BCM

Cloud Backup for Microsoft 365: Why Microsoft's Retention Is Not Enough

TL;DR
  • Microsoft operates the infrastructure but does not back up your data. The Shared Responsibility Model places responsibility for data protection and recovery squarely on the customer.
  • The built-in retention mechanisms (retention policies, recycle bin) have limits: maximum retention periods, no granular point-in-time recovery, and no protection against deliberate deletion by administrators.
  • Exchange Online, SharePoint, OneDrive, and Teams data are all affected. Teams data (chat messages, files in channels) is particularly often overlooked.
  • Dedicated M365 backup tools like Veeam for Microsoft 365, AvePoint Cloud Backup, or Hornetsecurity 365 Total Backup offer granular recovery, unlimited retention, and ransomware protection.
  • The cost of an M365 backup is 2 to 5 euros per user per month, depending on the tool and storage volume. For 100 users, that is 200 to 500 euros monthly.

The Shared Responsibility Model: what Microsoft protects and what it does not

Microsoft operates one of the most reliable cloud infrastructures in the world. Data centers with redundant power supply, geo-redundant data storage, and guaranteed SLAs of 99.9% availability. This creates the impression among many organizations that their data in Microsoft 365 is automatically protected. That is a fallacy.

Microsoft clearly distinguishes between responsibility for the infrastructure (Microsoft's job) and responsibility for the data (your job). This principle is called the Shared Responsibility Model and is documented in the Microsoft service terms.

Microsoft takes responsibility for protecting the physical infrastructure (data centers, network, hardware), service availability (SLA of 99.9%), replication of data within the infrastructure (geo-redundant), and protection against platform-level outages.

You take responsibility for protection against accidental deletion by users, protection against malicious deletion by insiders or attackers, compliance with regulatory retention obligations, recovery of data after ransomware or malware, and data backup beyond Microsoft retention periods.

This is not an academic distinction. If an employee accidentally deletes a SharePoint document library and the retention period has expired, Microsoft cannot restore the data. If ransomware encrypts a user's OneDrive files and versioning stores the encrypted files as new versions, Microsoft's replication does not help because it replicates the encrypted versions.

What Microsoft's built-in protection mechanisms deliver

Microsoft does offer protection mechanisms for data in Microsoft 365. They are helpful but not sufficient for a complete backup.

Exchange Online: recycle bin and retention

When a user deletes an email, it goes to the "Deleted Items" folder. The user can restore it from there. When the user empties the "Deleted Items" folder or permanently deletes the email (Shift+Delete), it moves to the "Recoverable Items" folder. It remains there for 14 days by default (configurable up to 30 days). After the period expires, the email is irrevocably deleted.

With an Exchange Online Retention Policy or a Litigation Hold, you can extend retention -- theoretically indefinitely. That sounds like a solution but has limitations. Retention Policies prevent deletion but do not enable granular point-in-time recovery. You cannot say: "Restore my mailbox as it was on January 15 at 2:00 PM." You can only recover individual deleted items that fall under the Retention Policy.

Additionally, the "Recoverable Items" folder counts against the mailbox quota. With an active Litigation Hold, this folder can grow substantially and push the mailbox to its limits.

SharePoint and OneDrive: versioning and recycle bin

SharePoint and OneDrive offer file versioning (up to 500 versions per file by default) and a two-stage recycle bin. Deleted files go to the user recycle bin (93 days), then to the site recycle bin (remaining time up to 93 days total), and are then irrevocably deleted.

Versioning protects against accidental overwriting but has limits. In a ransomware attack that encrypts thousands of files, each encrypted file is stored as a new version. The old versions are still present, but restoring thousands of files to an older version is extremely laborious manually. Microsoft has offered a "Files Restore" function for OneDrive since 2022 that can reset all files to an earlier point in time. For SharePoint libraries, this function is more limited.

What happens when an administrator deletes an entire SharePoint site? It remains in the site collection recycle bin for 93 days. After that, it is gone. If the administrator also empties the recycle bin, it is gone immediately. No backup, no recovery.

Teams: the problem child

Microsoft Teams is the most complex Microsoft 365 product from a backup perspective because Teams data is stored in various locations. Chat messages reside in Exchange Online mailboxes of users (for 1:1 chats) or in group mailboxes (for channel messages). Files shared in Teams channels reside in the SharePoint document library of the Team. Files shared in 1:1 chats reside in the sender's OneDrive. Teams settings (channel structure, memberships, tabs, connectors) reside in the Microsoft Graph API and are only partially coverable through standard backup tools.

This means: even if you back up Exchange and SharePoint, Teams metadata may be missing (who was in which channel, which tabs and apps were configured). A complete restoration of a Teams team requires more than just recovering files and messages.

Five scenarios where Microsoft's protection mechanisms fail

Scenario 1: the forgotten offboarding process

An employee leaves the organization. Their Microsoft 365 account is deleted after 30 days. A clean user lifecycle management would have addressed this problem. Three months later, it turns out that their OneDrive contained important project documents not stored anywhere else. The account is deleted, the data is gone. Microsoft cannot help.

Scenario 2: ransomware encrypts SharePoint

A user unwittingly executes ransomware that encrypts all synchronized SharePoint files via the OneDrive sync client. The encrypted files are uploaded as new versions to SharePoint. The "Files Restore" function can reset OneDrive to an earlier point in time, but for the SharePoint library accessed by 50 users, it is more complicated. And versioning only helps if no more than 500 versions per file have been created.

Scenario 3: the malicious administrator

An IT administrator who leaves the organization on bad terms deletes several SharePoint sites and empties the recycle bins before their last working day. They have the necessary permissions, and Microsoft's recycle bin mechanism does not apply when the recycle bin is manually emptied. Without an external backup, the data is irretrievably lost.

Scenario 4: compliance requirements beyond retention

Your organization is subject to a legal retention obligation of 10 years for business-relevant emails (HGB, AO). Microsoft Retention Policies can technically be configured for 10 years, but the configuration is complex, and an error in the policy (e.g., a wrong condition) can cause emails to be deleted anyway. An independent backup gives you assurance that the data is present even if the Retention Policy does not function correctly.

Scenario 5: tenant compromise

In a targeted attack on your Microsoft 365 tenant, the attacker gains global administrator rights. They can disable Retention Policies, empty recycle bins, lift Litigation Holds, and delete data. Microsoft's internal protection mechanisms are all controllable via administrative rights and provide no protection in this scenario. Only an external backup stored outside the Microsoft 365 tenant is safe.

Microsoft 365 backup tools compared

There are numerous tools for Microsoft 365 backups. Here are the most established options for SMEs.

Veeam Backup for Microsoft 365

Veeam is the market leader in virtualization backup and offers a dedicated M365 backup solution with "Veeam Backup for Microsoft 365."

Strengths: Granular recovery (individual emails, files, contacts, calendar entries), support for Exchange Online, SharePoint Online, OneDrive for Business, and Teams, various storage targets (local storage, S3-compatible cloud storage, Azure Blob), Object Lock support for immutable backups, free Community Edition for up to 10 users and 1 TB SharePoint data.

Weaknesses: Requires a dedicated server (physical or VM) for the backup infrastructure, management via Veeam console (not cloud-native), storage costs are in addition to the Veeam license.

Cost: The Community Edition is free. The licensed version costs approx. 3 to 4 euros per user per month (depending on licensing model and volume discounts). Storage costs are additional (e.g., Wasabi: 6.99 USD per TB per month).

Suited for: Organizations that already use Veeam for their on-premise backups and want unified backup management. Organizations that want to retain control over backup storage.

AvePoint Cloud Backup

AvePoint specializes in Microsoft 365 management and backup and offers a purely cloud-based solution.

Strengths: Fully cloud-native (no dedicated server needed), support for Exchange, SharePoint, OneDrive, Teams, Groups, and Dynamics 365, automatic discovery of new users and sites, granular recovery with comparison function (before/after), compliance reports and audit logs.

Weaknesses: Backup storage resides with AvePoint (Azure-based); you have no control over the physical storage location. Higher per-user costs compared to self-hosted solutions.

Cost: Approx. 4 to 6 euros per user per month, including storage.

Suited for: Organizations without their own backup infrastructure that prefer an easy-to-manage cloud solution.

Hornetsecurity 365 Total Backup

Hornetsecurity (formerly Altaro) offers an M365 backup solution with "365 Total Backup" that integrates into their broader email security platform.

Strengths: Fully cloud-native, support for Exchange, OneDrive, SharePoint, and Teams, unlimited backup storage (no per-user storage limit), simple setup (connect tenant and done), integration with Hornetsecurity email security.

Weaknesses: Less granular restore options than Veeam or AvePoint, backup storage resides with Hornetsecurity (no BYOS), limited reporting features.

Cost: Approx. 2 to 4 euros per user per month, depending on the package.

Suited for: Organizations seeking an uncomplicated solution with unlimited storage that already use Hornetsecurity for email security.

Microsoft's own backup (Microsoft 365 Backup)

Microsoft announced its own backup solution for Microsoft 365 in 2024 and has been rolling it out gradually. It offers fast backups and restores for Exchange, SharePoint, and OneDrive, with point-in-time recovery and granular restoration.

Strengths: Native integration into Microsoft 365, very fast backup and restore speeds (up to 2 TB per hour restore according to Microsoft), management via the Microsoft 365 Admin Center.

Weaknesses: Dependence on the same provider (if the tenant is compromised, the backup may also be affected), limited Teams support (at the time of publication), no option to store backups outside Microsoft (no BYOS), relatively high per-GB costs.

Cost: 0.15 USD per GB per month (estimated, pay-as-you-go). For 100 users with an average of 50 GB data per user: approx. 750 USD per month.

Suited for: Organizations that prefer a Microsoft-native solution and accept the limitations.

Setup: Microsoft 365 backup with Veeam

Here is a concrete example of setting up an M365 backup with Veeam Backup for Microsoft 365.

Prerequisites

You need a server (physical or VM) running Windows Server 2019/2022 or Ubuntu. Veeam recommends at least 4 cores, 16 GB RAM, and fast local storage for the proxy role. You also need a Microsoft 365 application registration (App Registration) in Azure AD with the necessary API permissions. Veeam provides a wizard that creates the App Registration automatically.

Step by step

1. Install Veeam: Download Veeam Backup for Microsoft 365 and install it on the prepared server. Installation is straightforward and takes a few minutes.

2. Add organization: Add your Microsoft 365 organization. Veeam guides you through creating the App Registration and granting the necessary permissions (Application Permissions for Exchange, SharePoint, and Teams).

3. Create backup repository: Create a backup repository -- the storage location for the backups. For local storage, select "Local" and specify the path. For S3-compatible cloud storage, select "Object Storage" and configure the endpoint (e.g., Wasabi: s3.eu-central-1.wasabisys.com), the bucket, the credentials, and optionally Object Lock.

4. Create backup job: Create a backup job that backs up the desired objects: all users, all sites, all teams, or a selection. Configure the backup schedule (e.g., every 6 hours).

5. Configure retention: Define how long backup data is retained. For most organizations, 1 to 3 years is appropriate. If legal retention obligations exist: correspondingly longer.

6. Start and monitor backup: Start the first backup job. The initial backup can take hours to days depending on data volume. Subsequent backups are incremental and significantly faster.

Costs and storage planning

Estimating data volume

A typical Microsoft 365 user generates the following data volume: Exchange Online mailbox 5 to 15 GB (standard quota 50 GB, with archive mailbox up to 100 GB), OneDrive 5 to 20 GB (standard quota 1 TB), SharePoint 1 to 5 GB per user (shared, therefore hard to quantify per user).

For 100 users, the estimated total volume is 2 to 5 TB, depending on usage intensity.

Calculating costs

Veeam + Wasabi: Veeam license approx. 350 EUR per month (100 users) + Wasabi storage approx. 25 EUR per month (3.5 TB) = approx. 375 EUR per month.

AvePoint: Approx. 500 EUR per month (100 users, including storage).

Hornetsecurity: Approx. 300 EUR per month (100 users, including storage).

Microsoft 365 Backup: Approx. 600 EUR per month (100 users, estimated 4 TB).

For a 100-user organization, costs range between 300 and 600 EUR per month, depending on the tool and data volume. That is a manageable amount compared to the potential costs of data loss.

M365 backup and compliance

A dedicated M365 backup helps with several compliance requirements. For DSGVO (GDPR) (right to erasure), you must be able to delete personal data on request, including in backups. Most M365 backup tools support this through targeted deletion of individual users or items in the backup. For GoBD and HGB (retention obligations), you must retain business-relevant emails and documents for 6 to 10 years. Your data backup policy should explicitly reflect these periods. An M365 backup with appropriate retention provides additional protection alongside Microsoft Retention Policies. For NIS2 (backup management), you must demonstrate that you operate a functioning backup management system. A documented M365 backup with regular restore tests fulfills this requirement.

Restore tests for Microsoft 365

As with any backup: an M365 backup that has never been tested is not a backup. Regularly test the following scenarios.

Email restore: Restore a single deleted email. Restore a complete folder. Restore an entire mailbox.

SharePoint restore: Restore a single file from a SharePoint library. Restore a complete document library. Restore an entire SharePoint site.

OneDrive restore: Restore a single file. Restore a user's entire OneDrive.

Teams restore: Restore a Teams channel with its files. Verify that the channel structure and memberships are correctly restored.

Document every test with date, scenario, result, and duration. In ISMS Lite, backup strategies, restore tests, and retention policies for Microsoft 365 can be evidenced in a structured way. This documentation is your evidence for audits.

Related articles

Document your M365 backup strategy

ISMS Lite helps you document your Microsoft 365 backup strategy, define retention policies, and prove compliance for audits.

Install now