{"id":62938,"date":"2026-08-10T16:02:03","date_gmt":"2026-08-10T12:02:03","guid":{"rendered":"https:\/\/www.msp360.com\/resources\/?p=62938"},"modified":"2026-08-10T16:02:03","modified_gmt":"2026-08-10T12:02:03","slug":"retention-policies-vs-microsoft-365-backup","status":"publish","type":"post","link":"https:\/\/www.msp360.com\/resources\/blog\/retention-policies-vs-microsoft-365-backup\/","title":{"rendered":"Retention Policies vs Microsoft 365 Backup: How to Protect Your Data"},"content":{"rendered":"<p>There is no single safety net for your data in Microsoft 365. Instead, there are several layers of protection \u2013 each built for a different kind of failure.<\/p>\n<p><!--more-->The recycle bin can recover a deleted file. Version history can undo an unwanted change. Microsoft Purview can retain content for a defined period or indefinitely. And Microsoft 365 Backup can restore large volumes of Exchange Online, SharePoint and OneDrive data after ransomware or mass deletion. They all protect data, but they do it in different ways, within different recovery windows and for different failure scenarios.<\/p>\n<p>Retention belongs to the data governance strategy. Backup belongs to the recovery strategy. Microsoft 365 Backup narrows the gap between the two, but it does not eliminate every reason an organisation might choose an external backup platform.<\/p>\n<div style=\"display: none;\">\n<style>.entry-content .table-of-content ul ul{display:none;}<\/style>\n<\/div>\n<div class=\"table-of-content \">\n\t\t\t\t<p>Table of Contents<\/p>\n\t\t\t\t<ul><\/ul>\n\t\t\t\t<\/div>\n<h2>What Microsoft 365 Retention Covers<\/h2>\n<p>In Microsoft 365, retention is managed through <a href=\"https:\/\/learn.microsoft.com\/en-us\/purview\/retention\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Purview<\/a>, which uses two mechanisms for different purposes. Retention policies apply settings at the container level, such as an entire SharePoint site or mailbox. By contrast, retention labels work at a more granular level, applying to individual emails, documents, or records. Between the two, an organization decides what has to survive, for how long, and what happens once that period ends.<\/p>\n<p>When content under a retention policy gets edited or deleted in SharePoint or OneDrive, Microsoft keeps a copy in the site's Preservation Hold library \u2013 a secured, admin-managed location outside the normal user interface. For organizations that need retention to survive even their own administrators, <a href=\"https:\/\/learn.microsoft.com\/en-us\/purview\/retention-preservation-lock\" target=\"_blank\" rel=\"noopener noreferrer\">Preservation Lock<\/a> goes a step further: once applied, nobody, including a global admin, can turn the policy off, delete it, or loosen it. Locations can be added, retention periods can be extended \u2013 but never reduced, never disabled. What all of this governs is how long content exists, not how fast you can get it back, which is what Microsoft built a separate service for.<\/p>\n<h2>What Microsoft 365 Backup Covers<\/h2>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/backup\/backup-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft 365 Backup<\/a> is that service \u2013 Microsoft's own, sold separately from your license on a pay-as-you-go basis, covering Exchange Online, SharePoint, and OneDrive. Teams comes along partially: files shared in Teams live in SharePoint and OneDrive and are backed up with them, while chat and channel messages are stored elsewhere and fall outside the service. All of it runs under Microsoft's <a href=\"https:\/\/www.microsoft.com\/en-us\/servicesagreement\" target=\"_blank\" rel=\"noopener noreferrer\">shared responsibility model<\/a>: Microsoft runs the platform, you own your data. Uptime, infrastructure, and replication across data centers sit on Microsoft's side of that line; recovering what a user, an admin, or an attacker deletes sits on yours.<\/p>\n<p>Backup content sits on append-only Azure blobs, so the service can create new restore points but can't modify or overwrite existing ones. Retention and deletion policies from Purview don't touch the backup retention period either \u2013 the two are deliberately isolated, so a misconfigured retention policy can't shrink your recovery window on its own. If a potentially harmful action hits the backup itself, Microsoft notifies a set group of admins automatically. That covers the failure scenarios most tenants actually hit, up to the point where the scope of the service runs out.<\/p>\n<h2>M365 Backup and Retention Policies Limitations<\/h2>\n<p>Microsoft 365 retention and native backup cover a lot. The differences come down to four things: how long you can keep data, how firmly you can lock it, which workloads Microsoft protects, and where the copy lives.<\/p>\n<h3>Retention Period<\/h3>\n<p>Retention length comes first. Native backup keeps data for one year, and that period isn't adjustable. If you're in healthcare, finance, or legal \u2013 or working under client contracts that specify multi-year retention \u2013 native backup stops well short, and retention, which is built for governance rather than restore, doesn't pick up the difference.<\/p>\n<h3>Immutability<\/h3>\n<p>The immutability is narrower than the word suggests. Append-only means existing restore points can't be modified or overwritten \u2013 it doesn't mean they can't be removed. An admin with sufficient rights can still offboard the backup entirely. Microsoft applies a 90-day recovery grace period after that, but the recovery copy remains reachable from inside the same tenant it exists to protect.<\/p>\n<h3>Workloads Coverage<\/h3>\n<p>Then there's coverage. Teams chat and channel messages aren't a protected workload, and the same holds for other data your organization may depend on \u2013 Planner, Forms, and Entra ID configuration all sit outside the service. If your daily collaboration runs through Teams conversations, that's a gap worth accounting for.<\/p>\n<h3>Security Isolation<\/h3>\n<p>Last is location. Retention, Preservation Hold, and native backup restore points all sit inside Microsoft's service boundary, which makes restores fast because Microsoft never moves the data outside the platform. It also means production and recovery share the same fate. During an outage, both are unavailable at once. A compromised admin account can reach the same recovery points.<\/p>\n<p>That last scenario is where the gap turns practical. An attacker with Global Admin rights doesn't have to break your backup \u2013 they can strip file versions, alter retention settings, and delete restore points before encrypting anything. <a href=\"https:\/\/www.msp360.com\/resources\/blog\/microsoft-365-ransomware-recovery-guide\/\">Microsoft 365 ransomware recovery<\/a> depends on having a copy those credentials can't reach: stored outside the tenant, under separate access control, and locked against deletion for as long as your retention policy says.<\/p>\n<p><span class=\"further-reading \">Further reading<\/span> <a href=\"https:\/\/www.msp360.com\/resources\/blog\/third-party-backup-software-microsoft-365\/\">Microsoft 365 Backup Solution: Native vs third party backup software<\/a><\/p>\n<h2>How MSP360 Closes the Gap<\/h2>\n<p>An independent backup layer addresses a different set of requirements: retention beyond a fixed ceiling, storage outside the tenant, and coverage for workloads native backup doesn't protect.<\/p>\n<p>MSP360 <a href=\"https:\/\/www.msp360.com\/saas-backup\/m365\/\">Backup for Microsoft 365<\/a> stores your data outside Microsoft's own infrastructure, in storage you choose \u2013 AWS, Wasabi, Backblaze B2, Azure, or your own cloud storage, rather than a single bundled destination. Retention doesn't impose a fixed time limit. Policies run from days to years, and organizations can keep data for as long as they need by leaving it without a retention policy. On supported storage destinations, MSP360 gives you the flexibility to use Object Lock immutability with retention policies or independently, depending on your data protection requirements.<\/p>\n<p>Coverage extends to contacts, calendars, <a href=\"https:\/\/www.msp360.com\/saas-backup\/m365\/outlook-backup\/\">Outlook mail backup<\/a>, <a href=\"https:\/\/www.msp360.com\/saas-backup\/m365\/onedrive-backup\/\">OneDrive backup<\/a>, <a href=\"https:\/\/www.msp360.com\/saas-backup\/m365\/sharepoint-backup\/\">SharePoint backup<\/a>, and <a href=\"https:\/\/www.msp360.com\/saas-backup\/m365\/microsoft-teams-backup\/\">Microsoft Teams backup<\/a> \u2013 channels, posts, shared files, and metadata included, where native backup stops at the files.<\/p>\n<p>Recovery is item-level: individual emails, files, calendar events, or full mailboxes, with PST export for eDiscovery. Role-based access control, multi-factor authentication, audit logs, and encryption in transit and at rest cover what an audit asks for. Check that your edition includes retention configuration and immutability, as Microsoft manages both features.<\/p>\n<p>For MSPs, <a href=\"https:\/\/www.msp360.com\/saas-backup\/managed-backup-microsoft365-google-workspace\/\">MSP360 Managed Backup for M365\/Google<\/a> runs all of this multi-tenant from one console \u2013 every client domain in a single view, alerting and reporting across the estate, and white-labeling for client-facing delivery.<\/p>\n<h2>Microsoft Purview vs. Microsoft 365 Backup vs. MSP360 Backup<\/h2>\n<table>\n<tbody>\n<tr>\n<th><\/th>\n<th><strong>Microsoft Purview<\/strong><\/th>\n<th><strong>\u00a0Microsoft 365 Backup<\/strong><\/th>\n<th><strong>MSP360 Backup<\/strong><\/th>\n<\/tr>\n<tr>\n<td><strong>What is it for?<\/strong><\/td>\n<td>Governance, compliance, eDiscovery<\/td>\n<td>Native Microsoft 365 backup and recovery<\/td>\n<td>Independent backup and recovery<\/td>\n<\/tr>\n<tr>\n<td><strong>What is the scope of protection?<\/strong><\/td>\n<td>Container, site, item, or label level<\/td>\n<td>Selected users and SharePoint sites<\/td>\n<td>Per user, configurable<\/td>\n<\/tr>\n<tr>\n<td><strong>What data is covered?<\/strong><\/td>\n<td>Retention across supported Microsoft 365 workloads<\/td>\n<td>Exchange, SharePoint, OneDrive<\/td>\n<td>Outlook, OneDrive, contacts, calendars, SharePoint, Teams<\/td>\n<\/tr>\n<tr>\n<td><strong>How long can data be retained?<\/strong><\/td>\n<td>Admin-defined, days to indefinite<\/td>\n<td>Fixed at one year<\/td>\n<td>Configurable \u2013 days to years, or indefinite<\/td>\n<\/tr>\n<tr>\n<td><strong>Where is the protected data stored?<\/strong><\/td>\n<td>Inside the Microsoft 365 tenant<\/td>\n<td>Inside Microsoft's service boundary<\/td>\n<td>Your choice of cloud storage<\/td>\n<\/tr>\n<tr>\n<td><strong>Can it be made immutable?<\/strong><\/td>\n<td>Yes, via Preservation Lock (E5 required)<\/td>\n<td>Append-only; admin can still offboard\/delete<\/td>\n<td>Yes, via Object Lock on supported storage<\/td>\n<\/tr>\n<tr>\n<td><strong>Can MSPs manage multiple tenants?<\/strong><\/td>\n<td>Complicated multi-tenant management<\/td>\n<td>Complicated multi-tenant management<\/td>\n<td>Available via MSP360 Managed Backup<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"call-to-action\">\n<div class=\"call-to-action__left\" style=\"width: 40%;\"><img decoding=\"async\" class=\"aligncenter\" src=\"\/wp-content\/uploads\/2025\/04\/Why-You-Need-to-Back-Up-Microsoft-365-preview-2-3.png\" alt=\"Whitepaper Microsoft 365 icon\" \/><\/div>\n<div class=\"call-to-action__right\" style=\"width: 60%;\">\n<div class=\"call-to-action__title\">Why You Need to Back Up Microsoft 365 and How MSP360 Helps<\/div>\n<div class=\"call-to-action__text\">Discover the ins and outs of a cloud to cloud backup strategy using MSP360 Backup for Microsoft 365.<\/div>\n<!--HubSpot Call-to-Action Code --><span class=\"hs-cta-wrapper hs-cta-deferred\" id=\"hs-cta-wrapper-a03f1309-f6ae-439a-9be0-d11b29410547\" data-portal=\"5442029\" data-id=\"a03f1309-f6ae-439a-9be0-d11b29410547\"><span class=\"hs-cta-node hs-cta-a03f1309-f6ae-439a-9be0-d11b29410547\" id=\"hs-cta-a03f1309-f6ae-439a-9be0-d11b29410547\"><!--[if lte IE 8]><div id=\"hs-cta-ie-element\"><\/div><![endif]--><a href=\"https:\/\/cta-redirect.hubspot.com\/cta\/redirect\/5442029\/a03f1309-f6ae-439a-9be0-d11b29410547\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"hs-cta-img\" id=\"hs-cta-img-a03f1309-f6ae-439a-9be0-d11b29410547\" style=\"border-width:0px;\" src=\"https:\/\/no-cache.hubspot.com\/cta\/default\/5442029\/a03f1309-f6ae-439a-9be0-d11b29410547.png\" alt=\"CTA\"><\/a><\/span><\/span><!-- end HubSpot Call-to-Action Code -->\n<\/div>\n<\/div>\n<h2>How To Protect Your Data in M365 FAQ<\/h2>\n<h3>Does Microsoft 365 need a separate backup solution?<\/h3>\n<p>For most organizations, yes. A separate solution becomes relevant once you need retention beyond one year, storage outside Microsoft's own boundary, coverage for Teams conversations, or multi-tenant management. Our <a href=\"https:\/\/www.msp360.com\/resources\/blog\/office-365-backup-complete-guide\/\">complete guide to Microsoft 365 backup<\/a> walks through what each workload requires.<\/p>\n<h3>Does Microsoft 365 include backup?<\/h3>\n<p>Not by default. Microsoft 365 ships with retention and recovery features \u2013 recycle bins, version history, Purview retention. Microsoft sells Microsoft 365 Backup as a separate, paid, pay-as-you-go service rather than including it with every subscription<\/p>\n<h3>Is retention enough?<\/h3>\n<p>Yes, for governance and compliance. No, for a complete recovery strategy. Retention preserves records, but it doesn't deliver the fast, large-scale recovery organizations need after ransomware or mass deletion.<\/p>\n<h3>What is the difference between Microsoft 365 backup and retention?<\/h3>\n<p>Retention controls how long content remains available and when users can delete it. Backup creates independent, restorable copies you can recover from after something goes wrong. One is a policy; the other is a recovery point.<\/p>\n<h3>Can Microsoft 365 native backup replace third-party backup?<\/h3>\n<p>Only where its limits line up with your requirements. Microsoft 365 Backup keeps data for up to one year, stores backup data inside Microsoft's service boundary, and protects Exchange, SharePoint, and OneDrive\u2014but not Teams conversations.\u00a0Longer retention, an independent copy, or full workload coverage each require something else. Workload-level guides are available for <a href=\"https:\/\/www.msp360.com\/resources\/blog\/how-to-backup-outlook-emails\/\">Outlook<\/a>, <a href=\"https:\/\/www.msp360.com\/resources\/blog\/how-to-backup-onedrive\/\">OneDrive<\/a> <a href=\"https:\/\/www.msp360.com\/resources\/blog\/how-to-backup-sharepoint\/\">SharePoint<\/a>, and <a href=\"https:\/\/www.msp360.com\/resources\/blog\/how-to-backup-microsoft-teams\/\">Teams<\/a>.<\/p>\n<h3>Is Microsoft 365 Backup enough for ransomware protection?<\/h3>\n<p>Not on its own. Microsoft designed Microsoft 365 Backup to recover from ransomware and mass-deletion scenarios within its supported workloads, but it stores restore points inside the same tenant that an attacker with admin rights can access. An independent copy outside Microsoft's boundary is advisable for any organization treating ransomware as a realistic threat \u2013 see the full <a href=\"https:\/\/www.msp360.com\/resources\/blog\/microsoft-365-ransomware-recovery-guide\/\">Microsoft 365 ransomware recovery guide<\/a> for what that setup looks like in practice.<\/p>\n<h3>Can Microsoft recover deleted data?<\/h3>\n<p>Often, within limits. Exchange Online keeps deleted items for 14 days by default, configurable up to 30. SharePoint and OneDrive keep deleted items in the recycle bin for up to 93 days. Microsoft 365 Backup extends retention to one year for supported workloads. After that, you'll need a separate backup to recover the data<\/p>\n<h2>How to Protect Your Data in M365 in Short<\/h2>\n<p>Retention keeps records where compliance and legal can find them. Microsoft 365 Backup does what retention can't \u2013 it gives you an actual restore point, built for scale and for ransomware, within the year it covers and the three workloads it protects.<\/p>\n<p>Neither one, on its own, gives you a copy that lives outside Microsoft's boundary, survives an attacker with admin rights, or keeps data for as long as your business \u2013 not Microsoft's default settings \u2013 decides it should. That's the case for looking closely at third-party backup: not because native protection is broken, but because full control over where your data lives, how long it stays, and who can reach it is a different job than the one retention or native backup were built for.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There is no single safety net for your data in Microsoft 365. Instead, there are several layers of protection \u2013 each built for a different kind of failure.<\/p>\n","protected":false},"author":106,"featured_media":62941,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[877,1010],"tags":[],"class_list":["post-62938","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-articles","category-msp360-m365-google-backup"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/62938","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/users\/106"}],"replies":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/comments?post=62938"}],"version-history":[{"count":10,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/62938\/revisions"}],"predecessor-version":[{"id":62951,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/62938\/revisions\/62951"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/media\/62941"}],"wp:attachment":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/media?parent=62938"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/categories?post=62938"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/tags?post=62938"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}