MacarenoNet
OneDrive does not **back up** your data. Microsoft said so. In the fine print.
GovernanceOneDriveExplanatory

OneDrive does not back up your data. Microsoft said so. In the fine print.

The folder was there yesterday. The file too. Today it's gone. And OneDrive Backup was active the whole time.

Macareno5 min read

Someone deleted an entire folder. It could have been a distracted user, an admin who ran the wrong script, or an attacker with stolen credentials. The organization had OneDrive for everyone. Sync was working perfectly. The recycle bin was active.

Three weeks later, someone noticed the files were gone. They went looking for the backup. And that is when they found what Microsoft had written in the terms of service since day one.

What Microsoft actually protects

Microsoft guarantees the service works. Geographic redundancy, high availability, resilient infrastructure: if a datacenter goes down, Microsoft 365 keeps running in another one. That is what the SLA covers, and what Microsoft considers its responsibility.

The data inside the service, the files, the emails, the messages, the documents: those are the responsibility of the organization that created them. The shared responsibility model defines this precisely: Microsoft does not cover accidental or intentional deletion by users or administrators, ransomware that encrypts files synced to OneDrive, or any data loss resulting from actions taken inside the tenant.

That is not an interpretation. It is in the terms of service. And most organizations never read them.

The four safety nets that look like backup and are not

The recycle bin. Deleted files stay in the recycle bin for up to 93 days. Then they are gone. And if an admin empties the bin, they are gone sooner. It is a net for recent mistakes caught quickly, not a recovery policy.

Version history. SharePoint and OneDrive keep previous versions of files. That handles unwanted edits. It does not handle ransomware: if a user's device is encrypted and syncs the modified files, OneDrive simply preserves the encrypted versions. All of them. Version history lives inside the same library that was attacked. If the library goes, the versions go with it.

Purview retention policies. Retention is a compliance tool, not a recovery tool. It keeps data according to policy for legal and regulatory needs, but it does not offer granular recovery from deletions, corruption, or errors. Proving to a regulator that an email existed is not the same as restoring 400 mailboxes to where they were Tuesday morning.

Geo-redundancy. Geo-redundancy keeps services running during outages. It is an operational safeguard designed to keep the service online, not to restore organizational data after an attack, accidental deletion, or insider threat. When a file is deleted, redundancy replicates the deletion across all datacenters.

The scenarios where everything fails at once

Deleted user account. After a user account is deleted from the tenant, there is a 30-day window during which another user can access and download the files. After that, the OneDrive moves to the site collection recycle bin. If nobody saved what they needed in that window, it is gone. This happens frequently when someone leaves the company and access is revoked before anyone thinks about their files.

Ransomware with active sync. The OneDrive client does exactly what it was designed to do: sync. When ransomware encrypts local files, the attack that really hurts is not deletion, it is encryption and overwrite at scale, synced to the cloud by the OneDrive client doing exactly its job.

Bulk deletion by an admin. A malicious insider who double-deletes content from recycle bins eliminates all remaining native recovery options. If administrator credentials were compromised, whoever attacked now controls both the data and the native recovery tools at the same time.

The data nobody noticed was gone. Most organizations do not notice missing files or messages immediately. Data requests usually surface months later, during audits or legal proceedings. By that point, the retention windows have already expired.

Microsoft 365 Backup exists. And it also has limits.

Microsoft launched a product called Microsoft 365 Backup in 2024, still in preview in 2026. It covers SharePoint Online and OneDrive for Business with point-in-time restore. It is a real improvement over what existed before.

As of 2026, that product covers only a subset of workloads and has significant limitations on retention period and recovery granularity compared to third-party solutions. Teams Chat messages, for example, are not covered. Files shared in Teams live in SharePoint and OneDrive, so they appear in coverage. Channel conversations and messages do not.

Another relevant detail: in-place restores are rollbacks. A full site or OneDrive restore to the same URL overwrites all content and metadata written after the restore point. The work done Friday afternoon, after Tuesday's snapshot, is gone unless you restore to a different URL and merge manually.

It is a layer of protection. It is not the same as an independent backup.

The point

Under the shared responsibility model, Microsoft keeps the service running and holds deleted items for a short window, but it does not take a restorable backup of your data. Protecting and recovering emails and files is the organization's responsibility.

Turning on OneDrive sync is not a backup policy. Enabling version history is not a backup policy. Having retention configured in Purview is not a backup policy.

The question worth answering before the next incident: if an admin accidentally deletes a three-year-old document library today, how long does recovery take, and from where?

If the answer is not immediate, there is a gap.

If you want to keep reading about Microsoft 365, data governance, and everything changing in the Microsoft ecosystem, subscribe to the macareno.net newsletter.

Sources

Share article

Next business step

Connect this article with a relevant service and a real MacarenoNet case to move from insight to execution.

Recommended service

Security, Compliance and Governance

Information protection and compliance by design for enterprise teams.

View service

Recommended case

Cybersecurity Portal

Incident reporting portal with SLAs and cybersecurity guidance.

View case