Microsoft 365 Backup and ransomware recovery — what IT admins need to know
The uncomfortable truth: Microsoft 365 does not back up your data by default. If ransomware encrypts your SharePoint sites today, your recovery options without M365 Backup are more limited than most IT admins realise.
This is the question that comes up every time a client gets hit: "Can we get everything back?" The honest answer depends entirely on what you have configured — and most tenants have less protection than they think.
What Microsoft 365 actually protects by default
Microsoft provides some built-in data protection, but it is not the same as backup. Understanding the difference matters.
Exchange Online
Deleted items go to the Deleted Items folder, then to the Recoverable Items folder for 14 days by default (extendable to 30 days). After that, items are permanently gone unless a retention policy or litigation hold is in place. Ransomware that encrypts your mailbox and then waits 31 days before demanding payment would result in permanent data loss without M365 Backup.
SharePoint and OneDrive
The recycle bin retains deleted files for 93 days. File versioning is on by default, but ransomware that encrypts files in place — rather than deleting them — creates a new encrypted version of every file. Without M365 Backup, restoring to a point before the encryption requires manually rolling back every file version. On a site with thousands of files, this is not realistic.
Microsoft Teams
Teams data lives in Exchange (chat) and SharePoint (files). The same limitations apply. There is no separate Teams-specific backup.
Microsoft 365 Backup — what changed in October 2024
Microsoft released M365 Backup as a generally available feature in October 2024. It provides genuine point-in-time restore for Exchange, SharePoint, and OneDrive — up to 1 year retention — and is designed specifically for ransomware recovery scenarios.
M365 Backup is a paid add-on and requires separate licensing. It is not enabled by default. Most tenants we scan have it either partially configured or not configured at all.
Check your M365 Backup status: In M365Clarity, the Backup & Recovery Readiness tab shows the status of M365 Backup for Exchange, SharePoint, and OneDrive — along with a ransomware scenario analysis specific to your tenant's current configuration.
The four layers of recovery protection
Beyond M365 Backup itself, a well-protected tenant uses several overlapping layers.
1. Retention policies
Purview retention policies can preserve data even after users delete it. They are not backup — you cannot do a point-in-time restore — but they prevent permanent deletion and are the minimum baseline for compliance. If you have no retention policies configured, ransomware-encrypted data that gets deleted is gone after the recycle bin window closes.
2. Audit logging
You cannot investigate an incident if you have no audit trail. Standard audit log retention is 90 days. Most breaches are discovered after 90 days. If your audit logs have been purged by the time you investigate, you cannot establish what was accessed, by whom, or when.
3. Safe Attachments and Safe Links
Prevention is cheaper than recovery. Defender for Office 365's Safe Attachments detonates email attachments before delivery. Safe Links rewrites URLs and checks them at click time. These do not prevent all ransomware, but they significantly reduce the volume that reaches users.
4. Immutable backups
For organisations in regulated sectors, consider a third-party backup solution alongside M365 Backup. The key requirement is immutability — backups that cannot be modified or deleted by a compromised admin account.
The ransomware scenario most organisations are not ready for
The most damaging ransomware attacks targeting M365 do not encrypt files on endpoint devices. They target SharePoint directly through a compromised user account or third-party app with excessive permissions. The attacker uses Files.ReadWrite.All permissions to encrypt every file across every site. By the time the attack is discovered, the 30-day recycle bin period may be running.
If you have no M365 Backup and no retention policies in place, you may be looking at permanent data loss across your entire SharePoint estate.
What to check today
- Is M365 Backup enabled for Exchange, SharePoint, and OneDrive?
- Do you have Purview retention policies covering Exchange, SharePoint, Teams, and OneDrive?
- Is the audit log enabled and is retention set to at least 1 year?
- Do you have Safe Attachments and Safe Links active?
- Are any third-party apps in your tenant using
Files.ReadWrite.Allpermissions?
Check your recovery readiness in 60 seconds
M365Clarity's Backup & Recovery Readiness tab analyses your tenant configuration and generates a plain-English ransomware scenario — what would you actually lose if hit today?
Run a free scan →