bin to do the rewinding. Content already purged from those is outside its reach, and 30 days is the hard ceiling.
Retention policies and litigation hold can stretch the windows, and admins should use them. But they're compliance tools. They keep specific content from being purged; they don't give you a point-in-time restore of a mangled site, a rolled-back mailbox, or a tenant recovered to the hour before an incident. That's what backup means, and nothing native to a standard license does it.
What Counts as Backup in a SaaS World
The word backup gets stretched to cover everything from a recycle bin to a retention policy, so it's worth pinning down what the real thing does. A backup is an independent copy, taken on a schedule, restorable to a point in time you choose. Independent means it survives whatever hits the original, including a compromised admin. Scheduled means the copy exists before you need it. Point-in-time means you can pick the hour before the incident, not just the most recent state of the wreckage.
Restore granularity matters as much as the copy. A single email for the client who deleted one contract thread. A full mailbox for the offboarded employee. A whole site collection for the ransomware case, at a speed that doesn't turn a bad day into a bad month. Any tool that can't do all three levels will eventually leave you explaining why the data exists but can't come back in usable form.
Measured against that bar, everything native to a standard Microsoft 365 license is either a grace period or a compliance hold. Useful, worth configuring, and not backup.
Four Ways Tenant Data Disappears for Good
Kaseya's State of Backup and Recovery Report 2025 surveyed over 3,000 IT professionals, and the causes of SaaS data loss it found are worth pinning to the wall. Malicious deletion drove more than half of reported incidents. Accidental deletion and human error accounted for another 34%.
In a Microsoft 365 tenant, loss usually arrives through one of four doors:
- Accidental deletion that outlives the window. A cleanup script, a wrong folder, a "we'll never need this" moment. If nobody notices within the retention window, it's permanent.
- Malicious deletion. A compromised admin account or a departing employee with a grudge. The report's data says this is the front door, and it's the one that empties recycle bins on purpose.
- Ransomware. Files encrypted through a synced OneDrive client or a compromised account replicate as encrypted. Files Restore helps inside its 30 days; beyond it, Microsoft can't roll your tenant back.
- Offboarding. A license gets removed, 30 days pass, and the departed employee's mailbox and OneDrive quietly stop existing. This one hides inside routine IT hygiene.
None of these are infrastructure failures. Microsoft's SLA stays intact through every one of them. That's the gap in one sentence: the platform can be perfectly healthy while your data is perfectly gone.
Microsoft's Own Backup: What $0.15 Per GB Buys
Microsoft ships a native product for this now, and it changes the conversation. Microsoft 365 Backup covers Exchange, SharePoint, and OneDrive, holds a rolling 365 days of restore points, and restores at speeds third-party tools struggle to match because the data never leaves Microsoft's estate. Pricing is pay-as-you-go through Azure at a list price of $0.15 per GB of protected content per month (September 2026), with no separate charge for restores.
Setup is straightforward but has one operational wrinkle for MSPs: billing runs through an Azure subscription, not the Microsoft 365 license. A client with no Azure footprint needs one created just to pay for backup, and the charge scales with data rather than seats, which makes the invoice a moving number. Protection policies are set per workload in the admin center, and restore points start accumulating from the day you turn it on, not before. Turn it on before the incident, or it has nothing to restore.
The per-GB model deserves arithmetic before you commit a client to it. Take a 50-seat tenant averaging 40 GB of protected content per seat: that's 2 TB, or $300 a month at list, and the protected total includes recycle bins and held deleted content. Mailboxes with years of archives make the meter run.
The same design choice that makes it fast is also its limit. Backups live inside the same Microsoft estate as the tenant, so a compromised global admin or a billing lapse touches both the data and its copies. The 365-day cap is fixed, Teams chat isn't a target, and there's no cross-tenant or off-platform copy. For plenty of tenants that's an acceptable trade. For a compliance-bound client, or an MSP that wants backups a tenant admin can't reach, it isn't.
A side-by-side of what Microsoft's own backup covers against what a third-party tool adds, worked through on real tenants:
Native or Third Party: How to Make the Call
Backup sits inside a wider continuity plan, and the right choice depends on the recovery objectives you've set in your BCDR strategy. The short version:
| Question | Native Microsoft 365 Backup | Third-party backup |
|---|---|---|
| Where do copies live? | Inside Microsoft's estate | Separate cloud, separate credentials |
| Retention | Rolling 365 days, fixed | Configurable, often unlimited |
| Coverage | Exchange, SharePoint, OneDrive | Varies; Teams, Groups, Planner in some tools |
| Pricing | $0.15/GB/month, list | Typically flat per seat |
| Restore speed | Fast, same-platform | Slower, network-bound |
| Multi-tenant MSP console | Limited | Standard in MSP-focused tools |
| Admin compromise isolation | No | Yes, when credentials are separated |
Two client profiles show how the table plays out. A 20-seat professional services office with light mailboxes and no retention obligations gets real protection from the native product for tens of dollars a month, and the fast same-platform restore is exactly what its deletion incidents need. A 200-seat firm with seven-year retention requirements, heavy Teams usage, and an insurer asking pointed questions about ransomware isolation needs copies outside the tenant, retention past the 365-day cap, and an audit trail. That's third-party territory, and the per-seat fee is the cost of being able to say yes to the auditor.
Two rules of thumb hold up. If the client's main risk is deletion and the budget is tight, native backup at $0.15 per GB beats no backup by an enormous margin. If the client has compliance retention beyond a year, needs Teams coverage, or you want copies that survive a compromised tenant admin, a third-party tool earns its fee.
The 3-2-1 logic that shaped on-prem backup still applies in SaaS: more than one copy, more than one platform, at least one set of credentials that a tenant breach can't reach.
If you want the shortlist that MSPs running this in production keep landing on, this thread is the one to read:
Backup Is a Margin Line, Not a Cost Line
For MSPs, Microsoft 365 backup is one of the cleanest recurring lines in the stack. The client pays per seat, the tool bills per seat, and the delta is margin earned by owning recovery when it counts. What you're selling is the restore: named recovery objectives, a tested process, and an answer within hours instead of a support ticket into the void.
Packaging decides whether that margin survives contact with procurement. Folding backup into the per-user managed services price keeps the conversation about outcomes and spares you re-selling it seat by seat. Passing the native product's per-GB Azure charge through at cost works too, but then you're forwarding a fluctuating invoice instead of owning a predictable line. Either way, the quarterly business review is where backup earns its keep: showing the client their tested restore timings turns an invisible line item into visible proof of competence.
The same Kaseya 2025 report has the stat that sells it. More than 60% of organizations believed they could recover from a downtime event within hours; only 35% could. That spread between confidence and reality is the pitch, and it's also the risk you carry if you're reselling backup you've never test-restored.
Picking the tool layer is its own decision, and we've covered the field in our roundup of MSP backup platforms. Whatever you pick, put restore SLAs in the contract and test against them. A backup you've never restored is a guess with an invoice.
Rolling Out Microsoft 365 Backup Across Client Tenants
A rollout that holds up under audit follows the same sequence every time:
- Audit each tenant's current retention settings and document what native windows apply today.
- Set recovery objectives per workload. How much data can the client lose, and how long can they wait? Our guide to continuity planning covers how those targets get set.
- Choose coverage deliberately: Exchange, SharePoint, OneDrive as the floor, Teams and Groups where the tool and the client's usage justify it.
- Automate enrollment so new users and new sites land in the backup policy on creation, not at the next quarterly review.
- Test restores quarterly, at file, mailbox, and site level, and record the timings against the SLA you sold.
Write the restore runbook into your PSA while you're at it, per tenant: which tool holds the copies, who holds the credentials, what the tested timings were. When the restore request lands at 4:50pm on a Friday, the tech who picks it up shouldn't need tribal knowledge to start.
Step 5 is the one that separates a backup line item from a recovery practice. The report numbers above show confidence outrunning tested reality by nearly two to one. Be the operation whose numbers are measured instead.
Provider risk is its own failure mode. After the Cove incident, MSPs started pricing what a second backup vendor against the same tenant would cost them:
Where OpenFrame Fits
OpenFrame doesn't back up Microsoft 365, and we won't pretend it does. It's Flamingo's AI-native all-in-one MSP/IT platform: RMM, native PSA included, and AI agents that resolve tickets instead of suggesting replies. Backup tooling runs alongside it, and the restore requests, retention questions, and offboarding tickets that backup generates are exactly the level one and two work the agents take off your techs' plate.
The stack economics connect, too. Consolidating RMM and PSA into one affordable platform with no vendor lock-in frees budget for the layers that genuinely need a dedicated tool, and a tested backup is high on that list. Here's what practitioners made of it when it hit r/msp:
And if you'd rather watch it work than read about it:
The Only Copy That Counts Is the One You Can Restore
Microsoft keeps the lights on and says so precisely: uptime is theirs, data is yours. The retention windows are grace periods measured in days, the loss scenarios are mostly human, and both the native product and the third-party market now give you workable ways to close the gap. Price the native option with the per-GB math done, hold third-party tools to the isolation standard, and test every restore you sell.
The clients won't ask about any of this until the day they ask about nothing else. Have the answer measured before the question arrives.
Content Marketing Lead
Ohayo! I'm Kristina, and I'm doing good things with content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
