NetFusion Designs logo
Heart icon
Support
Email
info@nfd.ca
Phone
289 212-3930(Canada)
IT Services
Icon dropdown arrow

Infrastructure Implementation

Project PlanningHardware Voice over IP (VoIP)Application DevelopmentCloud DesktopSecurity Cameras

Managed IT Services

IT Support24/7 HelpDeskCyber Security & AntivirusData Backups & Disaster
Recovery
Co-Managed ITComplianceEmergency Ransomware
Recovery
Penetration & Vulnerability
Assessment

Optimization of Processes

Microsoft 365 OptimizationVirtual CIO ServicesPenetration TestingInventory Lifecycle
Management
Transforming SMEs with AI
Industries
Icon dropdown arrow
Dental Managed IT Services
Construction
Hotels & Hospitality
Franchises
Financial & Insurance Services
Government
Health Care & PharmaceuticalLegal & Professional Services
Local Small & Medium Businesses
Manufacturing
Non-profit
Real Estate
Retail
Transportation & Logistics
Enterprise & Consulting
Publicly Traded Companies
Our Story
Icon dropdown arrow
About UsTestimonials
Partners
Sponsorship
BlogContact Us
Open menuClose menu
Icon chevron up
Browse Blog:
Business
Insight
Advice
Insight

SMBs: Prove Microsoft 365 Backup Works With a 90 Day Restore Test

Microsoft 365 alone is not sufficient for real business continuity. Its native retention windows are built for short-term recovery, not disaster protection, and the Canadian Centre for Cyber Security explicitly calls for independent, encrypted copies and regular restore testing. If you have not confirmed your retention settings or tried a restore in the last 90 days, do that this week, not after an incident.


TL;DR:

  • Microsoft 365 native retention windows are short-term solutions and require regular testing and verification to ensure data recovery is possible.
  • Native retention does not cover audit logs or compliance records, and it offers no protection against ransomware that encrypts live data and recycle bins simultaneously.
  • Microsoft 365 Backup is a separate, paid service with a default one-year recovery window, and policies must be carefully configured to match actual business needs.
  • Building an effective backup plan involves defining scope, setting realistic recovery objectives, storing independent copies, encrypting data, and consistently testing restore procedures.
  • Operational ownership, including monitoring, testing, and dedicated personnel, is more critical than the backup product itself for actual data recovery success.

NetFusion Designs Inc
Strengthen Your Microsoft 365 Recovery
NFD helps businesses manage secure, monitored IT and Microsoft 365, with support for compliance and continuity needs.
Explore managed IT services

Table of Contents

  • What Microsoft protects, and where its native retention falls short
  • Microsoft 365 Backup and built-in options: coverage, pricing and policy mechanics
  • How to build a practical Microsoft 365 backup plan for your business
  • Restore testing and offboarding: proving your backups actually work
  • Why operational ownership matters more than the backup product you buy
  • Get a working backup and recovery plan, not just a checkbox
  • Sources
  • FAQ

What Microsoft protects, and where its native retention falls short

Microsoft 365 gives you meaningful protection out of the box, but every workload has a clock running on it. Understanding those clocks is the first step toward knowing whether your business is actually covered or just assumes it is.

Exchange Online keeps deleted items for 14 days by default, and admins can extend that retention up to 30 days. A mailbox that gets soft-deleted, say, after an employee leaves and IT removes the account, sticks around for up to 30 days before it is gone for good. That sounds generous until you consider how many businesses discover a deletion problem weeks after it happened, not days.

Microsoft 365 deleted-item retention timeline

SharePoint and OneDrive work on a similar logic but with more moving parts. Deleted files pass through a first-stage and second-stage recycle bin, and an entire deleted site can be recovered for roughly 93 days before it is permanently purged. Microsoft holds an additional limited retention period of site backups specifically to support full site collection restores, but that is the outer edge, not a safety net you can rely on indefinitely.

Three practical gaps trip up SMBs more than any single retention number:

  • Audit logs and certain compliance records are not always captured by the retention windows above, which matters if you face a regulatory inquiry months after an event.
  • Closing a user’s account or cancelling a subscription can trigger deletion, and the Microsoft Services Agreement is explicit that customers should keep their own backups because Microsoft may delete content tied to a cancelled service.
  • None of this native retention behaves like a true backup: there is no independent, immutable copy sitting outside your production tenant that survives a ransomware attack encrypting live data and its recycle bin simultaneously.

Microsoft 365 Backup and built-in options: coverage, pricing and policy mechanics

Microsoft does sell a purpose-built backup product, separate from native retention, called Microsoft 365 Backup. It covers Exchange Online mailboxes, OneDrive accounts, and SharePoint sites, and it is priced as a consumption service rather than a flat monthly fee.

Pro Tip: Before you assume Microsoft 365 Backup solves everything, check whether your compliance obligations require audit-log retention, since that workload sits outside the product’s standard coverage.

Microsoft publishes a rate of US$0.15 per GB per month, and new policies default to a recovery window of about one year unless an administrator changes it. That default matters: a business assuming “Microsoft backs it up forever” is wrong, and a business that never checks the policy setting may find its actual protection window is shorter than expected.

Setting up policies involves a few mechanical choices worth understanding before you flip the switch:

  • Protection scopes define exactly which mailboxes, OneDrive accounts, or SharePoint sites get included, and you can bulk-add accounts through CSV files or dynamic rules.
  • Full-workload backup, which would extend coverage automatically as new accounts appear, is still a preview feature, so treat it as promising rather than guaranteed.
  • Recovery windows apply at the policy level, so different policies may have different recovery guarantees without anyone noticing.

How to build a practical Microsoft 365 backup plan for your business

A backup plan is not a product purchase. It is a short sequence of decisions that determine whether your business can actually get back to work after data loss, and most SMBs skip at least two of the six steps below.

  1. Define scope first. List every mailbox, OneDrive account, SharePoint site, and Teams data store that matters to daily operations. If it is not on the list, it is not protected, no matter what tool you buy.
  2. Set recovery windows against real business needs. Decide your recovery time objective (how fast you need data back) and recovery point objective (how much data loss is tolerable) before comparing tools. A one-year default recovery window is meaningless if your actual exposure runs longer.
  3. Keep an independent copy off the production tenant. This is the single most important structural decision. If your only copy lives inside the same tenant a ransomware attacker just compromised, you do not have a backup, you have a second target.
  4. Encrypt everything and separate admin access. The Canadian Centre for Cyber Security recommends restricting who can trigger a restore, since backup credentials are a favourite target for attackers who want to delete your recovery option before encrypting live data. Confirm contractually where your provider stores data and who can access metadata, because marketing language about “Canadian storage” is not a substitute for a written commitment.
  5. Operationalize monitoring. Someone needs to get an alert when a backup job fails, and that alert needs an owner who actually checks it, not a mailbox nobody reads.
  6. Schedule restore tests and document the results. A backup you have never restored is a theory, not a plan.

Pro Tip: Treat step six as non-negotiable. A backup system that has never restored anything in production is functionally unproven, no matter how well the vendor’s dashboard looks.

Restore testing and offboarding: proving your backups actually work

Confidence in a backup system comes from restoring something, not from a green checkmark on a dashboard. Run these specific tests on a recurring schedule, not just once after setup:

  • Restore a single email and confirm the metadata, folder location, and read/unread status came back correctly.
  • Restore an entire mailbox and time how long it takes from request to usable inbox.
  • Restore a SharePoint folder or full site and check that permissions mapped correctly, not just that files reappeared.
  • Restore a single OneDrive file and confirm version history survived the round trip.

Offboarding deserves the same rigour. When a departing employee’s licence is removed, some retention features stop applying immediately, so your offboarding workflow needs a step that preserves or reassigns that person’s data before licence removal, not after.

Restore test What to verify Who owns it
Single email Metadata, folder, read status IT admin
Full mailbox Elapsed time, completeness IT admin + manager sign-off
SharePoint site Permissions, versions IT admin + site owner
OneDrive file Version history intact End user + IT admin

Assign one person to authorize restores, a separate person to perform them, and store backup credentials with the same access discipline you apply to your domain admin account.

Why operational ownership matters more than the backup product you buy

Why operational ownership matters more than the backup product you buy — overview diagram

A backup product is only as good as the people running it. That is the uncomfortable truth most vendor pitches skip: the failure mode that actually sinks businesses is rarely “we picked the wrong tool,” it is “nobody tested the restore” or “the backup credentials were sitting in a shared spreadsheet.”

NetFusion Designs Inc operates under SOC 2 Type II certification with a 24/7 NOC watching for failed backup jobs before they become failed recoveries, and we run tested restores as a standing operational practice, not a one-time onboarding checkbox. If your internal IT team is stretched thin across helpdesk tickets, security patching, and everything else, a managed provider closes the gap between owning a backup tool and actually being able to recover from it.

— Geeshan

Get a working backup and recovery plan, not just a checkbox

Buying a backup tool and knowing you can recover from it are two different problems, and most SMBs only discover the gap between them during an actual incident. NetFusion Designs Inc’s Cloud Backup & Disaster Recovery service is built around the practices this article just walked through: independent copies outside your production tenant, encryption, restricted restore access, and scheduled restore tests with documented results.

NetFusion Designs Inc

A typical engagement starts with an assessment of your current Exchange, OneDrive, and SharePoint retention settings, followed by policy design that matches your actual recovery time and recovery point needs, and a first test restore so you see proof of recoverability before you ever need it in a real emergency. We also handle Microsoft 365 optimization alongside backup, since tenant hygiene and backup coverage are closely linked, especially during offboarding. If you want a straightforward next step, request a backup assessment through our managed IT services page and we will walk you through exactly what your current setup does and does not cover.

Sources

  • Learn about retention for Exchange | Microsoft Learn
  • Back up and encrypt data | Canadian Centre for Cyber Security

FAQ

Is Microsoft 365’s built-in retention the same as a backup?

No. Native retention windows, like the 14 to 30 day mailbox recovery period and the 93-day SharePoint site deletion window, are designed for short-term recovery, not indefinite protection. A true backup keeps an independent copy outside your production tenant.

What should an SMB back up first in Microsoft 365?

Start with Exchange mailboxes, OneDrive accounts, and SharePoint sites tied to daily operations, then extend to Teams data. Anything supporting a regulatory or client obligation should be prioritized regardless of how often it is used.

How often should we test restores?

Run at least one documented restore test per quarter, covering a single file, a full mailbox, and a SharePoint site or folder. The Canadian Centre for Cyber Security treats regular verification as a core requirement, not an optional extra.

What does Microsoft 365 Backup cost, and does it cover everything?

Microsoft prices Microsoft 365 Backup at US$0.15 per GB per month with a default one-year recovery window. It covers Exchange, OneDrive, and SharePoint, but not all audit-log data, so check compliance requirements separately.

Should we manage backup in-house or use a managed provider?

If your internal team already struggles to monitor failed jobs or test restores consistently, a managed provider closes that gap. NetFusion Designs Inc’s current pricing for managed backup and disaster recovery is available directly on the site.

Recommended

  • Backup & Disaster Recovery Toronto | Tested Restores
  • Microsoft 365 Optimization

Continue Reading

Start with MFA: 30/60/90 Zero Trust Plan for Canadian SMBs
Autopilot Deployment Steps That Stop Week One Failures: Admin Runbook
Pilot First AI Invoice Processing for Finance & IT
90 Day Legacy App Modernization for CIOs, AI Mapping and Wave Results
NetFusion Designs logo
NetFusion Designs is a globally recognized IT service provider and services clients across North America.

We hold a SOC 2 Type 2 report, and maintain internal processes and procedures that keep our clients’ data secure and confidential.
NetFusion Designs IT support team
IT Services Near Me
BurlingtonOakvilleHamiltonMississaugaMiltonBramptonEtobicokeBrantfordGuelphKitchenerWaterlooCambridgeSt CatharinesTorontoMarkhamCaledonNewmarket
Services
Project PlanningHardwareTelephony & VoIPApplication DevelopmentCloud DesktopSecurity CamerasHelpdesk & SupportCyber Security & Anti-VirusData Backups & Disaster RecoveryMicrosoft 365 OptimizationVirtual CIO ServicesPenetration TestingPricingSchedule a MeetingRemote Support
Pricing
Pages
Free Security ScanAbout UsOur Migration ApproachWork CultureOur Core ValuesCode of ConductTestimonialsContactBlogSchedule a MeetingRemote Support
TORONTO
Bank capital office building law
401 Bay St, 16th Floor, Toronto Ontario
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
MARKHAM
Bank capital office building law
141 Main Street N, Markham, ON L3P 1Y2
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
TRI-CITY AREA
(Kitchener / Waterloo / Cambridge)
Bank capital office building law
22 Frederick St, Suite 700, Kitchener Ontario
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
PEEL REGION
Bank capital office building law
6700 Century Ave, 3rd floor, Mississauga, ON L5N 1V8
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
DURHAM REGION
Bank capital office building law
1315 Pickering Parkway, Pickering, ON L1V 7G5
Email
info@nfd.ca
MONTREAL
Bank capital office building law
8815 Av du Parc #402, Montréal, QC H2N 1Y7
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
Special Offers
Pie chart piechart stats analytics
IT-Optimization Session
Icon chevron right
Money safe safebox
800% ROI Consultancy Offer (Video)
Icon chevron right
Radio station signal antena tower
Coming Soon!
Icon chevron right
Terms and ConditionsPrivacy PolicyCookie Policy
© 2026 NetFusion Designs Inc.
LinkedInFacebookAlignable logo