Microsoft’s longtime mantra—“your data, your responsibility”—has gained a new tool. As of early 2025, Microsoft 365 Backup is generally available, promising restore speeds measured in hours rather than weeks. The service, built directly into the Microsoft 365 trust boundary, backs up Exchange Online mailboxes, SharePoint sites, and OneDrive accounts with a 1-year retention period and restore points as frequent as every 10 minutes. Yet a closer look reveals that the platform still doesn’t protect a wide swath of collaboration data—including Microsoft Teams chats, Planner tasks, and the identities stored in Entra ID. For businesses, that means the new native backup is a powerful but incomplete piece of a broader cyber resilience strategy.

What the Native Service Actually Does

Microsoft 365 Backup is a pay-as-you-go service that charges $0.15 per GB per month for all protected data, with restores free of charge. It creates backups within the same data centers where your Microsoft 365 data lives, honoring geo-residency requirements and using append-only storage to prevent backups from being altered. The service supports:

  • Exchange Online: full mailbox restore or granular item recovery, with unchanged items left untouched.
  • SharePoint Online: full site rollback to a previous state, overwriting all changes.
  • OneDrive for Business: full account rollback or file-level restore via versions (coming soon).

Restore speeds are a headline feature: up to 1,000 average-sized sites or accounts can be recovered at a rate of 1–3 TB per hour. For common scenarios like a ransomware attack or mass accidental deletion, that’s a dramatic improvement over traditional third-party tools that pull data from remote, air-gapped storage. Microsoft says initial backups take about 15 minutes per 1,000 protection units, and new restore points appear within minutes for the most recent two weeks, with weekly snapshots thereafter.

The service is tightly integrated with the Microsoft 365 admin center and supports PowerShell, making it accessible to admins without leaving the ecosystem. It also supports Government Community Cloud (GCC) tenants, though some features may vary.

Where the Native Tool Falls Short

Despite its speed, Microsoft 365 Backup was designed with a narrow scope—and that’s by design. The company has been explicit that it’s not trying to replace the entire third-party backup market. The service’s own documentation lists only Exchange, SharePoint, and OneDrive as supported workloads. Notably absent are:

  • Teams: While chat and channel messages exist in Exchange mailboxes for compliance, they aren’t protected as a distinct workload. Microsoft’s compliance retention can retain Teams data for eDiscovery, but restoring a single conversation or channel in-place isn’t something the native backup can do.
  • Planner, Power Platform, and Viva Engage: These services, increasingly central to business processes, are not covered at all.
  • Microsoft Entra ID (formerly Azure AD): User accounts, groups, roles, and application registrations are entirely outside the backup scope. A compromised admin account or accidental deletion of a conditional access policy can’t be rolled back with this tool.
  • Extended retention: One year is the maximum, which may not satisfy regulatory requirements or long-term archival needs.

Moreover, Microsoft 365 Backup’s restores are all-or-nothing at the site or account level (with granular file restore in preview). For Exchange, you can search and restore individual items, but for SharePoint and OneDrive, you’re typically rolling back entire sites. That can be overkill for a single deleted file.

Perhaps most critically, the service’s backups are stored within Microsoft’s own cloud. While append-only storage prevents tampering, there is no option for an independent, air-gapped copy outside the Microsoft environment. If an attacker gains sufficient privileges to delete the backup policy or the entire tenant, recovery may still be possible thanks to a 90-day recycle bin grace period—but for many compliance teams, that’s not enough of a separation.

What This Means for You

For Small Businesses

If you primarily use Exchange, SharePoint, and OneDrive, and your recovery needs are short-term (accidental deletions, a single user’s data loss), Microsoft 365 Backup might be sufficient—and it’s far better than having no backup at all. The pricing is consumption-based, so you pay only for what you protect. However, if you use Teams extensively or have regulatory retention requirements exceeding one year, you’ll need to supplement it.

For Mid-Market and Enterprise

Most organizations will need a layered approach. Use Microsoft 365 Backup for fast, bulk recovery of core data in disaster scenarios, and add a third-party solution for broader coverage (Teams, Planner, Power Platform, Entra ID), longer retention, and independent storage. Many third-party tools now integrate with Microsoft 365 Backup Storage via APIs, meaning you can get the speed of native restore with the breadth of a specialist platform. For example, AvePoint has already announced Cloud Backup Express, which layers its broader protection on top of Microsoft’s fast restore backbone.

For Admins and IT Teams

The shared responsibility model hasn’t changed: Microsoft ensures service availability; you’re responsible for your data. Start by auditing what data you actually have—beyond mailboxes and files, map out Teams, Groups, Power BI dashboards, and any custom solutions. Then, define recovery point objectives (RPO) and recovery time objectives (RTO) for each workload. If an executive’s Teams chat history disappearing would halt a deal, that workload needs protection the native tool can’t provide.

How We Got Here

Microsoft’s reluctance to offer a comprehensive backup service wasn’t an oversight; it was a strategic line drawn by the shared responsibility model. For years, the company argued that its built-in redundancy—recycle bins, versioning, litigation hold—was enough for most data loss scenarios. But high-profile ransomware attacks and accidental deletions proved otherwise. Third-party vendors like Veeam, Druva, and AvePoint built thriving businesses filling the gap, and even Microsoft’s own partners began publicly detailing the risks of relying solely on native retention.

In 2023, Microsoft announced the first inklings of a native backup service, emphasizing speed and integration. By late 2024, it rolled out to general availability with the features described above. The market reaction was mixed: IT pros praised the performance but immediately pointed out the coverage gaps. Petri’s comprehensive comparison of third-party solutions, published mid-2024, underscored that a “best of both worlds” approach—native speed plus third-party depth—was the emerging standard.

What to Do Now

  1. Audit your Microsoft 365 data landscape. Document every workload your teams rely on: Exchange, SharePoint, OneDrive, Teams, Planner, Power Automate, Entra ID, etc. Identify which contain critical business data.
  2. Define your recovery requirements. For each workload, determine acceptable data loss (RPO) and downtime (RTO). An e-commerce site’s product catalog may need a 10-minute RPO; an HR team’s old files might tolerate 24 hours.
  3. Start with Microsoft 365 Backup for core workloads. Enable it for Exchange, SharePoint, and OneDrive. It’s simple to set up and provides a fast recovery safety net. You’ll pay only for what you consume.
  4. Evaluate a third-party solution for the gaps. Look for vendors that explicitly cover Teams, Entra ID, and any niche services you use. Key features to prioritize: immutable backups, independent storage (outside Microsoft’s cloud), granular restore, and cyber-threat detection. Solutions like Veeam Data Cloud for Microsoft 365 offer broad coverage in a single platform, while others like Keepit provide a completely independent backup cloud.
  5. Test restores regularly. A backup you haven’t tested is a wish, not a plan. Schedule quarterly drills: restore a SharePoint site, a departed user’s mailbox, and a critical Entra ID group. Document the process and measure the actual time taken. Remember that restore performance in a real incident may vary based on your tenant’s size and concurrent operations.
  6. Revisit your retention policies. Microsoft 365 Backup’s one-year limit may fall short of industry regulations. If your sector mandates 7-year retention, you’ll need a third-party tool or an archiving solution that can hold data for longer—and make it recoverable, not just searchable.
  7. Lock down admin access. The most advanced backup is useless if an attacker can delete your backups. Enforce multi-factor authentication, use Privileged Identity Management, and separate backup admin roles from day-to-day IT roles. Configure the multi-admin email notification feature in Microsoft 365 Backup so that any offboarding action triggers an alert.

Outlook

Microsoft is unlikely to let its native backup service stagnate. Expect future updates to add more granular restore options (file-level for SharePoint is already on the roadmap) and possibly deeper Teams integration, though the architecture of Teams chat storage makes that challenging. The partner ecosystem will continue to innovate around identity protection, anomaly detection, and AI-driven recovery orchestration. For now, the smart money is on hybrid strategies that leverage Microsoft’s speed for mass recovery and third-party tools for completeness and cyber resilience. The mantra holds: trust but verify—and always have a backup plan for your backup plan.