Home›Guides›Microsoft 365 and Google Workspace
Microsoft 365 and Google Workspace
How do you back up Microsoft 365 emails?
Microsoft 365 emails are backed up by copying Exchange Online, mailbox by mailbox, to storage outside the tenant, with several restore dates. Manually exporting a PST from time to time is not a backup: it is a snapshot that is already out of date the next day, and often forgotten on a workstation.
Updated October 20263 min read5 sources cited
Key points
- Include shared mailboxes (accounts@, contact@): they do not always have a licence and drop out of inventories.
- At least a daily frequency: the interval between two copies is your RPO.
- The Exchange recycle bin keeps a purged message for 14 days by default, 30 at most: that is where backup takes over.
- The tool connects through an application with limited permissions, never through a “Global Administrator” account.
- Test restore to another mailbox twice a year, timed.
Which mailboxes
- All user mailboxes that receive real work.
- Shared mailboxes (
accounts@,contact@,support@). They do not always have a licence, and inventories forget them. - Resource mailboxes only if their content has value (rare).
- Former employees, for as long as their mail must remain accessible, followed by an explicit stop so as not to keep personal data without a reason. Microsoft only allows a deleted account, mailbox included, to be restored for 30 days.
Calendars and contacts usually follow the same mailbox. Covering them avoids restoring messages whose meetings have disappeared.
Settings that matter
- Frequency. Once a day is the minimum. Every few hours if email is your ordering channel. The interval is the RPO: an incident at 17:00 with a copy from 22:00 the previous evening loses the whole day. Cybermalveillance.gouv.fr, the French government’s cyber-assistance platform, advises setting this frequency by asking what the loss of a day, a week or a month would cost.
- Retention. 30 to 90 days covers human error and a compromise discovered late. Beyond that, you need a specific reason (ongoing litigation, sector-specific obligation). Microsoft retention within the tenant can coexist: it does not replace these dated copies held by a third party.
- Tool permissions. An application registered in Entra ID, permissions limited to reading mailboxes, admin consent, a protected secret, multi-factor authentication on admins. Not a “Global Administrator” account whose password sits in a file. More broadly, the ANSSI, France’s national cybersecurity agency, recommends that the backup infrastructure does not use production authentication.
- Immutability of the copy during the anti-ransomware window, so that a compromised admin cannot empty the backup as well.
- Test restore to another mailbox, twice a year: a folder, an opened attachment, a calendar. Measure the time taken. The ANSSI requires backups to be tested regularly and a restore procedure to be written down.
What the recycle bin allows, so as not to overestimate it
A deleted message first goes to “Deleted Items”. If it is permanently deleted from there (emptied folder, Shift+Delete), Exchange Online moves it to the Recoverable Items folder and keeps it for 14 days by default. The administrator can extend this to 30 days at most, mailbox by mailbox. After that period, or after a deliberate purge, the recycle bin no longer returns the message. Nor does it protect against an attacker who has purge permissions.
| Need | Exchange recycle bin | Backup outside the tenant |
|---|---|---|
| Message deleted yesterday | Yes | Yes |
| Folder purged six weeks ago | No (30 days at most) | Yes, depending on the chosen retention |
| Mailbox emptied by a compromised admin | No | Yes, if the copy is protected |
| Restore to a verification mailbox | No | Yes |
Restoring on the day
- Revoke the sessions of the affected account and remove suspicious forwarding rules. Restoring without doing so means refilling a mailbox that is leaking.
- Choose the date before the incident.
- Restore the folder or mailbox to a verification location, then to production.
- Tell the user what was lost between that date and the discovery (the RPO).
The full step-by-step guide is in A mailbox has been emptied or hacked.
At WeDoBack
Microsoft 365 emails, as well as calendars and contacts, are within the published scope. Billing is based on one agent per address, plus the storage volume, under the SMART or INTEGRAL offer. The copy is encrypted at source, with the key held by the customer, and hosted outside the tenant. Setup is done from the console or with a technician (€45 excl. VAT per hour). WeDoBack does not publish an imposed RPO: it equals the frequency you set. Support can be reached on +33 9 72 50 78 28, from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time).
Frequently asked questions
Is a regular PST export enough?
Rarely. The export is manual, so it gets forgotten. It often stays on a workstation or a disk, exposed to the same ransomware as production. It does not provide several restore dates and does not cover new mailboxes.
Should the mailboxes of former employees be backed up?
Yes, for as long as their mail must remain accessible. Microsoft only allows a deleted account to be restored, with its mailbox, for 30 days. After that, explicitly stop the backup so as not to keep personal data without a reason.
What should you do first if a mailbox has been emptied by a hacker?
Revoke the account’s sessions and remove any suspicious forwarding rules before restoring anything. Otherwise, you are refilling a mailbox that is leaking. Only then should you choose a copy from before the incident.
Sources
Documents consulted in October 2026.
- Change how long permanently deleted items are kept for an Exchange Online mailbox — Microsoft Learn
- Restore a user — Microsoft Learn
- Information system backup – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025, in French) — ANSSI
- Ransomware: what to do if your organisation falls victim to an attack? (in French) — Cybermalveillance.gouv.fr
- Offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
