In this video
- What the Microsoft shared responsibility model actually covers, and where it stops
- Why retention policies are built for compliance and legal hold rather than disaster recovery
- The three ways businesses most often lose Microsoft 365 data: accidental deletion, ransomware, and a departing staff member
- What point-in-time recovery and granular restore mean in practice
- Where POPIA obligations sit in the picture
Retention is not backup
Microsoft's native retention features keep data available for a defined period so that it can be produced for compliance or legal hold. They cannot restore a mailbox to a specific point in time, they cannot recover data that ransomware has encrypted inside the tenant, and they do not protect against a deliberate deletion by someone with legitimate access.
Once data falls outside that limited retention window it is gone permanently. That includes Exchange Online mail, contacts and calendars, SharePoint and OneDrive files, Teams messages and channel data, and OneNote notebooks.
What proper backup adds
A dedicated backup gives you point-in-time recovery, granular restore of a single email or file without touching the rest of the mailbox, recovery of clean data from before a ransomware event, and independent immutable storage held separately from Microsoft's infrastructure. ROI Technologies uses Cove Backup, a cloud-first platform with immutable storage and South African data residency options, managed and health-monitored as part of the service.
Frequently asked questions
Doesn't the recycle bin cover this?
Only within Microsoft's retention window, and only for items deleted in the ordinary way. It does not help with a mailbox removed after an account compromise, a SharePoint library encrypted by ransomware, or a file deliberately purged by someone with access.
Where is the backup data actually stored?
ROI Technologies uses Cove Backup, a cloud-first platform with immutable storage, held independently of your Microsoft 365 tenant. South African data residency options are available.
How is this different from a Microsoft 365 retention policy?
A retention policy keeps data available for a set period. A backup takes independent point-in-time copies that can be restored regardless of what caused the loss — deletion, ransomware, or account compromise.
Keep reading
Talk to us about Microsoft 365 backup
We can review what is currently protected in your tenant and what isn't, and show you what a proper restore looks like.
Contact Us




