Direct answer: Exchange Online has useful native item recovery, retention, hold, inactive-mailbox, and eDiscovery controls. Microsoft 365 Backup adds customer-operated backup and restore workflows. An independent backup can add a different service boundary and retention model. Select among them by testing the exact message, folder, mailbox, and former-employee outcomes your organization requires.
Understand Recoverable Items First
Deleting a message normally moves it to Deleted Items. Removing it from there, or using Shift+Delete, soft-deletes it into the Recoverable Items structure. Microsoft documents a default deleted-item retention period of 14 days, configurable by an Exchange administrator up to 30 days. This is a mailbox setting, not simply an Exchange Online Plan 2 rule. Microsoft's Recoverable Items reference explains the Deletions, Purges, DiscoveryHolds, SubstrateHolds, and Versions subfolders and the controls that use them.
Purview retention and eDiscovery holds can preserve deleted or modified content in Recoverable Items when the policy applies. That preserved copy supports search and discovery, but it should not be assumed to provide the same in-place operational restore, folder reconstruction, or conflict handling as backup software. Review Microsoft's Exchange retention behavior with the compliance owner.
Exchange Recovery and Capture Matrix
| Object or event | Native or Microsoft path | Independent-backup requirement | Pilot proof |
|---|---|---|---|
| Recently deleted message | Deleted Items or Recoverable Items within the configured period | Older recovery point, separate boundary, or different restore workflow | Restore body, headers, recipients, dates, categories, and attachment |
| Message under retention or hold | Purview search/eDiscovery; behavior depends on policy and role | Operational restore only if the product explicitly supports it | Search, export, and restore tested as separate outcomes |
| Mail folder and hierarchy | Native item recovery does not prove point-in-time folder reconstruction | Capture parent relationships and test folder restore | Nested folder names, IDs, item placement, and conflicts |
| Calendar, contact, task, or note | Workload-specific mailbox items with different properties | Each object needs its own capture and restore path | Recurrence, attendees, time zones, attachments, and custom fields |
| Mailbox rule or setting | Use Exchange administration and audit capabilities | Do not infer settings recovery from message backup | List supported settings and test each required restoration |
| Deleted user mailbox | Soft-deleted mailbox recovery is normally limited to 30 days; holds can create inactive mailboxes | Longer recovery requires a protected copy and supported destination | Recover to the documented user or alternate-mailbox workflow |
| Microsoft 365 Backup | Mailbox and granular item restore under the current Microsoft product rules | Separate boundary only if that is an approved requirement | Run the required mailbox and item restores in a pilot policy |
Microsoft documents the 30-day soft-deleted mailbox state and the conditions for inactive mailboxes in Delete or restore user mailboxes. Do not replace those rules with an assumed 30-to-90-day license window.
How to Back Up and Restore Office 365 User and Shared Mailboxes
For teams asking how to backup an Office 365 mailbox, the first decision is mailbox type and recovery outcome. A user mailbox belongs to a sign-in identity and can have a primary mailbox plus an online archive. A shared mailbox is intended for access by delegated users and has different sign-in, licensing, permission, and offboarding behavior. To back up a shared mailbox in Office 365, verify that discovery includes it explicitly; do not assume a protected user count automatically includes every shared mailbox.
Microsoft's shared mailbox guidance describes shared-mailbox access and licensing conditions. Converting a departing user's mailbox to shared can preserve mailbox content, but conversion is an Exchange administration operation, not a backup. Follow Microsoft's conversion procedure, retain the source account and required license until conversion and access are verified, then test the backup scope again. Offboarding must separately address OneDrive, Teams, holds, archive mailboxes, and delegated access.
| Decision area | User mailbox | Shared mailbox | Required evidence |
|---|---|---|---|
| Scope discovery | Match the mailbox, Entra user, license, primary SMTP address, and Exchange GUID | Discover as its own mailbox; record delegates and licensing conditions | Current handler inventory names both test mailboxes and reports no unexplained exclusion |
| Messages and attachments | Verify body, MIME properties needed by the business, recipients, flags, categories, and attachments | Use the same object tests; shared status does not prove identical handler behavior | Source-to-restored comparison and attachment hashes |
| Nested folder hierarchy | Capture folder IDs, parent relationships, names, and item placement | Test delegated mailbox folders, including nondefault folders | Three-level hierarchy restored without missing or misplaced items |
| Contacts and calendars | Test contacts, recurrence, attendees, time zones, reminders, and exceptions | Verify the shared mailbox actually contains and exposes each required object type | Object-specific pass/fail results, not a message-only result |
| Online archive | Treat primary and archive as separate discovery and recovery scopes | Archive availability can require licensing; do not infer inclusion | Current handler verification and a seeded archive-item restore |
| Rules, settings, and permissions | Inbox rules, forwarding, delegates, Full Access, Send As, Send on Behalf, and mailbox settings are configuration objects | Delegation is central to shared-mailbox operation | Mark each as supported, native/manual, capture-only, or unsupported; message backup is not proof |
| Restore destination | Original mailbox, recovered identity, or approved alternate mailbox | Original shared mailbox or compatible alternate mailbox | Destination exists, is authorized, and passes access tests |
| Conflicts and duplicates | Original-item IDs might not be retained when an item is recreated. Define overwrite, skip, duplicate, or alternate-folder behavior before restore. | Compare a composite of Internet Message ID where present, folder, sender, recipients, time, subject, size, and attachment hash | |
North Brook Vault public policy examples identify user and shared mailboxes as possible Exchange scope, but an example is not a current handler guarantee. North Brook Vault registers Exchange backup handlers, while restore support remains selective and object-specific. Before approving a backup O365 mailbox design, obtain the current handler matrix and run the same representative test against one user mailbox and one shared mailbox. Do not claim archive, rule, setting, permission, folder, or alternate-destination support unless that test passes.
Recoverable Items and Purview retention remain native preservation and recovery layers. They can retain or surface deleted items under the configured rules, but they do not prove that backup software can reconstruct a nested hierarchy, restore a mailbox to an alternate destination, prevent duplicates, or recreate delegates and settings. Test native recovery and operational backup restore as separate procedures.
Copyable Seeded Mailbox Recovery Test
MAILBOX RECOVERY TEST
Test date:
Product/version:
Source A: PILOT-USER (user mailbox)
Source B: PILOT-SHARED (shared mailbox)
Destination 1: original mailbox
Destination 2: approved alternate mailbox
SEED
[ ] Create Inbox/Pilot/Level-3 in both mailboxes.
[ ] Send HTML and plain-text messages with small and large attachments.
[ ] Add categories, flag, read/unread state, and non-ASCII subject text.
[ ] Create a contact and recurring calendar series with one exception.
[ ] Add one item to the online archive, if archive scope is required.
[ ] Record item IDs, folder IDs, Internet Message IDs, times, and hashes.
[ ] Capture a backup, then move, edit where supported, and delete test items.
RESTORE
[ ] Restore one item and the nested-folder scenario to the original mailbox.
[ ] Repeat to the alternate destination.
[ ] Repeat one restore to test skip/overwrite/duplicate behavior.
[ ] Verify shared-mailbox delegate access after restore.
PASS
[ ] Required objects were discovered by current handlers.
[ ] Content, attachments, hierarchy, contacts, and calendars match evidence.
[ ] Archive, rules, settings, and permissions are explicitly classified.
[ ] No unexplained duplicate or name/ID conflict remains.
[ ] Measured RPO and RTO meet the approved targets.
FAIL
[ ] Any required object or mailbox type lacks a verified handler.
[ ] Retention/export is offered where operational restore is required.
[ ] Alternate restore needs unsupported structure or identity mapping.
Admin Procedure
- Classify the request: user self-service, admin item recovery, compliance discovery, complete mailbox recovery, or point-in-time operational restore.
- Inspect configuration: record deleted-item retention, single-item recovery, archive, retention policies, labels, holds, mailbox type, and license.
- Define fidelity: list required MIME content, attachments, folder path, categories, flags, read state, dates, IDs, permissions, calendars, contacts, and settings.
- Choose a destination: original mailbox, recovered user, alternate mailbox, or export. These are not interchangeable.
- Run the least disruptive native path first: preserve audit evidence before changing holds, rules, or mailbox state.
- Use the backup path only after confirming support: verify that the selected product restores the exact object and destination required.
Set business-approved objectives using the M365 RTO and RPO guide, then record ownership in a backup and recovery policy.
Seeded Pilot Scenarios
- Create a message with HTML, an attachment, categories, a follow-up flag, and non-ASCII text; then delete it from Recoverable Items after capture.
- Create a three-level folder hierarchy, move two messages, rename the middle folder, and restore to both original and alternate mailboxes.
- Create a recurring calendar series with attendees and an exception, plus a contact with multiple fields.
- Apply a test retention policy to one pilot mailbox and verify preservation, search, export, and operational restore as separate tests.
- Delete a pilot user according to an approved test plan and exercise the documented soft-deleted or inactive-mailbox path.
Pass/Fail Evidence Checklist
- Record source mailbox, license, holds, retention settings, item IDs, folder IDs, and test timestamps.
- Record backup snapshot, restore handler, destination, conflict mode, operator, start/finish time, and item errors.
- Compare message body, internet headers where required, attachments, recipients, sent/received dates, categories, flags, and folder placement.
- For calendars and contacts, compare recurrence, attendees, time zone, reminders, addresses, and custom properties required by the business.
- Fail any required scenario that is export-only when the requirement is in-place restore, or preservation-only when the requirement is operational recovery.
North Brook Vault Fit and No-Fit Boundaries
North Brook Vault registers Microsoft Graph backup handlers for Exchange data. Selected handlers use delta endpoints and others enumerate current data. Snapshot payloads use North Brook Vault-managed storage. Restore support is selective and varies by object type, so this article does not claim that every captured Exchange object can be restored. Confirm the current handler and restore matrix during onboarding and prove required scenarios in the pilot.
Compromised-Mailbox Caution
A malicious inbox rule can delete, move, or forward mail, but the recovery path depends on what happened. An applicable retention policy or hold can preserve deleted mailbox content in Recoverable Items; it is incorrect to assume deletion always bypasses retention. A message forwarded away before it was delivered to the mailbox is different: no backup of that mailbox can recover content it never received.
For a suspected compromise, preserve audit logs and message-trace evidence, disable the malicious session and rule, identify its active period, and search native retained content before restoring. Validate any restored messages against message trace and known sender records so recovery does not create duplicates or conceal messages that were never delivered.
The service is not a legal-archive product, compliance certification, PST export service, or native Object Lock control. It is a no-fit where those are mandatory, where a required mailbox setting lacks a documented restore path, or where measured recovery misses the approved objective.
Review Exchange recovery coverage Discuss an Exchange recovery consultation Review managed-service pricing