Microsoft 365 Backup is Microsoft’s own first party backup service, and most writing about protecting Microsoft 365 data still proceeds as though it does not exist. That is the first correction this page makes. The second is that the service covers three workloads for one year, which is narrower than the name implies. What follows is what is actually protected, what the native recycle bins already gave you before you paid for anything, what drives the bill, and where the remaining gap sits.
What Microsoft 365 Backup actually protects
It is a first party service, administered from the Microsoft 365 admin center and billed through Azure. Per the Microsoft 365 Backup overview on Microsoft Learn, checked 19 August 2026, it protects three things and only three things: OneDrive accounts, SharePoint sites, and Exchange Online user mailboxes covering mail, contacts, calendar and task items.
Retention is one year, 365 days, on all three. Restore point granularity differs by workload. OneDrive and SharePoint get ten minute restore points for the preceding two weeks, then roughly daily express restore points, then weekly express restore points out to 52 weeks. Exchange Online gets ten minute restore points across the full 52 weeks. Everything stays inside the Microsoft 365 data trust boundary, which is the operationally interesting part: no data leaves the tenant, and there is no separate vault to secure, licence, patch or audit. If you are pricing the wider compliance estate around this, that is a different exercise and it sits in Microsoft Purview cost and licensing.
What the native retention already gave you
Work out what you already had before buying anything, because a good deal of backup marketing is aimed at people who never checked.
Exchange Online holds deleted items in the Recoverable Items folder. The deleted item retention period defaults to 14 days and can be raised to a maximum of 30, per Microsoft’s Recoverable Items folder documentation on Microsoft Learn, checked 19 August 2026. Recoverable Items carries subfolders for Deletions, Versions and Purges, and adds DiscoveryHolds and SubstrateHolds when a hold applies. That is why a mailbox under litigation hold behaves nothing like one that is not, and why two colleagues can get different answers to the same question about recovering an email on the same day.
SharePoint and OneDrive are more generous. The second stage recycle bin runs to 93 days. When a user account is deleted from Microsoft Entra ID, that user’s OneDrive is retained for 30 days by default, then moves to the site collection recycle bin for a further 93 days: 123 days in total before permanent deletion, per OneDrive retention and deletion on Microsoft Learn, checked 19 August 2026. During that recycle bin period the content is not indexed and not searchable, so it is recoverable but invisible. If you want the detail on how that storage is laid out underneath, I have covered how OneDrive stores files separately.
Read all of that as a recovery window, not as a backup. It is time limited, it is not point in time across a whole site, and it is designed for the accident someone notices this week. It does nothing for the corruption nobody notices for four months.
What Microsoft 365 Backup costs and what drives the bill
List price is 0.15 US dollars per gigabyte per month of protected content, per the pricing model documentation on Microsoft Learn, checked 19 August 2026. Restores are not billed separately, and Microsoft states there are no additional Azure API or storage costs beyond the backup usage charge itself.
The subtlety is what counts as protected content, and this is where estimates go wrong. Billing covers the live footprint, meaning OneDrive accounts and SharePoint sites as they appear in the usage reports including the first stage recycle bin, plus live user and shared mailboxes with their online archives. It also covers the retained material: the second stage recycle bin for sites and accounts, and the deleted and versioned items sitting inside protected mailboxes. A tenant with permissive versioning settings and a large volume of deleted but still retained content will bill noticeably higher than its headline storage figure suggests. Model from retained volume, not from the number on the storage dashboard.
Billing runs pay as you go, which means an Azure subscription with Owner or Contributor access, a resource group and a region, all configured before a single backup policy can be created. On roles, Global Administrator covers all three workloads, SharePoint Administrator covers OneDrive and SharePoint, Exchange Administrator covers Exchange, and there is a dedicated backup administrator role that covers all three without handing out the rest of Global Administrator. Use the dedicated role. There is no good reason for a backup operator to hold tenant wide privilege.
What is not in scope
Three workloads is the coverage list, and the documentation does not claim more. The omissions people trip over are Teams chat as a first class restorable object, Planner, Loop workspaces, Power Platform environments and Dataverse, Entra ID objects such as users, groups, app registrations and Conditional Access policies, and the configuration of the compliance estate itself: retention labels, sensitivity labels and Data Loss Prevention policy definitions.
Look at the shape of that list. It is mostly configuration rather than documents. That matters, because the disaster people plan for is a deleted file and the disaster that actually costs a week is a Conditional Access policy set someone rewrote badly on a Friday. Documents are the well covered part of Microsoft 365. Configuration is not, and no amount of backup spend on the three protected workloads changes that.
The failure modes
Treating backup as a hold. Backup and legal hold answer different questions. A hold preserves in place for a legal obligation and is discoverable through eDiscovery. A backup exists so you can put data back. Buying one and telling the legal team you now have the other is how organisations find out mid case that they have neither.
The 365 day cliff. One year of retention is a real limit, not a starting point that grows. Anything with a multi year regulatory retention requirement needs retention policies doing that job, with the backup service sitting alongside for operational recovery. If the compliance answer is that it gets backed up, the retention period will eventually be the thing that fails the audit.
Budgeting from live storage. Covered above and worth repeating because it is the most common surprise: second stage recycle bin contents and mailbox versions are billable. A tenant that has never pruned versioning can see a materially larger protected footprint than its usage report headline.
Assuming Teams is covered because Teams files are covered. Files posted in a Teams channel live in the underlying SharePoint site and are therefore inside the protected scope. The chat itself is not the same object and is not on the coverage list. Anyone equating the two is going to promise a restore they cannot deliver.
What I would do differently
I have not run a large restore in production. My tenant is a lab with no enrolled devices, so what follows is judgement about the shape of the decision rather than a measured recovery time, and I would rather say so than invent a figure.
The decision I would actually make is not first party against third party. It is whether the thing being protected is documents or configuration. For documents in the three covered workloads, the first party service is the low friction answer: nothing leaves the tenant, restores are not separately billed, and there is no additional infrastructure to run or secure. The argument for a third party product on those same workloads has narrowed considerably, and articles written before this service existed do not reflect that.
For configuration, none of this helps and I would not pretend otherwise. Conditional Access policies, DLP rules, label taxonomies and app registrations need exporting and version controlling as code, on a schedule, to somewhere outside the tenant. That is a Graph and PowerShell job, not a backup product purchase, and it is the piece almost every backup conversation skips.
The one thing I would want to test before trusting any of it is restore behaviour under permission drift: what happens when you restore a site whose membership has changed since the restore point. Microsoft publishes restore time objectives, and they look reasonable. It publishes far less about what the permission state looks like afterwards, and that is exactly the sort of gap between the documentation and production where I would expect the first unpleasant surprise.
Last verified: 19 August 2026.



