Compliance

Microsoft 365 Retention and Backup: A Control-Mapping Guide

Published Jul 26, 20266 min readBy Audit Lead

Direct answer: Microsoft Purview retention, eDiscovery holds, native recovery, Microsoft 365 Backup, and independent backup are separate controls. Use retention to preserve or dispose of content according to an approved schedule. Use a hold to preserve content for an authorized matter. Use native recovery or a tested backup service to restore supported operational data. Do not infer one control's scope, time window, or restore behavior from another.

This guide is a planning aid, not legal advice. Retention periods, suspension of deletion, privacy requests, and evidence obligations depend on the organization, record class, contracts, jurisdiction, and facts. Legal or records-management owners must approve the schedule; technical owners must prove that the configured controls behave as approved.

Choose the Control by Required Outcome

Required outcomePrimary control to evaluateWhat it does not proveAccountable owner
Keep a record for an approved minimum periodPurview retention policy or retention labelThat the item can be restored to its original application stateLegal or records management
Delete content after an approved periodPurview retention and disposition configurationThat every copy, backup, export, or third-party system is coveredPrivacy and records management
Preserve potentially relevant content for a matterPurview eDiscovery hold, authorized by counselCompleteness, admissibility, or a legal conclusionLegal
Undo recent user deletionWorkload-specific recycle bin, Recoverable Items, or native restoreA universal recovery window across Exchange, SharePoint, OneDrive, and TeamsM365 operations
Recover after corruption or destructive changeNative recovery and/or tested backupCoverage of untested object types, permissions, versions, or metadataService owner
Demonstrate that a control operatedPolicy export, process report, audit event, job result, and recovery testCompliance or certification by itselfControl owner

Microsoft documents how retention behaves differently in Exchange Online and in SharePoint and OneDrive. For example, Exchange uses Recoverable Items locations, while SharePoint and OneDrive can use the Preservation Hold library. Recycle-bin and deletion behavior are workload-specific; there is no general "93-day Microsoft 365" rule.

Build the Retention Control Record

Create one row for each record class, not one row for an entire tenant. A controlled operating process starts with the business record and its owner, then maps it to locations and controls. Use these required fields:

Do not turn framework names into fixed technology settings. HIPAA's contingency-plan requirements include retrievable copies and restoration procedures, but the organization still has to determine scope and implementation; see the HHS audit protocol. GDPR Article 32 includes the ability to restore availability and access to personal data in a timely manner as appropriate to risk; it does not prescribe one backup interval. See the official GDPR text. A SOC 2 report is an examination of a service organization's system and controls, not a regulation or a universal daily-backup rule.

Run the Control-Mapping Procedure

  1. Inventory the record. Identify the authoritative copy, duplicates, shared locations, owners, and downstream exports. Do not begin with a product setting.
  2. Approve the rule. Legal or records management records the source, trigger, period, hold behavior, and disposition authority. Resolve conflicts with privacy, contractual, or jurisdictional requirements.
  3. Map the technology. Document the exact Purview policy or label, included and excluded locations, adaptive or static scope, license, and expected preservation or deletion behavior.
  4. Map recovery separately. Define the required object types, recovery points, restore destinations, and fidelity. Use the RTO and RPO worksheet rather than setting targets from a vendor default.
  5. Test before enforcement. Use non-production or approved test content. Verify creation, edit, deletion, hold, policy removal, disposition, and recovery behavior for each workload.
  6. Approve and monitor. Record the configuration, approvers, test evidence, exceptions, job failures, and next review date in the organization's control register.

Evidence Checklist

North Brook Vault Boundary and Limitations

North Brook Vault provides policy-driven retention for supported backup snapshots and selective restore for supported object types. It does not make a tenant compliant, issue a compliance report, provide legal-hold administration, or establish the organization's retention schedule. Its managed storage does not currently expose native Object Lock configuration or enforcement. A snapshot date also does not prove complete capture or restore fidelity; validate required objects during a pilot and record the result in the organization's backup and recovery policy.

Decision gate: approve production retention only when the legal rule, technical scope, deletion behavior, recovery requirement, evidence owner, and exception path are all documented. If any field is unknown, keep the control in design or simulation rather than claiming coverage.

Model a managed backup deployment