Microsoft 365 is highly resilient, but resilience of the cloud platform is not the same as a complete recovery plan for your organisation. Accidental deletion, malicious changes, ransomware, compromised administrator accounts and poor offboarding can all create recovery requirements that normal day-to-day features were not designed to meet on their own.
Retention and backup do different jobs
Retention policies help preserve information for a defined period and support legal or compliance requirements. Recycle bins and version history are useful for routine recovery. A backup service is designed to create protected recovery points and restore data after a larger or more complex incident.
Microsoft’s Microsoft 365 Backup documentation describes protected recovery for Exchange Online, OneDrive and SharePoint. Partner backup platforms may also add broader coverage, longer retention, independent administration or consolidated reporting.
Define the recovery requirement first
Before choosing a product, decide:
- which mailboxes, shared mailboxes, OneDrive accounts, Teams-connected sites and SharePoint sites are critical;
- how far back you may need to recover;
- how much recent work the business could afford to lose;
- how quickly a single file, mailbox or complete department must be restored;
- who is authorised to request and approve a restore;
- what happens to data when an employee leaves or a licence is removed.
Protect the backup administration
A backup is less useful if the same compromised account can delete both live data and recovery copies. Use separate administrative roles, multi-factor authentication, least privilege and alerts for significant changes. Where possible, protect backups from modification and keep recovery administration isolated from normal user accounts.
Test more than the success notification
A green backup report confirms that a process ran; it does not prove the business can recover what it needs. Schedule sample restores of email, individual files and complete collaboration sites. Record the time taken, data integrity and any permissions or sharing changes caused by the restore.
At least once a year, run a wider exercise based on a compromised tenant or ransomware event. Confirm who makes decisions, how clean devices are prepared, how users communicate and which systems return first.
Include Microsoft 365 in business continuity
Document critical dependencies such as identity, domain names, internet connectivity and administrator access. Keep emergency contact and recovery information somewhere that remains available if Microsoft 365 itself cannot be accessed.
MSP247 can review your Microsoft 365 configuration, retention, backup coverage and recovery process, then manage ongoing monitoring and testing. Our managed hosting and IT support services are designed around recoverable business operations. Contact us for a backup and recovery review.

