"It's in the cloud, it's backed up." That sentence comes up in almost every meeting, and it is not absurd: Microsoft does replicate data across several data centres, manages high availability and publishes serious service commitments.
The misunderstanding is about what those commitments cover.
The principle: availability versus content
Microsoft itself describes its model as shared responsibility. The dividing line is fairly simple to state:
- Microsoft answers for the infrastructure: the servers run, the service is reachable, no hardware failure makes your tenant disappear.
- You answer for the content: what your users create, change and delete belongs to you — and its fate is yours.
In other words: if a disk fails in a Microsoft data centre, that is not your problem. If a user empties a folder and nobody notices for three months, that is not Microsoft's.
What native retention actually covers
It is not nothing, and it would be dishonest to pretend otherwise.
In Exchange Online, a deleted item goes to Deleted Items, then to a recovery area. A user can go back on their own, an administrator for a while longer. On windows of a few weeks, and adjustable by an administrator.
In OneDrive and SharePoint, there is a user recycle bin and then a second-stage recycle bin, of the same order of magnitude. SharePoint versioning also keeps several versions of a document, which covers accidental overwriting well.
Purview retention policies let you go further, provided they are configured, understood and maintained.
Three things are true at once: this is useful, it is enough for the majority of everyday incidents, and it does not replace a backup.
The five situations where it stops being enough
1. Detection takes longer than the retention window
This is the most frequent case and the most mundane. A badly migrated SharePoint library, a shared folder cleaned out "to free up space", a functional mailbox nobody watches any more. By the time somebody notices, the window has passed.
An independent backup shifts the question: the depth of history becomes yours, not the provider's.
2. Someone leaves the company
The licence is released, the mailbox is deleted, and the OneDrive with it. Mechanisms exist to delay this — inactive mailbox, OneDrive retained for a configurable period — but they assume somebody thought of it beforehand. The real scenario is usually: HR reports the departure, IT releases the licence in order to reassign it, and six months later a dispute requires finding one specific exchange.
3. Ransomware travelling through sync
A workstation is compromised, the OneDrive client does its job and dutifully propagates the encrypted files to the cloud. SharePoint versioning theoretically lets you go back — file by file, across thousands of files, in an interface that was not designed for it.
4. An administration mistake
A retention policy changed, a PowerShell script cast too wide, a bulk deletion aimed badly. These are precisely the actions that are allowed to delete everything — and native retention obeys the administrator.
5. Leaving the service
Migration to another provider, a commercial dispute, an account suspended over an unpaid invoice. Having a copy outside the tenant is then the difference between a migration and a loss.
What a service provider must be able to answer
Three questions come up, and it is better to have the answers before they are asked:
"How far back can I go?" A figure, decided with the client, not "it depends on the tenant settings".
"How long to recover a single email?" If the answer involves a mass restore followed by manual sorting, it is not an answer. The restore has to be granular: search, preview, restore one item.
"Where is the data?" A backup that leaves the tenant has to go somewhere. Knowing where, and being able to say so, is part of the service.
The blind spot: SharePoint and lists
Mailboxes get all the attention. In practice, what costs the most to rebuild is often a SharePoint library — documents shared by several departments, with a tree built up over years — or a SharePoint list used as a small line-of-business application.
This content has no single owner, nobody watches it, and its loss is discovered late. A backup that covers only mailboxes leaves out what hurts most.
BeBackup backs up mailboxes, contacts, calendars, tasks, OneDrive, sites, SharePoint libraries and lists through the Microsoft Graph API, and restores item by item from the browser. See the Microsoft 365 page or ask for a demo.