
Microsoft 365 Retention vs. Backup: What Small Businesses Need to Know
Retention, recovery and backup are three different things in Microsoft 365. What each one protects, how long it lasts, and when you need more.
On a Tuesday afternoon, someone on your team is tidying up. A SharePoint folder looks obsolete, so they delete it. Three weeks later a client asks for a document that lived in it. Nobody noticed at the time, and nobody is quite sure when it went.
Deletion is only one of the ways this goes. A file gets overwritten with a worse version and saved. A spreadsheet quietly corrupts. Someone leaves and their account is closed. Each of those is a different kind of accident, and Microsoft 365 answers each one with a different tool.
Whether you get that folder back depends entirely on which protection is doing the work, and every one of them runs on a clock. That is the part most people are surprised by. Microsoft 365 has several protections built in, they are genuinely good at what they do, and not one of them is designed to answer the question "put the business back the way it was on the 3rd."
The confusion is understandable, because a handful of words get used as though they mean the same thing. Resiliency, recovery, retention and backup are four different mechanisms with four different jobs. Sorting them out takes about ten minutes and it changes what questions you ask your IT provider.
What Microsoft 365 already protects
Start with the part that works well, because it genuinely does. Microsoft operates the service to a standard almost no small business could match on its own.
Every Exchange Online mailbox database is held in at least three copies spread across multiple datacenters, replicated to geographically separate locations within the same territory. SharePoint and OneDrive use the same idea: multiple copies of your data in different fault zones, with failover to a live copy happening automatically and invisibly. If a disk dies, a server fails, or an entire datacenter has a bad day, your email keeps working and you never find out.
This is called service resiliency, and it is Microsoft's job. They do it well. But notice what it is for: it protects your data from something going wrong at Microsoft. It is not built to reverse something that happened at your end. When your team member deleted that folder, every replicated copy faithfully recorded the deletion, because from the service's point of view that was a legitimate instruction from an authorized user.
Microsoft is direct about where the line sits. In the shared responsibility model that governs their cloud services, the customer owns their data and identities, and the customer is responsible for protecting them. That is not a disclaimer buried in a contract. It is a reasonable division of labor, and knowing which side of the line you are on is the whole point of this article.
Recycle bins, version history, and rolling back in time
Microsoft gives you three separate ways to undo an ordinary mistake, and they solve three different problems. Most people know about the first one and are surprised by the third.
Deleted email
When someone deletes an email it goes to Deleted Items, and they can drag it back out. When they empty Deleted Items, it is not gone yet either. It moves into a hidden area called the Recoverable Items folder, which is what sits behind Outlook's "Recover Deleted Items" option. By default, Exchange Online keeps items there for 14 days. An administrator can raise that to a maximum of 30 days, and that maximum is a hard ceiling.
Whole mailboxes work differently again. If you delete a user account, Exchange Online holds the mailbox and its contents for 30 days before permanent deletion. The same 30 days applies if you simply remove someone's license. Put the license back inside that window and the mailbox comes back intact. Miss it, and it is gone.
Deleted files in SharePoint and OneDrive
Files get a two-stage recycle bin. Delete something and it lands in the site recycle bin, where any user can restore it. If someone empties that, it drops into a second-stage recycle bin that ordinary users cannot see but a site collection administrator can.
There is one more clock worth knowing. When you delete a user account, their OneDrive is kept for 30 days by default, and an administrator can set that anywhere from 30 days up to 3,650 days in the SharePoint admin center. After the first seven days the OneDrive moves into the site collection recycle bin, where it is held for 93 days.
So back to the Tuesday folder. Three weeks is 21 days. It is still inside the 93-day window, so the folder is recoverable, and someone with the right admin access can go and get it. Discover the same loss four months later and the answer is different, through no fault of anyone at Microsoft.
Earlier versions of a file that still exists
The recycle bin only helps when something was deleted. When a file is still sitting there but the contents are wrong, version history is the tool. SharePoint and OneDrive keep previous versions of a document automatically, and anyone with access can open the version history and restore an earlier one.
By default a document library keeps up to 500 versions of a file with no expiry, and that limit can be adjusted for the whole organization, a single site, a library, or one person's OneDrive. There is also an automatic setting that trims older versions over time to save storage, and under that setting people can reach versions from roughly the last 30 days rather than the last 500 edits.
This is the answer to the overwritten spreadsheet, and it is worth knowing simply because so few people ever open the menu. It does nothing for a file that has been deleted outright.
Rolling a whole OneDrive or library back to an earlier point
This is the one most small businesses do not know they have. A OneDrive can be restored as a whole to any point in the previous 30 days, using a feature Microsoft calls Restore your OneDrive, and SharePoint offers the same thing for a document library. It undoes everything that happened after the point you pick, whether that was deleting, overwriting, corrupting, or a malware infection working through the files.
It is genuinely a point-in-time rollback, self-service, with no extra product to buy. It is also capped at 30 days, and it works on one OneDrive or one library at a time rather than across the whole business. Within that window it is often the fastest way out of a bad afternoon.
What Microsoft Purview retention actually does
Purview retention is where the vocabulary starts working against people, because "retention" sounds like it means "keeping your data safe." What it actually means is closer to the opposite of a recycle bin. A recycle bin holds things you deleted for a while, just in case. Retention decides, in advance and by policy, what must be kept and what must be thrown away.
Purview retention policies and retention labels exist for compliance and data lifecycle management: retaining the content you are required to keep, and disposing of content you should not keep indefinitely. If you are in a regulated trade, or you have a document policy that says client files are held for seven years and then destroyed, this is the tool that enforces it.
It does preserve copies, and this is the part worth understanding properly. In SharePoint and OneDrive, when someone edits or deletes an item that is covered by a retention policy, the original is copied into a Preservation Hold library. Your team member's Tuesday deletion cannot actually destroy the file, because a copy was taken the moment they tried.
Microsoft describes the Preservation Hold library as a hidden system location that is not designed to be used interactively. It exists so that content survives, not so that anyone can browse it. That distinction is the whole reason the next section exists.
Holds are the same idea taken further. An eDiscovery hold preserves content that might be relevant to a legal case, securing it against deletion, whether inadvertent or deliberate, while an investigation runs. If your business is ever facing litigation this matters a great deal. As a way to recover from an ordinary Tuesday, it is the wrong instrument.
Why retention is not the same thing as backup
Here is the distinction in one sentence: retention is very good at making sure something still exists somewhere, and a backup is what lets you put it back.
Those are not the same problem. Retention answers "does a copy of this file survive?" A backup answers "can I return this mailbox, this site, or this whole set of folders to the state it was in at 9am last Thursday, without reconstructing it by hand?"
In practice the difference shows up in two ways. Retention has no point in time you can roll back to, and no bulk restore that puts hundreds of files back where they belong. What it preserves lives in a system location built for compliance officers, not for getting a team working again before lunch.
Rolling back a OneDrive or a library, described above, does give you a point in time, and for a single library inside 30 days it may be all you need. What it does not give you is coverage across mailboxes, sites and accounts together, or any reach beyond a month.
None of that is a flaw. Retention is doing exactly the job it was designed for, and doing it well. The mistake is assuming that job includes yours.
Two questions that decide what you actually need
Before comparing products, it helps to answer two questions about your own business. Your IT provider may call them recovery point and recovery time objectives; they are simpler than they sound.
The first is how much work you could afford to redo. If everything since 9am this morning vanished, is that an irritating afternoon or a serious problem? That answer tells you how frequently your data needs to be captured.
The second is how quickly you would need to be working again. An hour, a day, a week? That answer tells you how much the speed and convenience of the restore matters, as opposed to whether a copy exists at all.
Most small businesses have never put numbers to either. It is worth ten minutes, because the two answers between them tell you whether the built-in windows are already enough.
Microsoft 365 Backup: what Microsoft's own backup product provides
This is where a lot of older advice on this subject is now simply out of date, and where you should be skeptical of anyone who tells you Microsoft does not back up your data. Microsoft sells a product called Microsoft 365 Backup, and it is a real backup product.
It protects Exchange Online mailboxes, OneDrive accounts, and SharePoint sites. Backups are created inside the protected services' own data boundaries, so the data never leaves the Microsoft 365 trust boundary. It uses append-only storage, which means existing restore points cannot be altered or overwritten, including by malware.
The restore granularity is genuinely good. For SharePoint and OneDrive you get a restore point every 10 minutes for the last two weeks, then weekly snapshots from weeks 2 through 52. For Exchange Online you get a restore point every 10 minutes across the entire year. You can restore to the original location, which overwrites what is there now, or to a new location, in which case content arrives in a folder named for the date and time of the restore.
There are two limits worth knowing before you assume it covers everything.
- Retention is 365 days. Backups and their restore points are kept for a full year from the moment each restore point was created, and that is the ceiling. It is far longer than 93 days, and it is still one year.
- Mailbox items can only be restored back into the same mailbox. They cannot be restored into a different one, which matters when the mailbox you are recovering belonged to someone who has left.
It is bought as a pay-as-you-go service rather than bundled into a license. You enable consumption billing in the Microsoft 365 admin center and then create backup policies choosing what to protect. Microsoft publishes a per-gigabyte monthly list price for protected content and does not charge for restores; because that figure can change, it is worth checking the current rate rather than budgeting from a number in an article.
For a lot of small businesses, this is a sensible answer. It is Microsoft's own tooling, there is no third-party vendor in the chain, and turning it on is an afternoon's work rather than a project.
When a small business should consider independent backup
Independent backup means a copy of your Microsoft 365 data held by a separate provider, outside Microsoft's systems. It is not mandatory, and any business telling you it is has skipped a step. It solves specific problems, and if you do not have those problems you may not need it.
It earns its keep in four situations.
- You need to keep data longer than a year. Microsoft 365 Backup stops at 365 days. If your industry, your insurer, or your contracts require you to produce records from three or seven years ago, something has to cover the years beyond that ceiling.
- You specifically want a copy outside the vendor. Microsoft 365 Backup deliberately keeps your data inside the Microsoft 365 trust boundary, which is a genuine advantage for compliance and speed. If your reason for wanting a backup is to hold a copy somewhere that does not depend on your Microsoft tenant at all, that same design is the thing you are trying to avoid.
- Your recovery plan involves people who have left. Because mailbox items restore only to the same mailbox, recovering a departed employee's email into a manager's mailbox is not something the native product does.
- You are consolidating several systems. If Microsoft 365 is one of several places your business keeps important data, one backup covering all of it is usually easier to test and easier to trust than several tools that each cover a slice.
If none of those describe you, the honest answer is that Microsoft's built-in protections plus Microsoft 365 Backup may well be sufficient, and that is the advice we give when it fits. What is not sufficient is assuming you are covered without knowing which of these mechanisms you actually have switched on.
Questions worth asking about your Microsoft 365 recovery plan
You do not need to become an administrator to have this conversation. These six questions will tell you where you stand, and any competent IT provider should be able to answer them without hedging.
- If we discovered today that a folder was deleted four months ago, could we get it back? This is the one that exposes the gap fastest, because it is past every default window.
- Do we have Microsoft 365 Backup switched on, and for which mailboxes and sites? It is not automatic. Someone has to enable it and choose what it protects.
- How long do we actually need to keep things, and does anything we have cover that period? Answer the business question first, then check whether the tooling matches it.
- Has anyone ever tested a restore, rather than checking that a backup ran? A backup that has never been restored from is an assumption, not a protection.
- What happens to a departed employee's mailbox and OneDrive, and how long do we have to act? Both clocks start the moment the account is deleted.
- Who is responsible for noticing that something went wrong? Most of the loss in situations like this comes not from the deletion but from the delay in spotting it.
How to tell whether the answers are any good
A confident answer names the mechanism and the window. "Files are covered by the recycle bin for 93 days, mailboxes for 30, and we have Microsoft 365 Backup on these five sites with a year of history" is a real answer. So is "we do not have backup switched on, and here is what that would cost."
A vague answer is the warning sign. "It's in the cloud, so it's backed up" describes resiliency, not recovery, and the two are not the same thing. If nobody can tell you how far back you can go, the honest position is that nobody knows yet, and finding out is the first job.
If the answer to the fourth question is no, that is where to start. A restore that has never been tested is the cheapest thing on this list to fix.
The short version
Microsoft 365 is a well-run, resilient service, and it includes real protections against ordinary mistakes: recycle bins, version history, and a 30-day rollback for a whole OneDrive or library. Every one of those protections has a shape and a deadline: 14 or 30 days for deleted email, 30 days for a deleted mailbox, 93 days for files in the recycle bin, 30 days for a rollback, a year with Microsoft 365 Backup. Retention keeps things; backup puts them back. Knowing which you have is not a technical detail, it is a business decision about how much history you could afford to lose.
If you are not sure which of these are switched on for your business, that is worth half an hour. We work with small businesses across southeastern Wisconsin, and we can look at what your Microsoft 365 setup would actually survive and tell you plainly whether you need anything more, including if the answer is that you do not. Our backup and disaster recovery service covers exactly this, and if you would rather just talk it through first, get in touch.
Key Takeaways
- Microsoft 365 protects your data against failures at Microsoft. Reversing a mistake made inside your business is a separate job, and it is yours.
- There are three built-in ways to undo a mistake, and they solve different problems: recycle bins for deletions, version history for bad edits, and a 30-day rollback for a whole OneDrive or library.
- Every built-in protection has a deadline: 14 to 30 days for deleted email, 30 days for a deleted mailbox, 93 days across both recycle bin stages for files.
- Purview retention makes sure a copy still exists somewhere. That is not the same as being able to put things back where they were.
- Microsoft 365 Backup is a real backup product with 10-minute restore points, and its retention ceiling is 365 days.
- Independent backup is a tradeoff, not a requirement. It matters most for multi-year retention and for keeping a copy outside your Microsoft tenant.
Schedule Your Free IT Evaluation
Let’s review your current setup and show you where risk may exist — at no cost and no obligation.
Call 262-878-5497 or email kevin@proformancepc.com