What you need to know
Microsoft 365 resiliency, native deleted-item recovery, Purview retention, and Microsoft 365 Backup solve different problems. Map the available mechanism, protect its administration, and prove recovery with realistic tests.
Potentially affected
Exchange Online mailboxes, SharePoint sites, OneDrive accounts, Microsoft 365 Backup policies, Purview retention and holds, backup administrators, deleted users, permissions, sharing, and business records.
DSE recommendation
Inventory critical data, define recovery objectives, verify protection-policy coverage and restore points, separate backup administration, test full and granular restores, and record functional recovery evidence.
Source fact: backup, retention, and resiliency are different controls
Microsoft describes Microsoft 365 Backup as protection and recovery for Exchange Online, SharePoint, and OneDrive. Its service architecture is separate from ordinary deleted-item recovery and from Microsoft Purview retention, which preserves content for records, legal, or compliance purposes. Service resiliency helps Microsoft keep the platform available, but it does not prove that an organization can return its own data to the required business state after deletion, corruption, or a damaging change.
Microsoft’s current Microsoft 365 Backup overview documents restore-point frequency. For OneDrive and SharePoint, full restore points are available every ten minutes for the prior 14 days and weekly from 15 through 365 days. Exchange restore points are available every ten minutes for the prior year. Granular file and folder restore points use a different cadence: approximately daily for the most recent 14 days and weekly afterward. Restore points begin after a protection policy is created, so enabling a policy today does not create historical coverage.
Choose the recovery mechanism before an incident
Define scenarios such as one deleted file, a damaged folder tree, an overwritten mailbox, an encrypted site, a deleted user, or a broad permission change. Map each scenario to native recovery, retention, Microsoft 365 Backup, or another approved service. Record recovery-point and recovery-time objectives, licensing, protected populations, exclusions, delegated administration, and data-location requirements.
Microsoft documents full, granular, and new-location restore options whose behavior differs by workload. A restore can affect names, permissions, sharing, versions, links, mailbox state, or user access. Microsoft also describes backup data as append-only, while controlled offboarding and deletion workflows still exist. Treat that as tamper resistance with governed administrative boundaries, not an unlimited promise of absolute immutability.
DSE recommendation: run evidence-producing restores
- Reconcile critical mailboxes, sites, and OneDrive accounts to active protection policies. Confirm the first usable restore point and investigate objects that are unprotected or newly created.
- Separate routine content administration from backup-policy and restore authority. Protect privileged roles with strong authentication, monitoring, and emergency-access procedures.
- Create a controlled test dataset that includes versions, folders, permissions, sharing, representative mail, and a known business workflow.
- Test a granular restore and a larger recovery appropriate to each workload. Use a new location where it reduces overwrite risk and compare results before returning data to production.
- Verify more than item count: open files, inspect versions, search mail, test permissions and sharing, validate ownership, and have a business owner confirm usability.
- Record requested and achieved restore points, duration, missing data, role use, alerts, user impact, decision makers, defects, and retest evidence.
Repeat testing after licensing, policy, workload, identity, or administrative changes. A green policy screen proves configuration, not recoverability. Keep a separately accessible recovery plan and contact path so responders can act if ordinary Microsoft 365 identities or documentation are unavailable.
Review the official source
Microsoft Learn: Overview of Microsoft 365 Backup · Published July 6, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE