Direct answer: Microsoft is responsible for operating and securing the Microsoft 365 service, but your organization still decides who may access data, which native and optional recovery controls to enable, how long information must remain recoverable, and whether recovery has been tested. Microsoft does offer a separate Microsoft 365 Backup product; the shared-responsibility decision is therefore not "Microsoft backup or no backup," but whether the configured controls satisfy each approved recovery scenario.
Microsoft's shared-responsibility guidance assigns customer data, identities, account management, and access management to the customer even in SaaS. Microsoft operates the application and physical platform. An MSP or backup provider adds another service boundary but does not take ownership of the customer's business requirements.
Assign Responsibility by Control
| Control | Microsoft | Customer | MSP or backup provider | Evidence to retain |
|---|---|---|---|---|
| Service resilience | Operates Microsoft 365 infrastructure and built-in service resilience. | Chooses services and plans business continuity around service dependencies. | Documents dependencies and escalation where contracted. | Current service documentation, incident plan, dependency register. |
| Identity and authorization | Provides Entra roles, authentication, and access-control capabilities. | Approves administrators, consent, MFA, Conditional Access, and offboarding. | Uses only assigned access and reports authorization failures. | Role export, consent record, access review, named owner. |
| Native retention and recovery | Provides workload-specific recycle, version, retention, hold, and recovery features. | Configures and verifies the controls required for each workload. | May operate approved procedures but cannot define legal requirements. | Policy export, workload matrix, recovery test. |
| Optional backup | Offers Microsoft 365 Backup for supported Exchange, OneDrive, and SharePoint protection. | Selects scope, billing, administrators, and recovery objectives. | Operates the contracted product and reports outcomes. | Protection scope, latest usable recovery point, job history, restore evidence. |
| Compliance decision | Publishes service and compliance documentation. | Legal, privacy, security, and records owners determine applicable obligations. | Supplies control evidence within its service boundary. | Approved requirement, control mapping, exceptions, review date. |
Choose a Recovery Path Per Scenario
There is no universal 93-day Microsoft 365 deletion clock. SharePoint and OneDrive use a combined 93-day recycle-bin period for many deleted items, documented in Microsoft's SharePoint and OneDrive resiliency guidance. Exchange, Teams, deleted accounts, Purview retention, and Microsoft 365 Backup follow different rules. Build the decision from the object and event, not from a workload-level slogan.
| Scenario | First control to verify | Decision question | Required proof |
|---|---|---|---|
| Recent file deletion | Recycle bin, version history, or native restore. | Can the exact file and metadata be restored within the approved time? | Timed item restore with identity and timestamp checks. |
| Old mailbox item | Exchange recovery, Purview retention or hold, then configured backup. | Is the requirement operational restore, search/export, or legal preservation? | Policy lookup and tested retrieval procedure. |
| Bulk site corruption | Version/native site recovery and available backup recovery points. | Can clean data be restored without overwriting valid newer work? | Representative site test and conflict-handling record. |
| Compromised administrator | Role separation, deletion controls, alerts, and provider boundary. | Can the compromised identity alter production and recovery controls? | Role matrix, deletion procedure, access review, incident exercise. |
For native Microsoft 365 Backup specifically, Microsoft documents one-year retention, workload-specific recovery points, append-only storage, and an offboarding path that can ultimately delete backups. Review the current Microsoft 365 Backup overview rather than assuming native backup is either fully immutable or merely another recycle bin. Purview retention is a separate preservation control; Microsoft's retention documentation should be checked for the exact location and policy.
Copyable Responsibility Checklist
- [ ] Define the event: Record workload, object type, deletion or corruption event, required date, and destination.
- [ ] Name the business owner: Identify who approves acceptable data loss, recovery time, retention, and exceptions.
- [ ] Map available controls: Record native recovery, Purview, Microsoft 365 Backup, and independent backup coverage separately.
- [ ] Assign operators: Name who authorizes access, reviews jobs, starts restores, approves destructive actions, and communicates incidents.
- [ ] Test the exact path: Follow the RTO/RPO measurement procedure and retain elapsed time and fidelity evidence.
- [ ] Review periodically: Repeat after material licensing, permission, workload, provider, or policy changes.
Evidence Record
| Scenario and business owner | [Enter scenario, owner, and approval date] |
|---|---|
| Configured controls | [Native recovery, retention/hold, backup product, protection scope] |
| Administrators and approvers | [Named roles; avoid shared-account descriptions] |
| Latest successful test | [Date, recovery point, destination, elapsed time, result] |
| Known gaps and decision | [Unsupported objects, expired windows, accepted risk, remediation owner] |
North Brook Vault Coverage and Limits
North Brook Vault is managed SaaS with provider-managed infrastructure, storage, and service-side monitoring. It supports scheduled backup for supported Exchange, OneDrive, SharePoint, and Teams object types, with selective restore only where a restore handler exists. Teams chat and channel messages are not restorable; OneDrive file version history is not captured; and the service does not provide customer-selected S3 or on-premises storage, native Object Lock enforcement, PST/PDF/ZIP export, compliance reports, or a zero-throttling guarantee. Customers retain responsibility for tenant consent, customer-side operator access, requirements, approvals, and representative restore tests. Use the operations checklist to validate that split.
Worked Decision Example
A project owner needs a SharePoint document deleted six months ago. The service owner first confirms the exact site, file, required date, and whether legal preservation or operational restore is needed. The team checks Purview policy assignment and each configured backup product rather than assuming the 93-day recycle window decides the outcome. If North Brook Vault contains a supported drive-item snapshot, the operator tests restoration to an approved destination and records content, metadata, permissions, elapsed time, and differences. If no usable point or supported restore exists, the business owner records the gap and chooses another control or accepts the risk.
Decision
Use independent backup when a documented scenario is not met by configured native controls and the proposed backup can pass the required restore test. Do not buy it solely from a generic shared-responsibility slogan.
Review the service responsibility boundary Discuss a responsibility consultation Estimate managed-service pricing