Back to Insights
Guides & AnswersProblemSecurity
Part of: Cybersecurity for UK SMEs

Do I Need Backups If My Business Is Already on Microsoft 365?

Oliver Mogg10 Aug 20269 min read

The short answer

It depends on where your data actually lives. Under Microsoft's Shared Responsibility Model, Microsoft is responsible for the service and you are responsible for your data - and native tools like the Recycle Bin and version history are retention, not a backup. A small minority of businesses can reasonably rely on native tools alone, but for most SMEs that genuinely run on Exchange, SharePoint, OneDrive and Teams, the honest answer is yes: you still need an independent, third-party backup that sits outside your Microsoft 365 tenant.

Do I Need Backups If My Business Is Already on Microsoft 365?

Introduction: the question every M365 business owner eventually asks

One of the questions I get asked all the time is: "If I'm on Microsoft 365 and using OneDrive, do I really still need backups?" It's a fair question, and the honest answer up front is: it depends. It depends on how you actually use Microsoft 365, where your important data really lives, and how much risk your business could absorb if something went wrong. For some businesses the answer is a clear no, for most it ends up being yes, and the aim of this post is to help you work out which side of the line you sit on.

Most people already know that OneDrive comes with some level of recoverability. There's a Recycle Bin, there's a second stage Recycle Bin, and if something gets deleted, in most cases you can get it back. So on paper, yes, Microsoft 365 does give you a form of backup. The point I want to demystify is that having some recoverability inside Microsoft 365 isn't the same as your business being properly protected, and a separate, third-party backup, one that sits outside your tenant and that you'd need to speak to your IT team to restore from, is a very different thing.

It's also worth being fair to the other side of the argument. Plenty of businesses genuinely can get by on the native tools alone, and I'll walk through when that's a reasonable position to hold rather than dismissing it. The word "backup" gets thrown around a lot in the marketing, and it's genuinely a vague term. There are different types of backups, they cover different scenarios, and unless you work in IT it's very easy to lose track of what actually protects what. My aim here is to strip out the jargon and explain, plainly, where the confusion comes from and what it means for your business.

The short answer

Let's not bury it. The short answer is no, not every business needs a third-party backup on top of Microsoft 365. It genuinely depends on how you use the platform, where your important data actually lives, and how much risk your business can absorb if something went wrong. Backup is a risk management decision, not a product every business has to buy.

Here are the main situations where a full third-party M365 backup may not be the right first move:

  • Very small businesses and sole traders on M365. If it's just you or a handful of users, with a small amount of data and no significant compliance obligations, the native Recycle Bin, version history and retention windows may be enough for you. A total loss would be inconvenient but not business-ending, and the cost of a third-party backup may outweigh the risk you're actually carrying.
  • Businesses whose data mainly lives in Google Drive (or another platform). A lot of businesses use Microsoft 365 primarily for email and Teams, but their day-to-day documents actually sit in Google Drive, Dropbox or somewhere else. If that's you, then it's the other platform you should be looking to back up first, not M365. Backing up the wrong system is a common and expensive mistake.
  • Businesses running an on-premises server as their main data store. If your files, line-of-business apps or databases still live on a local server, that's a different backup problem to solve. Server backups protect that environment. They aren't a substitute for M365 backup, and M365 backup isn't a substitute for them. They cover different data, and you need to think about them separately.

That last point is worth pausing on, because it trips a lot of people up. Off-site backups and server backups are related but not the same thing. A server backup captures your on-premises environment, typically as an image or file-level backup on a device in your office. An off-site backup takes a copy of that (or of your cloud data) and stores it somewhere completely independent, so a fire, theft or ransomware event on-site doesn't take your only copy with it. Some businesses need one, some need both, and the right answer depends entirely on where your data actually lives.

For the majority of SMEs who genuinely run their business inside Microsoft 365, using Exchange, SharePoint, OneDrive and Teams as the main home for their data, the honest answer swings back to yes, you probably do still need a third-party backup. Microsoft protects the service. You are responsible for your data. But the starting question isn't "should I buy a backup?" It's "where does my data actually live, and what would it cost me to lose it tomorrow?" Once you've answered that, the decision becomes much easier.

The rest of this post walks through why, for most M365-first businesses, the answer does end up being yes, and what to look for if you decide you need one.

Why people assume Microsoft 365 already includes backup

If I zoom out and look at this without my IT hat on, the reason is pretty simple. People hear the word "cloud" and assume that anything in it is automatically backed up. It's the same vagueness we talked about at the start, and it can lull businesses into feeling safer than they actually are.

Features like the Recycle Bin and version history genuinely do give a sense of recoverability, and to an extent that's true. But once data is gone from those safety nets, or if someone gains access to an account and deliberately clears them out, that recoverability disappears with it. Microsoft's own marketing also focuses heavily on uptime and reliability, and it's very easy to confuse "the service is always available" with "my data is always safe." They're two very different things.

Most businesses also never have a reason to test a restore until something goes wrong. It's only when the problem hits that the gap becomes obvious, and by then it's often too late.

So to be clear, this isn't a silly question to ask. Microsoft do publish all of this on their own website, but realistically no business owner is sitting down to read it. That's exactly what we're trying to unpack here, and it leads neatly into the next section: something Microsoft call the Shared Responsibility Model.

The Microsoft Shared Responsibility Model

The Shared Responsibility Model is Microsoft's own published position on who is responsible for what. It's not opinion, and it's not something the IT industry has made up.

Microsoft is responsible for: the underlying infrastructure, uptime, physical security of their data centres, and service availability.

You (the customer) are responsible for: your data, who has access to it, how long it's retained, and how it's recovered.

That's where the line is drawn, and it's the single biggest reason most businesses don't realise there's a gap. When you're using a brand as big as Microsoft, it's natural to assume it's a complete package. In reality, there are deliberate areas that Microsoft leave to you, and those areas can turn into real holes in your business's data security if nobody's paying attention.

The easiest way to think about it: Microsoft provides the safe. You're responsible for what's inside it, and how you'd get it back if something happened. Native retention tools are useful, but they are not the same thing as a backup. This isn't just our interpretation either. Microsoft spell it out in their own Services Agreement (section 6.b), where they recommend that you keep a separate backup copy of the content you store on their services.

What can actually go wrong with your M365 data?

Here are the scenarios we see most often as an IT and Managed Service Provider. None of these are meant to be scare stories, they're just the day-to-day realities of running a business on Microsoft 365.

  • Accidental deletion. By far the most common cause of data loss. You're busy, you clear out a folder, empty the Recycle Bin, and a week later realise you needed something in there.
  • Malicious deletion by a leaver. Sadly, it happens. Someone leaves on bad terms and takes data with them, or deliberately deletes things on the way out.
  • Ransomware encrypting synced OneDrive and SharePoint files. Ransomware doesn't care that your files are in the cloud. If it hits a device that's syncing OneDrive or SharePoint, those encrypted files sync straight back up. With a proper backup, we simply roll back to before the attack. Without one, you're stuck.
  • Retention policy gaps. Microsoft's native retention windows are finite, and it's very easy to miss the notifications when they're about to expire. Once the window closes, the data is gone.
  • Third-party app errors or sync corruption. Microsoft 365 talks to a lot of other apps and services. When something goes wrong at that layer, data can be lost or corrupted, and a backup is often the only clean way back.
  • Data loss when a user's license is removed. This one catches most business owners out. As best practice, when someone leaves, we archive their mailbox and unassign the licence so it can be reused. The mailbox can usually be preserved, but OneDrive data has a default retention of only 30 days after the account is deleted (an admin can extend this, but many don't). After that, it's gone. A third-party backup means we can still recover that data months, or even years, later.

The important point is that none of these situations are Microsoft's fault. They sit outside what Microsoft are responsible for under the Shared Responsibility Model. We tend to use the phrase "not if, but when" for a reason, and that's why the responsibility for backing up your business data sits with you, the business owner.

What Microsoft 365 does give you natively

To be fair to Microsoft, the native tools genuinely are useful. They just aren't a backup. Here's what you actually get:

  • Recycle Bin (first and second stage). In SharePoint and OneDrive, deleted items go through two stages of Recycle Bin. Between them, items are retained for a total of 93 days before they're permanently gone. In Exchange (mailboxes), deleted items are typically kept for 14 days by default, and this can be extended to a maximum of 30 days.
  • SharePoint and OneDrive version history. You can roll a file back to an earlier version, but only while that file still exists. If the file is deleted and the Recycle Bin windows expire, the version history goes with it.
  • Retention Policies. These are designed to keep data around for compliance reasons, not to help you recover from accidental loss.
  • Litigation Hold and Preservation Policies. These are often mistaken for backup. They're compliance tools, designed to preserve data for legal or regulatory reasons, not to give you a clean, point-in-time restore.

The simplest way to think about it is this: retention preserves for compliance, backup restores after loss. Version history lets you go back to an earlier draft, but only for files that still exist.

Why native retention isn't the same as a backup

The core issue is independence. A true backup is a separate copy of your data, held outside the system it came from. Native retention doesn't give you that. If your tenant is compromised, or an admin account is hijacked, the "safety nets" inside that same tenant can be wiped along with everything else.

On top of that:

  • Retention windows are finite, and often shorter than businesses realise (as we saw above, 93 days for SharePoint/OneDrive, 30 days maximum for mailbox deleted items, and 30 days for a deleted user's OneDrive data).
  • Restores are limited in granularity and speed. Recovering a single item from a specific date isn't always straightforward, and rolling back a large amount of data can be painful.
  • There's no real protection against admin error, malicious deletion, or ransomware syncing. If it can happen inside the tenant, native tools can be affected by it.
  • There's no true point-in-time recovery across an entire tenant. You can't easily say "roll everything back to 3pm last Tuesday" using native tools alone.

Native tools cover some scenarios well. They just don't cover the ones that tend to hurt the most.

What a proper third-party backup gives you

A third-party backup gives you an independent, immutable copy of your data stored outside your Microsoft 365 tenant. "Immutable" simply means it can't be altered or deleted, even by an admin. Because the backup lives outside your tenant, if your business is ever compromised by a malicious attack, that data stays safe and separate. You'd typically need to go through your IT provider to restore from it, which is exactly what you want.

You also get:

  • Point-in-time restore. You can roll back to a specific moment, for example the day before a ransomware attack or the morning a file was accidentally deleted.
  • Granular restore. A single email, a single file, a specific SharePoint item, or a Teams chat. You don't have to roll back the entire company just to recover one thing, and that alone can save hours of admin time.
  • Coverage across Exchange, OneDrive, SharePoint, and Teams, including Teams chats where supported.
  • Long-term retention beyond native windows. Most native retention tops out at around 90 days. With a third-party backup, retention is configurable, and most businesses set this to years rather than months.
  • Protection against ransomware and insider threats, because the backup is completely segregated from your live environment.

The best way to think about backups is that they're invisible right up until the day you need them, and on that day they're invaluable.

What about Microsoft 365 Backup, Microsoft's own paid product?

There's one more option worth being straight about, because Microsoft have muddied the water themselves. In 2024 they launched Microsoft 365 Backup, their own paid, first-party backup product. It takes snapshot backups of Exchange, OneDrive and SharePoint and is billed on a pay-as-you-go basis per gigabyte of protected data (Microsoft set the list price in US dollars, which currently works out at roughly 12p per GB per month), so there are no per-user licences to buy.

Credit where it's due, it's a genuinely good tool for what it does. Restores are fast, it works from frequent recommended restore points, the snapshots are immutable so they can't be tampered with, and mass restores after something like a ransomware event are far quicker than older methods. Since April 2026 you can also restore individual files and folders from SharePoint and OneDrive rather than being forced to roll back a whole site or account, so it's no longer the all-or-nothing tool it was at launch. Retention is configurable up to a year. If your main worry is getting a file, site, account or mailbox back quickly and in one piece, it does that job well.

Here's the important caveat, and it's the same point this whole post is built on. Even though the backups sit in a separate Azure store rather than in your live tenant, they still live inside Microsoft's own trust boundary. It's Microsoft backing up Microsoft. That's absolutely fine for everyday accidents and fast recovery, but it doesn't give you the independence of a copy held completely outside Microsoft by a third party. If your concern is a wider compromise of your Microsoft relationship, identity or tenant, a backup that still sits within Microsoft's boundary carries some of the same risk. It's also worth knowing what it does and doesn't cover: Exchange, OneDrive and SharePoint are included, and because Teams files live in SharePoint and OneDrive they're effectively protected too, but Teams chat messages themselves are not backed up.

So think of Microsoft 365 Backup as a strong middle ground rather than the finish line. For many businesses it's a real step up from native retention alone. For those who specifically want their data held independently of Microsoft, it complements a third-party backup rather than replacing it.

The strongest arguments against, and where they actually land

Rather than knock down weak versions of the "we don't need a backup" argument, it's more useful to take the strongest form of each position, and then look honestly at where it holds up and where it breaks.

  • "OneDrive already keeps a copy of my files, so that is my backup." The strongest version of this argument is that OneDrive stores files in Microsoft's data centres with geo-redundancy, keeps deleted files in the Recycle Bin for 93 days, and holds version history for anything that still exists. For a single user losing a single file, that genuinely is often enough. Where it breaks down is that OneDrive is a sync service, not a backup. If a file is deleted or encrypted on your device, that change syncs everywhere. Redundancy is not the same as recoverability.
  • "SharePoint version history covers me." Fairly stated: version history is genuinely powerful for accidental overwrites, bad edits, or rolling a document back to Tuesday's draft. If your main concern is people fat-fingering a file, this really does help. Where it stops helping is the moment the file itself is deleted and the Recycle Bin windows expire. No file means no version history to roll back to.
  • "Microsoft will restore my data if I ask." Microsoft run one of the most resilient cloud platforms on the planet, they replicate data across regions, and if there is a platform-level incident they will recover the service. All true. What they explicitly don't offer is restoring your specific data because a user, a leaver, or an attacker deleted it and the retention window has passed. That is your side of the Shared Responsibility Model, and Microsoft's own Service Agreement recommends using a third-party backup for exactly this reason.
  • "We're too small to need this." The honest version of this argument is that for a very small team with a small amount of data and no compliance obligations, the cost and admin overhead of a backup can genuinely outweigh the risk. That is a legitimate position and I covered it in the short answer. It stops being legitimate the moment the business grows, takes on regulated data, or becomes dependent on M365 for day-to-day operations, at which point the risk profile changes and the same argument no longer holds.
  • "Our retention policy is enough." Properly configured retention policies, Litigation Hold and Preservation Policies are powerful tools, and if you have a mature compliance setup they cover a lot of ground. A well-run tenant with the right retention labels really can hold data for years. The issue is that retention is designed for compliance, not clean recovery. It preserves data in place, inside the same tenant that could be compromised, and it doesn't give you point-in-time restore. Different job, different tool.

Pulling those threads together, there are a handful of situations where staying with the native tools alone is a genuinely reasonable call: a very small team with minimal data and no real compliance burden; a business whose data actually lives somewhere else, such as Google Drive or Dropbox, with Microsoft 365 used mainly for email and Teams; a business whose real data store is an on-premises server that's already properly backed up and copied off-site; and a mature tenant with strong native retention that has been deliberately configured and tested. In each of those cases the decision has been made on purpose rather than by accident. For most SMEs that genuinely run their business inside Microsoft 365, though, the honest answer still sits firmly in the "yes, you need it" camp.

What to look for if you decide you need one

If you do decide to put a third-party backup in place, this is the checklist to work through with any provider. Treat it as a buyer's checklist rather than a product recommendation:

  • Coverage across Exchange, OneDrive, SharePoint, and Teams (including chats).
  • Immutability and ransomware protection, so the backup can't be tampered with.
  • Restore flexibility: granular, point-in-time, and cross-user restores.
  • Where the backup data is stored. UK or EU data centres are important for UK GDPR compliance.
  • Retention length and pricing model. Understand what you're paying for and for how long data is kept.
  • Ease of restore and admin experience. A backup you can't easily restore from isn't much use on the day.

Ask any provider these questions before signing anything.

Conclusion

To recap: it genuinely depends, and for a small minority of businesses the "no" is a fair one, for the reasons set out earlier. Those are legitimate positions rather than excuses, and I'd rather you spent that money on the right thing than the wrong thing.

For the majority of SMEs who genuinely run inside Microsoft 365, that's where the honest answer swings back to yes, you need a third-party backup. Microsoft is responsible for the service, you are responsible for your data, and native retention was never designed to be a clean recovery tool. That single line sits behind every point in this post.

This all comes down to your acceptance of risk and how much risk you're willing to carry as a business. The purpose of this post isn't to sell you anything, it's to help you make an informed decision. If nothing else, it's worth taking a quick look at your current setup and asking yourself: "If I lost everything in my tenant tomorrow, could I get it back?" If the answer isn't a confident yes, that's your starting point.

Awareness is the first step. The action can follow when you're ready.

Comparison table: native Microsoft 365 retention vs Microsoft 365 Backup vs third-party backup

Feature Native Microsoft 365 retention Microsoft 365 Backup (paid add-on) Third-party backup
Independent copy of data No, sits inside your tenant No, snapshots sit in Azure but remain inside Microsoft's trust boundary Yes, stored outside your tenant
Immutable (tamper-proof) No, admins can alter or delete Yes, immutable append-only storage Yes, cannot be altered even by an admin
SharePoint / OneDrive retention Up to 93 days (Recycle Bin stages 1 and 2) Configurable up to 1 year (365-day retention) Fully configurable, typically years
Exchange mailbox deleted item retention 14 days default, up to 30 days maximum Configurable up to 1 year (365-day retention) Fully configurable, typically years
Retention after a user licence is removed 30 days by default for OneDrive data Retained while the account stays in the backup policy, up to 1 year Retained per your backup policy, long-term
Point-in-time restore Limited Yes, restore to a recommended restore point Yes, restore to a specific moment
Granular restore (single email, file, chat) Limited Item-level for Exchange; file and folder restore now available for SharePoint and OneDrive Yes, full granular restore
Ransomware protection Vulnerable to sync-based encryption Protected, snapshots sit outside the live service Protected, sits outside the live environment
Protection against admin error or malicious deletion Limited Yes Yes
Coverage of Teams chats Limited No chat messages; Teams files are covered via SharePoint and OneDrive Yes, on most modern platforms
Purpose Compliance and short-term recovery Fast in-place recovery within Microsoft 365 Full data recovery after loss

Sources

Topics

securityoffice-365backupmicrosoft-365
Part of our pillar guideCybersecurity for UK SMEs

Need help with your IT?

Our team of UK-based IT experts are ready to help your business thrive. Get in touch for a free, no-obligation consultation.