Microsoft 365 data protection
Does Microsoft 365 Back Up Your Data? What Irish Businesses Miss
Ask ten Irish business owners whether Microsoft 365 backs up their data and most will say yes. It feels safe. Your emails, files and Teams messages all sit in Microsoft's cloud, so surely Microsoft protects them. That assumption is where the trouble starts.
Default recovery windows
Recycle-bin windows, not a backup
In short
Here is the honest answer on Microsoft 365 backup.
Microsoft keeps your data online and lets you recover it for a short window, but it does not give you a true backup. Microsoft says as much itself: protecting your data is your responsibility, not theirs. For an Irish business, that gap is not only an IT risk. It is a GDPR risk.
This guide explains what Microsoft 365 actually protects and for how long, where the gaps are, what the new Microsoft 365 backup product does and does not cover, and what your business needs to stay safe and compliant.
The honest answer
Does Microsoft 365 back up your data?
Not in the way most people think. Microsoft 365 keeps your data online and lets you recover recently deleted items for a limited time, usually 14 to 93 days depending on the app. It does not keep long-term, point-in-time copies that you fully control. Under Microsoft's shared responsibility model, backing up your data is your job.
The confusion is understandable. Microsoft does protect a lot. It keeps the service running, guards against hardware failure, and copies your data across data centres so an outage in one place does not wipe you out. That is availability. It is not the same as a backup you can reach into months later to pull back a single deleted file.
Think of the recycle bin as a safety net for recent mistakes, not a vault. It catches the "I deleted that yesterday" moments. It does not catch the file someone removed four months ago, or the mailbox that left with a former employee.
Recovery windows
What Microsoft 365 actually protects, and for how long
Microsoft 365 gives every app a short recovery window through recycle bins and deleted-item folders. Exchange holds deleted email for 14 days, which an admin can extend to 30, then keeps it 30 days more in a hidden Recoverable Items folder.
OneDrive and SharePoint keep deleted files for 93 days. After those windows close, the data is usually gone for good.
Here is the full picture:
| Microsoft 365 app | Where deleted data goes | Default recovery window | After that |
|---|---|---|---|
| Exchange Online (email) | Deleted Items, then Recoverable Items | 14 days (up to 30), then 30 more | Permanently deleted |
| OneDrive | Two-stage Recycle Bin | 93 days | Permanently deleted |
| SharePoint | Two-stage Recycle Bin | 93 days | Permanently deleted |
| Teams files | Stored in OneDrive and SharePoint | 93 days | Permanently deleted |
| Teams chat and channel messages | Stored in Exchange | About 30 days | Permanently deleted |
| Deleted employee's OneDrive | Held after the account is removed | 30 days (configurable) | Permanently deleted |
Two points matter here. These are recycle-bin windows, not a backup, and they run down whether you notice a problem or not.
Microsoft can restore a whole SharePoint site within 14 days of permanent deletion if you raise a support ticket, but only the entire site, never a single file you choose. You can read the detail on Microsoft's own retention and deletion page.
Where it fails
What Microsoft 365 does not cover
Microsoft 365's recovery windows miss the events that cause real damage. Anything found after the recycle-bin window has closed is gone. A departing employee's mailbox and files can vanish when the account is deleted.
Ransomware can encrypt files and then sync those encrypted versions straight into the cloud. Restoring many users at once is slow and manual.
The common gaps:
- Late discovery. Data loss and breaches often go unnoticed for months. By the time anyone looks, the 93-day window may already have passed.
- Accidental deletion past the window. A file removed and forgotten, then needed long after the recycle bin has emptied.
- Malicious deletion. A disgruntled or compromised user clearing out data on purpose.
- Departed staff. Delete the account and the mailbox and OneDrive can go with it once the short holding period ends.
- Ransomware sync. OneDrive syncs local devices to the cloud, so encrypted files can replace your good ones. This is exactly a ransomware attack scenario Irish SMEs are hit with.
- Mass restore. Microsoft's own guidance notes that file versions and legal holds do not scale for large ransomware recovery, where an admin needs to roll back many users at once.
These are the moments when a business finds out the hard way what losing that data can cost, from lost billing records to a customer database that cannot be rebuilt.
The 2024 add-on
What about the new Microsoft 365 Backup product?
In 2024 Microsoft launched Microsoft 365 Backup, a paid add-on that stores point-in-time copies of Exchange, OneDrive and SharePoint for one year.
It is charged per gigabyte rather than per user, keeps data inside Microsoft's own boundary, and can restore quickly. It closes some gaps. It is not free, not switched on by default, and still leaves the setup and responsibility with you.
It helps with fast recovery from ransomware and mass deletion, with recovery points as close as 10 minutes apart. You can read Microsoft's own backup FAQ for the mechanics.
Two limits are worth weighing before you rely on it alone. First, retention caps at one year, which does not meet the multi-year records many Irish sectors must hold.
Second, the copy stays inside Microsoft. If your goal is an independent copy that sits outside your Microsoft tenant, this product does not give you that. For a lot of businesses, it works best alongside a separate backup, not instead of one.
Compliance, not just IT
Why does this matter for Irish businesses?
For Irish businesses, Microsoft 365 backup is a compliance issue as much as an IT one. GDPR Article 32 requires you to be able to restore access to personal data in good time after an incident. The Data Protection Commission expects that ability. Regulated firms carry more weight again: NIS2 duties for many sectors, and DORA for financial services, both of which call for tested recovery.
If a client database or years of emails are lost past the recycle-bin window, "Microsoft was holding it" is not a defence. The law treats the ability to recover personal data as a security measure you are meant to have in place. Recycle bins that empty after 93 days do not meet that bar on their own.
There is a location point too. Keeping your backup copy inside the EU supports data residency and keeps you clear on where personal data sits. It is the same thinking behind how Microsoft 365 supports GDPR in your day-to-day setup, extended to your recovery plan.
What good looks like
How can I back up Microsoft 365 properly?
A proper Microsoft 365 backup keeps an independent, long-term copy of your data that you control and can restore quickly. The accepted standard is the 3-2-1 rule: three copies of your data, on two types of storage, with one kept separate from the rest.
For an Irish business, that separate copy should sit in the EU, resist tampering, and be tested.
What good looks like:
- A copy outside your Microsoft tenant, so deletion or ransomware inside 365 cannot reach it.
- Immutable storage, meaning the backup cannot be altered or encrypted by an attacker.
- Retention that matches your rules, measured in years where compliance needs it, not weeks.
- EU or Ireland data residency, for sovereignty and GDPR comfort.
- Granular restore, so you can bring back one email or one file, not only a whole site.
- Tested restores on a schedule. A backup you have never restored is a guess, not a safety net.
Frequently asked questions
Microsoft 365 backup questions from Irish businesses.
Does Microsoft 365 back up your data automatically?
No. Microsoft 365 keeps your data available and lets you recover recently deleted items for a short window, but it does not create long-term backups you control. Microsoft's shared responsibility model makes protecting and restoring your data your responsibility, and Microsoft recommends you back up your content separately.
How long does Microsoft 365 keep deleted files?
It depends on the app. Exchange keeps deleted email for 14 days, extendable to 30, then 30 more in the Recoverable Items folder. OneDrive and SharePoint keep deleted files in the recycle bin for 93 days. Once these windows pass, the data is usually deleted permanently and cannot be recovered.
Is Microsoft 365 backup required for GDPR in Ireland?
In practice, for most businesses, yes. GDPR Article 32 requires you to restore access to personal data in a timely way after an incident. If data can be lost past Microsoft 365's short recovery windows, relying on those windows alone does not meet that standard. An independent backup is treated as an appropriate security measure.
Does the paid Microsoft 365 Backup product replace third-party backup?
Not fully. Microsoft's paid backup stores copies for one year and keeps them inside Microsoft's boundary. It is useful for fast recovery, but it does not give you multi-year retention or an independent copy outside your tenant. Many Irish businesses use it alongside a separate managed backup, not instead of one.
Can you recover a deleted employee's mailbox and OneDrive?
Only for a short time. When you delete a user, their OneDrive is held for about 30 days by default, and their mailbox for a limited period, before permanent deletion. Once those windows close, the data is gone unless you had a separate backup in place capturing it beforehand.
What is the shared responsibility model in Microsoft 365?
It is the split between what Microsoft protects and what you protect. Microsoft keeps the service secure, running and available. You are responsible for your own data: keeping it, protecting it, and being able to restore it. This is why a deleted file can be lost for good even though it lived in Microsoft's cloud.