Microsoft 365 Does Not Back Up Your Emails: The Real Risks for Your Business and How to Address Them

The short answer: Microsoft is responsible for keeping the service running—not for restoring your deleted email. Business Basic, Standard, and Premium licences do not automatically provide long-term backup: you get recycle bins, version history, and recovery windows ranging from 14 to 93 days. Once those expire, the data is gone. You need to arrange backup separately—through the paid Microsoft 365 Backup service, a third-party service, or your own copy on a NAS—and, above all, periodically perform a real recovery test to verify that restoration actually works.

Microsoft keeps the service running. It does not preserve your history

A company’s email service can run without a single outage while a signed contract disappears from it, or while the entire mailbox of an employee who left in May vanishes. Microsoft handles the resilience of its own infrastructure: replication, data centres, and availability. That is different from restoring the state from before someone accidentally emptied a folder, an attacker signed in with a stolen password, or a retention rule did exactly what someone had configured it to do.

The shorthand claim that „Microsoft does not offer any backup" is no longer true. It does—it is called Microsoft 365 Backup. But you must enable it yourself, select what should be protected, and connect it to usage-based billing through an Azure subscription. No Business Basic, Standard, or Premium licence activates it, and it is not included in the per-user price.

The right question is therefore not „Does Microsoft back us up?" but: From what point in time can we restore a specific email, an entire mailbox, and a SharePoint library—and who last tested it?

How much time you actually have without paying extra

Microsoft 365 provides several safety nets. They are not one universal „30-day backup"—they are recovery windows of different lengths, each with its own logic and procedure. The following values apply to a tenant without a hold or retention policy:

What was lostWhere it can still be foundHow much time you have
A message also removed from Deleted Itemsthe Recoverable Items folder14 days; an administrator can extend this to no more than 30 days (Set-Mailbox -RetainDeletedItemsFor 30.00:00:00)
An entire mailbox after the account was deletedsoft-deleted mailbox30 days
A file in OneDrive or SharePointthe user’s recycle bin, then the site administrator’s recycle bin93 days in total from deletion—the second-stage recycle bin does not extend the period; it only uses the remainder
An overwritten or encrypted filethe library’s version history (default limit: 500 versions)bulk recovery using „Restore this OneDrive / this library" can go back no more than 30 days
The OneDrive of a former employeethe personal site after account deletiondefault retention of 30 days (Set-SPOTenant -OrphanedPersonalSitesRetentionPeriod), followed by another 93 days in a deleted state
Teams chat messageshidden folders in the user’s mailboxthey cannot be restored through standard email recovery procedures

People most commonly confuse two figures in that table: 14 days applies to an individual message, while 30 days applies to an entire mailbox. If a colleague tells you after a month that she deleted an email containing an order, that is a different situation from „I deleted the account and need it back."

One exception has saved many companies: if a Microsoft Purview retention policy applies to a mailbox or site, deleted content is preserved instead of discarded—in Recoverable Items for email and in the Preservation Hold Library for SharePoint—for the period specified by the policy. This is not a backup (you cannot restore the entire state from last Tuesday with one click), but when searching for one specific document, it is often the only remaining copy.

Where the gap actually arises for a small business

SituationWhat happensWeak point
An employee leavesThe administrator deletes the account or immediately removes its licence to avoid further charges.Without a hold, the mailbox is gone after 30 days. A shared mailbox can operate without a licence only up to 50 GB—and because it remains tied to the user object, deleting the account deletes the shared mailbox as well.
Ransomware on a workstationEncrypted files are uploaded to the cloud through OneDrive synchronisation.Synchronisation faithfully transfers the malicious change too. Only a clean version can help, provided it still exists—and every additional version consumes tenant storage capacity (a base allocation of 1 TB plus 10 GB per licensed user).
Administrator errorSomeone bulk-deletes emails, a library, or an entire site.Each data type has a different recovery window and tool. There is no single button for all of them.
Retention rulePurview deliberately deletes content after the configured period.Retention controls the data lifecycle. It does not create a copy from which you can freely select a date.
Compromised global administratorAn attacker changes accounts and policies and deletes data inside the tenant.A copy protected by the same identity as production can fail along with it.
Site migration or clean-upA site is moved or deleted „because nobody was using it."The 93-day period starts when the site is deleted, not when someone notices.

Retention is not backup, and backup is not archiving

Three different things are often bundled together in proposals:

  • A recycle bin corrects a recent mistake. Hours to days.
  • Retention preserves or deletes content according to a company, contractual, or legal rule. Its purpose is compliance, not rapid recovery.
  • A backup creates recovery points from which a previous state can be restored.

Long-term retention may preserve an email for eDiscovery while still preventing you from restoring an entire mailbox to its state two weeks ago. Conversely, a backup should not retain everything forever without careful thought—the more data you keep, the higher both the cost and legal exposure. A company must therefore make two separate decisions: how long it is allowed to retain the data and how quickly it must restore that data to operation.

Microsoft 365 Backup: what you get for USD 0.15 per GB

Microsoft 365 Backup protects Exchange Online, OneDrive, and SharePoint. It has its own one-year retention period, independent of standard Purview rules, and operates within the tenant. Restoring large volumes is therefore not limited by internet downloads—the data is not transferred elsewhere.

Recovery points are not equally frequent for every type of restoration. For Exchange, they are available at ten-minute intervals throughout the year. For a full SharePoint site or entire OneDrive restoration, they are available at ten-minute intervals for the first 14 days and become less frequent after that; individual file and folder restoration has its own coarser granularity. Before promising anyone that „we can restore the exact state from 2:20 p.m.," check which of these three cases applies.

The price is USD 0.15 per GB of protected content per month. As a rough estimate, 500 GB costs about USD 75 per month, while 1 TB costs around USD 150—before exchange rates, taxes, and administrator labour. Billing is based on volume, not the number of user licences purchased, so ten people with extensive archives will cost more than thirty people who mainly write emails.

Check two things before declaring the problem solved. First, protection covers whatever is included by your policy rules—a new SharePoint site created next month will be added to the backup automatically only if the rule is configured to include it. Second, the backup lives in the same tenant under the same administration. Recovery points are immutable: an administrator cannot overwrite them or use an ordinary action to delete them before their retention period expires. What an administrator can do is stop protection, meaning no new recovery points will be created from that moment onwards. The real reason for keeping a second copy outside Microsoft is therefore not concern that someone will delete existing recovery points, but independence: a different provider, identity, and administrative domain. As long as the backup depends on the same account, tenant, and contract as production, it is not an independent second line of defence.

Teams, Planner, and Loop: what is not covered

Files from Teams channels are stored on the team’s SharePoint site, while files shared in chats are stored in the sender’s OneDrive under the Microsoft Teams Chat Files folder. These are backed up together with the storage services. The chat messages themselves, reactions, team membership, Planner tasks, Forms responses, and Loop content are not. Although Teams messages are physically stored in hidden mailbox folders, restoring a mailbox does not return them to Teams.

The practical consequence when selecting a provider is that its proposal must list specific data types. Simply stating „we back up Microsoft 365" and adding a logo is not enough.

Microsoft, a third-party service, or your own NAS

OptionWhat it providesWhat to check
Microsoft 365 BackupFast recovery of large data volumes directly within the tenant, one-year retention, and no transfer of data outside Microsoft.It covers Exchange, OneDrive, and SharePoint—nothing else. Both the data and administration remain with Microsoft, so it is not an independent copy.
Third-party backup SaaSA separate portal, a different administrator identity, and usually broader coverage and longer retention.Data location, online archives and shared mailboxes, protection against backup deletion, bulk recovery speed, and data export after contract termination. Also ask whether the service uses Microsoft 365 Backup Storage under the hood—in that case, you share its limitations.
Your own NASA copy physically stored on your premises, with no monthly volume-based fee.Synology Active Backup for Microsoft 365 (included with DSM) and QNAP Boxafe are tools, not complete protection. You need a compatible NAS, sufficient capacity, updates, job monitoring, and another copy outside the office. RAID is not backup—our Synology vs. QNAP comparison for businesses explains what each platform involves in practice.

The cheapest sensible combination for a small business is usually one layer within Microsoft for fast recovery and one copy outside Microsoft for independence from the tenant and from a single set of credentials.

How much it will cost and how to recognise a good proposal

The number of employees does not determine the price. A company with twenty people may have 100 GB or three terabytes of data. Before comparing proposals, have someone measure active mailboxes, shared mailboxes, online archives, OneDrive accounts, SharePoint sites used through Teams, and projected growth. Without this inventory, every figure is a guess—and the estimate always rises once the actual volume becomes clear six months later.

If you do not want to prepare the inventory yourself, contact us: we will review the tenant, document the data volumes and recovery windows you currently have, and perform a real test by restoring one email and one file. The result is a one-page summary containing the figures you need to assess proposals.

Before you sign, the provider should answer seven questions:

  1. What is the RPO—how many hours of the latest data could we lose?
  2. What is the RTO for a single message, an entire mailbox, and the entire tenant?
  3. Does the service include online archives, shared mailboxes, SharePoint sites, and the data of people who have already left?
  4. What can our own global administrator do to the protection—can they stop it, shorten retention, or even delete recovery points that have already been created?
  5. Who handles a failed job, and who receives the alert—us, or a queue nobody monitors?
  6. When was a randomly selected email and file last restored in a test, and how long did it take?
  7. How do we retrieve our data after the contract ends, and in what format?

There is one more frequently overlooked question: an external administrator can see company data during recovery. The contract should include confidentiality, restricted permissions, access auditing, and a data processing agreement. A single technician’s account without MFA or backup coverage is a vulnerability even when the product itself is excellent.

Six steps you can complete this week

  1. List everything that must not disappear: mailboxes, archives, shared mailboxes, OneDrive accounts, and SharePoint sites.
  2. Check your current recovery windows—Recoverable Items settings, deleted OneDrive retention, and the version-history limit.
  3. Implement offboarding in this order: block sign-in → revoke active sessions → convert the mailbox to a shared mailbox and hand over OneDrive → verify the backup → only then remove the licence. Keep the user account in place—the shared mailbox remains tied to it and will disappear if the account is deleted, leaving only a 30-day recovery window. If the account genuinely must be removed, preserve the data separately first through a backup, export, or transfer to another mailbox, and only then delete it. Reversing this order is the most common route to data loss after an employee leaves.
  4. Define the retention period, RPO, and RTO for critical data. A proposal cannot be evaluated without these three figures.
  5. Enable your chosen backup and configure alerts for both job failures and policy changes.
  6. Restore one older email and one file. Record the date, result, and duration. A backup that nobody has tested is only a promise.

The final point is what separates a company that has a backup from one that merely thinks it does. It takes half an hour.

What the law and security questionnaires have to do with it

Nový zákon o kybernetické bezpečnosti č. 264/2025 Sb. (the new Cybersecurity Act) has been effective since 1 November 2025, but not every small business is automatically regulated—who zákon 264/2025 Sb. actually applies to is a separate question, and the answer is often surprising in both directions.

Even unregulated companies, however, frequently receive security questionnaires from major customers. „We use Microsoft 365" will not be accepted as an answer. They want to know the scope of the backup, the date of the most recent recovery test, and the name of the responsible person—exactly the information produced by completing the six steps above.

If you are already in the middle of an incident, it is too late to start thinking about backups. The first-day procedure is covered separately in ransomware in a business—the first 24 hours.

When it makes sense to call an IT administrator

A one-off setup is enough when someone internally monitors alerts, capacity, and employee departures. Ongoing management makes sense when accounts and sites change every month and the company does not want to discover the state of its backups only when they are needed—which is exactly one of the areas covered by monthly IT management.

Our process begins with a tenant inventory and a recovery test, not a licence order. The result should answer five questions: what is protected, for how long, at what cost, who responds to failures, and how the data will be handed over if our cooperation ends. If the conclusion is that you only need to enable Microsoft 365 Backup and configure two alerts, we will say so.

Frequently asked questions

Does Microsoft 365 Business Premium automatically back up emails?

Not in the sense of providing an annual backup as part of the licence price. Business Premium includes security features and built-in recovery options such as recycle bins, version history, and Recoverable Items, but the paid Microsoft 365 Backup service must be activated, configured, and paid for separately according to data volume.

How long can a deleted email be recovered?

After a message has also been removed from the Deleted Items folder, Exchange Online retains it in Recoverable Items for 14 days by default. An administrator can extend this period to no more than 30 days. A retention policy or hold can preserve the content for longer—but it must be configured in advance and cannot be applied retroactively.

Does OneDrive version history protect against ransomware?

It can help if you detect the attack in time and clean versions still exist—the „Restore this OneDrive" feature can return the state to a point up to 30 days in the past. It is not a separate copy, however: the malicious change is synchronised to the cloud, and an expanded version history consumes tenant storage capacity. Bulk recovery across dozens of libraries also takes hours.

Is backing up Microsoft 365 to a company NAS sufficient?

Yes, provided the tool genuinely downloads all required data, jobs are monitored, recoveries are tested, and another copy exists outside the office. RAID alone does not protect against deletion, ransomware, theft, or fire—it only protects against disk failure.

What should we do with a departing employee’s data?

First, block sign-in and revoke active sessions. Then hand over OneDrive and email, and convert the mailbox to a shared mailbox if appropriate. If the licensing conditions are met, you can remove its licence (up to 50 GB and without an online archive or hold), but the user object must remain—the shared mailbox is still tied to it and will disappear if the account is deleted, leaving a 30-day recovery window. If you genuinely need to remove the account from the directory, use a different procedure: preserve the data separately beforehand through a backup, export, or transfer to another mailbox. Set the retention period according to operational, contractual, and legal needs, not according to when the licence becomes available.