Exchange Online mailbox recovery: what you can actually get back
Deleted mail, a purged item, a whole mailbox from a leaver. Here are the real Exchange Online recovery windows — 14 days, 30 days — and where they stop.
Exchange Online mailbox recovery comes down to which of three clocks you are racing. A user who emptied their Deleted Items has 14 days by default to get an item back themselves, and an administrator can raise that ceiling to 30 days but no further. A mailbox belonging to a user you deleted is recoverable for 30 days before it is purged. And there is no way at all to roll a mailbox back to how it looked last Tuesday — Exchange has bins you fish items out of, not point-in-time restore. Knowing which clock is running, and when it started, is usually the difference between a five-minute fix and an apology.
The three windows that actually exist
| The situation | Native window | Who can act |
|---|---|---|
| Item in Deleted Items | Until the folder is emptied | The user |
| Item purged from Deleted Items | 14 days by default, raisable to 30 | The user, via Recover Deleted Items |
| Item purged past that, with single item recovery on | The remainder of the retention period | Administrator, via a compliance search |
| Mailbox of a deleted user | 30 days | Administrator |
| Mailbox held by a retention policy or legal hold | Preserved for the life of the hold | Compliance administrator |
Deleted items: 14 days, not 30
When a user permanently deletes a message — shift-delete, or emptying Deleted Items — it moves into a hidden Recoverable Items folder rather than disappearing. From there, Recover Deleted Items in Outlook brings it back without any admin involvement. The default retention for that folder in Exchange Online is 14 days. An administrator can extend it, up to a maximum of 30 days, with the RetainDeletedItemsFor setting.
Two things follow. First, the common belief that "we have 30 days" is often wrong by half, because nobody ever changed the default. Second, 30 days is a ceiling imposed by the service, not a starting point you can negotiate upward.
Single item recovery: worth checking, not assuming
Beneath the user-recoverable layer sits a second one, holding items a user has purged. It is reachable by an administrator through a compliance search rather than by the user, and it is what allows recovery after somebody has deliberately cleaned up after themselves. Whether it is available to you depends on whether single item recovery is enabled on the mailbox and what the retention period is set to — both worth checking on your own tenant now rather than in the middle of an incident, because the answer varies with how and when the mailbox was created.
A deleted user's mailbox: 30 days
Delete the user and the mailbox is soft-deleted, not destroyed. For 30 days an administrator can bring it back — by restoring the user account, or by restoring the mailbox contents into another mailbox or an archive. After 30 days it is purged and no longer recoverable through any admin action.
The exception is a mailbox covered by a hold or retention policy at the moment of deletion, which becomes an inactive mailbox and is preserved for as long as the hold lasts. That is a preservation mechanism, not convenience: the contents are retrievable through eDiscovery, not restorable with a click.
Why chat history is a mailbox problem too
Worth knowing before you delete a leaver's mailbox: Microsoft Teams stores its messages in Exchange. Channel messages sit in a hidden folder in the mailbox of the Microsoft 365 Group behind the team, and one-to-one and group chats sit in hidden folders in each participant's own mailbox. Removing a departed employee's mailbox therefore removes one side of every conversation they were part of. We map each Teams artefact to its real storage location in our post on where Teams data actually lives.
Where Exchange Online mailbox recovery stops
There is no point-in-time restore. Every mechanism above recovers items or a whole mailbox. None of them answers "put this mailbox back the way it was before the change," which is what you actually want after a bad migration, a rule that filed thousands of messages into the wrong place, or a compromised account that reorganised a mailbox.
The clock starts at deletion, not at discovery. Fourteen days is not much time to notice something quiet. An attacker with access to a mailbox, or a departing employee tidying their tracks, only has to be unremarkable for a fortnight for the default window to close on its own.
Corruption and overwrites are not deletions. Bins catch things that were deleted. They do nothing about a mailbox whose contents were altered, or an account whose rules quietly redirect and remove incoming mail as it arrives.
Holds preserve, they do not restore. A retention policy or legal hold keeps data from being erased and makes it discoverable. Getting it back into a working mailbox is an export-and-reimport exercise, done by hand, while people wait. We draw out that distinction — and who is responsible for which half — in the SaaS shared responsibility model.
Offboarding compounds it. Mail is on a 30-day clock after user deletion, while the same person's files run on their own schedule. Our post on the OneDrive recycle bin covers that side; the two windows do not align, and neither waits for you.
What to look for instead
- Retention you define, so a request that arrives months later is still answerable
- Point-in-time restore of a mailbox as it stood before a specific event
- Granular restore of a single message, folder or calendar item without touching the rest
- Coverage of the whole mailbox — mail, calendar, contacts, and the folder structure around them
- Anomaly detection on mass-delete activity, so the 14-day default is not your only alarm
- Exportable restore logs for GDPR, NIS2 and cyber-insurance questions
- A restore you have actually performed at least once, on purpose, before you needed it
We are independent and we do not run your tenant for you. We help you choose the platform that fits your Exchange Online setup and your obligations, and get it deployed with guided onboarding — after which you own and operate it. Our Microsoft 365 backup and recovery page details what is protected across each workload.
If you cannot say with confidence whether a mailbox deleted 40 days ago is still recoverable on your tenant, an assessment is the fastest way to find out — a short, practical review of the windows you are relying on and what a real restore would involve.
Related reading
SaaS disaster recovery plan: the failures backup alone will not fix
Most SaaS disasters destroy access, not data — a vendor outage, a failed sign-on, a lapsed subscription. A SaaS disaster recovery plan has to cover all five hazards, not just the one a backup fixes.
OneDrive recycle bin: how long you actually have to restore
The OneDrive and SharePoint recycle bin gives you 93 days from the original deletion, not from when the item reached the second bin. Here is what that covers.
Microsoft 365 ransomware recovery: what actually gets your data back
Microsoft 365 keeps the service running — recovering your data after ransomware is on you. Here's what native retention covers, where it fails, and how a real restore works.