Microsoft 365 Backup Is Not a Backup: What NYC Law and Accounting Firms Lose in a Tenant-Wide Ransomware Event
A 15-user Microsoft 365 tenant is not a “small” email system. For a New York law or accounting practice, it is the practice: Outlook is the client file, SharePoint is the matter room, OneDrive is the partner’s working set, and the calendar is the court or IRS date. If an attacker who already has a privileged identity encrypts, overwrites, or purges that tenant, Microsoft will still be up. Your firm may not be.
The question is narrow: when the same credentials that run the tenant can empty Recycle Bins, delete sites, and change holds, what actually comes back?
Retention is not a backup
CISA defines a backup as a secure copy of critical data stored separately from your primary systems. Microsoft 365’s built-in recycle, hold, and retention features live inside the tenant. They are useful. They are not a second copy an attacker cannot reach.
Microsoft’s shared-responsibility model for SaaS is explicit: you own customer data, identities, and the configurations you control. Microsoft runs the service. High availability is not the same as “we will roll your mailbox back to last Tuesday after a Global Admin purge.”
Microsoft also sells a separate, paid product named Microsoft 365 Backup (pay-as-you-go, Exchange / SharePoint / OneDrive). If you have never turned that on—or bought an equivalent third-party Microsoft 365 backup—you do not have a backup of the tenant. You have a Recycle Bin.
What Microsoft actually keeps (and for how long)
These windows are from Microsoft Learn and Microsoft Support documentation current in 2026. They are recovery windows, not isolation.
Exchange Online: Deleted Items and Recoverable Items
When a user deletes mail (including Shift+Delete), the item lands in the Recoverable Items folder. The default deleted-item retention period in Exchange Online is 14 days. An admin can raise that to a maximum of 30 days. After that, unless a hold or retention policy still applies, the item is gone from the service.
Users can also permanently purge from Recover Deleted Items. Holds change what an admin can still find. They do not move the data to a separate system.
SharePoint and OneDrive: two-stage Recycle Bin, 93 days
Deleted files go to the site Recycle Bin, then—if emptied—to the site-collection Recycle Bin. Microsoft keeps them for 93 days from the original deletion. The clock does not reset at the second stage. A site-collection admin can purge that bin immediately; quota pressure can drop the oldest items.
After hard deletion, Microsoft retains service backups of SharePoint content for 14 additional days so Support can attempt a full site-collection or subsite point-in-time restore—not a surgical “just the one engagement letter.” After that 14-day window, Microsoft states the data is no longer retained and is not recoverable.
API deletes can skip the Recycle Bin and purge at once.
Versioning
On Microsoft 365, versioning is on by default for new libraries and lists and typically keeps the last 500 versions. That undoes a bad overwrite. It is still the same library: Delete Versions permission or a lower version cap can erase history. Versioning is not a tenant-wide restore.
Litigation Hold and retention policy are not a second copy
Litigation Hold and eDiscovery holds stop the usual purge of Recoverable Items and, for SharePoint/OneDrive, keep copies in a Preservation Hold library. Microsoft says that for long-term retention not tied to a case, use retention policies and labels—not eDiscovery.
Retention policies copy originals into the Preservation Hold library when content is edited or deleted, then eventually send expired copies through that same 93-day Recycle Bin path. They keep records. They do not create an immutable copy outside the tenant.
Two facts matter in a ransomware or insider-wipe event:
- Recycle Bin content is not indexed. An eDiscovery search cannot find it and cannot place a hold on it.
- Holds and retention live where the attacker already is. A compromised Global Admin or Compliance admin can release holds, change policies, empty bins, and delete sites. Microsoft applies a delay hold of about 30 days after some hold removals. That is still in-tenant time, not a vault.
If the same identity can administer Purview and the SharePoint admin center, “we have Litigation Hold on the partners” is not a restore plan.
What a tenant-wide event actually takes from a firm
“Tenant-wide” means the attacker can act as the tenant: encrypt or overwrite SharePoint and OneDrive, purge mail, delete sites, or lock you out and extort you with a stolen copy. CISA calls the pattern ransomware plus theft (“double extortion”), and sometimes leak threats with no encryptor at all.
For a New York law firm, the live systems are usually:
- Exchange: client advice, privilege, opposing-counsel traffic, engagement letters, and the calendar that is the court date.
- SharePoint: matter workspaces, discovery productions, closing binders, templates.
- OneDrive: partner drafts that never made it into the matter site.
For a CPA or tax practice, substitute tax workpapers, organizer files, e-file acknowledgments, engagement letters, and the April/October calendar. Client Social Security numbers and financial account data sit in those libraries. That is “private information” under New York’s SHIELD Act.
A 14-person Staten Island or outer-borough office often has no second file server. The tenant is the file room. Without a known-good restore of mailboxes and matter sites, you are reconstructing files from laptops—if those were not encrypted too.
A clean restore does not undo an extortion leak. Backup restores availability. Confidentiality still depends on how fast you catch a compromised admin.
Why this is a New York duty-of-care issue, not a slogan
The SHIELD Act (N.Y. General Business Law § 899-bb) requires any person or business that owns or licenses computerized private information of a New York resident to develop, implement, and maintain reasonable safeguards for its security, confidentiality, and integrity.
The statute’s list of reasonable technical safeguards includes detecting, preventing, and responding to attacks or system failures, and regularly testing and monitoring the effectiveness of key controls. Reasonable administrative safeguards include selecting service providers who can maintain appropriate safeguards and requiring those safeguards by contract.
Small businesses under SHIELD (fewer than 50 employees, or under $3 million gross annual revenue in each of the last three fiscal years, or under $5 million in year-end assets) still need safeguards appropriate to their size, work, and data sensitivity. A 15-person firm is not exempt because it is “too small for backup.”
The Attorney General may seek injunctive relief, restitution, and civil penalties. Failure to maintain reasonable safeguards can draw up to $5,000 per violation. SHIELD has no private right of action; clients and courts can still ask why the matter file disappeared.
A restore you have never run is a control you have never tested.
What a real Microsoft 365 backup looks like
A backup of Exchange, SharePoint, and OneDrive is a separate recovery copy with its own retention, its own restore points, and access that is not identical to everyday Global Admin work.
Microsoft 365 Backup (the paid service, documented August 2026) is built for ransomware and mass-delete recovery inside the Microsoft 365 trust boundary. Storage is append-only: existing restore-point blobs are not overwritten. Purview retention and eDiscovery policies do not shorten the backup window. Policies keep restore points for 3 months, 6 months, 1 year, or 2 years (existing policies default to 1 year). Exchange restore points can be every 10 minutes.
Microsoft is careful with the word “immutable.” Admins can still offboard and delete backups. There is a 90-day grace period after offboarding to recover those backups, plus multi-admin notifications on harmful actions. Append-only is not the same as “nobody with a token can destroy the vault.”
Third-party Microsoft 365 backup (including products on Microsoft 365 Backup Storage) can add a second console, a second identity boundary, and sometimes copies outside the tenant. CISA still wants offline, encrypted backups and a tested restore, because operators hunt credentials and delete reachable backup stores. Isolation and a drill matter more than the logo on the dashboard.
Seven steps a 15-user tenant can actually finish
- Write down what lives in the tenant. Mailboxes, the matter or client SharePoint sites, the tax or workpaper library, and OneDrive for anyone who keeps original files there. If it is not on the list, it will not be in the restore.
- Name your current recovery path in one sentence. If the sentence is “Recycle Bin, 93 days, Litigation Hold on the partners,” you have retention. You do not have a backup.
- Turn on a dedicated Exchange / SharePoint / OneDrive backup—Microsoft 365 Backup or a third-party product that covers those three workloads. Protect every mailbox and every client/matter site, not only the owners.
- Split the keys. Backup delete and offboard should require a different admin path than daily Microsoft 365 work. Limit Global Admins. Treat backup-offboard as a two-person change.
- Leave versioning on; stop emptying Recycle Bins as housekeeping. Versioning and the 93-day bin still save accidents. They do not replace step 3.
- Run one restore drill this quarter. Restore one mailbox (or a folder), one SharePoint library or site, and one OneDrive account to a new location. Time it. Write who clicks what. CISA’s SMB guidance is to test full and partial restore.
- Put the firm’s calendar into the runbook. Who calls the court or the client if Monday’s filing is on an encrypted site? Who owns SHIELD/breach notice if private information left the tenant? Store a copy of that runbook outside Microsoft 365.
Identity and mail filtering still decide whether the attacker gets the admin token. Backup is what you have after they did.
How MicroSky helps—on this problem, not a generic stack
MicroSky is a Staten Island / NYC MSP. On Microsoft 365 recovery we do the unglamorous work:
- Confirm whether the tenant has a real backup of Exchange, SharePoint, and OneDrive, or only Recycle Bin / retention / hold.
- Turn on and operate that backup with restore points you can actually use.
- Run a restore test (mailbox, site or library, OneDrive) and leave you the timing and the runbook.
- Point the assessment at the gaps that let an attacker become the tenant. EDR is not a second copy.
For the configuration side of the same tenant, see the Microsoft 365 security hardening checklist and email and identity. Privileged sign-in gaps are covered separately. This post is the restore question those pieces do not answer.
Talk to us before the restore is theoretical
Call MicroSky at (718) 672-2177 or visit microskyms.com for a free, no-obligation Microsoft 365 backup assessment. We serve NYC, Staten Island, New Jersey, and the tri-state.
Ask which mailboxes and sites are covered, how far back you can go, and the date of the last successful test restore.

