SecureMyEmail logoSecureMyEmail

Microsoft 365 security guide

Back up and retain Microsoft 365 data

A practical guide for Australian businesses. Combine Microsoft Purview retention policies with a dedicated backup service for recoverable, compliant data protection.

Microsoft 365 backup and retention data protection

Recommended method: combine Microsoft Purview retention policies with a dedicated Microsoft 365 backup service

Deleted or corrupted email and files may still be required later for business continuity, legal, compliance or security investigations. Microsoft 365 retention policies help preserve information, but they should be combined with a dedicated backup service that supports point-in-time recovery.

Recommended configuration

For most small businesses:

  • Retain Exchange Online email, SharePoint, OneDrive and Microsoft 365 Group content for at least seven years, subject to legal and business requirements.
  • Use a dedicated Microsoft 365 backup service covering all active users, shared mailboxes, OneDrive accounts, Teams and SharePoint sites.
  • Continue backing up former employees until their retention obligations have expired.
  • Protect the backup administration account with MFA and least-privilege access.
  • Perform and document test restores at least quarterly.

A retention policy is not a complete replacement for backup. Retention is primarily designed to preserve content for compliance and discovery. Backup is designed for efficient recovery following accidental deletion, malicious deletion, corruption or ransomware.

1

Confirm what must be protected

Before changing anything, prepare a list of:

  • Licensed user mailboxes
  • Shared mailboxes
  • Microsoft 365 Groups
  • SharePoint sites
  • OneDrive accounts
  • Teams and Teams-connected sites
  • Former employees whose data must be retained
  • Prepare a list of the items above.
  • Confirm your required retention period with management, your legal adviser or compliance adviser.
  • Identify any data that must be kept indefinitely or placed under a legal hold.
  • Confirm available storage, licensing and backup costs.
  • Record the approved retention period and the person who authorised it.

A seven-year period is commonly selected by Australian businesses, but it is not automatically correct for every organisation or every type of information.

2

Create a Microsoft Purview retention policy

You normally need a Microsoft 365 Global Administrator, Compliance Administrator or Retention Management role. Licensing requirements vary according to the locations, policy type and advanced features selected.

  • Sign in to the Microsoft Purview portal.
  • Select Solutions.
  • Select Data Lifecycle Management.
  • Open Policies and then Retention policies.
  • Select New retention policy.
  • Enter a descriptive name, such as Organisation-wide retention – 7 years.
  • Add a description explaining what the policy protects, the approved retention period, whether information will eventually be deleted, and who authorised the policy.
  • On the Assign admin units page, select Full directory unless your organisation deliberately uses administrative units.
  • Select the policy scope. Static is normally the simplest option for a small business; Adaptive automatically includes users or sites based on defined attributes, but it may require additional licensing and configuration.
  • Select the locations to protect. Where available, enable Exchange mailboxes, SharePoint sites, OneDrive accounts, and Microsoft 365 Group mailboxes and sites. Leave the locations set to include all users and sites unless there is a documented reason to exclude something.
  • Choose Retain items for a specific period.
  • Enter the approved retention period—for example, seven years.
  • Select when the retention period begins. For a general policy, this will commonly be when the item was created. Confirm this against your compliance requirements.
  • Choose what happens after the retention period. Do nothing preserves the item until somebody deletes it after the retention requirement expires; Delete items automatically permanently removes items after the retention period.
  • Review the locations, retention period and deletion behaviour carefully.
  • Select Submit or Create policy.

Microsoft advises that a retention policy can take up to seven days to apply fully. Check the policy’s distribution status after implementation.

3

Configure separate Teams retention if required

Teams messages may require a separate retention policy.

  • Return to Solutions → Data Lifecycle Management → Policies → Retention policies.
  • Select New retention policy.
  • Give it a descriptive name, such as Teams messages – 7-year retention.
  • Select Static unless adaptive scopes have already been designed.
  • Select the applicable Teams locations: Teams channel messages, Teams chats, and Teams private channel messages if presented separately in your tenant.
  • Include all relevant users and teams.
  • Configure the approved retention period.
  • Review the deletion behaviour carefully.
  • Create the policy and monitor its deployment status.

Teams files are not necessarily stored with Teams messages: files shared in channels are generally stored in SharePoint, and files shared in chats are generally stored in the sender’s OneDrive. Consequently, Exchange, SharePoint, OneDrive, Microsoft 365 Groups and Teams messages may all require coverage.

4

Implement an independent Microsoft 365 backup

Use Microsoft 365 Backup or a reputable third-party Microsoft 365 backup service. The service should protect Exchange Online, SharePoint and OneDrive and, where required, Teams data.

Select a backup product that provides:

  • Automated backups
  • Point-in-time recovery
  • Item-level email and file restoration
  • Full mailbox, OneDrive and SharePoint restoration
  • Protection for shared mailboxes
  • Coverage for former employees
  • Backup failure alerts
  • Audit logs
  • Role-based access
  • MFA for administrators
  • Suitable data location and retention
  • Protection against backup deletion or tampering
  • Select a backup product that provides the features listed above.
  • Create a dedicated backup administrator account.
  • Apply MFA or a phishing-resistant authentication method to that account.
  • Grant only the permissions required by the backup product.
  • Connect the backup service to Microsoft 365 using its authorised Microsoft Entra application.
  • Select all required users, shared mailboxes, OneDrive accounts, SharePoint sites, Microsoft 365 Groups and Teams.
  • Enable automatic protection for newly created users and sites if the product supports it.
  • Configure the required backup retention period.
  • Enable alerts for failed backups, missed backups, authentication failures, permission changes, backup policy changes, and unprotected users or sites.
  • Run the initial backup.
  • Confirm that every expected mailbox, OneDrive account and SharePoint site reports as protected.

Microsoft explains that Microsoft 365 Backup is designed for point-in-time recovery and recovery at scale, whereas version history, disaster-recovery copies and legal holds do not provide the same recovery capability.

5

Protect departing employees’ data

Before deleting a Microsoft 365 user:

  • Before deleting a Microsoft 365 user, confirm that the mailbox and OneDrive have completed a successful backup.
  • Record the user’s required retention period.
  • Convert the mailbox to a shared mailbox where appropriate and permitted.
  • Transfer ownership of important OneDrive files.
  • Confirm whether the user must remain within the retention policy.
  • Confirm how the backup provider handles licence removal, account deletion, shared mailbox conversion, and archived or former-user data.
  • Perform a test search or restore of the former employee’s data.
  • Only then remove licences or delete the account according to the approved offboarding procedure.

Do not assume data will remain recoverable indefinitely after deleting the Microsoft Entra user.

6

Test recovery

A backup should not be considered reliable until restoration has been tested.

  • Select a test mailbox and restore one deleted email, one email folder and one calendar item.
  • Select a test OneDrive and restore one file, an earlier version of a file, and one deleted folder.
  • Select a test SharePoint site and restore one document, one folder or library, and an earlier point in time if supported.
  • Confirm restored information opens correctly and retains the expected permissions and metadata.
  • Document the test details listed below.

Test restores should cover items such as:

  • One deleted email
  • One email folder
  • One calendar item
  • One file
  • An earlier version of a file
  • One deleted folder
  • One document
  • One folder or library
  • An earlier point in time, if supported

Document:

  • Test date
  • Items restored
  • Time required
  • Result
  • Problems found
  • Corrective action taken
  • Repeat these tests at least quarterly and after major Microsoft 365, licensing or backup-platform changes.

Warnings

  • Retention is not the same as backup. Retained data may be searchable for compliance purposes without providing a convenient full-service recovery process.
  • Policy mistakes can cause permanent deletion. Carefully review any option that deletes content automatically after the retention period.
  • Retention changes are not immediate. Microsoft advises that new policies can take up to seven days to apply.
  • Retention is not normally retrospective recovery. Creating a policy today will not recover content that was permanently deleted before the policy took effect.
  • Teams requires multiple locations. Protecting Teams messages alone does not necessarily protect files stored in SharePoint or OneDrive.
  • Licensing matters. Some retention, adaptive scope, records management, eDiscovery and backup capabilities require particular Microsoft 365 or Purview licences.
  • Offboarding can affect recovery. Deleting a user, mailbox, OneDrive account or backup licence without following a controlled process can make later recovery difficult or impossible.
  • More retention is not always better. Excessively retaining personal, confidential or obsolete data can increase privacy, legal, storage and discovery risks.
  • Do not rely only on recycle bins or version history. These have time, version and scale limitations and may not provide sufficient ransomware recovery.
  • Secure the backup itself. A compromised backup administrator account could allow an attacker to alter policies or delete recovery data.
  • Test restores regularly. A successful backup status does not prove that the required data can be restored in the required timeframe.

Microsoft 365 backup and retention disclaimer

These instructions provide general Microsoft 365 security and data-protection guidance only. They are not legal, regulatory or compliance advice. Microsoft licensing, portal layouts and product functionality can change, and the correct retention period depends on your organisation’s industry, contracts and legal obligations.

Incorrectly configured retention or deletion policies can cause unexpected storage growth, prevent legitimate deletion or permanently remove business information. If you are not experienced with Microsoft Purview, Exchange Online, SharePoint, OneDrive and Microsoft 365 backup systems, engage a qualified Microsoft 365 engineer and obtain appropriate legal or compliance advice before applying these settings to a production tenant.