Cloud

Microsoft 365 Retention vs Backup – A Recovery Decision Guide

in 𝕏 ✉
By Adrian Weir | Published 24 September 2026

Recovery decisions

Retention and backup solve different problems

Microsoft 365 gives administrators several ways to retain or recover information. Those controls are useful, but they solve different problems. A retention policy preserves content for governance and eDiscovery. A recycle bin helps with recent deletion. OneDrive Restore can roll a user's files back after a damaging event. An independent backup keeps separate recovery points under a separately configured service.

That distinction matters when a Sydney business asks a practical question. Can we get this exact item back, from the date we need, within the time available? A useful Microsoft 365 retention vs backup decision starts with the failure scenario, then checks the workload, licence, configured window and recovery evidence.

Microsoft explains that retention settings can preserve content in hidden system locations so it remains available for eDiscovery, or delete content according to policy.[1] That is a compliance control. It does not automatically give every user a simple browse-and-restore experience. Independent backup is designed around separate recovery copies and restore sessions. The right design often uses both.

Failure scenarios

Four incidents that need different answers

Accidental deletion

Exchange Online keeps deleted items for a defined period. An administrator can recover purged items only while they remain inside that configured retention period, and the administrator needs the required role.[2] SharePoint and OneDrive recycle bins can also recover recent deletions.

Record when deletion occurred, who owned the content and whether the item was moved, deleted or purged. Confirm the real tenant setting. A default value does not prove what is configured.

Overwritten files

Version history may recover an earlier copy when the file still exists. OneDrive Restore can reverse file and folder actions across a user's OneDrive for the previous 30 days.[7] It cannot recover a file permanently deleted from the recycle bin.

Independent backup gives the recovery team another source to inspect. The evidence that matters is a completed restore test, rather than a dashboard that only says jobs ran.

Departed-user data

Microsoft states that a deleted user's OneDrive is retained for 30 days by default. It then moves to a deleted state for 93 days before permanent deletion, subject to Microsoft's documented process.[3]

Decide who receives the mailbox, OneDrive and shared work before removing the account. Check whether legal or contractual retention applies and confirm the backup scope.

Malicious bulk changes

A compromised account can delete messages or damage many folders before anyone notices. OneDrive Restore can undo actions within the previous 30 days, including changes associated with malware.[7]

Contain the account first. Choose a clean recovery point from before the incident, then review identity controls and endpoint protection before users resume work.

Operating models

What each control is built to do

Retention and native recovery

Retention policies and labels support governance. They can retain content, delete it after a period, or do both in sequence. Microsoft stores retained copies in workload-specific locations such as the Preservation Hold library, Recoverable Items and SubstrateHolds.[1]

These controls depend on scope and configuration. Teams retention covers chat and channel messages, while files shared through Teams are governed through SharePoint or OneDrive retention.[8] Exchange recovery, recycle bins, version history and OneDrive Restore each have their own limits and permissions.

Separately configured backup

Independent backup creates another recovery path. Cove Microsoft 365 Backup supports Exchange, OneDrive, SharePoint and Teams channel messages. N-able documents up to six backup sessions a day for Exchange and Teams, up to four for OneDrive and SharePoint, with seven-year retention.[4]

Milnsbridge offers Cove Microsoft 365 Backup from $9.95 per mailbox per month, excluding GST, as a separately scoped service.[5] It is distinct from native retention and the Microsoft 365 licence itself.

Decision matrix

A Microsoft 365 retention vs backup decision matrix

Recent deletion

Start with Deleted Items, Recoverable Items or the relevant recycle bin. This is usually the quickest path. If the item is unavailable, inspect independent backup sessions from before deletion. Record the successful method for the service desk.

Changed or corrupted file

Check version history and OneDrive Restore when the event sits inside the native window. Use independent backup when the required version is older, native history is missing, or the business needs a separately held recovery point.

Former employee

Pause account deletion until ownership is settled. Transfer required live content and confirm the backup scope. If the account is already removed, compare its deletion date with Microsoft's recovery stages and the dates available in backup.[3]

Malicious change

Contain the account before recovery. Establish the first known bad change and choose a recovery point from before it. Native rollback may resolve a recent OneDrive event. Independent sessions give the recovery team another clean source to assess.

Recovery readiness

Document four checks before an incident

Scope

List the workloads the business relies on. Exchange mailboxes, OneDrive accounts, SharePoint sites and Teams channel messages need separate confirmation. Record exclusions clearly. A green tenant-wide status can hide a site or account that was never added.

Licence and configuration

Write down which Microsoft licences enable the chosen retention features. Record policy names, assigned users and sites, plus the administrator roles needed for recovery. For independent backup, record protected accounts and the service owner.

Recovery window

State the usable period for each method. SharePoint items remain in its recycle-bin system for 93 days. Microsoft may restore a whole site collection from an additional 14-day backup window, but that restore is not available for a single item.[6]

Evidence

Run a controlled restore with a sample mailbox item and document. Record the date, recovery point, destination, elapsed time and result. Repeat the test after a material licensing, policy or tenant change. Job completion and restore success are different evidence.

Verified windows

Recovery numbers worth remembering

30 days

OneDrive Restore can reverse file and folder actions across the previous 30 days. (Microsoft Support)[7]

93 days

SharePoint and OneDrive site recycle-bin retention runs for 93 days. (Microsoft Support)[6]

Up to 6 daily

Cove documents up to six backup sessions a day for Exchange and Teams. (N-able)[4]

7 years

Cove documents seven-year Microsoft 365 backup retention. (N-able)[4]

Practical preparation

Build a recovery plan your team can use

Give the plan an owner. For each workload, record the native recovery path and the independent backup path. Add the contact who can authorise a restore. Keep the document available when the tenant itself is under investigation.

Run a restore test each quarter or after a major tenant change. Use a small sample and verify the restored item at its destination. A failed test is useful if it exposes a missing permission, an unprotected account or an unclear approval path while normal work is still running.

Milnsbridge can review the tenant, set up Cove Microsoft 365 Backup and connect recovery procedures with ongoing Microsoft 365 support. The service starts from $9.95 per mailbox per month excluding GST.[5] Native retention remains useful for governance and recent recovery. The independent service adds separate recovery points and managed restore support.

A wider cyber security plan should cover the controls that reduce repeat incidents. Recovery also belongs in the operating procedures used by your Sydney IT support team.

Common questions

Microsoft 365 recovery questions

Does Microsoft 365 include backup

Microsoft 365 includes retention and recovery features, but their scope and windows vary by workload, licence and configuration. Microsoft describes retention as a governance control that preserves or deletes content according to policy.[1] A separately configured backup adds an independent recovery source.

Can retention replace independent backup

Retention can preserve content for compliance and eDiscovery. It may also support recovery in some cases. It does not provide the same operating model as a separate backup service with its own sessions, retention period and restore workflow. Many businesses use the two controls for different jobs.

What happens to a former employee's OneDrive

Microsoft states that the deleted user's OneDrive is retained for 30 days by default, then remains in a deleted state for 93 days before permanent deletion.[3] Offboarding should transfer ownership and confirm backup before that process runs out.

What should a restore test prove

The test should prove that the required workload is protected, the chosen recovery point is available, authorised staff can start the restore and the recovered item opens at the intended destination. Keep the result with the recovery plan.

Explore more

Related Microsoft 365 and security services

Microsoft 365 Backup

Review the separately scoped Cove service, workloads and public pricing.

View Microsoft 365 Backup

Microsoft 365 support

Get help with tenant management, security and day-to-day administration.

View Microsoft 365 support

Endpoint protection

Reduce the chance that malicious changes return after recovery.

View endpoint protection

Managed IT services

Connect recovery procedures with your wider Sydney IT support plan.

View managed IT services

Test recovery now

Plan a restore before you need one

Milnsbridge supports Sydney businesses from Sydney CBD and Penrith. Our service desk has a 20-second average answer time and 87% first-call resolution. Talk to a specialist about your Microsoft 365 recovery requirements, backup scope and first restore test.

Talk to a Specialist

About the Author

Adrian Weir

Adrian Weir is the Managing Director and founder of Milnsbridge Managed IT Services, with over 30 years of global IT experience spanning Telstra, Citibank, Unilever, and hundreds of Sydney SMBs. A Microsoft Partner since 2002, Adrian leads a team of IT specialists delivering responsive, business-focused managed IT support across Greater Sydney.

Meet the Milnsbridge Team
← Back to Tech News

Need IT Support for Your Business?

Managed IT services for Sydney businesses with 10–200 seats. Explore our published plans, support scope and service commitments.

Talk to a Specialist Book a 30-Minute Call