When firms move to Microsoft 365, many assume Microsoft now handles backup. It is an understandable belief. The service is reliable and files seem to live safely in the cloud. But Microsoft describes a shared responsibility model: it is responsible for keeping the service available and the infrastructure secure, and you are responsible for your data, who can access it, and how long you can recover it.
Check Microsoft's current documentation for retention settings and licensing details, since they change over time. This post covers the concepts firm leaders should understand.
What Built-In Protection Usually Covers
Microsoft 365 includes features such as recycle bins, version history, and retention for deleted items. These help with everyday mistakes, such as recovering a file deleted last week. But they have limits:
- Time limits. Deleted items are retained for limited periods that vary by service and settings. After that, they may be gone.
- Sync and replication. If a file is corrupted or encrypted by ransomware on a synced device, the damage can replicate to the cloud.
- Admin-level deletion. An attacker or careless administrator with sufficient rights can delete data, and some retention protections may not stop them.
- Granularity. Restoring a single mailbox or site from some historic point can be difficult or impossible with native tools alone.
- Account deletion. When a user account is deleted, associated data may be removed after a short period.
How Data Gets Lost in a Law Firm
Accidental deletion
A paralegal deletes a matter folder or an assistant empties a mailbox. Often nobody notices for weeks.
Malicious or disgruntled insiders
A departing employee deletes or exports files before leaving.
Ransomware and sync
Ransomware that encrypts files on a laptop can sync encrypted versions to OneDrive or SharePoint, overwriting good copies. Version history may help, but at scale recovery is slow.
Account compromise
An attacker who takes over a mailbox can delete email or, worse, remove evidence of their activity.
Migration and configuration errors
Mistakes during a migration or a poorly planned policy change can remove or overwrite data.
Legal holds and retention
Obligations to retain or preserve data are separate from backup. Retention policies keep data for compliance; backups let you restore to a point in time. Firms often need both, and they should be configured deliberately. Check your state's rules on file retention.
What a Third-Party Backup Should Cover
- Exchange Online mailboxes, including shared mailboxes and archives
- OneDrive for Business
- SharePoint sites and document libraries
- Microsoft Teams data, including chats and files where supported
- Configuration and identity information where supported
Ask what is and is not covered, because Teams and some other workloads vary by product.
Questions to Ask a Backup Provider
- How often are backups taken?
- Are backups stored separately from our Microsoft 365 tenant, under different credentials?
- Are backups immutable, meaning they cannot be altered or deleted by an attacker with our admin credentials?
- How long is data retained, and can we match our retention needs?
- Can we restore a single mailbox, folder or file to a point in time?
- How long does a large restore take, and has it been tested?
- Is data encrypted, and where is it stored?
- What happens to our backups if we end the contract?
Test It
Run restore tests. Pick a mailbox, a folder and a SharePoint library, restore each to an alternate location, and record how long it took. Repeat on a schedule and after major changes.
Protect the Backup Itself
- Use MFA and a separate administrative account for the backup platform
- Limit who can delete or change backup settings
- Alert on backup failures and configuration changes
- Keep documentation of the recovery procedure where staff can reach it during an outage
The Ethics Angle
ABA Model Rule 1.1, Comment 8, refers to understanding the benefits and risks of relevant technology, and Rule 1.6(c) asks for reasonable efforts to prevent unauthorized disclosure of client information. Losing client data or being unable to access it can affect client service under Rule 1.4. Confirm with your state bar how these apply.
Counsel Cyber's Role
Counsel Cyber configures and tests independent Microsoft 365 backup for law firms, aligned to your retention needs and recovery goals. If you are relying on the built-in recycle bin, we can walk through your actual exposure.