Microsoft 365 and Google Workspace keep your data running. Neither one backs it up in the way most businesses assume. Both operate on a shared responsibility model, where the platform is responsible for keeping its infrastructure available, and you are responsible for protecting your own data within it. That distinction is easy to miss until something gets deleted and the recovery window has already closed.
For a business relying on either platform daily, understanding exactly what’s excluded from native retention is the difference between a five-minute recovery and a permanent loss.
Microsoft and Google guarantee uptime, not your data’s survival
The shared responsibility model splits accountability cleanly. Microsoft and Google commit to keeping Exchange, SharePoint, Gmail, and Drive running, patched, and available. They do not commit to protecting you from your own accidental deletions, a malicious insider, or ransomware encrypting files that then sync across every connected device.
This split exists because it reflects what each party can actually control. The platform controls infrastructure uptime. Your business controls what happens to the data inside it, who has access, what gets deleted, and how quickly anyone notices.
Microsoft 365 and Google Workspace exclude more than most businesses realise
Native retention exists in both platforms, but it’s built around short-term recovery windows, not long-term protection.
Retention windows are shorter than most people expect
| Platform and service | Native retention window | What happens after |
|---|---|---|
| Exchange Online mailbox items | 30 days | Permanently deleted, no recovery |
| OneDrive and SharePoint | 93 days, plus a 14-day admin-only window | Permanently deleted after that combined period |
| Google Workspace Trash (Gmail, Drive) | 30 days | Permanently deleted, no recovery |
| OneDrive after a licence is removed from a leaver | 30 days | Data deleted unless reassigned or exported first |
Accidental deletion and malicious deletion both run out the same clock
An employee accidentally deleting a shared folder and someone deliberately deleting data before leaving the business both hit the same retention limits. Native tools don’t distinguish intent. Once the window closes, both scenarios end the same way, permanently.
Ransomware spreads through sync before anyone notices
Ransomware that encrypts files on a synced OneDrive or Google Drive folder propagates to every device connected to that account almost immediately. By the time it’s spotted, encrypted versions may have already overwritten clean ones across the retention window, leaving nothing recoverable natively.
Once the retention window closes, recovery options disappear fast
This is where the gap becomes a genuine business risk rather than a technicality. Once native retention lapses, Microsoft and Google have no obligation, and often no technical mechanism, to recover what’s gone. Support tickets asking for data back after the window has closed are almost always declined.
A proper cloud-to-cloud backup tool closes this gap by taking its own independent copies on a schedule, stored separately from the platform itself, with retention set by your business rather than the platform’s defaults. Dr Logic deploys CloudAlly for clients who need this, configured with UK or EU data residency where that matters for compliance, alongside the wider cyber security work we already do for a business.
If your business relies on Microsoft 365 or Google Workspace daily and has never checked what’s actually covered beyond the default retention window, our IT Support team can walk through the gap and what closing it properly looks like.
What this means for your business
Native retention in Microsoft 365 and Google Workspace is a short-term safety net, not a backup strategy. It protects against a handful of accidental deletion scenarios within a tight window, and nothing beyond that. Businesses that treat “it’s in the cloud” as synonymous with “it’s backed up” usually only discover the difference once it’s too late to act on it.
Related articles
- IT Disaster Recovery Planning: Minimising Downtime & Data Loss
- Business Continuity Planning for SMEs: More Than Just Backups
- Simplified Tech Stacks: The Double-Edged Sword for Lean Businesses
FAQs
Isn't data automatically backed up if it's in Microsoft 365 or Google Workspace?
No. Both platforms offer short-term retention windows for recovering recently deleted items, but neither runs a true backup service. Once the retention window closes, typically 30 to 93 days depending on the service, the data is gone unless a separate backup tool has its own copy.
What's the difference between the shared responsibility model and backup?
The shared responsibility model defines who is accountable for what. Microsoft and Google are responsible for platform uptime and infrastructure. Your business is responsible for the data inside it. Backup is the practical tool that fulfils your side of that responsibility, since native retention alone doesn’t.
Can ransomware spread through OneDrive or Google Drive sync?
Yes. Files encrypted by ransomware on one device sync to every other device connected to that account almost immediately. This can overwrite clean versions across the retention window before the attack is even noticed, leaving nothing recoverable through native tools alone.
What happens if we don't notice a deletion until after the retention window closes?
Once the window has closed, native recovery is generally not possible, and Microsoft or Google support will typically not be able to restore the data. This is precisely the scenario a third-party backup tool is designed to prevent, since it keeps independent copies outside the platform’s own retention schedule.



















































