Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Free Microsoft 365 Backup Checklist:
Is Your Cloud Actually Backed Up? Find Your Gaps in 2 Minutes

Microsoft 365 Backup Assessment

  • 9 quick questions
  • Takes about 2 minutes
  • No sign-up to see your result

Your top next moves

    Nothing critical flagged. Keep everything current and re-check yearly.

    Book a call

    Answer 10 quick questions or the 8 assessment checks and get your gap report in about 2 minutes: your risk level, the specific gaps to fix, and a summary you can hand to your IT provider.

    No sign-up to see your result.

    “Not sure” counts, because if you can’t confirm it, your data isn’t protected.

    What Microsoft 365 Actually Backs Up, and What It Doesn’t

    Microsoft 365 keeps the service running. That’s not the same as backing up your data. Microsoft’s built-in safety nets are short-term recovery windows, not backups.

      • The Recycle Bin and version history in SharePoint and OneDrive retain deleted or overwritten files, but only for a limited time, and they can be cleared by ransomware or a compromised admin before you realize anything is wrong.

      • Exchange Online’s Deleted Items and Recoverable Items folders give you a window to recover deleted email, but once that window closes, the data is gone.

    Microsoft does not perform data recovery on your behalf for user-caused deletion: when data is past the native retention window, their support will confirm it is unrecoverable and close the ticket.

    The practical implication: your organization owns the responsibility for protecting your data inside Microsoft 365. Microsoft owns the infrastructure uptime. That division of responsibility, the shared-responsibility model, is explicit in the Microsoft 365 service agreement and is the source of most M365 data loss incidents.

    The checklist below maps to the 8 assessment questions in the tool above. Anything you can’t confirm is a gap.

    The Microsoft 365 Data Backup Checklist

    Work through each area. A “no” or “not sure” is a gap, if you can’t confirm it, your data isn’t protected against that scenario.

    • 1. Third-Party Backup Running Daily Copies:

      A dedicated third-party backup solution is taking daily copies of your Microsoft 365 data, Exchange Online, SharePoint, OneDrive, and Teams, outside of Microsoft’s infrastructure.

      Your backup solution is independent of your Microsoft 365 tenant (so a compromised admin or ransomware that hits the tenant cannot reach your backup).

      You know the name of the backup product and where your backup data is stored.

      Why this matters. Microsoft’s built-in recycle bins and version history are short-term recovery windows, not backups. They expire, they can be cleared by ransomware, and they do not cover all workloads. A third-party backup tool that writes copies outside Microsoft’s infrastructure is the primary gap to close.

      Source: Syncro 2025 Industry Survey on Microsoft 365 Management (152 MSPs, July 2025).

    • 2. Ransomware Rollback Capability:

      If ransomware encrypted your SharePoint or OneDrive files today, you could restore to a clean point from before the infection, not just roll back everything to a single point that may itself be compromised.

      Your backup solution retains enough history to give you a clean restore point even if the attack was not discovered immediately.

      You have a written ransomware recovery runbook that names who declares an incident, what the restore point target is, and which systems come back first.

      Why this matters. Microsoft’s File Restore covers up to 30 days for OneDrive, but it is an all-or-nothing rollback that overwrites everything after the chosen point, and attackers often clear version history first. An independent backup with granular, item-level restore is the protection native tools cannot provide.

      Source: Backupify State of SaaS Backup and Recovery Report 2025 (n=3,000+ IT/security professionals).

    • 3. Departed-Employee Data Preservation:

      A documented offboarding process applies a mailbox hold and designates a OneDrive data manager before any employee’s Microsoft 365 license is removed.

      The hold is applied before the license is removed, not after (once the license is removed the default deletion clock starts).

      You have confirmed your Microsoft 365 license tier supports litigation holds (entry-level plans do not).

      Why this matters. By default, a departed employee’s mailbox is deleted 30 days after the license is removed and their OneDrive is deleted 93 days after, no hold applied means the data is gone for good. Offboarding is one of the most common sources of accidental M365 data loss.

      Source: Proofpoint 2024 Data Loss Landscape Report (March 2024).

    • 4. Restore Actually Tested:

      Your team has tested restoring data from your backup solution in the past 12 months, not assumed it works, actually tested it.

      The test covered at least one email restore, one file restore from SharePoint or OneDrive, and one Teams or SharePoint site.

      The test result is documented so you have a baseline for your next test.

      Why this matters. An untested backup is an assumption, not a recovery plan. The first time many organizations discover their backup is broken or incomplete is during an actual incident, when the cost of that discovery is highest.

      Source: Veeam 2025 Ransomware Trends and Proactive Strategies Report (1,300 orgs, published April 23, 2025).

    • 5. Teams and SharePoint Covered, Not Just Email:

      Your backup coverage explicitly includes SharePoint sites and Microsoft Teams channel data, not just Exchange Online mailboxes.

      You have confirmed which workloads are in scope with your backup vendor or IT provider, in writing, not assumed.

      Teams data coverage is confirmed: Teams messages, channel files (stored in SharePoint), meeting recordings, and shared tabs are included.

      Why this matters. Teams data is distributed across SharePoint, OneDrive, and Exchange, most organizations that back up email leave at least one of those locations unprotected. Checking “email backup” on a vendor quote is not the same as confirming full M365 coverage.

      Source: Gartner press release, August 28, 2024.

    • 6. Retention and Legal-Hold Policies Deliberately Configured:

      Someone on your team or your IT provider has deliberately configured retention and legal-hold policies in Microsoft Purview (or the Microsoft 365 Compliance Center), not left them at the defaults.

      You know your license tier and have confirmed it supports the retention and litigation-hold features your organization needs (E1/Business Basic cannot configure litigation holds at all; shared mailboxes are excluded from standard retention policies).

      The configured policies are documented so you know what is covered, for how long, and what is excluded.

      Why this matters. Default retention settings in Microsoft 365 vary significantly by license tier. Organizations that have not deliberately configured retention are often surprised to discover what their license does and does not cover, after data is needed for legal, HR, or compliance purposes.

      Source: Hornetsecurity IT Cybersecurity Compliance Survey 2023.

    • 7. Protection Against a Compromised or Mistaken Admin:

      If an admin account was compromised or a bulk-delete mistake happened today, you have a way to recover that data independently of Microsoft, through your third-party backup.

      You have reviewed which admin accounts have permission to delete backup policies or bulk-remove data, and confirmed MFA and a secondary approver are required for those destructive actions.

      Admin access to your backup console is protected separately from your Microsoft 365 tenant credentials.

      Why this matters. A compromised admin with the right permissions can permanently destroy data before recovery is possible. Microsoft’s own Backup tool has an offboarding grace period, but if you rely only on native tools, your admin IS your backup, and that is the single point of failure.

      Source: Thales 2023 Data Threat Report (451 Research, ~3,000 IT/security professionals, 18 countries).

    • 8. Recovery Ownership Documented:

      You know specifically who at your organization (or your IT provider) would manage a Microsoft 365 data recovery request, by name, not “IT will handle it.”

      The escalation path to your backup vendor is documented: who calls whom, what the account number is, and what the expected response time is.

      The recovery owner has been through at least one test restore so the first hour of a real incident is not spent figuring out the process.

      Why this matters. Microsoft does not perform data recovery on your behalf for user-caused deletion. When data is gone past native retention windows, support will confirm it is unrecoverable and close the ticket. The recovery path runs through your backup vendor, and if no one at your organization owns that relationship, you will be discovering it under pressure.

      Source: Sophos State of Ransomware 2024 (Vanson Bourne, 5,000 orgs, 14 countries, Jan-Feb 2024).

    How to Read Your Gaps?

    • 0 – 1 Gap

      Solid coverage, keep your backup current, test restores annually, and verify your retention config when you change license tiers.

    • 2 – 4 Gaps

      Real, findable exposure: a single ransomware event or employee departure targeting an uncovered area can result in permanent data loss.

    • 5+ Gaps

      Your organization is relying on Microsoft’s native retention windows as its primary safety net, those windows are short, can be bypassed, and do not cover all workloads.

    Most of the technical items above, third-party backup, restore testing, admin controls, retention policy configuration, live in your IT setup, not a policy binder, which is the half of Microsoft 365 data protection a managed IT partner operates for you.

    Microsoft 365 Backup Checklist FAQ

    Does Microsoft 365 back up my data automatically?

    Microsoft keeps the service running, redundant infrastructure, 99.9% uptime SLA, but it does not back up your data in the sense that most businesses mean. The built-in recovery tools (recycle bins, version history, Recoverable Items) are short-term windows, not a backup: they expire, they have workload gaps, and they can be cleared by ransomware or a compromised admin. If you need to restore data to a clean point after a ransomware event, a bulk deletion, or a departing employee’s license removal, you need a third-party backup solution.

    What data in Microsoft 365 is at risk if I don’t have a backup?

    All of it, but the highest-frequency loss scenarios are: ransomware or malicious encryption of SharePoint and OneDrive files; accidental or malicious bulk deletion by a user or admin; data belonging to a departed employee whose license was removed without a hold applied (mailbox gone in 30 days, OneDrive in 93 days); and Teams channel data, which is distributed across SharePoint, OneDrive, and Exchange and often left out of backup scopes that only cover email.

    What should a Microsoft 365 backup solution cover?

    At a minimum: Exchange Online mailboxes (including shared mailboxes), OneDrive files, SharePoint site collections, and Teams data (channel messages, files, and meeting recordings). It should also cover calendar data, contacts, and, depending on your Microsoft 365 apps, Planner and OneNote. The backup should be stored outside your Microsoft 365 tenant so a compromised admin or ransomware event cannot reach it, and it should support granular, item-level restore rather than all-or-nothing rollbacks.

    What’s the difference between Microsoft 365 retention policies and a backup?

    Retention policies in Microsoft Purview control how long data is kept and whether it can be deleted, they are a compliance and legal-hold tool, not a recovery tool. They cannot restore data to a point in time before an incident, they do not cover all workloads or license tiers equally, and they are managed within your Microsoft 365 tenant (so a compromised admin can affect them). A backup is a separate, point-in-time copy stored outside your tenant that you can restore from regardless of what happened in the tenant. The two serve different purposes.

    How often should we test our Microsoft 365 backup restore?

    At minimum, once a year, and any time you change backup vendors, change your Microsoft 365 license tier, or add a major new workload (like moving from Exchange on-premises to Exchange Online, or expanding Teams use). The test should cover at minimum one email restore, one file restore from SharePoint or OneDrive, and one Teams or SharePoint site restore. Document the result so you have a baseline.

    What happens to a departed employee’s Microsoft 365 data?

    By default, once a Microsoft 365 license is removed, the employee’s mailbox goes into a soft-delete state and is permanently deleted after 30 days. Their OneDrive is deleted 93 days after the license removal unless a manager or admin is designated as the data steward before that window closes. If your organization needs to retain that data, for HR, legal, or continuity purposes, a litigation hold must be applied before the license is removed, not after. Entry-level Microsoft 365 license tiers do not support litigation holds; confirm your tier before relying on them.

    Does our IT provider cover Microsoft 365 backup, or do we need a separate product?

    It depends on the agreement, and it’s worth confirming in writing rather than assuming. Many managed IT providers include a Microsoft 365 backup product as part of their standard stack; others offer it as an add-on; some leave it to the client entirely. Ask your IT provider specifically: what backup tool is running on our Microsoft 365 tenant, what workloads does it cover, where is the backup stored, and when did we last test a restore? If they cannot answer those four questions, your backup coverage is worth reviewing.

    Ready to close your gaps?

    If your result flagged two or more gaps, most of them are technical work a managed IT partner handles as part of day-to-day operations. LeadingIT has helped Chicagoland businesses protect their Microsoft 365 data since 2010. We operate the backup tools, test the restores, manage the offboarding holds, and configure the retention policies, so you are not discovering a gap during an incident.

    Email yourself the full gap report from the tool above, book a free 30-minute backup review, or contact us.