ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Does Your Law Firm Need to Back Up Microsoft 365? Myth vs Reality

Many firms assume Microsoft backs up everything in 365. Learn what is actually protected, where the gaps are and how third-party backup fits.

3 min readBy Counsel Cyber Team

A common belief at law firms is that Microsoft 365 is cloud-based, so it is automatically backed up. Microsoft keeps the service available and resilient, which is a real benefit. But availability is not the same as backup, and the difference shows up at the worst possible moment: when a mailbox is deleted, a ransomware infection syncs to OneDrive, or a departing employee wipes a SharePoint library.

Here is a plain look at the myths and the reality.

Myth 1: "Microsoft backs up our data."

Reality: Microsoft operates under a shared responsibility model. It is responsible for the infrastructure, uptime and physical security of its datacenters. You are responsible for your data, your users and your access. Microsoft does provide built-in protections such as recycle bins, version history and retention features, but these are designed for convenience and compliance, not to serve as a full backup you control. Read Microsoft's current service agreement and documentation for the specifics.

Myth 2: "The recycle bin is our backup."

Reality: Deleted items typically stay recoverable for a limited window, which varies by service and configuration. After that, they may be gone. Items purged on purpose, or by an attacker with admin rights, may be harder or impossible to retrieve.

Myth 3: "Version history protects us from ransomware."

Reality: Version history can help, since you may be able to roll back files, but it depends on retention settings, scale and speed. If an infection or a sync tool encrypts thousands of files across many libraries, restoring them all by hand is slow. A dedicated backup can restore at scale to a known point in time.

Myth 4: "Retention policies and legal hold are backup."

Reality: Retention and hold features preserve data for compliance and litigation purposes. They are valuable for e-discovery, but they are not designed for fast operational restore of a damaged environment.

Myth 5: "A compromised account is Microsoft's problem."

Reality: If an attacker signs in as your user, deletes email or alters files, the platform sees a legitimate user acting. Recovery depends on what protections and retention you set up beforehand.

Where Law Firms Are Exposed

  • Accidental deletion by a user or administrator
  • Malicious deletion by a departing employee or a compromised account
  • Ransomware or malware that spreads through synced folders
  • Retention gaps from short default windows
  • Account closures when a departed user's license is removed and data is later deleted
  • Misconfigured sync that overwrites good files with bad ones
  • Compliance needs for preserving client records

What a Third-Party Backup Adds

A dedicated Microsoft 365 backup typically offers:

  1. Independent copies of mailboxes, OneDrive, SharePoint and Teams data, stored outside your tenant
  2. Point-in-time restore, so you can recover to a specific time before an incident
  3. Granular recovery of a single message, file or site
  4. Longer retention than the platform defaults
  5. Protection from admin-level deletion when combined with immutable storage and separate credentials

Not all products are equal, so ask what is covered, how restores work and how long they take.

Questions to Ask

  1. Which workloads are backed up: email, calendars, contacts, OneDrive, SharePoint, Teams chats and files?
  2. How often does the backup run?
  3. Where is the data stored and is it encrypted?
  4. Is it immutable or otherwise protected from deletion?
  5. Who holds the backup credentials, and is MFA required?
  6. How long does a full restore of a mailbox or site take?
  7. How are restores tested?

Don't Forget Confidentiality

A backup of Microsoft 365 contains privileged client information, so treat it with the same care as the source. Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized access. Review vendor contracts, encryption and access controls as part of your vendor oversight.

Right-Sizing the Decision

If your firm treats email and documents as the core record of client work, which most do, backing them up separately is usually reasonable. The cost is typically modest compared with the disruption of permanent data loss. Weigh your own risk, retention needs and recovery objectives, and decide deliberately.

Next Steps

Counsel Cyber implements and tests Microsoft 365 backup for law firms. If you are not sure what protection you really have today, we can check your retention settings and walk you through the gaps.