There is one assumption we hear in nearly every recovery conversation, and it is the one that costs the most: "It is in Microsoft's cloud, so it is backed up." By the time that assumption is tested, the data is usually already gone.
Microsoft 365 is highly resilient. Microsoft replicates your data across its infrastructure and keeps the service available through hardware failures and outages. But service resilience is not the same as data recovery, and the gap between the two is where businesses lose files, mailboxes, and, occasionally, their ability to operate.
Microsoft's shared responsibility model
Microsoft operates under a shared responsibility model, and it is worth reading the division of labor carefully. Microsoft is responsible for the platform: keeping the service online, protecting the infrastructure, and ensuring the physical resilience of the data centers. You, the customer, are responsible for your data, specifically, protecting it against accidental deletion, malicious deletion, ransomware, and retention gaps, and being able to recover it.
Microsoft states this directly in its service terms, which recommend that customers regularly back up their own content using third-party services. That is not a footnote. It is Microsoft telling you, in writing, that recovering your data is your job, not theirs.
Retention is not backup
Microsoft 365 has retention features, and they are useful. They are also routinely mistaken for a backup, which is where organizations get caught.
- Recycle bins hold deleted SharePoint and OneDrive content for a limited window, on the order of about 93 days, after which it is purged.
- A deleted mailbox is typically recoverable for around 30 days before it is gone.
- Deleted email items follow a retention window measured in days to weeks by default.
- Retention policies and Litigation Hold can preserve content for compliance, but they are designed to prevent deletion, not to give you a clean point-in-time restore of a tenant to how it looked last Tuesday.
Every one of these is time-bound and purpose-built for a specific scenario. None of them is a full-fidelity backup that lets you roll back to a known-good state after something goes wrong. When the window closes, the data is unrecoverable, regardless of how much you are paying Microsoft.
Where SMBs actually lose data
The scenarios are not exotic. We see the same four:
- Ransomware encrypts synced files. Malware on one laptop encrypts local files that OneDrive dutifully syncs to the cloud, overwriting the good versions. The cloud copy is now the encrypted copy.
- A departing employee cleans up. An unhappy or careless leaver deletes mail, files, or a shared mailbox, and the deletion is not noticed until the retention window has already expired.
- An accidental deletion surfaces late. A folder is deleted, nobody notices for four months, and by the time it matters the recycle bin has purged it.
- A misconfiguration or bulk change goes wrong. A script, a migration, or a permissions change quietly corrupts or removes data at scale, and there is no snapshot to return to.
In each case, the business assumed Microsoft had a copy. Microsoft had a running service. Those are not the same thing.
What a real recovery position looks like
Being able to recover is a decision you make before the incident, not during it. A defensible position has three parts.
First, know your actual windows. Most organizations have never mapped how long each type of content is truly recoverable in their tenant. That map is the difference between "we can get it back" and "we hope we can."
Second, configure retention and holds deliberately for the data that matters, so compliance-relevant content is preserved and not left to default settings.
Third, and most importantly, evaluate a third-party Microsoft 365 backup that provides independent, point-in-time recovery of Exchange, SharePoint, OneDrive, and Teams. This is the piece that turns "the retention window expired" into "we restored it in an hour."
How NeoDefender closes the gap
NeoDefender treats recoverability as part of the security architecture, not an afterthought.
- Discover: Map what is recoverable in your tenant today, for how long, and where the real exposure is.
- Design: Define retention, hold, and backup requirements based on your business and compliance needs, not on defaults.
- Validate: Test restores, because a backup you have never restored from is a theory, not a safeguard.
- Modernize: Implement independent point-in-time backup and correct the retention gaps that leave data exposed.
- Monitor: Verify backup coverage and recovery readiness continuously, so the answer to "can we get it back" is always yes.
The businesses that come through a data-loss event without lasting damage are not the ones who reacted fastest. They are the ones who decided, in advance, that "it is in the cloud" would never be their backup strategy.
Contact NeoDefender to find out exactly what is recoverable in your Microsoft 365 tenant today, and what is not.





