Ask your provider to restore one deleted email and one important file. The result will tell you more about your recovery plan than a green "backup successful" status.
Microsoft 365 has built-in recovery features, and Microsoft and other providers also offer backup services. What you can restore depends on the configuration, licences, selected backup and how long ago the loss occurred.
Retention and backup do different jobs
Retention rules decide how long information is kept or when it can be removed. They may preserve email for compliance or keep documents for an agreed period.
Backup creates recovery copies that can be used after data is lost or damaged. Microsoft and other providers offer backup services, but they must be selected, configured and checked. They are not the same as the standard recycle bins and version history available in Microsoft 365.
Your business should define what needs to be recoverable and for how long before choosing the setup.
What Microsoft protects
Microsoft operates the Microsoft 365 platform and protects the infrastructure that delivers it. Its systems are designed to keep the service available when hardware or parts of the platform fail.
That service protection does not prevent a staff member from deleting the wrong folder, an administrator from removing an account or a compromised user from damaging accessible data.
Built-in recovery can help with many everyday mistakes, but it has conditions and time limits.
Deleted email
A deleted message may remain in Deleted Items or Recoverable Items for a period determined by the service and your settings. Retention policies may preserve some messages for longer.
This can work well for a recent deletion. It may not help if the loss is discovered after the recovery period or if the required policy was never configured.
OneDrive and SharePoint files
OneDrive and SharePoint include recycle bins and version history. These features can restore some deleted files or earlier versions after an unwanted change.
They remain part of the same Microsoft 365 environment and are not a separate recovery copy. Large or complex restores may also take more planning than recovering one document.
Files shared through Teams are often stored in SharePoint, while chat attachments may be stored elsewhere in Microsoft 365. A backup review needs to account for those locations.
Departing staff and deleted accounts
A deleted user can usually be restored only for a limited period. The exact options depend on the service, settings and timing.
Before removing a user, decide what should happen to their mailbox, OneDrive files and access to Teams or SharePoint. A mailbox may need to be preserved or converted for continued business use. Important files may need a new owner.
Do this before removing the licence or account. Recovery after the available window may not be possible.
Ransomware and compromised accounts
Damaged files can sync from an infected computer into OneDrive or SharePoint. Version history may help, but restoring a large number of files can be difficult.
A compromised Microsoft 365 account may also be used to delete messages, create forwarding rules or alter files. Multi-factor authentication, alerts and limited permissions reduce this risk, but they do not restore data after it has been lost.
Recovery planning should cover both security incidents and ordinary staff mistakes.
Decide what the backup must cover
List the Microsoft 365 data the business relies on, including shared mailboxes, OneDrive files, SharePoint sites and any Teams information kept as a business record.
Then decide how far back the business may need to recover, how quickly a restore is needed and who is authorised to perform it.
Check the selected backup service's documentation rather than assuming it covers every Microsoft 365 item.
Test real restores
A successful backup job is only one part of the check. Restore a sample email, OneDrive file and SharePoint folder. Confirm that the recovered item opens and that the right people can access it.
Record how long the process takes and who knows how to do it. Repeat the test after major changes to licences, retention or backup settings.
Review the whole recovery plan
A recovery review should confirm the retention settings, the process for departing staff, what each backup covers and how backup administrator access is protected. It should also record the last restore test and anything the business cannot recover.
Overlapping tools add little value when their recovery coverage is unclear. Default settings may also fall short of the business's needs.
Book a Microsoft 365 backup consultation with JCPIT Support to review retention, backup coverage and the evidence from the most recent restore test. You will see what the current setup can recover and where the plan has gaps.