There is no single safety net for your data in Microsoft 365. Instead, there are several layers of protection – each built for a different kind of failure.
The recycle bin can recover a deleted file. Version history can undo an unwanted change. Microsoft Purview can retain content for a defined period or indefinitely. And Microsoft 365 Backup can restore large volumes of Exchange Online, SharePoint and OneDrive data after ransomware or mass deletion. They all protect data, but they do it in different ways, within different recovery windows and for different failure scenarios.
Retention belongs to the data governance strategy. Backup belongs to the recovery strategy. Microsoft 365 Backup narrows the gap between the two, but it does not eliminate every reason an organisation might choose an external backup platform.
Table of Contents
What Microsoft 365 Retention Covers
In Microsoft 365, retention is managed through Microsoft Purview, which uses two mechanisms for different purposes. Retention policies apply settings at the container level, such as an entire SharePoint site or mailbox. By contrast, retention labels work at a more granular level, applying to individual emails, documents, or records. Between the two, an organization decides what has to survive, for how long, and what happens once that period ends.
When content under a retention policy gets edited or deleted in SharePoint or OneDrive, Microsoft keeps a copy in the site's Preservation Hold library – a secured, admin-managed location outside the normal user interface. For organizations that need retention to survive even their own administrators, Preservation Lock goes a step further: once applied, nobody, including a global admin, can turn the policy off, delete it, or loosen it. Locations can be added, retention periods can be extended – but never reduced, never disabled. What all of this governs is how long content exists, not how fast you can get it back, which is what Microsoft built a separate service for.
What Microsoft 365 Backup Covers
Microsoft 365 Backup is that service – Microsoft's own, sold separately from your license on a pay-as-you-go basis, covering Exchange Online, SharePoint, and OneDrive. Teams comes along partially: files shared in Teams live in SharePoint and OneDrive and are backed up with them, while chat and channel messages are stored elsewhere and fall outside the service. All of it runs under Microsoft's shared responsibility model: Microsoft runs the platform, you own your data. Uptime, infrastructure, and replication across data centers sit on Microsoft's side of that line; recovering what a user, an admin, or an attacker deletes sits on yours.
Backup content sits on append-only Azure blobs, so the service can create new restore points but can't modify or overwrite existing ones. Retention and deletion policies from Purview don't touch the backup retention period either – the two are deliberately isolated, so a misconfigured retention policy can't shrink your recovery window on its own. If a potentially harmful action hits the backup itself, Microsoft notifies a set group of admins automatically. That covers the failure scenarios most tenants actually hit, up to the point where the scope of the service runs out.
M365 Backup and Retention Policies Limitations
Microsoft 365 retention and native backup cover a lot. The differences come down to four things: how long you can keep data, how firmly you can lock it, which workloads Microsoft protects, and where the copy lives.
Retention Period
Retention length comes first. Native backup keeps data for one year, and that period isn't adjustable. If you're in healthcare, finance, or legal – or working under client contracts that specify multi-year retention – native backup stops well short, and retention, which is built for governance rather than restore, doesn't pick up the difference.
Immutability
The immutability is narrower than the word suggests. Append-only means existing restore points can't be modified or overwritten – it doesn't mean they can't be removed. An admin with sufficient rights can still offboard the backup entirely. Microsoft applies a 90-day recovery grace period after that, but the recovery copy remains reachable from inside the same tenant it exists to protect.
Workloads Coverage
Then there's coverage. Teams chat and channel messages aren't a protected workload, and the same holds for other data your organization may depend on – Planner, Forms, and Entra ID configuration all sit outside the service. If your daily collaboration runs through Teams conversations, that's a gap worth accounting for.
Security Isolation
Last is location. Retention, Preservation Hold, and native backup restore points all sit inside Microsoft's service boundary, which makes restores fast because Microsoft never moves the data outside the platform. It also means production and recovery share the same fate. During an outage, both are unavailable at once. A compromised admin account can reach the same recovery points.
That last scenario is where the gap turns practical. An attacker with Global Admin rights doesn't have to break your backup – they can strip file versions, alter retention settings, and delete restore points before encrypting anything. Microsoft 365 ransomware recovery depends on having a copy those credentials can't reach: stored outside the tenant, under separate access control, and locked against deletion for as long as your retention policy says.
Further reading Microsoft 365 Backup Solution: Native vs third party backup software
How MSP360 Closes the Gap
An independent backup layer addresses a different set of requirements: retention beyond a fixed ceiling, storage outside the tenant, and coverage for workloads native backup doesn't protect.
MSP360 Backup for Microsoft 365 stores your data outside Microsoft's own infrastructure, in storage you choose – AWS, Wasabi, Backblaze B2, Azure, or your own cloud storage, rather than a single bundled destination. Retention doesn't impose a fixed time limit. Policies run from days to years, and organizations can keep data for as long as they need by leaving it without a retention policy. On supported storage destinations, MSP360 gives you the flexibility to use Object Lock immutability with retention policies or independently, depending on your data protection requirements.
Coverage extends to contacts, calendars, Outlook mail backup, OneDrive backup, SharePoint backup, and Microsoft Teams backup – channels, posts, shared files, and metadata included, where native backup stops at the files.
Recovery is item-level: individual emails, files, calendar events, or full mailboxes, with PST export for eDiscovery. Role-based access control, multi-factor authentication, audit logs, and encryption in transit and at rest cover what an audit asks for. Check that your edition includes retention configuration and immutability, as Microsoft manages both features.
For MSPs, MSP360 Managed Backup for M365/Google runs all of this multi-tenant from one console – every client domain in a single view, alerting and reporting across the estate, and white-labeling for client-facing delivery.
Microsoft Purview vs. Microsoft 365 Backup vs. MSP360 Backup
| Microsoft Purview | Microsoft 365 Backup | MSP360 Backup | |
|---|---|---|---|
| What is it for? | Governance, compliance, eDiscovery | Native Microsoft 365 backup and recovery | Independent backup and recovery |
| What is the scope of protection? | Container, site, item, or label level | Selected users and SharePoint sites | Per user, configurable |
| What data is covered? | Retention across supported Microsoft 365 workloads | Exchange, SharePoint, OneDrive | Outlook, OneDrive, contacts, calendars, SharePoint, Teams |
| How long can data be retained? | Admin-defined, days to indefinite | Fixed at one year | Configurable – days to years, or indefinite |
| Where is the protected data stored? | Inside the Microsoft 365 tenant | Inside Microsoft's service boundary | Your choice of cloud storage |
| Can it be made immutable? | Yes, via Preservation Lock (E5 required) | Append-only; admin can still offboard/delete | Yes, via Object Lock on supported storage |
| Can MSPs manage multiple tenants? | Complicated multi-tenant management | Complicated multi-tenant management | Available via MSP360 Managed Backup |

How To Protect Your Data in M365 FAQ
Does Microsoft 365 need a separate backup solution?
For most organizations, yes. A separate solution becomes relevant once you need retention beyond one year, storage outside Microsoft's own boundary, coverage for Teams conversations, or multi-tenant management. Our complete guide to Microsoft 365 backup walks through what each workload requires.
Does Microsoft 365 include backup?
Not by default. Microsoft 365 ships with retention and recovery features – recycle bins, version history, Purview retention. Microsoft sells Microsoft 365 Backup as a separate, paid, pay-as-you-go service rather than including it with every subscription
Is retention enough?
Yes, for governance and compliance. No, for a complete recovery strategy. Retention preserves records, but it doesn't deliver the fast, large-scale recovery organizations need after ransomware or mass deletion.
What is the difference between Microsoft 365 backup and retention?
Retention controls how long content remains available and when users can delete it. Backup creates independent, restorable copies you can recover from after something goes wrong. One is a policy; the other is a recovery point.
Can Microsoft 365 native backup replace third-party backup?
Only where its limits line up with your requirements. Microsoft 365 Backup keeps data for up to one year, stores backup data inside Microsoft's service boundary, and protects Exchange, SharePoint, and OneDrive—but not Teams conversations. Longer retention, an independent copy, or full workload coverage each require something else. Workload-level guides are available for Outlook, OneDrive SharePoint, and Teams.
Is Microsoft 365 Backup enough for ransomware protection?
Not on its own. Microsoft designed Microsoft 365 Backup to recover from ransomware and mass-deletion scenarios within its supported workloads, but it stores restore points inside the same tenant that an attacker with admin rights can access. An independent copy outside Microsoft's boundary is advisable for any organization treating ransomware as a realistic threat – see the full Microsoft 365 ransomware recovery guide for what that setup looks like in practice.
Can Microsoft recover deleted data?
Often, within limits. Exchange Online keeps deleted items for 14 days by default, configurable up to 30. SharePoint and OneDrive keep deleted items in the recycle bin for up to 93 days. Microsoft 365 Backup extends retention to one year for supported workloads. After that, you'll need a separate backup to recover the data
How to Protect Your Data in M365 in Short
Retention keeps records where compliance and legal can find them. Microsoft 365 Backup does what retention can't – it gives you an actual restore point, built for scale and for ransomware, within the year it covers and the three workloads it protects.
Neither one, on its own, gives you a copy that lives outside Microsoft's boundary, survives an attacker with admin rights, or keeps data for as long as your business – not Microsoft's default settings – decides it should. That's the case for looking closely at third-party backup: not because native protection is broken, but because full control over where your data lives, how long it stays, and who can reach it is a different job than the one retention or native backup were built for.



