billed monthly, in advance
| Workloads | Exchange · SharePoint · OneDrive · Teams |
|---|---|
| Retention, Exchange | 7 years |
| Retention, SharePoint / OneDrive / Teams | 1 year |
| Shared mailboxes | Included at no charge |
| Storage | 1 TB per user, pooled across the tenant |
| Encryption | AES-256 at rest; TLS in transit |
| Custody | Storage outside your Microsoft 365 tenant and its credentials |
| Restore unit | One message · one document · a library · a full mailbox |
| Restore target | Into the live tenant, or out as an export |
| Billing unit | Per licensed user, per month |
Microsoft runs the service. You own the data.
That sentence is the shared responsibility model, and it is in your agreement whether or not anyone has read it. Microsoft guarantees that the platform remains available. Protecting the contents against deletion, corruption, malice, and mistakes is your side of the line.
The native safety nets are real but shallow: deleted items expire on a clock you do not set, a departed employee's mailbox leaves with their license, retention policies have gaps exactly where somebody configured them in a hurry, and a compromised Global Administrator can purge SharePoint sites wholesale. Recycle bins were designed for accidents, not adversaries.
How it runs
A connector authorized against your tenant continuously copies Exchange, SharePoint, OneDrive, and Teams into an independent vault. Exchange mail is retained for seven years; SharePoint, OneDrive, and Teams for one. Shared mailboxes are covered at no additional charge, which matters because they are usually where the invoices, orders, and support history actually live, and usually the thing nobody licensed. Each user brings 1 TB of pooled storage.
Outside the tenant is the entire product
Backups are encrypted with AES-256 and stored outside your Microsoft 365 tenant: a different platform, different credentials, and a different administrative boundary. Read that as an attack scenario and it explains the rate. An intruder holding Global Administrator can destroy anything inside your tenant, including the retention policies you were relying on and the audit trail that would have revealed it.
They cannot reach a copy that does not live there. Independence from the tenant is what reduces a total account takeover to an afternoon of restores, and it is why a copy kept inside the thing it protects was never really a backup.
Getting it back
- Granular, to a chosen moment: a single message, one document, a full library, or a mailbox exactly as it stood the hour before the incident.
- Two directions: return the data to the live tenant, or take it out as an export for legal hold or handover.
- Departures: recover a former employee's mailbox years later without maintaining a license for them, which frequently pays for a substantial portion of the subscription on its own.
Where this line stops
Billing is per licensed user, and coverage follows the mailbox and its files. The directory itself is a separate concern. Users, groups, roles, applications, and conditional-access policies belong to Entra ID, which is the control plane sitting underneath all of this.