14 days. That is how long Exchange Online holds a deleted email by default before it is gone for good.
Microsoft publishes that figure openly, alongside every other retention limit in your tenant. Almost nobody reads them until the week they matter. By then, the clock has usually run out on something a board member needs back.
The Microsoft shared responsibility model draws one line through your entire 365 estate. Microsoft keeps the platform running. You keep the data recoverable.
What follows shows where that line falls, which of your workloads have no recovery route at all, and what UK regulators now expect you to prove. The eight questions at the end are the ones your auditor will ask first.
TL;DR
- Microsoft owns the infrastructure. You own data, identities, accounts, and endpoints at every tier, including SaaS.
- Exchange Online defaults to 14 days for deleted items, extendable to 30. SharePoint and OneDrive stop at 93 days.
- Geo-redundancy replicates whatever state your data is in. Encrypted files replicate perfectly.
- Microsoft 365 Backup is a real product with a 365-day ceiling. It also lives inside the tenant it protects.
- UK GDPR Article 32 requires you to restore personal data promptly and to test that you can.
- Identity configuration is the workload nobody protects, and everybody needs on day one of a recovery.
What the Model Says About Your Data
Ownership never transfers to Microsoft. Not at any tier, not under any licence.
Microsoft’s shared responsibility model documentation puts it plainly: for all cloud deployment types, you own your data and identities, and you are responsible for protecting them.
Microsoft takes the layers underneath. Physical data centre security, networks, hosts, the hypervisor, and, in SaaS, the operating systems and middleware.
Moving to a tenant transfers an enormous operational burden. Ownership of the information itself travels nowhere.
SaaS creates confusion because it transfers so much. When one vendor manages the application, the servers, the patching, and the failover, assuming they also manage recovery feels entirely reasonable.
The Contract Clause Most CTOs Read Too Late
The common claim: Section 6b of the Microsoft Services Agreement tells you to back up your own content.
The correction: those are consumer terms. Your commercial tenant is subject to the Microsoft Customer Agreement, the Microsoft Product Terms, and the Data Protection Addendum.
Check the versions live at your renewal date, because the Product Terms are revised monthly.
The clause people miss entirely: your service level agreement. Uptime commitments earn service credits when availability slips. No availability commitment obliges Microsoft to rebuild a SharePoint site that a compromised admin account emptied last quarter. Credits and recovery are separate instruments, and only one of them protects the business.
How Long Microsoft Really Keeps Your Deleted Data
Three numbers govern almost every recovery conversation you will have.
Exchange Online gives you 14 days. Deleted items move to the Recoverable Items folder and wait there. Microsoft sets the period at 14 days by default, adjustable to a maximum of 30. Quotas can cut it shorter still. The folder has a 20 GB soft limit and a 30 GB hard limit, and hitting either triggers a first-in, first-out purge. Your grace period can end early on volume alone.
SharePoint and OneDrive give you 93. A 93-day period spans both recycle bin stages. The clock starts at the first deletion and never resets. On day 94, the document is gone from wherever it sits.
Leavers get 30. The default retention for a deleted user’s OneDrive is 30 days. After that, the account enters a deleted state that only a SharePoint administrator can reverse using PowerShell.
One more thing worth knowing. Purview retention and litigation hold prevent permanent removal, and neither gives you a restore button. Preserved content comes back through eDiscovery search and export, item by item, run by someone trained to do it. Recycle bin contents are not indexed either, so no eDiscovery search can find them, and no hold can protect them.
Why Geo-Redundancy Will Not Save You
Picture a Friday afternoon. Ransomware encrypts a finance team’s SharePoint library at 15:40. By 15:41, that encrypted library has replicated cleanly to every geographic region Microsoft holds it in.
Replication protects against a data centre failing. It has no opinion about data quality. Whatever state your content is in at the moment of replication is the state that propagates, faithfully, everywhere.
Microsoft 365 Backup: What It Covers, Where It Stops
Microsoft now sells a first-party backup service, and it deserves a fair hearing.
What it does well. Coverage spans Exchange Online, SharePoint, and OneDrive on a pay-as-you-go model billed through Azure. Backups and restore points are retained for 365 days from creation. Restores run fast because data never leaves the platform. Append-only storage blocks overwrites; a 90-day grace period follows offboarding; Purview policies cannot shorten the backup retention period.
Where it stops. The service lives inside the tenant it protects, by design. A tenant-wide identity compromise reaches production data and the backup copy through one administrative plane. Deletion of backups is permitted, which Microsoft documents as an offboarding safeguard. An attacker holding global administrator rights inherits exactly the same capability. Independence is the one property that survives that scenario, and the full case for it sits in the guide to third-party Microsoft 365 backup.
What it never touches. Three workloads are in scope, and everything else in your estate sits outside it. Teams chat messages, Planner, Loop, and Whiteboard have no coverage. Neither does your Entra ID configuration, which means rebuilding wiped Conditional Access policies becomes manual work on the worst possible day. Scope is also explicit: a site, mailbox, or account left out of a protection policy is unprotected, and nothing in the admin centre will warn you.
What UK and EU Regulators Expect You to Own
Regulators settled the ownership question some time ago, and they settled it against you.
UK GDPR, Article 32(1)(c) and (d). You must be able to restore availability and access to personal data in a timely manner after an incident, and you must test those measures regularly. The word backup never appears. The obligation does.
FCA and PRA operational resilience. Regulated firms identify important business services, set impact tolerances, and stay within them during severe disruption. A plan resting on a 93-day window struggles to provide evidence of that.
DORA Article 12. Applies to EU financial entities and UK firms operating in the EU. Restoration must use ICT systems physically and logically segregated from the source, with periodic testing. Read that against an in-platform backup, and the tension is obvious.
ISO/IEC 27001:2022, control A.8.13. Information backup is a named control, and auditors expect evidence that it works.
Turn Shared Responsibility Into Targets You Can Defend
Ownership becomes useful the moment it produces numbers a board can review. Three steps get you there.
- Set objectives per workload, never per tenant. Finance mailboxes and a dormant project archive carry different levels of criticality. A single tenant-wide figure either overspends on one or underprotects the other. Record the reasoning, because auditors examine the logic as closely as the target. Our breakdown of RTO and RPO targets covers the calculation.
- Test the restore, not the backup job. A successful backup proves storage. Only a successful restore proves recovery. Measure elapsed time to usable data, including approvals and the person who has to be woken up.
- Plan your rehearsal capacity in advance. Microsoft asks customers to limit test restores to no more than twice a month per protection unit. Build your calendar around that ceiling rather than discovering it mid-audit. Large restores also meet API rate limiting, so a single tenant-wide figure rarely survives contact with a real incident. Tiering those targets by scope is covered in granular restore vs full-tenant recovery.
Eight Questions Before Your Next Board Review
- Who is accountable, by name, for Microsoft 365 data recovery?
- Do you hold documented RPO and RTO figures per workload?
- When did you last complete a full restore test, and how long did it take?
- Could a compromised global administrator account reach your backups?
- How would you recover the Entra ID and Conditional Access configuration?
- Which workloads sit outside your current protection scope?
- How long can you recover a leaver’s mailbox after their licence is removed?
- What evidence would you hand an auditor tomorrow morning?
Hesitation on any of these marks an unfunded risk rather than a technical gap.
Find Out Where You Actually Stand
The shared responsibility model is neither a loophole nor a warning label. It has said the same thing since your tenant was provisioned, and Microsoft has held up its half.
Closing the other half starts with one number.
Answer Question Three This Month
Look back at the checklist. Seven of those questions you can answer from a settings page. Question three cannot be answered that way, because a restore time is either a measured figure or a guess.
Thirty days is enough to turn it into a measured one.
Recoverable AI takes minutes to set up, and your first backup completes the same afternoon. From there you can restore a real mailbox or a real site, time it properly, and write the number down. Your copy sits outside your tenant throughout, so the test also shows you what recovery looks like on the day the tenant itself is the problem.
Start a 30-day trial. No card, no procurement conversation, nothing to uninstall if you decide against it.
What you keep at the end is the thing an auditor actually asks for: a restore you have performed, with a time attached to it.
Frequently Asked Questions: Microsoft Shared Responsibility Model
Is backup included in a Microsoft 365 E3 or E5 licence?
No. Backup is sold separately from every licence tier.
E3 and E5 include retention policies, litigation hold, eDiscovery, and version history, which are compliance and availability controls rather than recovery tools. Microsoft 365 Backup is an opt-in, pay-as-you-go service billed through an Azure subscription, and enabling it requires the Owner or Contributor role on that subscription. Upgrading your licence changes the compliance tooling available to you. It changes nothing about your backup position. Treat backup as a separate budget line, and scope it per workload rather than per user.
What happens to your data if you cancel a Microsoft 365 subscription?
Anything from 120 days to no time at all, depending on how you cancel.
Let a business subscription lapse, and it moves through three stages. Expired runs for about 30 days, with normal user access. Disabled runs for about 90 days, with administrator access only. Deleted is terminal, and the data becomes unrecoverable.
Microsoft states that content left behind may be deleted after 90 days and no later than 180 days after cancellation. Delete a subscription explicitly, though, and it skips both earlier stages. SharePoint and OneDrive content goes immediately, with no window at all.
Can Microsoft support recover data once the retention window has closed?
No. Once content is purged, it is permanently deleted, and no support escalation reverses that.
Recycle bins and the Recoverable Items folder run on automated timers rather than a support queue. Microsoft’s own agreements recommend independent backups for exactly this reason. Support can help within Windows, restore a deleted user within 30 days, or recover a deleted OneDrive via PowerShell as a SharePoint administrator. Beyond those limits, ticket priority and contract value make no difference. Assume your only recovery path is the one you built yourself.
Does UK GDPR require you to back up SaaS data?
Indirectly, yes.
Article 32(1)(c) requires the ability to restore availability and access to personal data in a timely manner following a physical or technical incident.
Article 32(1)(d) requires regular testing and evaluation of those measures.
The regulation never uses the word backup, which is why many teams miss the obligation entirely. If personal data sits in Exchange, SharePoint, or OneDrive, restoring it after ransomware or mass deletion falls to you. The ICO expects measures proportionate to the risk and expects you to provide evidence of the testing.
Does the shared responsibility model apply to Google Workspace and Salesforce?
Yes. Every major SaaS provider uses the same structure. The provider secures infrastructure, application code, and availability. The customer owns data, identities, and configuration.
Retention windows differ considerably between platforms, and that is where teams get caught, carrying assumptions from one provider to another. Google Workspace and Salesforce publish their own responsibility documentation and their own recovery limits. Run several platforms, and you run several clocks, all set differently. Map each one separately and name an owner for each.