# Cloud Backup for Microsoft 365: What You Need to Know

**Prepared by DP3**  
·  Published March 2026

## What Microsoft Actually Covers (and What It Doesn't)

Microsoft is responsible for the infrastructure that runs Microsoft 365 — the data centers, uptime, availability, and physical security. When it comes to your data, Microsoft provides limited short-term recovery tools, but does not take responsibility for comprehensive, long-term recoverability under your control.[1] Nikki Chapple Microsoft 365 Retention, Archive and Backup

Microsoft's Services Agreement states: _“We recommend that you regularly backup Your Content and Data that you store on the Services or store using Third-Party Apps and Services.”_[2] Microsoft Microsoft Services Agreement

This is known as the **Shared Responsibility Model**.[3] DrBackup OneDrive, SharePoint & Microsoft 365 Backup Whitepaper

### What About Microsoft 365 Backup?

Microsoft recently released its own backup product, **Microsoft 365 Backup**[4] Microsoft Microsoft 365 Backup Overview , which delivers faster in-tenant recovery for Exchange, SharePoint, and OneDrive data. This is a meaningful improvement over native retention limits alone, and Veeam has integrated with this technology as a platform partner.[5] Techzine Veeam Gets Microsoft 365 Backup Storage Integration for Faster Recovery

That said, many organizations still have good reasons to use a third-party backup platform:

- **Separation of duties** — a backup stored independently of your Microsoft tenant is not affected if the tenant itself is compromised, misconfigured, or ransomware-encrypted within M365
- **Longer retention** — Microsoft 365 Backup has its own retention limits; third-party platforms can retain data for 7+ years
- **Broader coverage** — third-party tools typically cover more workloads and offer more restore options
- **MSP management** — for organizations using a managed service provider, consolidating backup management outside Microsoft's admin center has operational advantages

### Native Retention Has Hard Limits

Microsoft 365 includes some built-in data recovery features, but they are short-term safety nets — not a backup strategy.

| Workload | Native Recovery Window |
| --- | --- |
| SharePoint & OneDrive | 93 days total (both recycle bin stages combined)[6]  
| Exchange Online | 14 days by default, configurable up to 30 days[7]  
| Microsoft Teams (files) | Follows SharePoint/OneDrive rules (93 days)[6]  
| Microsoft Teams (chat/messages) | Stored in Exchange; governed by separate M365 retention policies[8]

Organizations can configure longer records-management retention via Microsoft 365 retention policies in Microsoft Purview[9]

### Litigation Hold and eDiscovery Are Not Backups

They are compliance tools designed for legal holds, not for operational data recovery.[9] Microsoft Purview Learn About Retention Policies and Retention Labels

### Two Scenarios That Happen More Often Than You'd Expect

1. **Scenario 1: The Departing Employee**  
   A departing employee deletes a project folder from their OneDrive before offboarding. Nobody notices until months later when a colleague needs those files. At that point, the data is gone — the 93-day recycle bin window closed long ago.

2. **Scenario 2: Ransomware Propagation**  
   A ransomware attack encrypts files synced through OneDrive, and those encrypted versions propagate back to SharePoint. The attack is discovered days later. Without an independent backup taken before the encryption occurred, restoring clean data requires working backward through version history — which may not go far enough.

## Why This Matters

Every organization relying on Microsoft 365 faces the same exposure. Critical business data — contracts, financials, communications, project files — lives in Exchange, SharePoint, OneDrive, and Teams. When native recovery windows close, that data is unrecoverable without a third-party backup in place. Data protection is a core component of any [layered security strategy](/content/security/index.html).

## A Note for Legal and Law Firms

[Law firms](/content/industries/legal/index.html) carry an additional layer of obligation that makes Microsoft 365 backup more than an IT best practice — it is an ethical and professional responsibility.

### ABA Model Rules of Professional Conduct

- **Rule 1.1 (Competence)** requires attorneys to understand the risks of the technology they use, including how client data is stored and protected.[10] ABA Formal Opinion 477R – Securing Communication of Protected Client Information  
- **Rule 1.6 (Confidentiality)** requires “reasonable efforts” to prevent unauthorized access to or loss of client information.
- **Rule 5.3 (Supervision of Vendors)** requires firms to ensure that third-party vendors — including IT and cloud providers — comply with those same obligations.

### RPO and RTO: What Recovery Actually Means in Practice

Two terms worth understanding when evaluating backup vendors:

- **RPO — Recovery Point Objective**  
  How much data can your organization afford to lose? If a vendor backs up email 3x/day, your worst-case data loss in a recovery scenario is roughly 8 hours of mail. If they back up 6x/day, that window drops to 4 hours.

- **RTO — Recovery Time Objective**  
  How quickly does your organization need to be operational again? Granular item-level restores (a single email, a single file) typically take minutes. Mailbox-level or site-level restores can take longer.

### Vendor Options: What to Evaluate

The market for Microsoft 365 backup has matured significantly. Below is an overview of the vendors we evaluate most often for our clients, along with what distinguishes each one.

### Veeam Data Cloud for Microsoft 365

Best for: Enterprise-grade protection with unlimited included storage and a fully SaaS-delivered platform

### AvePoint Cloud Backup

Best for: Complex SharePoint environments or multi-SaaS backup coverage beyond just M365

### N-able Cove Data Protection

Best for: Backup coverage extending beyond M365 to include servers and workstations in a single console

### Backupify (by Kaseya / Datto)

Best for: M365-focused backup with strong compliance credentials and minimal configuration overhead

## Side-by-Side Comparison

|  | Veeam Data Cloud | AvePoint Cloud Backup | N-able Cove | Backupify |
| --- | --- | --- | --- | --- |
| Exchange | Yes | Yes | Yes | Yes |
| SharePoint | Yes | Yes | Yes | Yes |
| OneDrive | Yes | Yes | Yes | Yes |
| Teams | Yes (incl. private channels) | Yes | Yes | Yes |
| Entra ID | Yes (Advanced+ only) | Yes | No | No |
| Server & Workstation | No | No | Yes | No |
| Backup Frequency | Configurable by tier | Automated / configurable | Up to 6x/day (Exchange), 4x/day (SharePoint) | 3x/day + on-demand |
| Retention | Configurable | Configurable | Up to 7 years | Configurable |
| Storage Included | Yes (unlimited) | Optional (BYO or AvePoint) | Yes (pooled) | Yes (Datto cloud) |
| MSP Multi-Tenant | Yes | Yes | Yes (strongest) | Limited |
| Compliance Certs | SOC 2, ISO 27001 | SOC 2, ISO 27001 | SOC 1, SOC 2, ISO 27001, PCI-DSS, HIPAA | SOC 2 Type II, HIPAA |
