The gap, in Microsoft's own words
Microsoft keeps 365 running superbly โ and its shared-responsibility model states plainly that your data is your responsibility. Retention policies help but aren't backup: a leaver's mailbox deleted past its window is gone; a ransomware-encrypted OneDrive syncs its encryption to the cloud; a compromised admin (or a malicious one) can destroy years of SharePoint inside Microsoft's rules; retention itself can be misconfigured or legally insufficient. Independent backup snapshots mail, OneDrive, SharePoint and Teams to storage outside the tenant, immutable, with point-in-time restore โ the difference between an incident and an anecdote.
What good 365 backup looks like
Automatic multiple-daily backups; restore that's granular (one email from last March, one folder version from before the encryption, or a whole mailbox) and fast; retention set to your regulatory reality โ years, not Microsoft's defaults; and storage the attacker who owns your tenant still can't reach. We deploy it in an afternoon, monitor the jobs (an unmonitored backup is a hope, not a plan), and test restores on schedule โ because the only backup that counts is the one that restores. It completes the stack with wider backup & DR: 365 for the cloud estate, BDR for everything else.
Related: Managed IT (pillar) ยท Microsoft 365 ยท Email security ยท Cyber security
Frequently asked questions
Doesn't the Recycle Bin cover accidental deletion?
Only within short windows, and not against sync'd ransomware or admin-level deletion. Backup exists for everything the bin can't undo.
How far back can we restore?
Your policy decides โ we typically configure years, with point-in-time restore to any snapshot. Regulated firms get retention matched to their obligations.
How fast is a restore when we need one?
Single items in minutes, mailboxes and sites in hours. And we test restores routinely, because backup without tested restore is theatre.