Microsoft 365 Backup and Data Protection: What Nigerian Businesses Need to Know
Microsoft 365 guarantees that email stays online, documents sync, and collaboration tools keep working. It does not guarantee that data can be recovered once it is gone. Those are two different promises, and the gap between them is where most Nigerian businesses discover, too late, that native retention was never backed up in the first place.
Microsoft has since narrowed part of that gap itself, with a paid backup product it now sells directly. The real question is no longer whether Microsoft backs up data at all. It’s which combination of native retention, Microsoft’s own backup add-on, and third-party backup closes the gap for a given organisation.
Microsoft operates on a shared responsibility model: it protects the infrastructure, while the organisation using it is responsible for the data. This article works through what native retention covers and where Microsoft’s own backup product picks up. It then looks at what a complete backup position requires, and the risks Nigerian businesses face without one.
What Microsoft 365 Protects and What It Doesn’t
| Microsoft’s Responsibility | The Organisation’s Responsibility |
|---|---|
| Infrastructure and platform uptime | Business data |
| Service availability | Backup |
| Hardware and physical security | Retention policies |
| Platform resilience | Recovery testing and compliance |
Microsoft’s guarantee stops at uptime, and everything to the right of that table is the organisation’s to manage.
The Retention Windows
Each service inside Microsoft 365 has its own default retention limit, and all of them are shorter than most organisations assume.
- Exchange Online: deleted items are recoverable for up to 30 days by default, and soft-deleted mailboxes persist for a further 30 days before being permanently deleted.
- SharePoint and OneDrive: the recycle bin retains files for 93 days by default, after which they are gone. Version history is governed primarily by administrator configuration, within limits set by licence tier.
- Teams: chat messages and files are stored across Exchange Online and SharePoint, so their recoverability depends on the underlying retention configuration rather than on Teams itself.
These are default windows, not fixed ceilings. Microsoft Purview adds tools like litigation hold and retention labels that can preserve content for years, but these remain compliance and legal-hold features, not backup.
They still live inside the same Microsoft 365 tenant as the production data, so they stay exposed if an attacker gains sufficient administrative control over that tenant, a risk that genuinely independent backup does not share.
Nigerian Compliance Context
The Nigeria Data Protection Act 2023 requires appropriate security measures, including protection against data loss, and default retention policies fall well short of that bar on their own. Financial institutions must retain records for seven years under CBN guidelines; healthcare providers carry their own retention obligations for patient records; legal firms need client files long after a matter closes.
None of these requirements is met by a 30- or 93-day window.
Organisations planning an M365 deployment are better served by understanding these limitations from the outset. Our guide to Microsoft 365 implementation in Nigeria explains what a properly scoped rollout should include.
Microsoft’s Own Backup Product, and Where It Stops
Microsoft now sells a native product called Microsoft 365 Backup, distinct from retention and separate from Purview. It provides point-in-time backup and restore for Exchange Online, SharePoint, and OneDrive. Pricing is based on data volume consumed rather than per user, and it can hold backup data for up to a year.
According to Microsoft’s own announcement, backups created through the product are immutable and cannot be deleted except through deliberate administrative action. That is a genuine improvement over retention alone, though not a complete one.
The backup data stays inside Microsoft’s own environment rather than moving to independent, separate storage. There is no export option to move a copy outside the Microsoft 365 data boundary, and Teams chat history, Planner, and Lists currently fall outside its coverage. Because the backup stays within that same boundary, an attacker who compromises the tenant remains closer to both the production data and the backup than a truly separate, off-platform copy would allow.
That does not make it a poor choice, only a partial one, and organisations need to weigh that difference deliberately rather than by default.
Retention, Native Backup, and Third-Party Backup: What’s the Difference?
Most of the confusion about Microsoft 365 data protection comes from treating these three as interchangeable. They are not.
| Retention | Microsoft 365 Backup | Third-Party Backup |
|---|---|---|
| 30-93 days by default | Up to 365 days | Configurable, often years |
| Stored within the same tenant | Stored within Microsoft’s environment | Independent, separate storage |
| Policy-driven, automatic deletion | Point-in-time recovery, immutable | Point-in-time recovery, immutable |
| No export option | No export option | Full control over export and location |
| Vulnerable to the same threats as the source | Reduced exposure, still platform-bound | Isolated from a compromised tenant |
Retention handles recent mistakes well: a file deleted on Monday and restored on Tuesday is retention working exactly as designed. Microsoft’s own backup product handles a longer window of the same kind of loss, restoring SharePoint, OneDrive, and Exchange data from any point within a year.
Third-party backup is what protects against the scenario neither of the other two fully covers: a tenant-level compromise, a need for offsite storage, or coverage across Teams and other surfaces the native product does not yet reach.
The distinction comes down to one question: if the entire Microsoft 365 tenant were compromised today, is there a copy of the data that exists somewhere an attacker inside that tenant cannot reach? Retention and Microsoft’s native backup both answer no. Independent third-party backup answers yes.
What Genuine Backup Should Include
Proper backup follows the 3-2-1 rule: three copies of the data, on two different storage types, with one copy held offsite. Retention alone never satisfies this, and Microsoft’s own backup product only partially does.
A complete backup position meets four conditions. Storage must be immutable, meaning it cannot be deleted or encrypted; Microsoft’s native product and most third-party tools both meet this bar. Recovery must be point-in-time, restoring from any date rather than only the most recent version, which both native and third-party tools also handle.
It also needs to support long-term retention, since many Nigerian businesses need seven years of financial records held well beyond what a year of native backup covers on its own.
The fourth condition is where the native product falls short: the backup must be independent of the source, living in storage a compromised tenant cannot reach. That condition is what third-party backup exists to satisfy, and it is the reason organisations with real compliance or ransomware exposure should not treat Microsoft’s own backup product as the complete answer.
A few common practices get mistaken for backup, though none qualifies. OneDrive syncing to a local PC is not a backup, since ransomware reaches both copies at once. SharePoint version history alone is not backup, for the reasons already covered, and monthly PST exports are not backup either; they are manual, incomplete, and difficult to restore at any scale.
Nigerian infrastructure adds requirements on top of these four conditions. A backup solution needs to handle interrupted connections gracefully during power cuts, and restore times need to account for limited bandwidth. Naira-denominated pricing removes the exchange-rate uncertainty that comes with dollar-billed alternatives.
Proper document management systems build backup and retention policy together from the start, rather than treating them as separate concerns to bolt on later. The same 3-2-1 logic applies just as directly to website backups.
The Real Risks Nigerian Businesses Face
Ransomware That Syncs
Ransomware attacks on African businesses have risen over the past few years, and the mechanics of a Microsoft 365 environment make the damage worse, not better. Modern ransomware encrypts files on a local machine, and because OneDrive syncs automatically, those encrypted files upload straight to SharePoint, with the encryption then spreading into shared folders.
Version history can record successive encrypted versions of a file, gradually pushing older clean versions further back, and an attack that runs slowly, overnight, or over a weekend can fill that history with encrypted copies before detection kicks in. Microsoft’s built-in detection can roll back many incidents automatically, but that depends on catching the attack within hours, particularly when a compromise reaches an administrator account.
Recovery in Nigeria is complicated further by power disruption and limited bandwidth, making an independent backup copy even more valuable when recovery time matters. Our guide to ransomware protection for Nigerian businesses looks at prevention in more detail.
Insider and Access Risk
A common scenario: an oil services company terminates a senior project manager who, unknown to the business at the time, holds admin-level SharePoint access. In the final week, older projects, archived proposals, and reference materials get systematically deleted.
The damage typically surfaces months later, when the documentation is needed for a legal dispute, well past the point where retention could have helped. The resulting legal case costs far more to defend without the original documentation to draw on, and the lost institutional knowledge is harder to quantify at all.
Accidental Deletion
Another common scenario plays out through simple human error rather than malice. An operations manager, cleaning up a SharePoint document library, deletes what looks like an old folder.
Months later, during a routine audit, the business discovers that the folder held financial records, client contracts, and project documentation, and that Microsoft cannot recover it; the 93-day window has already passed. Reconstructing the records takes weeks of senior staff time, on top of the awkwardness of asking clients to resend signed contracts.
Costs like these scale with business size and the volume of records lost, and professional recovery services add further cost on top, often without guaranteeing the data comes back at all.
NDPA penalties add a separate, legislated layer: fines can reach ₦10 million or 2% of annual gross revenue, whichever is higher, for data controllers or processors of major importance, and ₦2 million or 2% of revenue for other organisations.
Reputational damage is harder to price, and in Nigeria’s tightly networked business community, it tends to spread faster than businesses expect.
Choosing and Implementing a Microsoft 365 Backup Solution
The first decision is no longer simply whether to buy backup. It is whether Microsoft’s own native product is enough on its own, whether it needs a third-party layer alongside it, or whether third-party backup should replace it entirely. That call depends on compliance exposure, ransomware risk tolerance, and how much Teams and other unsupported surfaces matter to the business.
Already decided third-party backup is necessary? Our guide to choosing Microsoft 365 backup solutions walks through vendor categories, evaluation criteria, and Nigeria-specific procurement considerations in detail.
Implementation follows a consistent sequence regardless of size: decide on the native-versus-third-party question first, then configure role separation between who can restore data and who can delete backups. Ongoing maintenance follows through monthly reporting reviews, quarterly restore tests, and annual compliance checks.
The most common failure point is not the technology but the follow-through: backups configured once and never tested again.
Organisations still deciding whether to manage this internally or bring in outside expertise may also find our guide on when to hire IT support in Nigeria useful.
The Cost of Doing Nothing
The reconstruction, recovery, and NDPA figures above hold true across incidents like these, and reputational damage on top of them resists a clean number entirely.
For some organisations, simply enabling Microsoft’s own backup product is the cheapest fix available. For others with real compliance exposure, that alone is not enough, and the third-party cost is what genuine independence requires.
The underlying arithmetic holds regardless of which combination an organisation lands on. For most Nigerian SMEs, a year of backup costs less than a single month of senior staff time spent reconstructing lost data. If it prevents even one major loss event every three to five years, it pays for itself several times over.
The value extends beyond the direct cost comparison. Backup gives an organisation confidence going into a compliance audit and cuts recovery time from weeks to hours. It also reassures clients and investors that data is managed professionally, which carries weight during due diligence.
Even organisations with relatively small datasets often underestimate how quickly Microsoft 365 becomes business-critical. The cost of backup usually becomes far easier to justify after the first serious data loss incident, rather than before it.
How to Audit Current Microsoft 365 Protection
A short internal audit is usually enough to reveal where the real gaps sit. It helps to confirm whether Microsoft’s own backup product is already enabled and, if so, whether its coverage is sufficient on its own or needs a third-party layer alongside it.
It is also worth confirming whether Exchange retention settings are documented, whether a restore has ever been tested rather than assumed to work, whether Teams chats are covered by anything beyond the default 30-day window, and whether SharePoint permissions get reviewed on a regular schedule.
Whether a mailbox from six months ago could realistically be recovered today is one good test. Whether any backup copy exists outside the Microsoft 365 environment itself is another. Most organisations that run through this exercise find at least one gap they did not know existed.
Ready to Secure Your Microsoft 365 Data?
A realistic risk assessment helps clarify what’s actually at stake for your business: what losing three months of email would mean operationally, or how you would handle ransomware encrypting your SharePoint sites. Getting this right usually benefits from expert input, ideally from a partner who understands both Nigerian regulatory requirements and the practical realities of your local infrastructure.
The real question is no longer whether Microsoft 365 needs backup. It’s whether the combination you have today would still let you restore your business tomorrow.
PlanetWeb Solutions provides backup assessment, implementation, and ongoing management aligned with NDPA requirements, and helps determine the right combination for your organisation.
Speak to our team or explore our IT consulting services and managed support services.






