A common belief among firm administrators is that Microsoft takes care of backups for Microsoft 365. It is a reasonable assumption, and it is only partly true. Microsoft operates a highly redundant service designed to keep its platform running through hardware failures. That is availability. What it does not do by default is act as a backup of your data against the kinds of problems that actually hurt law firms: accidental deletion, malicious deletion, ransomware that syncs encrypted files, a compromised account that purges mail or a departing employee who clears out a mailbox.
Microsoft describes this as a shared responsibility model: it protects the service, and you are responsible for your data. Understanding the gap helps you decide whether the built-in tools are enough.
What Microsoft 365 offers natively
Several features provide partial protection.
- Recycle bins and recoverable items. Deleted mail and files typically remain recoverable for a limited period, which varies by service and settings.
- Version history. SharePoint and OneDrive keep prior versions of files, subject to limits.
- Retention policies and litigation hold. Compliance features can preserve content for a set period or while a matter is pending, depending on your license.
- Restore options. OneDrive and SharePoint can roll a library back to an earlier point within a limited window.
These tools are valuable, and a firm should configure them intentionally. But they are designed for compliance and short-term recovery, not for guaranteed, independent backup.
Where the gaps appear
Limited recovery windows
Deleted items eventually age out. If someone deletes a folder and nobody notices for months, native recovery may no longer help.
Retention is not backup
A retention policy preserves content according to rules, but it generally does not give you an isolated, restorable copy you control. Misconfigured policies can also fail to preserve what you expected.
Ransomware and sync
Files synced to OneDrive can be encrypted by ransomware on a laptop and then synced up. Version history may help, but restoring thousands of files through native tools can be slow and incomplete.
Compromised or malicious users
An attacker with an administrator account, or a departing employee with legitimate access, can delete content and sometimes purge recovery locations. If the only copy is in the same tenant, the same compromised credentials threaten it.
Account deletion
When a user account is deleted, associated data may be removed after a short window. Offboarding mistakes can destroy mail and files.
Different tools, different rules
Exchange mail, SharePoint, OneDrive, Teams chats and other services each have their own retention behavior, which makes it hard to know what is actually protected.
What to add
A third-party Microsoft 365 backup service stores an independent copy of your mail, calendars, contacts, OneDrive, SharePoint and often Teams data in separate infrastructure with separate credentials. Evaluate options with these questions:
- What does it cover, and how frequently does it back up?
- How long is data retained?
- Is the backup separate from your tenant credentials, and does it require MFA?
- Can you restore a single message, a folder or an entire mailbox, and how quickly?
- Is the data encrypted, and where is it stored?
- Is it immutable or protected against deletion?
- How does it handle legal hold and records needs?
Tie it to your recovery objectives
Decide how much loss and downtime the firm can tolerate. If losing a day of email is unacceptable, a once-daily backup may not suffice. Write down the numbers and compare them with what native tools plus any added service deliver.
Test the restore
Pick a mailbox and a document library each quarter and restore items to a test location. Note how long it takes and who performs it. If you have never done this, do it before you need it.
Clean up the basics too
- Configure retention policies deliberately, with legal and records input.
- Limit global administrators, protect them with MFA and keep a break-glass account securely stored.
- Alert on mass deletions and unusual downloads.
- Follow a disciplined offboarding process that preserves mailboxes according to policy.
Professional duties
Your obligations around client files, confidentiality and competence do not disappear because data lives in the cloud. Rules 1.1 and 1.6(c) are often cited in this context, and Rule 5.3 reminds lawyers to supervise vendors, including cloud providers.
Getting help
Counsel Cyber configures retention, evaluates backup options and runs restore tests for firms on Microsoft 365. Ask us to check whether your tenant would let you recover what you assume it would.