Microsoft 365 Shared Responsibility Model — Why You Still Need Backup | Liyatech Solutions

Cloud Backup

Why ‘it’s in the cloud’ doesn’t mean it’s backed up

Cyber Security Team·August 2026

Microsoft keeps the Microsoft 365 platform running. It has never promised to keep a restorable copy of your data — and its own service agreement says so in as many words.

“It’s in the cloud” gets treated as a synonym for “it’s backed up,” and that assumption is one of the most common gaps we find during a new client’s first security review. It isn’t true, and it hasn’t been for as long as Microsoft 365 has existed.


What the shared responsibility model actually splits

Microsoft is responsible for the infrastructure: uptime, physical security of its data centres, and geo-redundant replication so the platform itself doesn’t go down. Everything about the data you put into it — who can access it, whether it’s recoverable after a mistake, and how long it’s retained — sits on your side of the line. Microsoft’s own service agreement recommends that customers regularly back up their content using third-party apps and services, which is about as direct a statement as a vendor can make on the point.


Replication is not backup

This is the distinction that catches people out. If a user deletes a SharePoint site, or ransomware encrypts files synced through OneDrive, that deletion or encryption replicates across Microsoft’s infrastructure exactly like any other change — because from the platform’s point of view, it’s just data doing what data does. The recycle bin and retention policies help for a limited window, but they live inside the same tenant they’re meant to protect, and both can be cleared by an attacker with the right access, or simply expire before anyone notices the problem.


What a real backup covers that native retention doesn’t

Independent storage, separate from the tenant it protects, so a tenant-wide compromise doesn’t take the backup down with it. Coverage across Exchange, SharePoint, OneDrive and Teams — Teams is the workload most often assumed to be covered and most often isn’t, since its data is spread across chat, SharePoint and Exchange underneath. Retention on your own terms rather than a fixed recycle-bin window, and point-in-time recovery rather than an all-or-nothing restore.

Microsoft protects the platform. You protect the data on it. That split isn’t a gap in the service — it’s the design.Liyatech Cyber Security Team

Where this fits with compliance

For POPIA-conscious businesses, being able to demonstrate that reasonable technical measures were in place is part of the story if something goes wrong — and “we assumed Microsoft backed it up” is not a position anyone wants to explain to a regulator or a client after a data-loss incident. A proper backup strategy sits alongside, not instead of, the security and compliance work we do with clients elsewhere.

Keep reading

_____


Financial Services

Cloud compliance for financial and professional services firms

Read more
Public Sector

Cloud adoption in the public sector: moving carefully, not slowly

Read more
Microsoft 365

Microsoft Copilot: what it's actually useful for in a South African SMB

Read more