Microsoft keeps the Microsoft 365 service running and keeps your data available. That is different from a backup you control. If a file is deleted, overwritten or encrypted and nobody notices for a few months, Microsoft's built-in protections may no longer have a copy.
What Microsoft does
Microsoft replicates data across its datacentres so a hardware failure doesn't lose your mailboxes or files. It also provides recycle bins, version history and retention features. These are useful, and they are the first place to look when something goes missing.
Where the gaps are
The built-in protections have time limits. Deleted SharePoint and OneDrive files stay in the recycle bin for 93 days. Deleted mailbox items can be recovered for 14 days by default. A departed staff member's mailbox and OneDrive are removed after their licence is taken away, unless someone acts first. After those windows, the data is gone.
The situations that hurt
The common ones are a staff member who deletes years of files on the way out, a sync client that overwrites a shared library, ransomware that encrypts files which then sync to the cloud, and a legal or tax request for something from years ago.
What a separate backup gives you
A third-party or add-on backup takes its own copies of mailboxes, OneDrive, SharePoint and Teams on a schedule, keeps them for as long as you choose, and lets you restore a single email or a whole site to a point in time. The copies sit outside the accounts an attacker would compromise.
How to decide
Ask how long the business could work without its email and files, how far back you may need to reach, and what your insurer, auditor or customers expect. For most businesses that run on Microsoft 365, a separate backup is a modest cost against a serious loss.
Test it
Whichever way you go, restore something every quarter and write down how long it took. That is the only proof the backup works.
Want Microsoft 365 set up and run properly? Managed Microsoft 365
All resources
