“Does Microsoft back up my data?” is still one of the most-searched questions in enterprise data protection, and for the first time the honest answer is: partially, for a fee, with conditions. For years the answer was a flat no — Microsoft replicated your data for availability, kept recycle bins and retention policies, and told you in the services agreement to use third-party backup. Now Microsoft sells Microsoft 365 Backup as a native, metered service, and every renewal conversation I’ve sat in this year has included some version of “can we just use Microsoft’s?”
Sometimes you can. This brief lays out what the native service actually covers, where it stops, how the third-party platforms — Veeam, Druva, Keepit, AvePoint — genuinely differ, and a decision rule that works better than any feature checklist: choose by threat model.
The short answer
Microsoft 365 Backup is a recovery-speed product that lives inside the Microsoft trust boundary. Third-party backup is a survivability product that lives outside it. That is the entire decision.
If your worst realistic day is a user deleting a SharePoint library or ransomware encrypting OneDrive content, the native service is credible and fast. If your worst realistic day includes tenant-level compromise, a rogue global admin, a licensing or billing lockout, or a regulator asking for four years of mailbox history, native cannot get you there — retention caps at one year and every copy sits with the same vendor, in the same tenant, inside the same failure domain. Backup that can’t survive the failure of the thing it protects isn’t backup. It’s a faster undo button.
What Microsoft’s native backup covers
Microsoft 365 Backup protects three workloads: Exchange Online, SharePoint Online, and OneDrive. Restore points land roughly every ten minutes for the first two weeks, then weekly snapshots carry you out to a maximum of one year. Pricing is consumption-based — as of mid-2026, roughly $0.15 per GB per month of protected data, metered to an Azure subscription, with restores themselves free. Because the data never leaves Microsoft’s platform, bulk restores are dramatically faster than anything pulling content back through public APIs.
What it does not do matters just as much. There is no retention beyond twelve months. There is no export of backup data to storage you control. Teams chat, Planner, Loop, and Entra ID objects are not first-class citizens. And there is no independent restore path — if your tenant is suspended, compromised, or in a billing dispute, the backup is exactly as unreachable as the production data. Microsoft has also opened the same engine to partners as Microsoft 365 Backup Storage, which is why several third-party vendors can now offer native-speed restores under their own control plane — more on that below.
Native vs third-party, side by side
| Microsoft 365 Backup (native) | Third-party platforms | |
|---|---|---|
| Where copies live | Inside your tenant, Microsoft infrastructure | Vendor cloud (AWS, Azure, or vendor-owned) — outside the tenant |
| Max retention | 1 year | Multi-year to unlimited, policy-driven |
| Restore points | ~10-minute for 2 weeks, then weekly | Typically 1–4x daily; varies by vendor |
| Workloads | Exchange, SharePoint, OneDrive | Adds Teams fidelity, Entra ID, groups; varies |
| Survives tenant compromise | No — same trust boundary | Yes — independent access and restore path |
| Pricing model | ~$0.15/GB/month, Azure-metered | Mostly per-user/month; list pricing varies |
Where the third-party platforms differ
Veeam
Veeam Data Cloud for Microsoft 365 is the SaaS packaging of the most widely deployed M365 backup engine in the enterprise, and Veeam still lets you self-host the software edition if you want to own the storage tier. Strengths: restore granularity, a huge installed base, and the option to consume Microsoft’s Backup Storage APIs for express restore speed while keeping Veeam’s control plane. The trade-off is portfolio complexity — editions, licensing tiers, and a heritage in infrastructure backup that can feel heavy if all you want is a SaaS checkbox. It fits enterprises already running Veeam for the datacenter (we’ve compared that side of the house in Veeam vs Rubrik) that want one data-protection vendor.
Druva
Druva is 100% SaaS on AWS — no software, no storage to size, per-user pricing. Its March 2026 Identity Resilience launch is the most interesting strategic move of the group, extending protection to Entra ID, on-prem Active Directory, and Okta in one platform. Strong for teams that want zero infrastructure and a security-led posture. The flip side: there is no self-hosted option, and data residing in Druva’s AWS environment can complicate strict sovereignty requirements.
Keepit
Keepit runs its own vendor-owned data centers — not AWS, not Azure — which makes it the cleanest answer to “is my backup truly outside Microsoft’s blast radius?” Coverage is broad across SaaS workloads including Entra ID. It’s a strong fit for European buyers with data-residency mandates and for anyone whose auditors ask pointed questions about infrastructure independence. The honest caveat: Keepit is a smaller vendor with a narrower enterprise ecosystem than Veeam, and that matters if you want one platform across SaaS and datacenter.
AvePoint
AvePoint Cloud Backup sits inside a broader Microsoft 365 governance and management platform, and that context is its edge: the deepest Teams and collaboration fidelity of the group, strong Entra ID coverage, and real traction with MSPs. Two caveats. Its backup infrastructure runs largely in Azure, which is operationally separate from your tenant but closer to Microsoft’s cloud than Keepit’s model. And the value case is strongest when you adopt the wider platform — as a standalone backup line item it competes on fidelity, not price.
The honest downsides — both directions
Native’s weaknesses are structural: the one-year ceiling, no export, workload gaps, and shared fate with the tenant. But third-party isn’t a free win. Per-user subscription fees compound quietly as M365 data grows — our backup storage cost-per-TB benchmarks show SaaS backup is routinely the most expensive tier per terabyte an enterprise pays for. Bulk restores through Graph APIs are throttled and slow unless the vendor integrates Microsoft’s Backup Storage. And a second vendor is a second security surface — your backup platform holds a copy of everything and deserves the same access scrutiny as the tenant itself.
The adjacent risk: identity
Here’s the gap most M365 backup RFPs still miss: restoring mailboxes doesn’t restore access. If Entra ID objects, conditional-access policies, or group memberships are deleted or maliciously rewritten, a content-only backup leaves you with perfectly preserved data nobody can sign in to reach. Druva cites incident-response data suggesting the large majority of investigations now trace back to identity compromise — treat the exact figure with caution, but the direction is right.
The market has responded: Druva’s Identity Resilience covers Entra ID, AD, and Okta; Veeam Data Cloud and AvePoint both back up Entra ID; Keepit covers Entra ID within its independent cloud. Microsoft’s native service does not. Takeaway for the meeting: any M365 backup evaluation in 2026 should score identity-object protection as a mandatory line item, not a nice-to-have.
How to decide
- Retention under 12 months, threat model is user error and content ransomware: native is defensible. Budget ~$0.15/GB/month against your protected volume and move on.
- Regulated retention (3–7+ years), legal hold beyond a year, or provable restore independence: third party, full stop. Native cannot satisfy any of these today.
- Apply the 3-2-1-1-0 rule honestly: a native-only copy fails the independent-copy test, because every copy shares one trust boundary. It counts as a recovery tier, not an off-site copy.
- The emerging pattern is both: native (or a vendor consuming Backup Storage) for fast operational restore, plus a third-party copy for long retention and tenant-failure survivability.
- Put identity in the RFP. If the shortlist can’t restore Entra ID state, it’s protecting the library while ignoring the keys.
Frequently asked questions
Does Microsoft automatically back up Office 365 data?
No. Microsoft replicates data for availability and provides recycle bins and retention policies, but none of that is backup. True point-in-time recovery requires either the paid Microsoft 365 Backup service or a third-party platform. The shared responsibility model puts the data itself on your side of the line.
Is Microsoft 365 Backup enough for compliance?
Usually not on its own. Retention is capped at one year, and most regulated industries — finance, healthcare, public sector — carry multi-year retention obligations that only third-party platforms can meet. Native works as an operational recovery layer alongside a compliance-grade copy.
How much does Microsoft 365 Backup cost?
As of mid-2026, roughly $0.15 per GB per month of protected data, billed as Azure consumption, with restores free. Third-party platforms mostly price per user per month, and list pricing varies — the crossover point depends heavily on how much data your average user carries.
What is the shared responsibility model in Microsoft 365?
Microsoft is responsible for infrastructure uptime and service availability. You are responsible for the data — its retention, its recoverability, and its protection against deletion, ransomware, and account compromise. Every backup decision flows from that split.
Can third-party tools restore faster than Microsoft’s native backup?
Generally no for bulk restores — API throttling limits anything pulling data back from outside. The exception is vendors that integrate Microsoft 365 Backup Storage, which combines native-speed restore with an independent control plane. Ask shortlisted vendors specifically whether they use it.
Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.
