Microsoft 365 has a backup problem. Sort of. - Troye
Microsoft 365 backup responsibility isn't as clear-cut as it seems. See why availability, resilience and recovery aren't the same thing in M365.
Microsoft 365 backup, data recovery Microsoft 365, SharePoint backup, OneDrive backup, Teams data protection, Microsoft 365 shared responsibility, ransomware recovery, data governance, information governance, Microsoft 365 compliance
11461
wp-singular,post-template-default,single,single-post,postid-11461,single-format-standard,wp-theme-bridge,bridge-core-3.3.2,qode-page-transition-enabled,ajax_fade,page_not_loaded,,qode_grid_1300,footer_responsive_adv,qode-content-sidebar-responsive,qode-theme-ver-29.5,qode-theme-bridge,qode_header_in_grid,wpb-js-composer js-comp-ver-8.0,vc_responsive
 

Microsoft 365 has a backup problem. Sort of.

Microsoft 365 cloud data connected to secure infrastructure, highlighting the importance of independent backup and recovery.

There is a dangerous assumption hiding inside Microsoft 365: if the data lives in Microsoft’s cloud, someone else must be responsible for getting it back when it disappears. Convenient, certainly. Correct, not necessarily.

Microsoft 365 is remarkably resilient, but resilience is not the same thing as having a complete, independent recovery strategy for everything your business stores in Teams, SharePoint and OneDrive.

The confusion is understandable because Microsoft has built impressive protection into the platform. SharePoint and OneDrive data is replicated across Azure infrastructure, while Microsoft 365 provides capabilities such as versioning, recycle bins, retention and recovery.

Microsoft also states explicitly that customers retain ownership and control of their data. The problem is that these capabilities solve different problems. A deleted file, a maliciously encrypted site and a compromised administrator account are not the same recovery scenario.

Why Teams complicates the picture

Teams makes the situation even more interesting because it is not really a single data store. Different types of Teams content live in different parts of the Microsoft 365 architecture. Team and channel files are stored in SharePoint, while OneDrive is used for files shared through chats.

Teams meeting recordings and other content can also be stored through SharePoint based services. In other words, telling the business that “Teams is backed up” without understanding what that actually means can create a rather unpleasant surprise when someone needs to restore something.

Availability versus recoverability

The distinction between availability and recoverability matters enormously. Microsoft provides substantial built in resilience, including replicated copies and automated failover for SharePoint.

Microsoft 365 Backup adds point in time protection for SharePoint and OneDrive and is specifically designed for scenarios such as ransomware and accidental or malicious deletion. But businesses still need to decide what data requires protection, how long it needs to be retained, who controls recovery and how quickly critical information needs to be restored.

The human problem behind the technical one

The more successful Microsoft 365 becomes, the more data employees put into it. Contracts sit in SharePoint. Personal working files sit in OneDrive. Project documents live in Teams. Customer information is shared through chats. Meeting recordings become corporate records almost by accident.

A platform designed to make information accessible can therefore make information surprisingly easy to overshare, alter or delete. Microsoft’s own compliance guidance recommends tools such as sensitivity labels, data loss prevention and lifecycle management to control how sensitive information is handled.

Why security and backup need to work together

Security and backup therefore need to work together. Protecting the data means controlling who can access it, detecting suspicious activity, limiting inappropriate sharing and applying appropriate retention policies.

Protecting the business means also having a reliable way to recover information when those controls fail. A beautifully configured Microsoft 365 environment without a tested recovery strategy is rather like having a very expensive safe and no idea where the spare key is.

The stakes become even higher as organisations introduce AI into the Microsoft 365 environment. Copilot and other AI tools can surface enormous amounts of corporate information, which makes permissions and data governance increasingly important.

Treating data protection as governance, not just backup

The answer is not to lock everything away. It is to understand what information exists, who should have access to it, how it is protected and what happens if it is compromised. Data protection has become an information governance issue, not simply a backup task.

The good news is that businesses do not need to panic about Microsoft 365. They need to stop treating it as a magic box. Microsoft provides extensive security, resilience and recovery capabilities, and its 2026 documentation makes clear that Microsoft 365 Backup now provides additional protection and faster recovery for SharePoint and OneDrive data.

The smarter approach is to understand exactly what Microsoft protects, what the organisation remains responsible for and where additional controls are justified. Because when someone says, “Don’t worry, it’s in the cloud,” the sensible response from IT should probably be: “Yes. And what’s our recovery plan?”

By Troye Managing Director Helen Kruger