Skip to main content

How to Set Up a Business Backup Strategy for Microsoft 365

A practical guide to backing up Microsoft 365 data including Exchange Online, OneDrive, SharePoint, and Teams. Covers the 3-2-1 rule, retention policies, and third-party backup tools.

7 min readUpdated March 29, 2026

Overviewsection

Microsoft operates Microsoft 365 infrastructure with high availability and geo-redundancy. However, Microsoft's responsibility ends at platform availability — they do not protect against data loss caused by accidental deletion, malicious insiders, ransomware, or retention policy gaps.

The Microsoft Services Agreement states: "We recommend that you regularly backup Your Content and Data that you store on the Services."

This guide explains what Microsoft protects (and what it does not), and how to build a backup strategy that covers the gaps.

What Microsoft Protects vs. What You Need to Protectsection

RiskMicrosoft's ResponsibilityYour Responsibility
Data centre failureYes — geo-redundant replication—
Hardware failureYes — automatic failover—
Accidental deletion by userPartial — recycle bin (93 days max)Yes — long-term recovery
Malicious deletion by insiderPartial — recycle bin (if not purged)Yes — immutable backup
Ransomware encrypting filesNo — encrypted files sync to cloudYes — point-in-time recovery
Retention policy gapsNo — data deleted after retention expiresYes — archive and backup
Legal hold / compliance archivePartial — requires proper configurationYes — backup as secondary copy
Account compromise + data exfiltrationNoYes — detection and backup
Danger

The biggest misconception about Microsoft 365 is that "it's in the cloud, so it's backed up." Microsoft guarantees the infrastructure is available — not that your data is recoverable after user error, attack, or policy expiry.

Microsoft 365 Built-In Retentionsection

Before setting up third-party backup, understand what Microsoft retains natively:

ServiceDeleted Item RetentionRecycle BinVersioning
Exchange Online14 days (recoverable items: 30 days)30 days deleted items folderN/A
OneDrive93 days recycle binSecond-stage: 93 days500 versions per file
SharePoint93 days recycle binSecond-stage: 93 days500 versions per file
Teams chatRetained indefinitely (by default)N/AN/A
Teams filesBacked by SharePoint/OneDriveSame as SharePointSame as SharePoint

What this meanssection

  • If a user deletes an email and empties their Deleted Items, you have 30 days to recover it from the recoverable items folder
  • If a user deletes a OneDrive file, you have 93 days to restore from the recycle bin
  • After retention expires, the data is permanently gone unless you have a backup

The 3-2-1 Backup Rulesection

The gold standard for backup strategy:

  • 3 copies of your data
  • 2 different storage media or locations
  • 1 copy offsite or offline (air-gapped)

For Microsoft 365, this translates to:

  1. Original data in Microsoft 365 (copy 1)
  2. Third-party backup in a separate cloud (copy 2)
  3. Offline or immutable copy that ransomware cannot reach (copy 3)
SolutionBackup CoveragePricing ModelBest For
Veeam Backup for M365Exchange, OneDrive, SharePoint, TeamsPer-user or per-TBBusinesses wanting self-managed backup
Datto SaaS ProtectionExchange, OneDrive, SharePoint, TeamsPer-userMSP-managed environments
Acronis Cyber ProtectM365 + endpoint backup in one platformPer-userBusinesses wanting unified backup
Afi BackupExchange, OneDrive, SharePoint, TeamsPer-userSimple, affordable, SMB-focused
Barracuda Cloud-to-CloudExchange, OneDrive, SharePoint, TeamsPer-userBusinesses already using Barracuda security

What to look for in a backup solutionsection

  • Point-in-time recovery — restore data to a specific date and time
  • Granular restore — recover individual emails, files, or folders (not just full mailboxes)
  • Immutable storage — backups that cannot be modified or deleted, even by an admin
  • Automated scheduling — backup runs 1-3 times daily without manual intervention
  • Cross-tenant restore — restore to a different M365 tenant (important for disaster recovery)
  • Compliance retention — configurable retention periods for legal and regulatory requirements

Setting Up Microsoft 365 Retention Policiessection

While third-party backup is the primary recommendation, you should also configure M365's built-in retention as a first layer of protection.

Create a retention policy for emailsection

  1. Go to compliance.microsoft.com (Microsoft Purview)
  2. Navigate to Data lifecycle management > Retention policies
  3. Click New retention policy
  4. Name: "Email Retention — 1 Year"
  5. Choose locations: Exchange mailboxes (all users)
  6. Retention period: Retain for 1 year, then do nothing (or delete, depending on your policy)

Create a retention policy for OneDrive and SharePointsection

  1. Same portal > New retention policy
  2. Name: "File Retention — 1 Year"
  3. Choose locations: OneDrive accounts + SharePoint sites (all)
  4. Retention period: Retain for 1 year

If you need to preserve all data for legal reasons:

powershell
# Place a user on litigation hold
Connect-ExchangeOnline
Set-Mailbox -Identity "user@company.com" -LitigationHoldEnabled $true -LitigationHoldDuration 365

Backup Schedule Recommendationssection

Data TypeBackup FrequencyRetention
Exchange mailboxes3x daily1 year minimum
OneDrive files3x daily1 year minimum
SharePoint sites3x daily1 year minimum
Teams chats and channels1x daily1 year minimum
Microsoft Entra ID config1x daily90 days minimum
Conditional Access policiesWeekly export1 year

Export Conditional Access policies (no backup tool needed)section

powershell
Connect-MgGraph -Scopes "Policy.Read.All"

$policies = Get-MgIdentityConditionalAccessPolicy -All
$policies | ConvertTo-Json -Depth 10 | Out-File "CA-Policies-Backup-$(Get-Date -Format 'yyyy-MM-dd').json"

Testing Your Backupssection

A backup that has never been tested is not a backup. Schedule quarterly restore tests:

Test 1: Recover a single emailsection

  1. Delete a test email from a user's mailbox
  2. Empty the Deleted Items and wait for the recoverable items window to expire
  3. Restore the email from your third-party backup
  4. Verify the email is intact (subject, body, attachments)

Test 2: Recover a OneDrive foldersection

  1. Delete a test folder from OneDrive
  2. Empty the recycle bin
  3. Restore the folder from backup
  4. Verify all files are present and not corrupted

Test 3: Full mailbox recoverysection

  1. Create a test user
  2. Simulate a mailbox loss (remove the licence)
  3. Restore the full mailbox from backup to a new user
  4. Verify all emails, folders, and calendar items are recovered
Tip

Document each test result and keep the records for compliance audits. CMMC, SOC 2, and ISO 27001 all require evidence that backups are tested regularly.

Disaster Recovery Scenariossection

ScenarioRecovery MethodExpected Recovery Time
User accidentally deletes a fileOneDrive recycle bin or backup restoreMinutes
User's mailbox corrupted by sync issueThird-party backup point-in-time restore30 minutes
Ransomware encrypts OneDrive filesBackup restore to pre-encryption point1-4 hours
Disgruntled employee deletes everythingThird-party backup full restore2-8 hours
Entire tenant compromisedCross-tenant restore to new M365 tenant1-3 days
Legal discovery requestLitigation hold + backup searchVaries

Next Stepssection

  • Evaluate and deploy a third-party M365 backup solution
  • Configure retention policies in Microsoft Purview as a first layer
  • Schedule quarterly backup restore tests
  • Document your backup and recovery procedures in a runbook
  • Review your cyber insurance policy — many require documented backup procedures

Need help managing backup and recovery?section

Explore managed IT support if you need help with backup planning and ongoing administration. Discuss your recovery objectives, restore testing, and the services included in your plan before choosing a solution.

BackupMicrosoft 365Disaster RecoveryBusiness ContinuityData Protection

Was this article helpful?