Many businesses assume that because they're using Microsoft 365, their data is automatically backed up.
Unfortunately, that's not the case.
The Shared Responsibility Model
Microsoft operates on a shared responsibility model. They're responsible for keeping the platform running — but the responsibility for protecting your data sits with you.
Microsoft 365 does include some built-in retention and recovery features. But retention policies are not the same as a backup.
What You Could Actually Lose
If an employee accidentally deletes an entire mailbox, a ransomware attack corrupts your SharePoint data, or a disgruntled staff member permanently removes critical files — Microsoft's native tools may not be able to recover what you've lost.
Here's what businesses are actually at risk of losing:
- Emails, contacts and calendar data from Exchange Online
- Files and folders from SharePoint and OneDrive
- Microsoft Teams messages and channel data
- OneNote notebooks and shared documents
- Entire mailboxes or sites wiped after an account compromise
In many cases, this data is gone permanently once it falls outside Microsoft's limited retention window.
Retention Policies vs Backup — What's the Difference?
This is where most IT managers get caught out.
Microsoft's retention policies are designed for compliance and legal hold — not disaster recovery. They keep data available for a set period, but they are not designed to restore a mailbox to a specific point in time, recover from ransomware encryption, or protect against insider threats.
A proper backup does all of these things.
The Solution — Dedicated Microsoft 365 Backup
A dedicated third-party Microsoft 365 backup solution creates independent, point-in-time copies of your data — completely separate from Microsoft's infrastructure.
This means that regardless of what happens — accidental deletion, ransomware, or a disgruntled employee — your data can be restored quickly and completely.
Key capabilities of a proper M365 backup solution:
- Point-in-time recovery — restore data to any previous state
- Granular restore — recover a single email, folder, or file without restoring an entire mailbox
- Ransomware protection — recover clean data from before the attack
- POPIA compliance — maintain control over where your data is stored and for how long
- Immutable, independent storage — backups stored separately from Microsoft's infrastructure where ransomware cannot reach them
What Does POPIA Say About Data Protection?
Under South Africa's Protection of Personal Information Act (POPIA), your organisation is responsible for ensuring that personal information is protected against loss, damage, or unauthorised access. Relying solely on Microsoft's native retention features may not be sufficient to demonstrate adequate data protection controls under POPIA.
A dedicated backup solution strengthens your POPIA compliance posture significantly.
How ROI Technologies Can Help
At ROI Technologies, we implement and manage Microsoft 365 backup solutions for South African businesses — ensuring your Exchange Online, SharePoint, OneDrive and Teams data is protected, recoverable, and aligned with POPIA requirements.
Our managed M365 backup service includes:
- Automated daily backups of all M365 data
- Unlimited retention options
- Fast, granular restore capability
- Regular backup health reporting
- South African data residency options
Because when it comes to your business data, assumption is not a strategy.
Microsoft 365 Backup and Cove Backup
At ROI Technologies, our preferred Microsoft 365 backup solution is Cove Backup. Cove is a cloud-first backup platform purpose-built for Microsoft 365 environments, with several characteristics that matter for South African businesses:
- Immutable backups — once written, backup data cannot be altered or deleted by ransomware, a rogue admin, or a compromised M365 account
- Cloud-first architecture — no on-premises backup server to maintain, patch, or worry about
- South African data residency options — keep backup data in a region that aligns with your POPIA and internal governance requirements
- Fast, granular restore — recover a single email, file, or Teams message, or roll an entire mailbox or SharePoint site back to a specific point in time
- Managed by ROI Technologies — we monitor backup health, verify restores, and report on protection status so you don't have to
Cove Backup gives you an independent, tamper-resistant copy of your Microsoft 365 data — exactly the kind of evidence your cyber insurer, auditor, and POPIA compliance posture require.
Frequently Asked Questions About Microsoft 365 Backup
Does Microsoft back up my Microsoft 365 data? No. Microsoft operates on a shared responsibility model — they keep the platform running, but protecting your data is your responsibility. Microsoft's native retention features are designed for compliance and legal hold, not disaster recovery. A dedicated third-party backup solution is required for true data protection.
What data does a Microsoft 365 backup protect? A proper M365 backup protects Exchange Online (email, contacts, calendars), SharePoint Online, OneDrive for Business, Microsoft Teams messages and channel data, and OneNote notebooks — essentially everything in your Microsoft 365 environment.
How is a backup different from Microsoft's retention policies? Retention policies keep data available for a set period for compliance purposes. They cannot restore a mailbox to a specific point in time, protect against ransomware that encrypts your M365 data, or recover from insider threat deletions. A backup creates independent, point-in-time copies that can be restored regardless of what caused the data loss.
What is Cove Backup? Cove Backup (formerly SolarWinds Backup) is the Microsoft 365 backup solution used by ROI Technologies. It is a cloud-first platform with immutable backup storage, meaning ransomware cannot alter or delete your backups. It supports granular restore — recovering a single email or file — as well as full mailbox and site restoration to any previous point in time.
Does Microsoft 365 backup help with POPIA compliance? Yes. Under POPIA, your organisation must take reasonable technical measures to protect personal information. A dedicated M365 backup solution demonstrates those controls — independent, encrypted copies of personal data, tested recovery capability, and documented retention — all of which strengthen your POPIA compliance posture.
Contact ROI Technologies to discuss Microsoft 365 backup for your business.
Need IT or Cybersecurity help in South Africa?
Talk to ROI Technologies — Johannesburg-based, certified, vendor-agnostic.
Contact Us