The short answer
Microsoft operates the Microsoft 365 service and provides workload-specific resilience and recovery features. These can include version history, recycle bins, retention features and service recovery processes. They are not a promise that every item can be restored to any point in time, and they do not remove the business owner's responsibility to decide how long data must be kept and how it will be recovered.
Features, limits and licensing change, and differ between Exchange Online, SharePoint, OneDrive, Teams and other workloads. Do not use a historic statement such as “Microsoft 365 keeps everything for 30 days” as a current rule. Check the current Microsoft documentation for the workload and configuration you actually use.
Retention is not the same as an independent backup
Retention policies can help preserve content for a defined purpose. A recycle bin can help recover a recent deletion. Version history can restore an earlier version of a file. None of these, by themselves, answers every recovery question. A business may need a separate, point-in-time copy after accidental deletion, malicious activity, a compromised administrator account, a retention-policy mistake or the departure of a user.
Microsoft's service agreement recommends that customers regularly back up content and data stored in its services or through third-party apps. That recommendation is a useful prompt to document your own recovery requirements rather than assuming that platform availability equals backup coverage.
Questions to ask about Microsoft 365 recovery
- Which mailboxes, SharePoint sites, OneDrive accounts, Teams data and other workloads are in scope?
- How far back must the business be able to recover, and how quickly must recovery happen?
- Can an administrator or ransomware event delete both live data and the copies intended for recovery?
- Who can access, delete or change the backup, and are those actions logged?
- How often are restores tested, and can an individual file, mailbox item, folder or site be recovered?
- How do retention, legal hold, data protection and sector requirements affect the design?
Designing an independent backup approach
Document the services and data that matter most, choose a recovery point and recovery time that the business can justify, and select a backup approach that meets those requirements. Separation from ordinary Microsoft 365 administrator access is important. Encryption, access controls, monitoring, retention and documented deletion should be considered alongside storage location.
The familiar 3-2-1 model—three copies, on two types of storage, with one copy separated from the primary environment—is a planning principle, not a guarantee. The design must fit the data, risk and recovery objectives. A restore test is essential evidence that the arrangement works.
See the managed backup solutions page for the service context, and keep the wider Microsoft 365 configuration review separate from the backup decision.
What this means for your business
Microsoft 365 can be a strong platform without being your complete backup plan. Inventory the workloads you use, read the current service documentation, define recovery objectives and test an independent restore where your risk or obligations require it. This approach avoids both extremes: assuming Microsoft provides no protection, or assuming the service automatically covers every recovery scenario.
If you need help checking scope, retention and restore testing, J700 Group’s managed backup service is a sensible next step.

