Microsoft 365 is one of the most important systems in many businesses. It holds email, files, Teams chats, SharePoint sites, OneDrive documents, calendars, contacts and business-critical information.
Because Microsoft 365 is cloud-based and highly reliable, it is easy to assume that backup and monitoring are already fully covered. That assumption can be risky.
Microsoft provides the cloud platform, service availability, built-in security features and resilience across Microsoft 365. However, businesses are still responsible for how users access the system, how data is protected, how security settings are configured and how quickly problems are spotted. Microsoft describes security and compliance in the cloud as a shared responsibility between Microsoft and the customer. Microsoft Learn explains this shared responsibility model here.
In plain English, Microsoft 365 is not a “set and forget” system. It needs backup, monitoring and active management.
Microsoft 365 is reliable, but reliability is not the same as backup
Microsoft 365 is designed to keep services available and protect against platform-level failure. That is very different from protecting a business against accidental deletion, ransomware, malicious activity, compromised accounts or long-term data loss.
For example, Microsoft may protect the underlying service, but that does not mean every deleted email, file, SharePoint site or Teams-related document can always be restored exactly how the business needs it, at the time the business needs it.
Microsoft now offers Microsoft 365 Backup for OneDrive, SharePoint and Exchange Online, which shows how important backup and recovery have become inside Microsoft 365 environments. Microsoft’s own documentation describes Microsoft 365 Backup as providing backup and recovery capabilities for OneDrive, SharePoint and Exchange Online. Microsoft’s backup overview explains the supported services and restore capabilities.
The key point is simple: Microsoft 365 includes resilience, retention and recovery features, but businesses still need to make deliberate decisions about backup.
Retention is not the same as backup
Microsoft 365 includes retention policies, recycle bins, version history and compliance features. These can be useful, but they are not the same as a proper backup strategy.
Retention is usually about keeping or deleting information according to policy. Backup is about being able to recover information when something has gone wrong.
That difference matters.
For example, retention policies may help preserve certain data for compliance purposes, but they are not always designed to provide simple, fast, user-friendly recovery after a large accidental deletion or ransomware event. Microsoft’s own FAQ for Microsoft 365 Backup notes that versions can help individual users restore files, but that this approach does not scale well for large-scale ransomware recovery where an administrator needs to orchestrate recovery. Microsoft explains this distinction in its Microsoft 365 Backup FAQ.
That is why businesses should not treat retention settings as a complete backup plan.
Deleted data may not be recoverable forever
Another common misunderstanding is that deleted Microsoft 365 data can always be recovered later. In reality, recovery depends on the workload, settings, retention policies, backup configuration and how long ago the deletion happened.
SharePoint, OneDrive and Exchange Online all have their own deletion and retention behaviours. Microsoft explains that deleted SharePoint site collections are retained for 93 days before permanent deletion, unless retention or backup settings affect the outcome. Microsoft documents SharePoint data deletion behaviour here.
For businesses, this means a missing file or mailbox problem should be investigated quickly. Waiting too long can turn a simple restore into a permanent data loss issue.
Microsoft 365 accounts are a major target
Backup is only one side of the problem. Monitoring is just as important.
Microsoft 365 accounts are valuable because they often provide access to email, documents, customer information, supplier conversations, invoices, Teams messages and internal files. If an attacker compromises one account, they may be able to read email, set forwarding rules, access SharePoint data, send phishing emails or impersonate the user.
This is why Microsoft 365 security should include active monitoring, not just basic settings.
Businesses should watch for warning signs such as:
- Sign-ins from unusual locations
- Impossible travel events
- Unexpected MFA prompts
- New inbox forwarding rules
- Suspicious mailbox delegation
- Large downloads from OneDrive or SharePoint
- New admin role assignments
- Changes to security settings
- Unusual email sending behaviour
Without monitoring, these issues may only be discovered after a customer, supplier or member of staff reports a problem.
MFA is important, but it is not enough on its own
Multi-factor authentication is one of the most important protections for Microsoft 365, but it should not be treated as the only control needed.
Attackers continue to adapt. Phishing pages, token theft, consent attacks, password reuse, weak recovery processes and poor admin security can all still create risk.
A stronger Microsoft 365 security setup should include:
- MFA for all users
- Stronger controls for administrator accounts
- Conditional Access policies where licensing allows
- Blocked legacy authentication
- Security alerts for suspicious sign-ins
- Mailbox forwarding rule monitoring
- Regular review of admin roles
- Email filtering and phishing protection
- User awareness training
This is one reason KES often recommends Microsoft 365 Business Premium for managed business users. It gives access to a stronger security and management toolset than basic email-only licensing.
Microsoft 365 backup protects against real business problems
A good Microsoft 365 backup strategy helps protect against day-to-day incidents, not just major disasters.
Common examples include:
- A user accidentally deletes an important folder
- A leaver’s OneDrive data is removed too quickly
- A SharePoint site is changed or deleted by mistake
- An email folder is removed and not noticed immediately
- A compromised account deletes or alters data
- Ransomware encrypts synchronised files
- A Teams-connected SharePoint site loses important files
These are not theoretical risks. They are the type of problems that happen in normal businesses.
Without backup, recovery may depend on what is still available in recycle bins, version history, retention policies or Microsoft’s native recovery options. With backup, the business has a clearer route to recovery.
If you want to review this area, see our Backup and Recovery services.
Monitoring helps spot compromise earlier
Monitoring is about reducing the time between something going wrong and someone noticing.
That gap matters. If a compromised mailbox is discovered within minutes or hours, the damage may be limited. If it is discovered weeks later, the attacker may already have read sensitive emails, changed rules, contacted customers or accessed files.
Microsoft 365 monitoring should help identify:
- Suspicious sign-in patterns
- Risky users
- Unexpected changes to mailbox rules
- External forwarding
- Unusual file access
- Security configuration changes
- Inactive or stale accounts
- Accounts without MFA
This is especially important for businesses that rely heavily on email for invoices, customer communication and supplier payments.
KES can help businesses review their exposure through our Business Email Exposure Check and wider Security Review.
Business owners need visibility, not just licences
Many businesses pay for Microsoft 365 every month but have very little visibility of how secure it actually is.
Useful questions include:
- Which users do we currently pay for?
- Which users have admin rights?
- Which accounts do not have MFA?
- Are any mailboxes forwarding externally?
- Are old employees still licensed or active?
- Are SharePoint permissions under control?
- Is OneDrive data protected when users leave?
- Can we restore Microsoft 365 data if something is deleted?
- Would we know if an account was compromised?
If those questions cannot be answered quickly, the Microsoft 365 environment probably needs a review.
How KES helps protect Microsoft 365
KES helps businesses manage Microsoft 365 as part of a wider support and security service.
Depending on the client and package, this can include:
- Microsoft 365 licence review
- Microsoft 365 Business Premium planning
- User and leaver management
- MFA and Conditional Access configuration
- Microsoft 365 backup
- Email security and phishing protection
- Dark web and credential exposure checks
- Identity and sign-in monitoring
- Endpoint protection
- Security awareness training
- Ongoing helpdesk support
This is brought together through our Business User Pack, which is designed to give businesses a more complete Microsoft 365, security and support wrapper.
What should businesses do next?
If your business relies on Microsoft 365, it is worth checking whether backup and monitoring are properly in place.
At a minimum, review:
- Whether Exchange, OneDrive, SharePoint and Teams data is backed up
- How long deleted data can be recovered for
- Whether leaver data is being retained correctly
- Whether all users have MFA enabled
- Whether admin accounts have extra protection
- Whether suspicious sign-ins are being monitored
- Whether external forwarding rules are being checked
- Whether users are trained to spot phishing attempts
Microsoft 365 is a strong platform, but it still needs the right configuration, protection and oversight.
Need help checking your Microsoft 365 setup?
KES can review your Microsoft 365 licences, security settings, backup position and monitoring to help identify risks before they become business problems.