Back to Blog
Cloud8 min read

Microsoft 365 Doesn't Back Up Your Data: What Every Canadian SMB Needs to Know

By Anton Kuznetsov

Most Canadian SMBs assume Microsoft is backing up their Microsoft 365 environment. Teams conversations, SharePoint files, Exchange emails, OneDrive documents — all in the cloud, all managed by a company with unlimited resources. Surely it's protected.

This assumption is widespread, and it is wrong.

Microsoft's shared responsibility model is explicit: Microsoft protects the infrastructure that runs Microsoft 365 — the datacentres, the network, the platform availability. Your data is your responsibility to protect. This appears in Microsoft's service documentation, its terms of service, and in every major backup vendor's product documentation. It is not ambiguous, but it surprises the majority of SMB owners who have never read it.

Microsoft 365 is the dominant productivity platform among Canadian SMBs — particularly in finance, legal, construction, and professional services. With 71% of Canadian SMBs now using AI tools — most delivered through the Microsoft 365 stack — that data footprint is only growing. Understanding what Microsoft actually provides, and what PIPEDA requires you to do about the gap, is foundational for any Canadian business that handles personal information.

What Microsoft Actually Provides: Retention, Not Backup

Microsoft 365 does have native data retention mechanisms. They exist primarily for compliance and governance purposes — satisfying litigation holds, eDiscovery, and regulatory obligations. They are not positioned as a substitute for point-in-time backup, and Microsoft does not describe them as one.

Here is what the native recovery windows actually look like:

WorkloadRecycle Bin / Deleted ItemsMaximum RecoverableVersioning
SharePoint Online93 days (first + second stage combined)93 daysUp to 500 major versions
OneDrive for Business93 days (first + second stage combined)93 daysUp to 500 major versions
Exchange Online14 days (Deleted Items, default)30 days (Recoverable Items)Not applicable
Microsoft Teams chatNot individually recoverableGoverned by Exchange mailbox retentionStored in Exchange

Source: Microsoft Learn — OneDrive retention and deletion; Microsoft Learn — Version history limits

Three things most SMBs don't know about these windows:

Versioning is not a backup. SharePoint and OneDrive retain up to 500 major versions of each file — but version thinning begins at day 31. Only hourly versions are kept between 31–60 days; only daily versions between 61–180 days; only weekly versions beyond 180 days. A file corrupted by ransomware that propagated slowly through your SharePoint library may have no uninfected recoverable version left by the time the compromise is discovered.

The Exchange window is too short for most breach timelines. Your permanently deleted emails are gone after 30 days at maximum. The CCCS National Cyber Threat Assessment 2025-2026 identifies ransomware as the top cybercrime threat facing Canadian organizations, and the average time to discover a breach — across all Canadian incident types — routinely exceeds 90 days. By the time you know what happened, your Exchange evidence is gone.

Deleted user accounts have a countdown. When an employee's Microsoft 365 account is deprovisioned, their OneDrive is retained for 30 days by default. After that window closes without administrator intervention, the data is permanently deleted. A missed offboarding step costs you the departing employee's entire document history.

The Four Scenarios That Destroy Microsoft 365 Data

Veeam's documentation on the Microsoft 365 shared responsibility model and Microsoft's own service terms identify four scenarios that fall entirely outside Microsoft's data protection responsibility:

Accidental deletion. A user deletes a folder containing three years of client correspondence and empties the recycle bin. Recoverable within 93 days; permanently gone after that. In a busy environment, the deletion may go unnoticed until recovery is impossible.

Ransomware propagation through sync clients. Ransomware that encrypts files on a local machine will sync the encrypted versions to OneDrive, potentially overwriting clean versions. Microsoft's versioning provides partial protection, but a slow-moving targeted campaign — the pattern the CCCS flags as most common against Canadian SMBs — can exhaust version history before the compromise is detected.

Malicious or departing employee actions. An employee with legitimate access who deliberately deletes files or overwrites documents does so within the Microsoft 365 permission model. Microsoft cannot distinguish malicious deletion from authorized deletion. Your backup is the only independent recovery point.

Administrative errors. A SharePoint site collection deleted by an administrator may be recoverable from the recycle bin for 93 days — or it may not, depending on configuration. Misconfigured retention policies applied globally can permanently delete data that should have been preserved. These scenarios are more common than most organizations expect, and the consequences scale with how critical the affected site was.

Statistics Canada's 2023 Survey of Cyber Security and Cybercrime found that 16% of Canadian businesses experienced a cybersecurity incident that year, and recovery spending doubled from $600 million in 2021 to $1.2 billion in 2023 — with small and medium businesses accounting for an estimated $600 million of that total. The cost of unrecoverable data — when no backup exists — is not captured in recovery spending figures and typically runs far higher.

Why This Is a PIPEDA Problem, Not Just an IT Problem

For Canadian SMBs that handle personal information — which includes nearly every business managing client records, employee files, or transaction data — the backup gap creates compliance exposure under PIPEDA.

PIPEDA's accountability principle requires organizations to protect personal information throughout its lifecycle, including information held by third-party processors like Microsoft. The OPC's guidance on accountability is explicit: your organization remains accountable for personal information transferred to a processor, and you must ensure through contractual or other means that the processor provides comparable protection.

Microsoft's service terms cover infrastructure protection. They do not commit to recovering your lost or deleted personal information. If client records are permanently deleted due to ransomware, an administrative error, or employee misconduct — and you have no independent backup — an OPC inquiry will ask why your safeguards were insufficient. "Microsoft is responsible for it" is not a defensible answer under PIPEDA's accountability framework.

OPC investigation records from 2024–2026 consistently identify the same two missed principles in Canadian SMB audits: accountability (no named privacy officer) and safeguards (no documented vendor due diligence). Operating Microsoft 365 without an independent backup and without documented data protection controls fails the safeguards principle.

Microsoft 365 Backup: The Native Option Most SMBs Don't Know About

In July 2024, Microsoft released Microsoft 365 Backup as a generally available service — a native, Microsoft-managed backup product accessible through the Microsoft 365 admin centre and Purview.

Microsoft 365 Backup covers Exchange Online, SharePoint Online, and OneDrive for Business. Pricing is $0.15 USD per GB per month of backup storage — consumption-based, not per-seat. For a 50-user professional services firm with approximately 2 TB of total data, that works out to roughly $300 USD ($415 CAD) per month.

What it adds compared to native retention:

Native RetentionMicrosoft 365 Backup
Recovery granularityFile/mailbox within retention windowPoint-in-time restore to a specific date
Maximum lookback93 days (SharePoint/OneDrive), 30 days (Exchange)Up to 1 year
Ransomware recoveryLimited by version thinningFull point-in-time restore bypasses corrupted versions
Admin error recoveryRecycle bin onlyRestore entire site collections, mailboxes, or OneDrive
PricingIncluded in M365 subscriptionAdditive: ~$0.15 USD/GB/month

Microsoft 365 Backup is a meaningful upgrade for organizations wanting to stay within the Microsoft ecosystem. Its limitations: it is managed within your Microsoft tenant, meaning a catastrophic tenant-level event (rare but documented) affects both primary data and backup; it does not cover Teams Channels content independently; and it does not provide a copy of your data that lives outside Microsoft's control.

Third-Party Backup: The Tenant-Independent Safety Net

For Canadian SMBs that want an independent copy of their Microsoft 365 data stored outside the Microsoft tenant — under their direct control — third-party backup solutions remain the standard approach. Established vendors include Veeam Backup for Microsoft 365, Acronis Cyber Protect, Barracuda Backup, and Dropsuite.

Pricing typically runs $4–$8 CAD per user per month for full coverage of Exchange, SharePoint, OneDrive, and Teams — $200–$400 CAD per month for a 50-user organization. Cost is comparable to Microsoft's native option, but the key advantage is an independent copy that survives tenant-level events, administrative errors that affect backup configuration, or any scenario in which Microsoft's own infrastructure is involved in the incident.

The right choice between Microsoft 365 Backup and a third-party solution depends on your risk tolerance, regulatory requirements, and whether your compliance posture requires tenant-independent data custody. For most Canadian SMBs, either option is substantially better than operating with only native retention windows as the sole safety net.

Four Decisions to Make Before Next Month

1. Conduct a data inventory. Identify your critical Microsoft 365 workloads: which SharePoint sites contain irreplaceable client records; which Exchange mailboxes carry regulatory or contractual obligations; what OneDrive data is the primary copy of business-critical documents. This is your risk surface, and you cannot protect what you have not mapped.

2. Verify your current retention configuration. Log into the Microsoft 365 admin centre and confirm your SharePoint site recycle bin settings, your Exchange deleted item retention period (30 days requires deliberate configuration — the default is 14 days), and whether any Purview retention policies are applied. Most SMBs have never changed the defaults.

3. Document your backup decision for PIPEDA. Having a backup is not enough — you need to show you made an informed, documented decision about how personal information in your Microsoft 365 environment is protected. That documentation is what survives an OPC inquiry or a client privacy audit.

4. Implement backup before an incident forces the decision. The CCCS National Cyber Threat Assessment 2025-2026 identifies ransomware as the top cybercrime threat facing Canadian organizations. Ransomware recovery without an independent backup routinely costs 10–50× the annual cost of the backup that would have prevented the data loss. The math is straightforward.


Sources


Our AI Continuity practice helps Canadian SMBs design and implement backup architectures for Microsoft 365, document data protection decisions for PIPEDA accountability, and ensure that when an incident occurs — ransomware, administrative error, or employee misconduct — recovery is measured in hours, not weeks. Contact us to assess your current Microsoft 365 backup posture and close the gap before you need it closed.

Anton Kuznetsov
Founder & Principal Engineer

Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.

Ready to bring AI to your business?

Book a free AI Readiness Consultation — no commitment required.

Book Free Consultation