Summary: Microsoft 365 is built for high availability and includes several ways to recover data. But recovery after incorrect deletion, ransomware, a misconfiguration or a major user mistake still needs to be planned. Microsoft now also offers Microsoft 365 Backup as a separate service for Exchange, OneDrive and SharePoint. The question is therefore not only whether you have backup, but which data must be recoverable, to which point in time, and how quickly the business needs to be running again.
Microsoft 365 includes many built-in features for redundancy, version history, recycle bins and restoration. That can easily create a sense that Microsoft already has backup covered.
But that is a simplification. What matters is the difference between Microsoft being able to keep a service available and your organisation being able to restore the right information to the right point in time after an event that affected your data.
Microsoft draws the same distinction. The Microsoft 365 Backup documentation separates disaster recovery from backup: a DR copy maintains the current state of the content so the service can keep operating, but not historical versions from prior points in time. Backup, by contrast, is meant to restore content to a previous healthy state.
This becomes particularly relevant when the cause is not a technical fault at Microsoft. It may instead be:
- a user deleting information
- an administrator making an incorrect change
- large-scale deletion or corruption
- a compromised account
- ransomware
- an incorrect retention rule
- a change that is only discovered much later
Do not start with the product, start with the recovery requirement
It is easy to open the backup discussion with the question of which backup product to buy. We think four other questions are better:
- Which information must we be able to restore?
- How far back do we need to be able to go?
- How quickly does the information need to be back?
- What happens to the business in the meantime?
Only once these questions are answered is it possible to judge which technical solution is needed. Two classic concepts help:
- RPO, Recovery Point Objective. How much data can the business accept losing?
- RTO, Recovery Time Objective. How quickly does the service or information need to be restored?
They need to be set by the business, not by whatever the backup product happens to offer.
Microsoft now has its own backup service
Microsoft today offers Microsoft 365 Backup as a separate backup capability. The service can protect selected or all Exchange mailboxes, OneDrive accounts and SharePoint sites. Microsoft describes it as a way to recover information quickly after both accidental and malicious data deletion, for example in a ransomware scenario or where content has been overwritten.
That changes the market somewhat. Previously, Microsoft 365 backup almost automatically meant an external third-party product. Today the choice may also be between:
- Microsoft’s own backup
- a third-party product built on Microsoft’s backup storage
- an entirely separate backup platform
- a combination, depending on the organisation’s requirements
There is therefore no general answer as to which solution is best. The choice needs to be driven by recovery requirements, retention, separation, administration, cost, regulatory requirements and what the rest of the organisation’s backup environment looks like.
Microsoft 365 is more than Exchange, OneDrive and SharePoint
An important part of backup planning is understanding what the organisation actually depends on. Microsoft 365 is not only about documents and email. The environment also contains, for example:
- users and groups
- application registrations
- service principals
- Conditional Access
- authentication policies
- identity-related configuration
On 30 June 2026 Microsoft made Microsoft Entra Backup and Recovery generally available. The service automatically backs up selected directory objects, including users, groups, applications, service principals, managed identities, Conditional Access policies, named locations and authentication and authorisation policy, and can restore them to a previously known good state.
Two conditions are worth knowing. The daily backup with seven days of history requires Microsoft Entra ID P1 or P2. The copies are also created and stored by Microsoft in the same geographic region as the tenant and cannot be disabled, deleted or modified by any signed-in user or app.
This illustrates an important point: backup of Microsoft 365 is not necessarily a single thing. The organisation needs to consider data, configuration and identity.
Backup without a restore test is still an assumption
A green backup job means the backup ran according to the system. It does not automatically mean the business can be restored as planned.
The Swedish National Cyber Security Centre (NCSC) therefore includes “back up and test restoration of information” as measure 6 among its ten recommended security measures. Both halves are there: copying and testing.
An organisation can have a hundred per cent successful backup jobs and still discover during an incident that:
- the right data was not included
- the restore takes too long
- the administrator account required cannot be used
- a dependent system is missing
- retention does not match the needs of the business
- nobody really knows who may authorise a major restore
Test different scenarios
Not every test has to mean restoring the entire Microsoft 365 environment. You can start smaller.
- A single file. Can a user’s incorrectly deleted document be recovered?
- OneDrive. Can larger volumes of data be restored to an earlier point in time?
- SharePoint. What happens if a whole site or large parts of the document structure are changed or deleted?
- Exchange. Can a mailbox or a large volume of email be restored to meet the needs of the business?
- A major incident. What happens if many users and data sources are affected at the same time?
The last question is particularly interesting. Restoring a document is a support matter. Recovery after a ransomware attack can be a crisis and continuity matter.
Retention is not the same as backup
There is an important boundary between retention and backup. Retention is often about keeping information according to defined rules. Backup is about the ability to restore.
In some situations retention features can help recover information. But that does not mean retention should be used as a substitute for a considered backup and recovery strategy. The organisation therefore needs to understand:
- why information must be kept
- for how long
- who should be able to restore it
- which events you need to protect against
- how quickly the restore must happen
Do not forget the administrators
The backup platform is itself a security-critical service. If the same administrator account that is compromised in Microsoft 365 can also delete backups, change retention or switch off protection, the organisation has built a risky dependency.
The backup environment therefore also needs:
- strong authentication
- least privilege
- separated administrative roles
- logging
- follow-up
- documented recovery procedures
Backup is therefore both an operational and a security matter.
Monitoring is part of backup
A common problem is that the organisation discovers a failed backup job only when information needs to be restored. Effective backup management therefore also needs to cover monitoring of backup jobs, deviations, storage capacity, protected objects, policy changes, retention and recurring restore tests.
That is how we work ourselves: continuous monitoring of backup jobs and regular reviews of status, capacity and retention among other things.
Seven questions to ask about Microsoft 365 backup
- Which Microsoft 365 data is most critical?
- How far back do we need to be able to restore?
- What RTO and RPO does the business have?
- Are identity and configuration data also part of the recovery plan?
- Who may initiate a major restore?
- When was the restore last tested?
- What happens if the Microsoft 365 account or the administrative environment itself is compromised?
If the answers are unclear, there is probably more work to do than simply checking whether the backup job is green.
How Kristensson i Skåne can help
Kristensson i Skåne helps organisations with Microsoft 365, backup and recovery capability. Support can include, for example:
- needs and risk analysis
- backup strategy
- Microsoft 365 backup
- retention
- RPO and RTO
- backup of servers and other environments
- restore testing
- monitoring
- documentation
- disaster recovery
- ongoing management
Our starting point is that backup should not be judged by whether the job succeeded last night. It should be judged by a much more practical question: can we get back what the business needs, when we actually need it?
A related topic is how support and operations around Microsoft 365 fit together, which we covered in our insight on what IT support costs and what should be included.
Frequently asked questions
Does Microsoft 365 really need backup?
It depends on the organisation’s recovery requirements. Microsoft offers both built-in recovery features and now a separate Microsoft 365 Backup service, but the organisation still needs to define what must be protected and how recovery should work.
What can Microsoft 365 Backup protect?
Microsoft’s service currently supports Exchange mailboxes, OneDrive accounts and SharePoint sites.
Is it enough to check that the backup job succeeds?
No. The restore needs to be verified too. The NCSC explicitly recommends both backing up and testing restoration as measure 6 of its ten recommended security measures.
Should Entra ID also be part of the recovery plan?
Identity and configuration objects can be business critical. Microsoft Entra Backup and Recovery has been generally available since 30 June 2026 for certain such objects, and the daily backup with seven days of history requires Entra ID P1 or P2.
Want to know whether your backups can actually be restored? Read more about our backup services for businesses or contact us for an informal conversation.
Sources: Microsoft Learn, Overview of Microsoft 365 Backup and Microsoft Entra Backup and Recovery overview; Microsoft Entra Backup and Recovery became generally available on 30 June 2026; Swedish National Cyber Security Centre (NCSC), 10 recommended security measures, measure 6 on backing up and testing restoration of information. Verified 9 September 2026.
This text is general information. Microsoft’s service content, licensing requirements and features change over time; always check the current terms before making decisions.

