Home›Guides›Microsoft 365 and Google Workspace
Microsoft 365 and Google Workspace
How to back up Microsoft 365 emails
Microsoft 365 emails are backed up by copying Exchange Online, mailbox by mailbox, to storage that is not the tenant, with several dates. Manually exporting a PST from time to time is not a backup: it is a snapshot that is out of date the next day, often forgotten on a workstation.
Updated October 20263 min read5 sources cited
Key points
- Include shared mailboxes (accounts@, contact@): they do not always have a licence and drop out of inventories.
- At least daily frequency: the interval between two copies is your RPO.
- The Exchange recycle bin keeps a purged message for 14 days by default, 30 at most: that is where backup takes over.
- Tool connected through an application with limited permissions, never through a “global admin” account.
- Timed test restore to another mailbox twice a year.
Which mailboxes
- All user mailboxes that receive real work.
- Shared mailboxes (
compta@,contact@,support@). They do not always have a licence, and inventories forget them. - Resource mailboxes only if their content has value (rare).
- Former employees, for as long as their mail must remain accessible, then an explicit stop so as not to keep personal data without a reason. Microsoft only allows a deleted account, mailbox included, to be restored for 30 days.
Calendars and contacts generally follow the same mailbox. Covering them avoids restoring messages whose appointments have disappeared.
Settings that matter
- Frequency. Once a day is the minimum. Every few hours if email is your order channel. The interval is the RPO: an incident at 17:00 with a copy from 22:00 the previous evening loses the day. Set this frequency by asking what losing a day, a week or a month would cost; CERT-MU also recommends an off-site copy and regular restore tests.
- Retention. 30 to 90 days cover human error and a compromise discovered late. Beyond that, a specific reason (ongoing dispute, sector obligation). Microsoft retention within the tenant can coexist: it does not replace these dated copies held by a third party.
- Tool permissions. An application registered in Entra ID, permissions limited to reading mailboxes, administrator consent, a protected secret, multi-factor authentication on admins. Not a “global admin” account whose password sits in a file. More broadly, the French cybersecurity agency (ANSSI) recommends that the backup infrastructure should not use production authentication.
- Immutability of the copy during the anti-ransomware window, so that a compromised admin cannot empty the backup as well.
- Test restore to another mailbox, twice a year: a folder, an attachment opened, a calendar. Measure the time taken. CERT-MU recommends regular restore tests, and ANSSI further requires a written restore procedure.
What the recycle bin allows, so as not to overestimate it
A deleted message first goes to “Deleted Items”. If it is permanently deleted from there (recycle bin emptied, Shift+Delete), Exchange Online moves it to the Recoverable Items folder and keeps it for 14 days by default. The administrator can extend this to 30 days at most, mailbox by mailbox. After that period, or after a deliberate purge, the recycle bin no longer returns the message. Nor does it protect against an attacker who has purge rights.
| Need | Exchange recycle bin | Backup outside the tenant |
|---|---|---|
| Message deleted yesterday | Yes | Yes |
| Folder purged six weeks ago | No (30 days at most) | Yes, depending on the chosen retention |
| Mailbox emptied by a compromised admin | No | Yes, if the copy is protected |
| Restore to a control mailbox | No | Yes |
Restoring when the day comes
- Terminate the sessions of the affected account and remove suspicious forwarding rules. Restoring without doing this means refilling a mailbox that is leaking.
- Choose the date before the incident.
- Restore the folder or mailbox to a control location, then to production.
- Inform the user of what was lost between that date and the discovery (the RPO).
The full step-by-step guide is in A mailbox has been emptied or hacked.
At WeDoBack
Microsoft 365 email, along with calendars and contacts, is within the published scope. Billing is based on one agent per address, plus storage volume, under SMART or INTEGRAL. The copy is encrypted at source, with the key held by the customer, and hosted outside the tenant. Setup is done from the console or with a technician (€45 excl. VAT per hour). WeDoBack does not publish an imposed RPO: it equals the frequency you set. Support can be reached on +33 9 72 50 78 28, from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time), i.e. from 11:00 to 15:00 and from 16:00 to 19:30 Mauritius time during the European summer (from 12:00 to 16:00 and from 17:00 to 20:30 during the European winter).
Frequently asked questions
Is a regular PST export enough?
Rarely. The export is manual, so it gets forgotten. It often stays on a workstation or a disk, exposed to the same ransomware as production. It does not provide several restore dates and does not cover new mailboxes.
Should the mailboxes of former employees be backed up?
Yes, for as long as their mail must remain accessible. Microsoft only allows a deleted account, with its mailbox, to be restored for 30 days. After that, explicitly stop the backup so as not to keep personal data without a reason.
What should you do first if a mailbox has been emptied by an attacker?
Terminate the account’s sessions and remove any suspicious forwarding rules before any restore. Otherwise, you are refilling a mailbox that is leaking. Only then choose a copy from before the incident.
Sources
Documents consulted in October 2026.
- Change how long permanently deleted items are kept for an Exchange Online mailbox — Microsoft Learn
- Restore a user — Microsoft Learn
- Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025, in French) — ANSSI (French cybersecurity agency)
- Guideline on Ransomware Removal — CERT-MU
- Offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
