ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Recycle Bin, Retention, Backup: Protecting Microsoft 365 Data

Many firms assume Microsoft 365 backs up their email and files. Learn the difference between retention, recycle bins and true backup, and what to close.

3 min readBy Counsel Cyber Team

Moving to Microsoft 365 feels like moving the backup problem to someone else. Email lives in Exchange Online, files in OneDrive and SharePoint, chats in Teams, and Microsoft runs the infrastructure. It is natural to assume your data is therefore backed up.

The reality is more nuanced. Microsoft generally operates under a shared responsibility model: the provider is responsible for keeping the service running and the infrastructure resilient, while the customer is responsible for their own data, accounts and how it is protected. Features like retention policies and recycle bins help, but they are not the same as an independent backup. Check Microsoft's current documentation and your licensing for the specifics, since details change.

What Microsoft 365 provides

Several built-in features offer a measure of protection.

  • Recycle bins and recoverable items. Deleted files and emails can often be restored for a limited time.
  • Version history. SharePoint and OneDrive keep prior versions of files, subject to settings.
  • Retention policies and holds. Administrators can keep content for specified periods for compliance or legal hold purposes.
  • Service resilience. Microsoft maintains redundancy so a hardware failure in a data center does not usually lose your data.

These are valuable. They are designed mostly for accidents and compliance, not for every disaster you might face.

What they do not reliably cover

Ransomware and mass deletion

If an attacker takes over an administrator account, they can delete content and empty recycle bins. Files may be encrypted by ransomware that syncs to the cloud, and versions can be overwritten. Recovery options exist in some cases, but you should not count on them.

Malicious or accidental insider deletion

A departing employee deleting matter folders, or a mistaken bulk operation, can exceed the recovery window.

Time limits

Recycle bins and recoverable-item windows are finite. If you discover a problem after the window closes, the data may be gone.

Retention is not recoverability

A retention policy keeps content for legal purposes, but it may not be organized for fast, granular restoration to a prior point in time. A hold and a restore are different things.

Account closure and license lapse

If a license lapses or a user is deleted, associated data can be removed after a grace period.

Tenant-level problems

A compromised tenant, a misconfiguration or a billing lapse affects everything in one place. Having a separate copy outside your tenant reduces single-point-of-failure risk.

What an independent backup adds

A third-party backup for Microsoft 365 stores copies of mailboxes, OneDrive, SharePoint and sometimes Teams in a separate environment. Look for:

  • Frequent automated backups, often several per day.
  • Point-in-time and granular restore for a single mailbox, folder or file.
  • Immutable or protected storage so deletion by an attacker is blocked.
  • Separate credentials and MFA for the backup service.
  • Clear retention that fits your records policy.
  • Encryption and a vendor agreement that addresses confidentiality.
  • Reporting and alerts when jobs fail.

Think about law-specific needs

Email is often the system of record for client communications, so losing it can have professional consequences. Competence and communication duties under Rules 1.1 and 1.4 are relevant when files or messages cannot be recovered. Legal holds also require that you preserve content, so coordinate backup retention with litigation hold procedures and your records policy.

If your firm stores matter files in a document management system such as NetDocuments or iManage rather than SharePoint, ask the vendor about its backup and recovery commitments, and consider whether you need a separate copy there too.

Questions to ask your IT provider

  1. Do we have a backup of Microsoft 365 separate from Microsoft itself?
  2. What is included: mail, calendars, contacts, OneDrive, SharePoint, Teams?
  3. How often does it run and how long do we keep backups?
  4. Can an administrator account delete the backups?
  5. When did we last test a restore of a mailbox and a document library?

A simple action plan

  1. Inventory what lives in Microsoft 365.
  2. Confirm current retention settings and recycle bin windows.
  3. Decide on recovery objectives for email and files.
  4. Add independent backup where gaps exist.
  5. Test restores at least twice a year.

How we help

Counsel Cyber provides Microsoft 365 backup and recovery for law firms and can review your current retention settings to show where you are exposed. Ask us for a short assessment if you are not sure what is covered.