Why ‘it’s in the cloud’ doesn’t mean it’s backed up
Microsoft keeps the Microsoft 365 platform running. It has never promised to keep a restorable copy of your data — and its own service agreement says so in as many words.
“It’s in the cloud” gets treated as a synonym for “it’s backed up,” and that assumption is one of the most common gaps we find during a new client’s first security review. It isn’t true, and it hasn’t been for as long as Microsoft 365 has existed.
What the shared responsibility model actually splits
Microsoft is responsible for the infrastructure: uptime, physical security of its data centres, and geo-redundant replication so the platform itself doesn’t go down. Everything about the data you put into it — who can access it, whether it’s recoverable after a mistake, and how long it’s retained — sits on your side of the line. Microsoft’s own service agreement recommends that customers regularly back up their content using third-party apps and services, which is about as direct a statement as a vendor can make on the point.
Replication is not backup
This is the distinction that catches people out. If a user deletes a SharePoint site, or ransomware encrypts files synced through OneDrive, that deletion or encryption replicates across Microsoft’s infrastructure exactly like any other change — because from the platform’s point of view, it’s just data doing what data does. The recycle bin and retention policies help for a limited window, but they live inside the same tenant they’re meant to protect, and both can be cleared by an attacker with the right access, or simply expire before anyone notices the problem.
What a real backup covers that native retention doesn’t
Independent storage, separate from the tenant it protects, so a tenant-wide compromise doesn’t take the backup down with it. Coverage across Exchange, SharePoint, OneDrive and Teams — Teams is the workload most often assumed to be covered and most often isn’t, since its data is spread across chat, SharePoint and Exchange underneath. Retention on your own terms rather than a fixed recycle-bin window, and point-in-time recovery rather than an all-or-nothing restore.
Where this fits with compliance
For POPIA-conscious businesses, being able to demonstrate that reasonable technical measures were in place is part of the story if something goes wrong — and “we assumed Microsoft backed it up” is not a position anyone wants to explain to a regulator or a client after a data-loss incident. A proper backup strategy sits alongside, not instead of, the security and compliance work we do with clients elsewhere.