Skip to content
RansomwareBackup
recovery microsoft 365

OneDrive recycle bin: how long you actually have to restore

The OneDrive and SharePoint recycle bin gives you 93 days from the original deletion, not from when the item reached the second bin. Here is what that covers.

If a file has vanished and you are hunting for the OneDrive recycle bin, the number you need is 93. Microsoft keeps a deleted OneDrive or SharePoint item for 93 days counted from the moment it left its original location — not from the moment it landed in the second bin. Inside that window, recovery is self-service and takes seconds. Outside it, the item is permanently gone and no support ticket brings it back. There is also a separate 30-day rollback for an entire OneDrive, and a different clock again for the files of a user you have deleted. Here is how each window really behaves, and where they run out.

The OneDrive recycle bin clock, precisely

OneDrive and SharePoint Online share the same storage layer, so they share the same two-stage recycle bin. The distinction that catches people out is that the two stages split one window rather than granting two:

  1. First-stage (site) recycle bin. A deleted file goes here and stays visible to the user who deleted it. Restoring is a right-click.
  2. Second-stage (site collection) recycle bin. If someone empties the first stage — or deletes the item from it — the item moves here, where a site collection administrator can still recover it.

The crucial part: SharePoint retains an item for 93 days from when you delete it from its initial location. Moving to the second stage does not restart the clock; the item simply spends the remainder of those 93 days there. If a file sat in the first-stage bin for 80 days before someone emptied it, there are 13 days left, not another 93.

What was deleted Native window Who restores it
A file or folder in OneDrive or SharePoint 93 days from the original deletion The user, then a site collection admin
An entire OneDrive, rolled back in time Any point in the last 30 days The user or an admin
A SharePoint site 93 days in the deleted-sites list SharePoint administrator
The OneDrive of a deleted user 30 days by default, then 93 days in the recycle bin Admin, via PowerShell at the later stage

After 93 days the item is purged. That is the end of the native story for deletions.

Restore your OneDrive: the 30-day rollback

Separately from the bin, OneDrive can roll a whole drive back to a point in the past 30 days, undoing a run of file actions in one operation. It is the closest thing Microsoft ships to a point-in-time restore, and it is genuinely useful after a sync client propagates a mess. Three limits matter before you rely on it:

  • It is all-or-nothing. You choose a moment to return to, and everything after that moment goes — including legitimate work saved since. You cannot pick a recovery point for some files and keep later versions of others.
  • It is manual. Nothing triggers it for you. Somebody has to notice the problem and start the restore, which means the clock is really "30 days minus however long it took anyone to notice."
  • It covers OneDrive and SharePoint files. It is not a tenant-wide undo button, and it does nothing for mail, chat or the other workloads on your tenant.

When a user leaves, a different clock starts

Offboarding is where most organisations discover the windows do not line up. Deleting a user from Microsoft Entra ID starts a cleanup process: their OneDrive is retained for 30 days by default (an administrator can change this), the departing user's manager or a secondary owner is given access to copy anything worth keeping, and reminder mail goes out before the deadline. Only after that does the OneDrive move into the site collection recycle bin for 93 days — and recovering it at that point requires PowerShell rather than a button.

The practical failure is mundane: nobody claims the files, the notification lands with a manager who has moved on themselves, and the request to retrieve "that folder from the person who left in spring" arrives well past the point where anything simple is possible.

Where the native windows run out

The problem nobody noticed in time. Every window above is a countdown that starts at deletion, not at discovery. A quiet insider deletion, or an attacker who moves slowly on purpose, empties the entire 93-day allowance before a ticket is ever raised. Our walkthrough of Microsoft 365 ransomware recovery covers what that timeline looks like from inside an incident.

Overwrites, not deletions. Recycle bins catch deletions. They do not catch files encrypted or corrupted in place, because nothing was ever deleted. Version history is your fallback there, but versions are capped per library, and a process that rewrites every file repeatedly can push good versions out of the retained set while the bin stays empty.

Retention policies are preservation, not recovery. A retention policy stops data being removed before a date you set. It does not give you a restore — retrieval runs through an eDiscovery search and export, producing files somebody then has to put back by hand. That is a compliance answer to an availability question, a distinction we unpack in the SaaS shared responsibility model.

Scale. Recovering one file from a bin is trivial. Recovering forty thousand files across nine sites, restoring the folder structure, permissions and sharing links they had before, is a different task entirely — and the recycle bin UI is not built for it.

Evidence. Frameworks such as NIS2 expect recovery capability that is tested and demonstrable. "We rely on the recycle bin" is a statement about a default, not about a control you have exercised.

What actually closes the gap

If the 93-day and 30-day windows are thinner than your obligations, the thing to look for is a backup that holds an independent copy on your own retention terms:

  • Retention you set, not a fixed 93 days, so a discovery six months late is still recoverable
  • Point-in-time restore of a drive, site or library as it stood before a specific change
  • Granular restore of a single file, folder or version without rolling anything else back
  • Structure, permissions and sharing preserved, so restored content comes back usable
  • Anomaly detection on mass-delete and mass-change activity, so the countdown starts when it happens rather than when someone complains
  • Restore logs you can hand to an auditor for NIS2, ISO 27001 and GDPR conversations
  • A restore you have rehearsed — an untested backup is an assumption

We are independent: we help you choose the solution that fits your tenant and your compliance position, and we get it deployed with guided onboarding. You own it and you run it afterwards, so getting your own data back never depends on us. Our Microsoft 365 backup and recovery page sets out what is covered workload by workload, and the same storage mechanics explain where Teams data actually lives.

If you are not sure whether a bulk deletion in SharePoint would still be recoverable four months after it happened, that is precisely the question an assessment answers — a short, practical review of the windows you are relying on today and what a real restore would take.