
Eon launched Microsoft 365 data protection this week. IDrive added Entra ID backup last month. And Microsoft itself quietly took native Entra ID backup and recovery from preview to general availability this summer. When the backup vendors and the platform vendor both move in the same direction at the same time, it usually means they are circling the same gap. This one has been there for years: Microsoft keeps the service running, and your data is still your problem.
The line Microsoft drew
Every Microsoft 365 subscription runs under a shared responsibility model. Microsoft guarantees the availability and durability of the infrastructure. Everything above that line is on you: data backup, access management, how you configure compliance, and how you recover when something goes wrong. This is not buried in fine print. It is how Microsoft documents backup and recovery for the service, and it is the single most misunderstood sentence in M365 administration.
Most shops never notice because the native tools cover the common cases. Someone deletes a file, you pull it from the recycle bin. A mailbox item goes missing, you check Recoverable Items. These are real recovery paths. They are also not a backup strategy, and the difference shows up exactly when the stakes are highest.
What the native tools actually cover
It helps to name them precisely, because "retention" and "backup" get used interchangeably and they are not the same thing.
Version history and recycle bins. SharePoint and OneDrive keep prior file versions, and deleted items sit in the recycle bins for 93 days before permanent deletion. This covers "I deleted the wrong thing last month," not a rollback point from four months ago.
Recoverable Items in Exchange Online. Permanently deleted mail stays recoverable for 14 days by default, extendable to 30. Fine for the accidental purge. Useless against a mailbox that was quietly compromised six weeks ago.
Retention policies and legal hold. These exist to stop data from leaving, so you can find it later for compliance or eDiscovery. They were designed for regulators and lawyers, not for rolling a library back to how it looked before the damage. Retention does not give you a clean restore point.
Microsoft 365 Backup. Microsoft's own paid answer: recovery points every 10 minutes for Exchange for a full year, 10-minute points for OneDrive and SharePoint for two weeks then weekly snapshots, one-year retention, and restore speeds Microsoft rates up to 1 to 3 TB per hour at scale. Note the important detail: those recovery points live inside your tenant. If the tenant itself is the casualty, your backups are standing in the same building as the fire.
Entra ID Backup and Recovery. The native directory safety net reached GA this summer. Daily automatic snapshots of users, groups, apps, service principals, managed identities, Conditional Access policies, named locations, and auth policies, retained for 7 days, requires Entra ID P1 or P2, workforce tenants only. Two details matter. The snapshots are genuinely tamper-proof: no Entra role can modify or delete them, which is the correct design for a compromised-admin scenario. But hard-deleted objects cannot be recovered, and a 7-day window does not help you discover a slow-burn change on day 30.
Where native tooling runs out
The scenarios that hurt are the ones native tools were never designed for:
- Ransomware and sync corruption. An encrypted OneDrive syncs the damage upward. Native copies live in the same tenant, under the same admin accounts the attacker may already hold. You need a recovery copy outside the blast radius.
- The departed employee. A leaver clears a mailbox or a OneDrive on the way out. By the time anyone notices, 14 or 30 days can be gone. Offboarding workflows should assume this, not discover it.
- Slow changes nobody noticed. A CA policy weakened three weeks ago, a service principal granted broad permissions over months. A 7-day snapshot window does not see these. You need drift detection and longer history, or both.
- Restore fidelity. Getting the file back is only half the job. Permissions, sharing settings, and sensitivity labels need to come back with it, or you have restored data into a broken access model.
None of this is an indictment of the native tools. It is a scope statement. They cover recent, small, accidental damage extremely well. Everything else is a tier you have to choose deliberately.
Picking the tier: a decision table
If you are evaluating whether you need more than native, compare options against the scenarios you actually have to survive, not the feature lists.
| Question to ask | Native only | Microsoft 365 Backup | Third-party SaaS backup |
|---|---|---|---|
| Where do recovery points live? | Same tenant | Same tenant | Outside the tenant (isolated) |
| Point-in-time depth | Days to weeks | 1 year (Exchange), 2 weeks of 10-min + weekly (SP/OD) | Vendor-defined, often years |
| Covers Entra ID config (CA policies, apps, service principals)? | Partial (7-day native snapshots, P1/P2) | No | Some vendors, check the object list |
| Ransomware isolation | No | No (same tenant) | Yes, if the copy is immutable and external |
| Restore granularity | Item and folder level | Account, site, item level | Varies; confirm item-level and metadata fidelity |
| Restore speed at scale | Manual, low volume | Up to 1 to 3 TB/hr | Vendor claims; test them |
The pattern worth noticing: nothing Microsoft sells keeps a copy outside your tenant. That is the dividing line between "Microsoft's backup features" and "a backup." In-tenant protection is fast and convenient. Out-of-tenant protection is what survives the worst case. A mature shop usually wants both.
What to do this week
This is not a purchase order, it is a scoping exercise. Answer these five questions and you will know which tier you belong in:
- If ransomware encrypted every OneDrive in the company tonight, where is the copy that survives? Name the system.
- If a departed employee's mailbox was wiped 45 days ago, what brings it back?
- If someone quietly disabled a Conditional Access policy last month, how would you know, and how would you roll it back?
- When was the last time you actually ran a restore and timed it? A backup you have never restored is a hope, not a plan.
- Do your restored files come back with their permissions and labels, or do you rebuild access by hand?
If you cannot answer all five, the native tools are carrying more weight than they were designed for. That was true before this week's announcements. It will still be true after you read all the vendor blogs.
Sources
- Expanding Eon Data Protection to Microsoft 365 — Eon, October 2026
- Microsoft Entra Backup and Recovery overview — Microsoft Learn
- General Availability: Microsoft Entra Backup and Recovery — Microsoft Learn, Entra what's new
- Overview of Microsoft 365 Backup — Microsoft Learn
- Microsoft 365 Backup: Necessity or Luxury? — Arvato Systems, September 2026
- Microsoft Entra Backup and Recovery: Practical Guide — Interian, March 2026



