Microsoft Backs Up Microsoft — Not You: The Shared Responsibility Gap
Microsoft keeps its platform running, but protecting your data is your responsibility. Here is why retention is not backup, and what a real Microsoft 365 backup should cover.
There is a comfortable assumption built into cloud services: since the data lives in Microsoft's cloud, Microsoft must be backing it up. It is an easy belief to hold and a dangerous one to rely on. Microsoft is responsible for keeping its platform available and resilient. You are responsible for protecting your own data within it.
This is the shared responsibility model, and misunderstanding it is how organizations discover, too late, that recovering deleted or corrupted data was always their job. For regulated businesses, that gap is not just an inconvenience, it can be a compliance problem.
Retention is not backup
The most common confusion is treating retention settings as if they were backups. They are not the same thing. Retention controls how long data is kept before it is purged, according to rules you configure. A backup is an independent copy you can restore from after something goes wrong.
Retention can help in some situations, but it operates within windows and policies that can expire, be changed, or be bypassed. Relying on it as your only safety net leaves real gaps.
The ways data actually gets lost
Data loss in the cloud rarely looks like a server catching fire. It looks like ordinary events that are far more common.
- Accidental or intentional deletion, where files or mail are removed and eventually purged past recovery.
- Ransomware that encrypts local files and then syncs the encrypted versions up to OneDrive.
- Malicious insiders who delete or alter data before leaving.
- Retention-window expiry, where data you assumed was safe is purged exactly as configured.
None of these are exotic. Each one is a realistic Tuesday, and each one can leave you without the data you need and without an easy way to get it back.
What a real backup should cover
A proper third-party Microsoft 365 backup fills the gap the platform leaves. It takes independent copies of your data so you can restore them on your terms, regardless of what happened inside the tenant.
- Exchange Online mailboxes, including mail, calendars, and contacts.
- SharePoint and OneDrive files, so documents survive deletion or ransomware sync.
- Teams data, which is easy to overlook but holds real business conversations and files.
The point is coverage across the services your business actually lives in, not just the ones that are easiest to protect.
A backup you have not tested is a hope
Having a backup and being able to restore from it are two different things. The moment you need a restore is the worst possible time to discover that it does not work, is incomplete, or takes far longer than you expected. Test restores are what turn a backup from a hope into a plan.
Schedule regular restore tests, confirm the data comes back complete and usable, and document how long it takes so you have realistic expectations during a real incident.
Close the gap deliberately
Start by acknowledging the split: Microsoft keeps the platform running, and protecting your data is your job. Confirm what your current retention settings actually do, then put an independent backup in place that covers Exchange, SharePoint, OneDrive, and Teams.
Finally, test your restores on a schedule so you know recovery works before you ever need it. A managed services partner can help you sequence this work, but the core message is simple: assuming your data is backed up is not the same as knowing it is.