OneDrive backup: why folder sync is not one
OneDrive gives you sync, a 93-day recycle bin and a 30-day rollback. None of them is a backup, and a licence condition can outrank your retention policy.
There is no such thing as a OneDrive backup in the sense most IT teams mean the word. OneDrive gives you sync, a recycle bin and a 30-day rollback, and all three live inside the same tenant as the data they are meant to protect. Microsoft's own interface does not help: the switch that turns on folder sync is labelled "Back up important PC folders". Below is what each native mechanism actually does, the documented windows, the licensing condition that can erase a OneDrive even when your retention policy says otherwise, and what has to sit on top before any of it deserves the word backup.
Why "back up your folders" is sync, not a OneDrive backup
PC folder backup covers Desktop, Documents, Pictures, Music and Videos on Windows, and Desktop and Documents on macOS. What it does is redirect those folders into OneDrive and keep them in step with the cloud copy. Microsoft's own guidance gives the game away when it describes what happens if you switch it off: you choose between keeping the files "only in OneDrive, removing them from your computer" or "only on my PC, removing them from OneDrive". One dataset, two viewing positions — not two copies.
The consequences follow directly:
- Deletions replicate. Remove a file locally and it leaves the cloud copy too. The recycle bin catches it, but a bin is a time-boxed undo, not a second copy.
- Encryption replicates. Ransomware running with a signed-in user's rights encrypts the local folder, and the sync client uploads every encrypted block as a new version. The upload is authenticated, so nothing about it looks anomalous to the service. This is the mechanism behind why cloud storage alone does not stop ransomware.
- There is no schedule you control. You cannot set a recovery point objective against a sync relationship. Your recovery point is whatever state the tenant happens to be in, which is a number nobody chose — the trap described in our ransomware disaster recovery plan guide.
The native recovery windows, precisely
| Mechanism | Documented window | Granularity | Who acts |
|---|---|---|---|
| Recycle bin | 93 days, unless an admin changed the setting | Per item | User, then site collection admin |
| Restore your OneDrive | Any point in the last 30 days | Entire OneDrive, all-or-nothing | User or admin |
| Deleted user's OneDrive | 30 days by default, then 93 days in the site collection recycle bin | Whole account | Admin, via PowerShell at the later stage |
The bin. Microsoft's support documentation states that items in the recycle bin "are automatically deleted after 93 days, unless the administrator has changed the setting". The stage mechanics matter and catch people out — we covered them in detail in how long the OneDrive recycle bin really gives you.
The rollback. Files Restore lets you "undo all the actions that occurred on any files and folders within the last 30 days", returning the entire OneDrive to a chosen moment. Two documented properties limit it. Anything created after the restore point "will be sent to your OneDrive Recycle Bin", so legitimate work since the incident is collateral. And "if a file has been permanently deleted from your OneDrive Recycle Bin, it can never be recovered" — which means an over-helpful user emptying the bin destroys the undo as well as the file.
Offboarding. The cleanup clock starts when the account is deleted from Microsoft Entra ID. Microsoft is explicit that "no other action causes the cleanup process to occur, including blocking the user from signing in or removing the user's license". The default retention is 30 days, adjustable in the SharePoint admin center or with Set-SPOTenant -OrphanedPersonalSitesRetentionPeriod. The manager or a secondary owner is given access, a reminder goes out seven days before expiry, and then the OneDrive moves to the site collection recycle bin for 93 days, where restoring it requires PowerShell.
Two footnotes worth knowing. Retention policies "always take precedence" over this process, so content can be deleted before 30 days or held well beyond it. And the recycle bin "isn't indexed and therefore searches don't find content there", which Microsoft spells out means "an eDiscovery hold can't locate any content in the Recycle Bin in order to hold it".
The licence condition that outranks your retention policy
This is the paragraph most teams have never read. Microsoft states that all OneDrive accounts without a valid OneDrive licence "are automatically archived on their 93rd unlicensed day". Retention settings, retention policies, eDiscovery and holds are all still honoured while the account sits in that paid archive state. Then comes the sentence that matters: "After 12 month of Unpaid storage/archive the OneDrive Data might be deleted regardless of Retention settings, retention policies, eDiscovery, and all holds."
Put that next to an ordinary offboarding process. Deleting the account makes the OneDrive unlicensed. Reclaiming a licence for cost reasons does the same thing — and, per the previous section, removing a licence does not start the deletion cleanup, so the drive sits in a state that is neither actively managed nor indefinitely safe. If your audit answer is "the data is still in the tenant", the licence position is load-bearing in that claim, and it has an expiry date that your retention policy does not override.
Microsoft's own backup add-on changes the window, not the boundary
Microsoft 365 Backup is a first-party, consumption-billed add-on covering OneDrive accounts, SharePoint sites and Exchange mailboxes, and it deserves a fair hearing. The recovery window is configurable per policy at 3 months, 6 months, 1 year or 2 years, with existing policies defaulting to 1 year. Restore points are taken every 10 minutes for the prior two weeks, then weekly from weeks 2 to 52. Against 30 and 93 days, that is a genuine improvement, and the restore speeds are the best available for in-tenant recovery.
Three documented limits decide whether it is enough on its own:
- Restore granularity is the whole OneDrive account. A OneDrive restore "rolls back to the state of the site at the prior point in time, overwriting all content and metadata since that prior point in time". Microsoft lists per-file restore via versions as coming soon, which is an accurate description of where it is today.
- The copy never leaves the tenant. "Data never leaves the Microsoft 365 data trust boundary." That is exactly what you want for data residency and exactly what you do not want for the scenario where the tenant itself is the problem: a compromised global admin, a lapsed subscription, a tenant-level misconfiguration.
- Append-only is not immutable. Microsoft says so directly — the service meets the immutability definition "except for disallowing deletion", because deletion "isn't blocked, giving customers the option to offboard". A fixed 90-day grace period after offboarding is the compensating control.
We went through the full picture, including the Exchange and SharePoint side, in what Microsoft 365 backup actually covers.
What an actual OneDrive backup has to do
Four properties, and the native tooling supplies none of them completely:
- A copy outside the tenant trust boundary, so that losing control of the tenant does not take the copy with it.
- A retention period you chose, tied to your own regulatory and contractual obligations rather than to a default or a licence state.
- Granular restore — one file, one folder, one user's drive, to a chosen point in time, without rolling back everybody's work since.
- Anomaly detection on the data itself, so that mass encryption or mass deletion is flagged while the recovery window is still open rather than discovered on day 31.
None of this prevents an attack. What it decides is how much of the last quarter you still hold when one happens, and whether anyone notices while recovery is still cheap. Which workloads actually need it is mostly a question of where your obligations sit — the SaaS shared responsibility model is the map for that, and our Microsoft 365 protection page lists what we cover per workload.
Where to start
If you run Microsoft 365 and the honest answer to "what is our OneDrive backup" is folder sync plus the recycle bin, the gap is not theoretical. It is 93 days wide, all-or-nothing on rollback, and governed by a licence condition that outranks your retention policy. We help you choose and deploy an independent backup platform that fits your tenant, your retention obligations and your team's capacity to run it day to day — you own and operate it afterwards, and we make sure it is set up correctly first.
Book a backup assessment and we will map your current recovery window per workload, in writing, and show you where the real exposure is.
Related reading
Microsoft 365 backup: what is actually covered
Microsoft 365 backup comes in three layers: the native windows in your tenant, Microsoft’s own Backup add-on, and an independent copy. What each one covers.
Microsoft Teams backup: where your Teams data actually lives
Teams has no database of its own. Here's where Teams messages, chats and files really live, what the native 30-day and 93-day windows cover, and what they miss.
The SaaS shared responsibility model — why Microsoft, Google and Atlassian don't back up your data
The short answer: your SaaS vendor keeps the platform running. Keeping your data is your job. Here's what that actually means for M365, Google Workspace, Slack and Atlassian.