Why Microsoft 365 retention is not a backup
14 January 2025 · NewTurn · 5 min read
There is a comfortable assumption inside a lot of Microsoft 365 tenants: “our data is safe — Microsoft keeps it.” It is comfortable, and it is wrong in a specific, dangerous way.
Microsoft 365 gives you recycle bins, version history, and retention policies. These are genuinely useful — for the everyday case of someone deleting the wrong file or overwriting a document. But they were built to protect you from mistakes, not from an adversary. And that distinction is where ransomware and insider threats live.
The problem: the keys unlock everything
Retention policies, holds and recycle bins all live inside the same tenant, governed by the same administrators. A global admin — or an attacker who has phished their way into that role — can change retention, purge recycle bins, and disable the very controls you were relying on. Microsoft’s own retention is not immune to someone holding the keys to your tenant.
That is not a hypothetical. The most damaging Microsoft 365 incidents are not clumsy deletions; they are deliberate ones, by someone who has enough privilege to also erase the trail.
What “immutable” actually means
The answer is a copy that cannot be changed or deleted by anyone — not an attacker, not a rogue admin, not even the vendor holding it — until a retention period you set has expired. This is what object storage with Object Lock in Compliance mode provides: a write-once, read-many (WORM) guarantee enforced by the storage layer itself, below the reach of any tenant administrator.
If a copy is truly immutable, the blast radius of a compromised tenant stops at the working tier. Your clean, point-in-time copy is still there.
What good looks like
A real safety net for Microsoft 365 has three properties:
- Separate trust domain. The copy is not governed by the same admins as the tenant it protects.
- Immutable on write. Object Lock, Compliance mode — extend-only retention, no early deletion.
- Verifiable restore. Every restored file is checked against the hash recorded when it was protected, so you know you got back exactly what was stored.
That is precisely the gap CloudOnBox was built to close: an immutable, sovereign second copy of your Microsoft 365 documents, one click from restore. Native retention is a good seatbelt. It is not an airbag.
Want to see it against your own tenant? Book a demo.