Ask most accounting firm owners who backs up their Microsoft 365 data and you'll hear the same answer: Microsoft does. It's a reasonable assumption. Your email, your client files in SharePoint, your working papers in OneDrive - it all lives in Microsoft's cloud, so surely Microsoft keeps a copy you can get back.
It doesn't. Microsoft's shared responsibility model guarantees that the service stays available and resilient. Recovering your data after a mistake, a departing employee, or a ransomware event is your job - and Microsoft says so in its own documentation and in the agreement you clicked to accept.
That gap matters more for CPA and accounting firms than almost anyone. You're required to keep client records for years, but Microsoft 365's default retention windows are measured in days. And because OneDrive and SharePoint sync files automatically, "it's already in the cloud" is not the safety net most firms think it is.
Here's exactly what Microsoft keeps, for how long, and where the gaps are - cited to Microsoft's own docs - plus a ten-minute self-audit you can run before tax season.
Key Takeaways
- Under Microsoft's shared responsibility model, protecting and recovering your data is the customer's job for every cloud deployment type, including Microsoft 365. (Microsoft, 2026)
- Microsoft 365's defaults are short: deleted email items are kept 14 days (up to 30), a deleted mailbox 30 days, and the SharePoint/OneDrive recycle bin 93 days. (Microsoft, 2026)
- Microsoft's own Services Agreement tells you to "regularly backup Your Content and Data," because it "won't be able to retrieve" your data once an account is closed. (Microsoft Services Agreement, 2026)
- The IRS expects tax records to be kept for 3 to 7 years - a mismatch with M365 safety nets measured in days. (IRS, 2026)
The Microsoft 365 Shared Responsibility Model, in Plain English
When you move to the cloud, some jobs become Microsoft's and some stay yours. Microsoft runs the datacenters, the servers, and the platform so the service is highly available. What you put into that service stays your responsibility.
- Microsoft is explicit: "For all cloud deployment types, you own your data and identities. You're responsible for protecting the security of your data and identities." (Microsoft, 2026)
- In Microsoft's own responsibility matrix, "Customer data" is marked as the customer's responsibility across on-premises, IaaS, PaaS, and software as a service - the category Microsoft 365 falls under. (Microsoft, 2026)
- "Regardless of the type of deployment, you always retain the following responsibilities: Data - You're responsible for your data, including data classification, data protection, encryption decisions, and compliance with data governance requirements." (Microsoft, 2026)
Read that again with your firm in mind. Microsoft promises the lights stay on. It does not promise to hand you back the three years of client working papers a bookkeeper deleted on the way out the door. For a 20-person CPA firm, that distinction is the whole ballgame.
What Microsoft Actually Keeps - and for How Long
Microsoft 365 does have built-in recycle bins and short recovery windows. They're useful for the "I deleted an email an hour ago" problem. They are not a backup, and the clocks are shorter than most firm owners expect.
- Deleted email items: "An Exchange mailbox keeps deleted items for 14 days by default," and an administrator can extend that only "up to a maximum of 30 days." (Microsoft, 2026)
- A deleted mailbox: when a user's account is removed, "the user mailbox is now soft-deleted in Exchange Online and stays in a soft-deleted state for 30 days" before it is permanently purged and unrecoverable. (Microsoft, 2026)
- A deleted user's OneDrive: "The default retention period for OneDrive is also 30 days" after the account is deleted. (Microsoft, 2026)
- Files in the SharePoint/OneDrive recycle bin: "A 93-day retention period spans both the first- and second-stage recycle bins. At the end of 93 days, the document is permanently deleted." (Microsoft, 2026)
Picture a common scenario: a staff accountant leaves in May, and in the summer cleanup their account is deleted to free up a license. The 30-day clock starts the moment that account is removed. Come the following filing season, when you need a client file that only ever lived in that person's OneDrive, it's long gone - no ransomware, no attacker, just a calendar.
"It's in the Cloud" Is Not a Recovery Plan
The most dangerous assumption is that syncing files to OneDrive and SharePoint protects them from ransomware. Sync is not backup. When ransomware encrypts files on a laptop, the OneDrive client faithfully syncs those newly encrypted versions up to the cloud - which is why Microsoft built ransomware detection and a limited rewind into the product in the first place.
- Microsoft 365 watches for this exact event: "When Microsoft 365 detects a ransomware attack, you'll get a notification on your device and receive an email from Microsoft 365." (Microsoft, 2026)
- The rewind is time-boxed. OneDrive's Files Restore lets subscribers "undo all the actions that occurred on any files and folders within the last 30 days" - after that window, the encrypted versions may be all that remain. (Microsoft, 2026)
- Microsoft's own backup product exists specifically for "a ransomware attack that encrypts large swaths of your data, or instances of an internal accidental or malicious data deletion or overwrite event." (Microsoft, 2026)
The trap is timing. If an infection isn't caught within that 30-day rewind - over a holiday break, or in a quiet second office - the clean history ages out and the cloud copy is encrypted too. A real backup keeps independent, point-in-time copies that an attacker on your network can't reach or overwrite.
Litigation Hold Is Not Backup
Firms that have turned on litigation hold or a retention policy often assume they're covered for recovery. Those features exist for legal preservation and compliance, not for getting your business running again - and Microsoft's documentation shows the seams.
- Retention and eDiscovery holds have blind spots. Microsoft notes the recycle bin "isn't indexed and therefore searches don't find content there," so "an eDiscovery hold can't locate any content in the Recycle Bin in order to hold it." (Microsoft, 2026)
- Microsoft treats backup as a separate product. Its Microsoft 365 Backup keeps restore data isolated from compliance rules: "Retention and deletion policies (for example, from Purview) don't affect the backup retention period, which remains fully isolated from those policies." (Microsoft, 2026)
- That backup product was built for "a ransomware attack that encrypts large swaths of your data, or instances of an internal accidental or malicious data deletion or overwrite event" - the recovery jobs holds were never designed to do. (Microsoft, 2026)
Put simply: a litigation hold might satisfy a subpoena, but it won't roll your mailboxes and document libraries back to the morning before an encryption event. Preservation and point-in-time recovery are different tools, and your firm needs both.
The Retention Math Doesn't Add Up for CPA Firms
Now line up your obligations against those defaults. The IRS measures record retention in years; Microsoft 365 measures its safety nets in days.
- Keep most records at least three years: "Keep records for 3 years if situations (4), (5), and (6) below do not apply to you." (IRS, 2026)
- Keep some records seven years: "Keep records for 7 years if you file a claim for a loss from worthless securities or bad debt deduction." (IRS, 2026)
- Keep employment tax records at least four years: "Keep employment tax records for at least 4 years after the date that the tax becomes due or is paid, whichever is later." (IRS, 2026)
A 14-to-93-day recycle bin cannot satisfy a three-to-seven-year obligation. The moment client data leaves those short windows - through deletion, an emptied recycle bin, or a closed account - Microsoft's own agreement is clear that it "won't be able to retrieve Your Content or Data once your account is closed." That's exactly why the agreement recommends you "regularly backup Your Content and Data" yourself. (Microsoft Services Agreement, 2026)
Microsoft's Own Answer: A Paid Backup Add-On
Microsoft has effectively acknowledged the gap by launching Microsoft 365 Backup - but it's an opt-in product that costs extra, not something switched on in your tenant by default.
- It's built for real recovery: Microsoft 365 Backup delivers "full SharePoint site and OneDrive account restore fidelity" and restores content to "specific prior points in time." (Microsoft, 2026)
- It extends retention to a full year: the product's retention period is "1 year" for OneDrive, SharePoint, and Exchange - far beyond the day-scale native defaults. (Microsoft, 2026)
- It's a paid, consumption-based add-on: "$0.15 per GB per month for all data protected by Backup," billed as a "pay-as-you-go offering that charges based on consumption." (Microsoft, 2026)
The takeaway isn't that you must buy Microsoft's version specifically - established third-party backup platforms are a common, often more cost-effective route for a small firm. The takeaway is that even Microsoft agrees Microsoft 365 needs a real backup, and the responsibility for turning one on is yours.
A Ten-Minute Microsoft 365 Backup Self-Audit
You don't need a consultant to find out whether your firm has this gap. Run these checks - most take a minute, and any "no" is a hole worth closing before filing season.
- Ask the direct question: is there a real backup of Microsoft 365 - mailboxes, OneDrive, and SharePoint - stored separately from the 365 tenant itself? "Retention is turned on" is not a yes.
- Confirm all three workloads are covered: Exchange Online email, OneDrive files, and SharePoint/Teams document libraries. Many setups back up email only.
- Check the offboarding process: when someone leaves, is their OneDrive and mailbox data captured before the account is deleted and the 30-day clock runs out?
- Verify the restore point range: can you recover a file or mailbox as it looked months ago - not just within the 14-to-93-day native windows?
- Test a restore, not just a backup: ask to see a single file and a full mailbox actually recovered from last quarter. A backup you've never restored is a hope, not a plan.
- Confirm the backup is isolated: stored outside the tenant so a ransomware event or a rogue admin can't encrypt or delete both copies at once.
If you can't get a confident yes to all six, your firm is relying on recycle bins and calendars to protect years of client data.
Final Thoughts
None of this means Microsoft 365 is unsafe - it's a strong, resilient platform. It means the platform does exactly what Microsoft says it does: it keeps the service running and gives you short recovery windows, while leaving the job of backing up your data to you. For an accounting firm holding years of client returns, payroll records, and working papers, that's a gap worth closing on purpose rather than discovering during an emergency.
Tech Advisors helps CPA and accounting firms close the Microsoft 365 backup gap - covering email, OneDrive, and SharePoint with real, isolated, point-in-time backups that line up with IRS retention obligations instead of Microsoft's day-scale defaults. If you're not sure what happens to your data when a file is deleted or an employee leaves, a short conversation and a quick audit are a good place to start.



