Microsoft 365 Backup: Why external backup is important for SME's
Microsoft 365 backup is crucial for SMEs because business-critical data in Exchange Online, OneDrive, SharePoint, and Teams is not automatically and fully backed up externally. While Microsoft provides a highly available cloud platform, high availability is no substitute for independent data backup.
In practice, data loss often occurs not due to a Microsoft outage, but rather due to accidental deletion, sync errors, compromised accounts, ransomware, incorrect permissions, or faulty automations. Without an external backup, recovery can be slow, incomplete, or even impossible.
This article explains why Microsoft 365 alone does not replace a complete backup, which data should be backed up, and what SMEs need to consider regarding RPO, RTO, restore testing, vendor selection, and compliance. You will also learn how FIGULI CONSULTING can support you in implementing a practical backup strategy.
Table of contents
- Is Microsoft 365 Backup automatically included?
- Shared Responsibility: Who is responsible for Microsoft 365 data?
- Common causes of data loss in Microsoft 365
- Which Microsoft 365 data should be backed up?
- Retention, archiving, and backup: What's the difference?
- Setting up Microsoft 365 Backup: Best practices for SMEs
- Vendor selection, costs, and compliance
- Conclusion
- FAQ: Microsoft 365 Backup
Is Microsoft 365 Backup automatically included?
Many companies assume that their data in Microsoft 365 is automatically and fully backed up. In reality, Microsoft primarily protects the availability of the platform. However, a complete backup that can independently restore deleted, corrupted, or encrypted data is not a standard feature.
The Recycle Bin, versioning, and retention policies are helpful, but they don't replace an external backup. They operate within defined limits and depend on licenses, configurations, retention periods, and user permissions. This creates a gap for small and medium-sized enterprises (SMEs) between "data is in the cloud" and "data can be reliably restored in an emergency."
An external Microsoft 365 backup creates independent restore points. This allows emails, files, SharePoint libraries, or Teams data to be restored even if accounts have been compromised, retention periods have expired, or data has been altered by errors.
Important: High availability means that Microsoft 365 is reliably accessible. However, it does not guarantee that accidentally deleted, manipulated, or encrypted data can always be fully recovered.
What misconceptions lead companies to forgo external backups?
Many companies forgo external Microsoft 365 backups because they confuse cloud storage with data backup. While Microsoft 365 offers high availability, it doesn't automatically protect against all data loss. The Recycle Bin, versioning, and retention policies can help in certain situations, but they don't replace an independent backup.
Typical misconceptions include:
- "Microsoft backs everything up anyway."
- "The Recycle Bin is sufficient for deleted files."
- "Versioning protects against overwriting."
- "Ransomware only affects local servers."
- "A restore will be possible somehow in an emergency."
These assumptions, in particular, lead to poorly defined restore destinations, retention periods, and responsibilities. An external backup closes this gap because it provides its own restore points and clearly defined restore processes.
Why is high availability not a backup?
High availability means that services such as Exchange Online, SharePoint or Teams generally remain accessible. This protects against platform failures, but not automatically against data loss at the content level. If a file has been deleted, overwritten or encrypted, the service can still be available - only the required content is missing.
A backup has a different goal: it provides a separate copy from which individual emails, files, folders, sites or entire workloads can be restored to a previous state.
What are the consequences of not having a Microsoft 365 backup?
Without an external backup, data loss quickly becomes an operational problem. Deleted emails are missing from customer communications, SharePoint libraries are incomplete, OneDrive files are overwritten, or Teams data is no longer traceable.
A typical example: An employee accidentally deletes a project folder in SharePoint. The error isn't noticed until weeks later. If the recycle bin, versioning, or retention periods no longer apply, the original state often cannot be fully restored without an external backup.
Possible consequences:
- Extended downtime due to manual reconstruction
- Missing documentation for business-critical communications
- Higher costs due to incident handling
- Loss of productivity in teams and projects
- Risk of permanent data loss after the retention period expires
Microsoft Standard vs. External Backup: A Comparison
| Function | Microsoft-Standard | External M365 Backup |
|---|---|---|
| Platform availability | Yes | Additionally |
| Wastebasket | Yes, for a limited time | Recovery regardless of recycle bin deadlines |
| Versioning | Yes, depending on the configuration. | additional recovery points |
| Independent backupSicherung | No | Yes |
| Restoration after ransomware | restricted | significantly better plannable |
| Granular recovery | partially | specifically for email, files, folders, sites |
| Separate admin rights | not automatically | possible and recommended |
| Restore-Tests | not part of the standard | Part of good backup processes |

Shared Responsibility: Who is responsible for Microsoft 365 data?
The Shared Responsibility Model describes the division of responsibilities between Microsoft and the company. Microsoft operates the cloud platform, provides services, and ensures infrastructure, availability, and numerous security mechanisms. However, the responsibility for data, users, permissions, configurations, and recovery processes remains with the company. Microsoft explains this responsibility model in detail in the Shared Responsibility Model.
This distinction is crucial for SMEs. Microsoft ensures that Microsoft 365 functions as a platform. However, this does not mean that every deleted file, mailbox, or SharePoint site can be independently and indefinitely restored.
Therefore, an external Microsoft 365 backup is the company's responsibility. It complements the standard Microsoft features with separate
backups, custom restore points, and traceable recovery processes.
What will Microsoft take over – and what will remain with the company?
Microsoft provides the Microsoft 365 services and ensures the platform's fundamental availability and secure operation. This includes infrastructure, data centers, service availability, and numerous platform-level security mechanisms.
However, the company remains responsible for its own usage. This includes user accounts, permissions, data classification, retention policies, security guidelines, and how data is restored after errors or attacks. Therefore, external backups fall under the company's responsibility.
- Microsoft: Platform, infrastructure, service operation, basic security
- Company: Data, users, access, configuration, backup and restore
- Service provider: Can support implementation, monitoring, and ongoing operation
Which recovery scenarios does Microsoft not fully cover?
Microsoft 365 offers standard features like the Recycle Bin, versioning, and retention policies. These help in simple cases, but they don't replace an independent backup. The situation becomes critical when data is deleted after it has been discovered, entire SharePoint sites are affected, user accounts have been compromised, or data needs to be restored to a clean point in time after a ransomware attack.
An external backup is especially important when restores need to be performed independently of the tenant state, over extended periods, or with clearly defined target times.
Why are admin errors and compromised accounts particularly critical?
Many data losses don't result from a Microsoft outage, but rather from misconfigurations or compromised accounts. Examples include overly broad permissions, incorrectly set retention rules, accidentally deleted SharePoint libraries, or automated processes that move or overwrite data.
Administrator accounts are particularly critical because they have extensive privileges. If such an account is compromised, attackers can not only delete or modify data, but also manipulate security and retention rules. Therefore, production administration and backup access should be secured separately.
To determine which backup responsibilities are currently unavailable in your Microsoft 365 environment, a brief inventory with clear recovery goals is helpful.
Check your Microsoft 365 backup
Which Microsoft 365 data should be backed up?
A Microsoft 365 backup should not only back up individual files, but also all business-critical data and services. In Microsoft 365, information is distributed across various workloads such as Exchange Online, OneDrive, SharePoint, and Microsoft Teams. These services work closely together and form the basis of many business processes.
Therefore, it's not just the content of a file that matters. Folder structures, permissions, versions, calendars, contacts, metadata, and team structures can also be crucial for business operations. A backup that simply copies files is often insufficient.
For SMEs, it's advisable to prioritize backups based on their business impact: Which data is needed daily? Which information is essential for customer projects, accounting, or compliance requirements? The scope of the data backup should be derived precisely from these answers.
- Exchange Online: Emails, calendars, contacts, and mailbox structures
- OneDrive for Business: Files, versions, and shares
- SharePoint Online: Sites, document libraries, lists, and permissions
- Microsoft Teams: Channels, files, and linked Microsoft 365 data
FIGULI CONSULTING helps companies identify business-critical Microsoft 365 data and develop a backup strategy that aligns with their actual business processes.
Exchange Online: Which data should be backed up?
Exchange Online often handles a large portion of business communication. Offers, orders, contract negotiations, customer inquiries, and internal approvals are usually conducted via email. Therefore, it's essential to back up not just individual messages, but entire mailboxes, including calendars, contacts, and folder structures.
Especially in cases of accidental deletions, compromised accounts, or migrations, an external backup allows for the targeted restoration of individual items or entire mailboxes.
OneDrive for Business: Which data should be backed up?
OneDrive for Business is often used to store work documents, project files, and employees' personal files. Because content is automatically synced across different devices, errors or accidental changes can be quickly propagated to all connected devices.
An external backup protects against sync errors, accidental deletions, or overwritten files and allows for the restoration of previous data states—regardless of the device's condition.
SharePoint Online: Which data should be backed up?
SharePoint Online serves as the central platform for documents, projects, and collaboration in many companies. Those who manage documents entirely digitally also benefit from a structured, paperless office. In addition to files, sites, document libraries, lists, permissions, and versions are business-critical.
Data loss therefore often affects not just individual documents, but entire project structures and access rights. A complete backup should therefore also include metadata and permissions.
Microsoft Teams: Which data should be backed up?
Microsoft Teams bundles various Microsoft 365 services. Files are typically stored in SharePoint, meetings access Exchange, and Teams itself manages channels, members, and permissions. Therefore, Teams should not be considered in isolation.
A complete backup includes files, team structures, and the associated Microsoft 365 objects. This is the only way to fully restore projects after an incident.
Before setting up a backup, you should determine which Microsoft 365 data is business-critical for your company. A structured analysis prevents unnecessary backups and closes potentially dangerous security gaps.

Common causes of data loss in Microsoft 365
Data loss in Microsoft 365 rarely results from a complete platform outage.
More often, everyday causes are at play:
- Files are deleted
- OneDrive synchronizes faulty changes
- SharePoint permissions are incorrectly set
- A compromised account modifies large amounts of data
The biggest problem is often not the initial error, but the time it takes to discover it. When the Recycle Bin, versioning, or retention periods fail, an external Microsoft 365 backup can provide the crucial point of recovery.
Accidental deletion and overwriting
Deleted emails, removed folders, or overwritten files often go unnoticed until later. The Microsoft Recycle Bin helps in simple cases, but only within certain limits. An external backup provides additional restore points and reduces the risk of permanent data loss.
Ransomware, sync errors, and compromised accounts
Ransomware doesn't just affect local servers. If encrypted or manipulated files are synchronized via OneDrive, the damage can spread to SharePoint and Teams. Protecting the endpoints used is equally important. You can learn more about this in the article Endpoint Security.
Compromised accounts can also delete, move, or modify data.
The risk can be significantly reduced, among other things, by consistently using multi-factor authentication.
An external backup helps because clean versions from before the incident can be restored. Separate backup access points, immutable backups, and regular restore tests are essential.
Misconfigurations, insider risks, and expired deadlines
Data loss can also occur due to incorrectly configured permissions, insufficient retention periods, or faulty automations. Accounts with elevated privileges are particularly critical because they can modify or delete large areas of data.
Therefore, a Microsoft 365 backup should be scheduled independently of production permissions. Backup retention, restore rights, and logging must be defined separately and regularly reviewed.
Storage, archiving and backup: What's the difference?
Retention, archiving, and backup are often confused in Microsoft 365, but they serve different purposes. Retention keeps data within the Microsoft 365 environment according to rules. Archiving provides long-term, searchable storage. Backup creates an independent copy to restore data after errors, attacks, or deletions.
This distinction is important for small and medium-sized enterprises (SMEs): compliance and recovery are not the same. A retention policy can keep content available for longer, but it doesn't replace an external backup with its own restore points.
| Term | Purpose | Does it replace backups? |
|---|---|---|
| Retention | Rule-based retention within Microsoft 365 | No |
| Archiving | Long-term filing and search | No |
| eDiscovery / Legal Hold | Locating and securing for testing or procedures | No |
| Backup | Independent recovery after errors or attacks | Yes, for restore purposes. |
When is retention sufficient – and when is an additional backup necessary?
Retention is sufficient if content only needs to be stored for defined periods. However, as soon as precise recovery, rapid bulk restores, or independent backup points are required, an external backup is necessary.
- Retention: good for storage and easy retrieval
- Backup: necessary for independent recovery
- Combination: beneficial for compliance and operational reliability
Why don't eDiscovery and Legal Hold replace a backup?
eDiscovery and Legal Hold primarily serve to keep content discoverable and secure for audits, internal investigations, or legal proceedings. They are not intended for quickly restoring operations after data loss.
A backup complements these functions because it enables operational recovery: individual emails, files, folders, mailboxes, or sites can be selectively restored.
Setting up Microsoft 365 Backup: Best Practices for SMEs
A good backup strategy doesn't start with the tool, but with clear goals. What is crucial is the maximum amount of data loss that is acceptable, how quickly data must be available again and who will authorize recovery in an emergency.
For SMEs, Microsoft 365 backup should be planned pragmatically. Not every file is equally critical. Email communications, project files, SharePoint libraries, and Teams data should be prioritized based on business impact.
Technically, automated backups, sufficiently long storage, separate admin rights and regular restore tests count. Only then does a backup become a reliable recovery process.
How can RPO and RTO be defined in an understandable way?
RPO describes the acceptable amount of data loss over time.
Example: If the RPO is four hours, then in a critical situation, no more than four hours of data may be lost.
RTO describes how quickly data or services must be restored.
Example: If the RTO is two hours, recovery must be completed within this timeframe.
What backup frequency is realistic?
The backup frequency depends on how often data changes and how critical it is to operations. Heavily used SharePoint libraries or OneDrive work folders often require more frequent backups than rarely used archives.
The retention period is also important. Errors aren't always detected immediately. Therefore, backup retention should be planned for a longer period than just for the short term when data is deleted.
What backup frequency is realistic?
The backup frequency depends on how often data changes and how critical it is to operations. Heavily used SharePoint libraries or OneDrive work folders often require more frequent backups than rarely used archives.
The retention period is also important. Errors aren't always detected immediately. Therefore, backup retention should be planned for a longer period than just for the short term when data is deleted.
How do you organize restore tests, roles, and approvals?
A backup is only as good as its restore. Therefore, restore tests should be performed regularly and documented. Various scenarios should be tested: a single email, a OneDrive folder, a SharePoint site, or a bulk restore after an incident.
Roles must also be clearly defined: Who is authorized to request a restore, who approves it, who performs it, and how is the result documented?
Checklist: Microsoft 365 Backup for SMEs
- Prioritize the most important workloads
- Define RPO and RTO
- Define backup frequency and retention
- Separate backup access from production administrators
- Document restore tests
- Clarify responsibilities and approvals
Provider selection, costs and compliance
When choosing a provider, it's not just about whether a solution can back up Microsoft 365. The crucial factor is how reliably restores work in an emergency. Important criteria include restore granularity, speed, protection against manipulation, separate access rights, reporting, and ease of use.
For SMEs, predictable costs and a system that runs smoothly without requiring specialized knowledge are also essential. A backup system must be regularly monitored, tested, and documented. Only then will it be more than just an additional technical feature in the event of an incident.
What criteria are crucial when choosing a backup provider?
Pay particular attention to practical recovery capabilities. Can the solution selectively retrieve individual emails, files, folders, mailboxes, or SharePoint sites? Can data be restored to an alternative location before being returned to production?
Security and operational reliability are equally important: separate administrator accounts, multi-factor authentication, protection against backup deletion, monitoring, and clear reporting.
Veeam, Barracuda, Hornet Security & Co.: Which solution is right for you?
Typical solutions for SMEs include Veeam, Barracuda, and Hornet Security. Both can be suitable depending on the environment, recovery requirements, and operating model. The key is not the vendor name, but whether the solution fits your specific needs.
Important questions to consider are: How granular can data be restored? How easy is it to use? Where are the backups located? What protection mechanisms are in place against manipulation? How well are reporting, monitoring, and support provided?
What are the costs associated with Microsoft 365 Backup?
Costs typically depend on the number of users, storage requirements, retention period, and functionality.
Some providers charge per user, others based on workload or storage. For SMEs, it's crucial to consider not only license costs but also operation, monitoring, restore testing, and potential support in case of emergencies.
Which compliance points are important?
When using external Microsoft 365 backups, GDPR compliance, data processing agreements, data location, logging, and deletion policies should be reviewed. It is crucial that access and recovery processes are documented transparently.
For Austrian companies, internal retention obligations and requirements related to accounting, data protection, and information security should also be considered. Any legal details should be discussed with tax advisors, legal counsel, or data protection officers.
Conclusion
Microsoft 365 is highly available, but without external backup, recovery remains unreliable in many realistic scenarios. Accidental deletions, sync errors, compromised accounts, ransomware, or incorrectly configured retention rules can make it impossible to reliably recover important emails, files, SharePoint libraries, or Teams data.
For SMEs, the pragmatic approach is to prioritize business-critical workloads, define Recovery Point Objective (RPO) and Recovery Time Objective (RTO), plan backup frequency and retention, clearly segregate restore rights, and regularly test restores. This transforms Microsoft 365 Backup into genuine protection for operations, compliance, and collaboration.
FIGULI CONSULTING helps companies implement Microsoft 365 Backup effectively – from risk analysis and vendor selection to configuration, restore testing, and ongoing monitoring.
Have your Microsoft 365 Backup reviewed
FAQ: Microsoft 365 Backup
Is Microsoft 365 Backup automatically included?
No. Microsoft 365 offers features like the Recycle Bin, versioning, and retention policies, but not a complete external backup with its own restore points. For true recoverability, organizations need a separate backup with clear RPO/RTO targets and documented restore processes.
Why isn't the Recycle Bin in Microsoft 365 sufficient?
The Recycle Bin helps with simple deletions within specific timeframes. However, if data has been permanently deleted, overwrites go unnoticed for too long, or an account is compromised, the Recycle Bin and versioning are often insufficient. An external backup provides additional restore points.
What data should I back up in Microsoft 365?
You should primarily back up Exchange Online, OneDrive for Business, SharePoint Online, and Microsoft Teams. This includes emails, calendars, contacts, files, versions, sites, lists, permissions, team structures, and linked Microsoft 365 data.
How often should a Microsoft 365 backup run?
Backup frequency depends on the rate of change, business risk, and desired Recovery Point Objective (RPO). Highly used areas such as email, SharePoint project repositories, or OneDrive work folders should be backed up more frequently than infrequently accessed data.
What are RPO and RTO in data backup?
RPO describes the maximum acceptable data loss, for example, four hours. RTO describes the maximum recovery time, for example, two hours. Both values should be defined for each workload because email, files, and Teams data can have varying levels of criticality.
Does an external backup help against ransomware in OneDrive and SharePoint?
Yes, if the backup offers separate access rights, sufficient historical versions, and protection against manipulation. This allows companies to revert to a clean data state before the mass change. Additionally, multi-factor authentication (MFA), endpoint security, and restore testing remain important.
What compliance issues are important for Microsoft 365 backup?
GDPR compliance, data processing agreements, data location, logging, a deletion policy, and traceable restore processes are crucial. Backups should be integrated into the organizational structure to ensure that access, restores, and retention periods remain auditable.
How can I tell if my Microsoft 365 backup is working?
Only through regular restore tests. Test various scenarios: a single email, an entire OneDrive folder, a SharePoint site, or a bulk restore. Document the restore time, process, and results to ensure the process functions correctly in an emergency.



