A one-person IT lead at a multi-brand retail and convenience company (gas stations plus food and shipping franchises inside them) got on a call with us last week, and one line stuck out: "I know it lives in the cloud, but I don't know how much I've done to make sure we have copies of SharePoint yet." That's the exact gap that bites people, so let's walk through it.
The assumption that trips up almost everyone
Microsoft 365 is redundant. Your files in SharePoint and OneDrive are replicated across data centers, so a hardware failure on Microsoft's side won't wipe your documents. That redundancy is real, and it's why people assume they're covered.
Here's the catch: redundancy protects against Microsoft's infrastructure failing. It does not protect against you. If someone deletes a folder, if ransomware encrypts files that sync up to the cloud, if a departing employee cleans out a site, or if a retention window quietly expires, that data can be gone. Microsoft operates on a shared responsibility model. They keep the platform running. Protecting your actual content is on you.
Cloud storage and cloud backup are two different things. Microsoft 365 gives you the first by default. The second is something you have to set up yourself or through a partner.
Why this hits harder after a breach
This company had already been hacked before their current IT lead started. The team had to rebuild an entire retail price book from scratch, and the people who lived through it made it clear they never want to repeat that. That experience is exactly why the backup question matters. It's one thing to lose operational data. It's another to lose the financial reports, contracts, and internal documentation that a growing multi-entity business runs on, simply because nobody set up a proper copy.
What a real backup for Microsoft 365 looks like
For businesses on Microsoft 365, the usual approach is a cloud-to-cloud backup: a scheduled, independent copy of your SharePoint, OneDrive, Exchange, and Teams data stored in a separate environment, with a defined retention policy. The key words there are independent and retention.
- Independent means the backup lives outside your Microsoft tenant, so a problem inside your tenant can't take the backup down with it.
- Retention means you decide how far back you can restore, so a deletion you don't notice for weeks is still recoverable.
- Granular restore means you can bring back a single file or a whole site without a painful, all-or-nothing recovery.
The right retention and scope depend on your business, and that's worth defining deliberately rather than accepting a default.
The OneDrive sprawl problem underneath it
There's a related issue worth naming. On this call, the IT lead noted that lots of people were storing and sharing company files out of their personal OneDrive, and he wanted to move that into structured SharePoint sites he could administer. That instinct is correct. When shared business documents live in individual OneDrive accounts, you lose visibility into who can see what, and you create a mess when someone leaves. Moving shared content into governed SharePoint sites gives you control over permissions, structure, and, yes, backup coverage.
If any of this sounds familiar
If you're running Microsoft 365 and you've been quietly assuming your files are backed up because they're in the cloud, it's worth a look before something forces the question. We're happy to walk through what you have today and where the real gaps are, at whatever pace makes sense for you.