Ten checks decide whether your Microsoft 365 backup works on the day you need it, and most procurement processes test only a handful.
This article gives you all ten, in the order a procurement process actually runs. You will also get the questions that expose a weak vendor in ten minutes, and the restore test to run before you sign anything. Read it once, and you will never again buy backup from a feature grid.
TL;DR
- Microsoft keeps the service running. The data inside it is your responsibility.
- Retention holds data in place. Microsoft 365 Backup Provider gives you a copy you own and control.
- The native service covers Exchange Online, OneDrive and SharePoint. Retention stops at one year.
- Ten checks settle the purchase, and the pricing model is the one finance will care about in year three.
- Ten questions will tell you more than any demo.
- Test three real restores in a live tenant before signature.
What Microsoft 365 Backup Covers, and What It Leaves to You
Microsoft protects the platform. You protect what sits inside it. That split is why the shared responsibility model keeps appearing in audit findings.
Retention policies stop deletion for a window. They do not give you a copy you own. The windows differ by workload, and none of them is long.
How Long Microsoft 365 Keeps Deleted Data
Microsoft 365 Backup closes part of the gap. It covers:
- Exchange Online mailboxes, OneDrive accounts and SharePoint Online sites
- Ten-minute recovery points
- Restore speeds of roughly one to three terabytes per hour
Check current figures on Microsoft Learn. The service changes quarterly.
The limits matter more than the coverage. Outside the service:
- Retention caps at one year
- Teams chat is not a covered workload
- Entra ID, Planner and Power Platform are excluded
- The copy never leaves Microsoft’s boundary
That last point splits buyers. Some find it reassuring. For others, it removes the whole reason for holding a second copy. The answer to who restores your data is you, through a provider whose copy sits outside the tenant.
Define Your Microsoft 365 Recovery Requirements First
Vendors will define your requirements for you if you let them. Do it first, and the shortlist writes itself.
Set recovery point and recovery time objectives per workload instead of per tenant. A shared mailbox and a finance SharePoint site do not carry the same tolerance.
Build a short table. Three rows filled in as an example:
Ransomware gets the budget, but it is not what most organisations actually face. The Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses identified a breach or attack in the previous year, while ransomware reached just 1% of them, down from 3%. Phishing accounted for the bulk of it.
Build the backup business case on ransomware alone, and you have built it on the least likely event. Most restores are triggered by something duller.
Then write down your three most likely restore requests. For most organisations:
- A leaver’s mailbox needed a year after departure
- A document library returned encrypted
- A scripted deletion that removes hundreds of sites overnight
Retention length comes from the functions that request restores, and each works on a different clock.
The Ten Checks That Decide Whether Your Backup Works
- Coverage, object by object. Ask for coverage by object type. Exchange, SharePoint, OneDrive, Teams files, Teams chat, Groups, Planner and Entra ID all behave differently. “We support Teams” often means the files and nothing else.
- Retention that matches your obligations. Establish whether one-, three- and seven-year retention are supported, and what each costs. Data that ages out is worse than no retention, because it creates a false record.
- Restore granularity. Item-level search matters more day-to-day than bulk capability. Check that a single email, a folder, a file version and a full site can each come back on their own. Point-in-time recovery should be selectable.
- Restore speed under load. Ask for a documented restore rate and the conditions it was measured under. Then ask whether restores carry a separate charge. Finance will question a metered restore fee mid-incident, which is the worst possible moment.
- Storage independence and residency. Find out where the copy physically sits. Find out whether a tenant compromise can reach it. UK and European data centres are usually a hard requirement for regulated buyers rather than a preference.
- Immutability. Neither NIS2 nor the UK’s Cyber Security and Resilience Bill uses the word immutable. NIS2 Article 21(2)(c) requires policies for business continuity, backup management and disaster recovery, and leaves the controls to you. Auditors have settled on the practical reading anyway. A copy that ransomware can alter does not count. Ask whether a privileged administrator can shorten retention or delete a restore point.
- Separation from tenant admin. Backup administration should not inherit Microsoft 365 global admin rights. Ask the blunt version: what can a compromised global admin account do to our backups? If the answer is “delete them”, the product covers accidental loss and little else.
- Pricing model. This is where the two markets part ways. Per-gigabyte pricing tracks data growth you do not control, and Microsoft 365 estates grow whether or not you planned for it. Per-user pricing moves only when headcount moves. Model both against your actual tenant. Then model both again with 40 per cent more data. Check for restore fees, egress charges and minimum terms while you are there.
- Encryption, authentication and certification scope. AES-256 at rest, OAuth and MFA support, ISO 27001 and a defensible GDPR position form the baseline. Ask for the certificate and read the scope statement. Certification that covers the head office but not the backup platform is a badge.
- Support and exit. Confirm the support hours and who answers at three in the morning. Then ask the question buyers skip. How do we get our data out if we leave, in what format, and with how much notice?
10 Questions to Ask a Microsoft 365 Backup Vendor
Copy these into your RFP.
- Which object types do you cover in Teams, and does that include chat history?
- What is your maximum retention period, and what does it cost?
- What restore rate can you commit to, and how was it measured?
- Are restores charged separately from backups?
- In which country does our backup data reside?
- Can a compromised global admin delete or alter our backups?
- What is the scope statement on your ISO 27001 certificate?
- What did your last customer’s price look like in year three compared with year one?
- What is your response target for a total loss event?
- On exit, in what format do we get our data, and how long do we have?
Send them in writing. Vendors who answer with object lists, retention tiers and certificate scopes are the ones worth a trial. Vendors who answer with adjectives have answered the question too.
Run a 30-Day Microsoft 365 Restore Test
Connect a live tenant, then:
- Run the three restore requests you wrote down earlier
- Time each one
- Record who performed it
- Record whether they needed the vendor’s help to finish
A restore nobody has rehearsed is an assumption. Thirty days can convert one into the other, and it costs nothing but calendar time.
5 Red Flags in a Microsoft 365 Backup Vendor
🚩 Coverage claimed at the product level with no object list behind it.
🚩 Retention quoted without a price attached.
🚩 A restore rate quoted with no test conditions.
🚩 No named data centre region.
🚩 A certificate offered as a logo rather than a scope statement.
Each one maps to a question above: 1, 2, 3, 5 and 7 in order. Ask it again, in writing.
Any one of these is worth pressing on. Two of them together usually mean nobody at the vendor has been asked before, which tells you what the 3am support call will feel like.
Microsoft 365 Backup vs Third-Party Backup: Which You Need
Match your requirements against what each delivers.
| Your requirement | Native Microsoft 365 Backup | Third-party provider |
| Workloads | Exchange, OneDrive, SharePoint | Varies, ask for the object list |
| Teams chat and Entra ID | Not covered | Varies by provider |
| Maximum retention | One year | Multi-year, configurable |
| Where the copy sits | Inside your tenant | Outside the tenant |
| Cost behaviour | Rises with data volume | Usually moves with headcount |
| Restore into a different tenant | Not supported | Commonly supported |
| Multiple tenants, one console | No | Common for MSPs and groups |
Native alone works only if all three are true: Exchange, OneDrive and SharePoint only; retention within a year; no need for a copy outside the tenant.
Most organisations belong in the second column. Most find out during an incident.
Your Next Step: Test a Microsoft 365 Backup Provider
If the answers come back as marketing language rather than object lists, retention tiers and certificate scopes, you have learned what you needed to know.
Recoverable protects Microsoft 365, SharePoint, Google Workspace, Box and Dropbox:
- Point-in-time recovery and granular item-level search
- ISO 27001 certification and GDPR compliance
- AES-256 encryption
- European data centres
Start a 30-day free trial, no credit card required, and run your three restore scenarios in your own environment this month.
Microsoft 365 Backup Provider: Frequently Asked Questions
What is the difference between backup and archiving?
They solve different problems. Backup creates point-in-time copies of active data so you can recover it after deletion, corruption or attack. Archiving moves inactive data into long-term storage, where it stays searchable but costs less to hold.
Buying an archive and calling it a backup is a common and expensive mistake. An archive will not return a mailbox to the state it was in last Tuesday. A backup will not reduce your primary storage bill. Most regulated organisations need both, bought separately and tested separately.
Does a restore bring back permissions and metadata?
Not automatically. Restore fidelity varies by provider and by workload, and permissions are the most common casualty. A file that returns without its sharing links, version history or original folder path has technically been recovered and practically has not.
Ask what the product restores alongside the content: permissions, metadata, version history, folder structure and sharing links. Then test it. Restore a SharePoint site during the trial and compare permissions on the restored library against the original. This is the easiest thing to verify, and the one buyers most often skip.
Do we still need backup if we have E5 with a litigation hold?
Yes. Litigation hold and retention policies preserve data inside the tenant. They do not give you a copy outside of it, and they are not a restore mechanism.
A hold stops content from being purged. It does not return a mailbox to a known good state after ransomware, and it does not help if the tenant itself is compromised or misconfigured. Retrieval runs through eDiscovery, which is built for legal review rather than operational recovery. E5 gives you strong compliance controls. It does not replace an independent, restorable copy.
How long does the first backup take?
Longer than most people expect, usually days rather than hours on a large tenant. The first run copies everything, and the pace is set by Microsoft Graph API throttling rather than by your provider’s infrastructure.
Later backups are incremental and finish far faster, so the initial seed is a poor guide to daily performance. Plan the first run for a quiet period and do not judge the product on it. Ask the vendor for a seeding estimate based on your user count and data volume before the trial starts.
Can we restore data into a different tenant?
Only with a third-party product. The native service restores into the tenant it protected, so a copy held inside that boundary cannot populate a different one.
Cross-tenant restore matters more than buyers expect. Acquisitions, divestitures and tenant consolidations all require moving historical data into a tenant that did not create it. So does recovery when a tenant is compromised badly enough that rebuilding beats cleaning. If any of that is plausible within your licence term, ask now. It is difficult to add later.
What does the Cyber Security and Resilience Bill mean for our backups?
It raises the evidence bar. The Cyber Security and Resilience Bill, now before the House of Lords, brings managed service providers and data centres into regulatory scope for the first time. It also introduces a 24-hour early warning duty, followed by a full incident report within 72 hours.
Neither deadline is survivable if you cannot say what was lost and what has been recovered. That answer comes from a backup with intact records, not from a tenant an attacker has had access to.