DEV Community

AdminPackStudio
AdminPackStudio

Posted on

Retention is not backup - what Microsoft 365 can restore natively, and a quarterly restore drill you can run in an afternoon

Retention is not backup: what Microsoft 365 can actually restore, and a quarterly drill

Ask five admins whether their Microsoft 365 tenant is "backed up" and you'll get answers like:

  • "We have retention policies, so yes."
  • "Microsoft handles that."
  • "There's a recycle bin."
  • "We bought a backup product." (When was the last restore test? "...")

All of these are partly right, and that's the problem. Retention, soft-delete, and backup solve different problems. You usually find out which one you actually have in the middle of an incident.

This post covers the distinction, what native recovery covers for each workload, a few read-only commands to see what protection you have today, and a quarterly restore drill. Retention periods, licensing, and admin-center locations change, so treat every number here as "check current Microsoft docs". None of this is legal advice.


1. Three different things

Retention / holds Soft-delete, recycle bin, versions Backup
Purpose Keep content for compliance and legal reasons Undo recent mistakes Restore from a separate copy when the primary data is gone or damaged
Who it's for Compliance, legal, eDiscovery Users and helpdesk IT, during an incident
Typical window Whatever the policy says (years, if needed) Days to weeks Whatever you configure and pay for
Getting data back Search and export, often process-heavy A few clicks, usually in place Restore to the original or an alternate location
Protects against Deletion before the policy allows it Accidental deletes and overwrites Mass deletion, ransomware, malicious admins, and data past native windows

The two sentences worth putting in front of leadership:

Retention keeps us compliant. Backup lets us restore when retention and the recycle bin can't.

Retention isn't designed for fast restores. Content kept by a retention policy is preserved (for example in a mailbox's Recoverable Items folder or a site's Preservation Hold library), but getting a whole folder or library back into place usually means an eDiscovery search and export. It isn't a "restore" button.


2. What native recovery covers, per workload

These are the documented defaults at the time of writing. Check current docs for your tenant and licenses.

Exchange Online mail

  • Deleted Items, then Recoverable Items. When a user empties Deleted Items or hard-deletes (Shift+Delete), items go to the Recoverable Items folder. Users can get them back with "Recover deleted items" in Outlook or Outlook on the web.
  • Deleted item retention is 14 days by default and can be raised to a maximum of 30 days per mailbox.
  • Folder structure is a trap. If a user hard-deletes a folder they created, Microsoft's docs say the items go to Recoverable Items but the folder itself can't be recovered. You get the mail back, but not the folder tree.
  • Holds. With Litigation Hold or a retention policy in place, purged items are kept for the hold period. Getting them back is typically an eDiscovery job.
  • Admin recovery cmdlets exist (Get-RecoverableItems / Restore-RecoverableItems), but they need the Mailbox Import Export role, which isn't assigned to any role group by default. Finding that out during an incident is exactly what a drill is for. Assign it narrowly and on purpose, not "just in case".
  • Deleted users: when a licensed user is deleted, the mailbox is soft-deleted and recoverable for a limited window (30 days by default) unless a hold keeps it.

OneDrive and SharePoint

  • Recycle bin: deleted items sit in the site recycle bin and then the second-stage (site collection) recycle bin, 93 days in total, counted from the original delete.
  • Version history covers overwrites and bad edits, as long as versioning is on and the version limit hasn't pushed the good version out.
  • Point-in-time restore of a OneDrive or a document library to any time in the last 30 days is built in ("Restore your OneDrive" / "Restore this library"). This is the native tool closest to "undo the ransomware", but it only works inside that window, and only if nothing keeps re-syncing encrypted files back.
  • Deleted sites are kept for 93 days and can be restored by a SharePoint admin. If the site belongs to a Microsoft 365 group, the group's other resources have a shorter window (30 days), so act quickly.
  • Departed users' OneDrive is kept for a tenant-configured period after the account is deleted (30 days by default). Check yours below.
  • Microsoft's own short-term backups. Microsoft documents that SharePoint keeps around 14 days of internal backups for service resilience. That's Microsoft's safety net for the service, not a restore tool you control, so don't build your plan around it.

Teams

  • Files shared in channels live in the team's SharePoint site. Files shared in chats live in the sender's OneDrive. Restore paths for Teams files are the SharePoint/OneDrive paths above. There's no separate "Teams file backup".
  • Deleted channels and deleted teams (through the Microsoft 365 group) have a restore window, 30 days at the time of writing.
  • Chat and channel messages kept by a retention policy are preserved for eDiscovery. They aren't restored back into the conversation.

Where native-only falls short

  • Anything past the window (day 31 for a library restore, day 94 for the recycle bin).
  • A privileged account going rogue or getting compromised. An admin who can delete content can often also change retention, unless retention is locked. Purview has a Preservation Lock option that even admins can't undo. Read the docs carefully before you turn it on, because that's the point of it.
  • Large-scale restores under time pressure. Restoring one library is easy. Restoring 200 OneDrives by hand isn't.
  • An independent copy. Native features keep the data inside the same service and the same admin boundary.

That's the gap backup products fill. Microsoft now sells Microsoft 365 Backup as a paid service, and there are many third-party options. Check current docs and contracts for workload coverage, restore granularity, retention length, and pricing. Whatever you pick, a restore you haven't tested is a hope, not a plan.


3. Read-only: see what protection you have today

These commands only read. Run them with a read role (for example Global Reader or View-Only Organization Management) where your tenant allows it.

Exchange: deleted item retention and holds

Connect-ExchangeOnline -ShowBanner:$false

$mb = Get-Mailbox -ResultSize Unlimited |
  Select-Object PrimarySmtpAddress, RecipientTypeDetails, RetainDeletedItemsFor,
                SingleItemRecoveryEnabled, LitigationHoldEnabled,
                @{n='InPlaceHolds';e={$_.InPlaceHolds -join ';'}}

$mb | Group-Object RetainDeletedItemsFor | Select-Object Name, Count
$mb | Group-Object LitigationHoldEnabled | Select-Object Name, Count
Enter fullscreen mode Exit fullscreen mode

If every mailbox shows 14 days and nobody chose that, you've learned something. 14 days is a short window if a user doesn't notice a deleted folder until after a two-week vacation.

Purview: retention policies that exist

Connect-IPPSSession
Get-RetentionCompliancePolicy | Select-Object Name, Enabled, Mode, DistributionStatus
Get-RetentionComplianceRule   | Select-Object Name, Policy, RetentionDuration, RetentionComplianceAction
Enter fullscreen mode Exit fullscreen mode

SharePoint/OneDrive: departed-user OneDrive retention and deleted sites

Connect-SPOService -Url https://contoso-admin.sharepoint.com
Get-SPOTenant | Select-Object OrphanedPersonalSitesRetentionPeriod
Get-SPODeletedSite | Select-Object Url, DeletionTime, DaysRemaining
Enter fullscreen mode Exit fullscreen mode

(The SharePoint Online Management Shell has its own PowerShell version requirements. Check current docs if the module won't load.)

Put the results in a one-page worksheet:

Workload / Native recovery window / Retention or hold in place? /
Backup product? (Y/N, which) / Owner / Last restore test date / Known gaps
Enter fullscreen mode Exit fullscreen mode

4. The quarterly restore drill

A drill turns "we think we can restore" into "we restored X in Y minutes using role Z". Keep it small, use test data only, and rotate workloads:

Quarter Drill
Q1 Mail: recover a hard-deleted folder of test messages
Q2 OneDrive: recover a deleted file and roll back an overwritten one with version history
Q3 SharePoint: restore a test library to an earlier point in time, or restore a test site from Deleted sites
Q4 Tabletop: "a user's OneDrive is encrypted at 4pm Friday", plus one live sample restore from your backup product (if you have one) to an alternate location

Example: the Q1 mail drill (about an hour)

  1. Use a test mailbox in your production tenant (or a lab tenant). Never practise on a real user's mail.
  2. Create a folder called Drill-Q1 and put 20 test messages in it. Note the time.
  3. Hard-delete the folder (Shift+Delete).
  4. As the "user", recover the items with "Recover deleted items" in Outlook on the web. Time it. Note that the folder is gone and the items come back without it.
  5. As the "admin", walk through how you would recover the same items if the user had also purged them: which role, which tool, which approvals. If the answer is "we'd need a role nobody has", write that down. That's a finding.
  6. If you have a backup product, restore the same test items to an alternate folder and time that too.
  7. Clean up the test data afterwards.

Drill record

Date / Quarter / Workload / Scenario /
Time to restore (observed) / Target / Data loss observed (RPO) /
Roles and tools used / Approvals needed / Issues found /
Follow-up ticket IDs / Pass? Y/N / Performed by (role) / Verified by (role)
Enter fullscreen mode Exit fullscreen mode

Starter pass criteria: the test data came back, no production data was touched, the steps are written down well enough for someone else to repeat, the time was within target, and the evidence is attached to the ticket.

The issues are the real output. Common first-drill findings: the recovery role isn't assigned to anyone, versioning limits are lower than people assumed, the backup product's restore needs a login only one person has, or nobody knows who approves restoring someone else's data.


5. Questions to settle with leadership

Restore decisions are business decisions. Get answers to these before an incident does it for you:

  1. Which workloads must we be able to restore? Mail, OneDrive, SharePoint, Teams files?
  2. How much data can we afford to lose (RPO), and how fast must it come back (RTO)?
  3. Do we accept native-only risk, in writing, for some workloads?
  4. Who can approve restoring another person's mailbox or files?
  5. Who protects us from a compromised or malicious admin account?

6. Common mistakes

Mistake What happens Fix
Treating retention policies as backup Data is "kept" but can't be put back quickly Use retention for compliance; plan restores separately
Assuming the recycle bin covers ransomware Synced encryption can outlast or overwhelm it Know the 30-day library/OneDrive restore and its limits; consider backup
Leaving deleted item retention at the default without deciding 14-day window surprises people Decide per policy (up to 30 days) and document it
Never testing the backup product First restore attempt happens during an incident Quarterly drill to an alternate location
Recovery roles nobody holds Restore stalls waiting for permissions Identify roles in the drill; assign narrowly with approval
Drilling on real user data Privacy and data-handling problems Test mailboxes, test sites, test files only
Deleting users before handoff Mailbox and OneDrive windows start running Disable first; delete after handoff and retention checks

Want the full restore runbook?

The M365 Backup Awareness & Restore Runbook ($19) from Admin Pack Studio turns this into five Markdown modules: a retention vs backup decision worksheet with leadership questions, mail restore paths in order plus a practice drill, OneDrive/SharePoint/Teams files restore paths (including a ransomware card), a quarterly restore drill calendar with a record template and pass criteria, and a backup vendor/approach scoring matrix with a workshop agenda. It's docs only. It isn't backup software, it has no scripts, and it doesn't restore or delete anything for you.

Get the runbook: https://cashflow4375.gumroad.com/l/m365-backup-awareness-restore-runbook?utm_source=devto&utm_medium=article&utm_campaign=m365_restore


Admin Pack Studio. Not affiliated with Microsoft or any backup vendor. Microsoft 365, Exchange Online, OneDrive, SharePoint, Teams, and Microsoft Purview are Microsoft products. Operational guidance for admins authorized to manage their tenant. Not legal advice. Retention periods, licensing, and admin-center steps change, so check current Microsoft documentation. Examples use placeholder names.

Top comments (0)