Backup & Recovery

How to Back Up Microsoft 365: A Complete Guide

OAS Editorial Team17 December 20256 min read

Most businesses assume Microsoft backs up their data. Microsoft does not.

This single misconception has caused more data loss incidents than any technical failure. If your organisation runs Microsoft 365 (M365) — Exchange Online, SharePoint, Teams, or OneDrive — your data is your responsibility. Here is why, and exactly how to protect it.


The Shared Responsibility Model

Microsoft operates under a shared responsibility model. Understanding this model is the first step to protecting your data.

Microsoft is responsible for:

  • Infrastructure uptime (data centres, servers, networking)
  • Platform availability (keeping M365 services running)
  • Physical security of their data centres
  • Operating system and application patching

You are responsible for:

  • Your data (emails, files, conversations, contacts)
  • Account security (access controls, passwords, MFA)
  • Retention policies and compliance
  • Recovery from accidental deletion, malicious deletion, or ransomware

Microsoft will keep M365 running. They will not recover the emails your finance team accidentally deleted three months ago. They will not restore the SharePoint site an ex-employee wiped before leaving. They will not roll back the Teams data encrypted by ransomware.

That is your job. And without a backup solution, you cannot do it.


Why Native M365 Retention Is Not Backup

Microsoft does offer retention features — deleted item recovery, litigation hold, and retention policies. These are not backups. Here is why:

Deleted item recovery has a time limit. Soft-deleted items are recoverable for 14-30 days (depending on configuration). After that, they are gone permanently.

Retention policies preserve data for compliance, but they are not designed for rapid, granular restore. Finding and restoring specific items is slow and cumbersome.

Litigation hold prevents deletion but does not protect against ransomware encryption or corruption.

No point-in-time recovery. If ransomware encrypts your Exchange mailbox, Microsoft cannot roll it back to yesterday's clean state. You need a backup that can.


What Cove Backs Up in Microsoft 365

Cove Data Protection provides purpose-built M365 backup that covers every critical service:

Exchange Online

  • Backed up 6 times per day
  • Granular restore: individual emails, contacts, calendars, or entire mailboxes
  • Point-in-time recovery to any backup snapshot
  • Covers shared mailboxes and archive mailboxes

SharePoint Online

  • Backed up 4 times per day
  • Site-level and item-level restore
  • Document libraries, lists, and site structure preserved
  • Version history maintained

Microsoft Teams

  • Backed up 4 times per day
  • Channel conversations and files protected
  • Team structure and membership preserved on restore
  • Covers both standard and private channels

OneDrive for Business

  • Included in backup schedule
  • Individual file and folder restore
  • Full account recovery available
  • Protects against accidental deletion and ransomware encryption

Setting Up M365 Backup: A High-Level Guide

Implementing Cove for Microsoft 365 follows a straightforward process:

Step 1: Authorise Cove to access your M365 tenant. This uses standard Microsoft OAuth — Cove connects via API with the permissions you grant. No agents to install.

Step 2: Select users and services to protect. Choose which mailboxes, SharePoint sites, Teams, and OneDrive accounts to back up. New users can be added automatically.

Step 3: Configure backup frequency and retention. Exchange defaults to 6 backups per day. SharePoint and Teams default to 4 per day. Set retention periods based on your compliance and business requirements.

Step 4: Verify initial backup completion. The first backup captures a full snapshot of your selected data. Subsequent backups are incremental, transmitting only changes.

Step 5: Test a restore. Perform a test restore of an individual email or file to confirm your backup is operational. Do not skip this step.


Retention and Compliance

For South African organisations, the Protection of Personal Information Act (POPIA) requires that personal data be retained only as long as necessary — but also that it be recoverable when legitimately needed.

Cove supports flexible retention policies that let you balance compliance with practical recovery needs. Set different retention periods for different data types. Archive mailboxes can retain longer than standard mailboxes. SharePoint data can follow different rules than Exchange.

All backed-up data is encrypted with AES-256 and stored in Cove's data centres, including facilities in South Africa, ensuring data sovereignty compliance.


Do Not Wait for a Data Loss Event

Most organisations implement M365 backup after losing data they could not recover. That is the expensive way to learn this lesson.

Microsoft protects the infrastructure. You protect the data. OAS + Cove makes that simple — automated, encrypted, and backed up multiple times per day.

Back Up Your M365 →

Keep going

Related solution

Explore

Ready to strengthen your defences?

Book a no-obligation security assessment. We'll map your gaps across Protect, Detect and Recover — and show you exactly where you stand.