Retention Policies in Microsoft 365 vs. Full Control Over Retention in Xopero ONE
🔎 SUMMARY:
– Modern organizations must set up and follow retention policies to ensure data security and compliance.
– Microsoft isn’t responsible for your organization’s data in Microsoft 365, following the Shared Responsibility Model.
– Native Microsoft 365 retention offers robust configuration options, but data remains at risk, stored in the main production environment.
– Xopero ONE lets you precisely set retention for backed-up Microsoft 365 data or keep it indefinitely to meet compliance requirements, while offering separation and immutability.
Modern organizations cannot retain and delete information based on a whim—especially when dealing with critical business records. They are bound by numerous legal obligations and regulatory requirements, such as GDPR, a domestic labor code, etc., which mandate a specific retention period for different types of information.
At the same time, many businesses rely on Microsoft 365 (formerly Office 365) as their primary productivity platform, using native data lifecycle management mechanisms and multiple retention settings to ensure data security and compliance.
In this article, we look into whether Microsoft 365 retention features are sufficient to meet all regulatory standards. We also explore how a dedicated Microsoft 365 backup tool like Xopero ONE gives you full control over your organization’s long-term data retention needs.
What are data retention, data retention policy, and data deletion?
Data retention simply refers to keeping data stored until it is deleted.
A data retention policy is a set of automated rules that define how long data must be retained and when you can safely delete content. Implementing a proper retention policy transforms chaotic storage growth into a predictable, compliant data lifecycle management process. It prevents situations where administrators process personal data indefinitely. By configuring retention policies tailored to your organization, you ensure that you retain data only as long as necessary, minimizing compliance risks under regulations like GDPR.
Data deletion is the action that occurs once the configured retention period expires. Data controllers are required to delete data when it is no longer needed for its original purpose. To satisfy industry regulations and maintain data safety, permanent deletion must be irreversible so that no deleted content can be recovered or exploited following a security breach.
How native Microsoft 365 data retention works
Microsoft 365 provides several mechanisms for short-term and long-term data storage.
Short-term retention: The recycle bin
The default baseline for protecting data against accidental deletion is the recycle bin. Across primary Microsoft 365 apps, the short-term retention rules operate as follows:
| Service/app | Single item/file retention period | Notes |
| Exchange Online | 14 days (can be extended up to 30 days)—after an item is removed from Deleted Items and goes to the Exchange Recoverable Items folder. | An entire deleted mailbox can be restored for up to 30 days. |
| SharePoint Online | Up to 93 days maximum total retention across the first-stage (user) and second-stage (admin) recycle bins before permanent deletion. | |
| OneDrive for Business | Up to 93 days maximum total retention across the first-stage (user) and second-stage (admin) recycle bins before permanent deletion. |
Long-term retention: Microsoft Purview portal
The Microsoft Purview portal centralizes governance policies and retention settings across all Microsoft 365 workloads. It’s the Microsoft’s recommended approach to retention, which replaces older legacy mechanisms like Messaging Records Management (MRM) for Exchange mailboxes.
Administrators with the Global Administrator or Compliance Administrator roles can define policies and retention labels. These specify two aspects: a) how long data should be retained and b) what retention actions trigger once the specified period ends.
You can set a specific period for retention or retain content forever, using two main methods described below.
Retention Policies
Retention Policies apply broadly across entire Microsoft 365 locations—such as all Exchange mailboxes, SharePoint sites, OneDrive accounts, or Microsoft Teams channel messages. These work globally at the site or mailbox level, performing background enforcement without requiring manual effort from end-users.
You can assign different retention settings using static scopes or adaptive scopes. Static scopes target specific users or sites, while adaptive scopes use dynamic query attributes to automatically cover sensitive accounts (e.g., executive mailboxes).
Note: When you configure Retention Policies or update existing rules, it can take up to seven days for the retention settings to take effect across one or more locations.
Retention Labels
Retention Labels provide granular control, allowing you to assign retention settings to a single document or an individual email message.
Employees can apply Retention Labels to content. In higher tier plans (like Microsoft 365 E5), you can automatically apply a default Retention Label or use auto-labeling based on sensitive content detection. Because Retention Labels travel with items, applying a specific retention label guarantees that regulatory records are preserved regardless of where that item moves within a tenant.
Limitations of native Microsoft 365 data retention
While Microsoft 365 retention policies provide extensive governance features, they are not a perfect solution. Here is why relying solely on native tools leaves operational gaps.
The Shared Responsibility Model
Like all SaaS platforms, Microsoft 365 operates under the Shared Responsibility Model. As the platform operator, Microsoft guarantees infrastructure availability, not the safety of your data. They have no obligation to recover items after permanent deletion or to restore data lost to external cyberattacks, account takeovers, or insider threats.
While native features let you retain data for long periods, all data stored directly in the live production environment remains exposed to security threats.
Learn more about the Shared Responsibility Model from the official Microsoft documentation
Cloud storage does not equal 100% resilience
Outages, ransomware attacks, and human errors affect every cloud provider. If all your retained content resides within a single production environment, it remains vulnerable to:
- AI-driven malware and ransomware attacks—account takeovers via phishing or credential theft are daily threats.
- Human errors—accidental deletions or misclicks.
- Insider threats—malicious actions by departing employees, compromised internal accounts, or saboteurs (e.g. in critical sectors).
- Cloud infrastructure failures—errors introduced by automated scripts or (flawed) system updates.
- Cloud outages—data center disruptions or physical disasters (e.g., fire or flood).
Complex employee offboarding
When an employee leaves your organization and an admin removes their user account, their Exchange Online mailbox is deleted and their Microsoft 365 license released after 30 days by default.
To retain data from departing staff without paying for ongoing licenses, administrators must apply a retention policy before deleting the account. This converts the user’s mailbox into an Inactive Mailbox, preserving its content without incurring extra license fees.
However, this process introduces operational friction:
- Strict sequencing—if an admin forgets to assign retention settings prior to account deletion, all the data is permanently lost.
- Slower search—content searches inside inactive mailboxes via eDiscovery in the Microsoft Purview portal can be slow and cumbersome.
- Storage limits—inactive mailboxes remain bound to quota caps (50 GB or 100 GB depending on the original license).
Retention is not a true backup
Native retention settings do not provide isolated recovery copies.
There’s no environment isolation—retained items stay inside the primary production environment. If an attacker compromises administrator’s credentials, they can modify rules, disable the preservation lock, and permanently delete content. True immutable backup and air-gapped storage apply a digital lock and place recovery data outside the live environment where no administrative action can alter existing copies.
There’s no independent replication—native retention lacks isolated off-site replication to secondary storage destinations for true disaster recovery, redundancy, and maximum security.
Full control over retention in Xopero ONE
Using a specialized Microsoft 365 backup platform like Xopero ONE combines regulatory compliance retention with comprehensive disaster recovery. On one hand, you get a fully flexible tool for data retention and archiving. On the other hand, you gain top-tier security for your corporate data in the form of a backup, which is crucial given the frequency and sneakiness of modern threats.
Customizable retention schemes and compliance
When creating a backup plan for your M365 tenant in Xopero ONE, you can configure retention rules using three distinct logic modes of retaining data:
- Indefinitely (Keep Forever)
- For a Specified Period
- By Number of Copies

Keeping content indefinitely allows you to fulfill regulatory requirements without a fixed end date (such as keeping personal records until consent is revoked under GDPR). You can access copies created months or even years ago, provided your storage space is sufficient enough. To optimize storage consumption, Xopero ONE features inline backup compression, deduplication, and backup policies.
Retaining copies for a specified period lets you meet exact legal requirements—such as keeping tax documents for 3 years (as per IRS guidelines) or medical employee records for 30 years after employment termination (as per US labor legislation). You can assign retention settings based on backup types (full, incremental, or differential). For example, you can keep full backups for years while aging out daily incremental points after 30 days. This means not only an automated storage optimization but also compliance automation where a copy is deleted by the system once retention period expires.
Retaining by copy count lets you define an exact number of historical recovery points to maintain (e.g., last 30 or 100 copies).
Optimizing storage with rotation schemes
Xopero ONE supports four rotation schemes, including Grandfather-Father-Son (GFS), allowing you to mix full, differential, and incremental backups across custom time schedules. For example, you can create a full copy monthly, a differential one weekly, and a incremental one daily.
Combining compression, deduplication, and automated rotation schemes minimizes storage overhead while improving restore speeds.
Learn more about the rotation schemes from our article on automated backups
No Microsoft 365 licensing overhead and flexible data preview
Xopero ONE restores and retains backup data independently of Microsoft 365 user licensing. If an account is deleted, all stored backup versions remain fully accessible without requiring inactive mailbox conversions or additional user licenses.
Administrators can browse backed-up emails and files directly within the web-based management console:

When you need to preview data in detail, email items or OneDrive/SharePoint files can be recovered directly to an on-premises machine or a different active Microsoft 365 account.

Cost-effective off-site archiving
Thanks to unlimited retention and multi-storage support, you can use Xopero ONE for archiving purposes. This allows you to free up expensive cloud licenses and production space, while storing your archive in a much more cost-effective location (such as network-attached storage) that remains completely isolated from the Microsoft 365 platform and targeted attacks.
Simply include former employees’ data or old SharePoint Online projects in a backup plan and assign a long-term retention policy, such as retaining data for 5 years or indefinitely.
Summarizing native Microsoft 365 retention vs. Xopero ONE
The table below compares the most important information on the native Microsoft 365 retention and the retention through Xopero ONE:
| Native Microsoft 365 Retention (recycle bin, Purview portal) | Backup & retention with Xopero ONE | |
| Primary focus | Accidental deletion prevention & eDiscovery governance | Business Continuity & Disaster Recovery |
| Retention period | Recycle Bin: 93 days (SharePoint/OneDrive), 14–30 days (Exchange) Purview: Custom duration or indefinite | Fully customizable (by number of months or copy count) and indefinite |
| Automated deletion for compliance | Supported | Supported |
| Malicious deletion protection | Low (with compromised admin credentials, an attcker can remove policies and purge data) | High (support for immutable backups, air-gap strategies, and isolated credentials) |
| Recovery capabilities | Difficult point-in-time recovery | Granular point-in-time recovery for specific versions of emails or files |
| Data preview & access | Limited search inside Purview, easy in basic recycle bin. | Direct preview in web console, restore to local storage or alternative M365 accounts |
| Additional storage cost | High, the Microsoft 365 Extra File Storage add-on costs about $0.20 – $0.25 USD per GB/month (about $200 – $250 USD per TB/month) | Low, support for on-premises storage (NAS, SMB) and S3 cloud storage (e.g., AWS, Azure, Google Cloud, Wasabi). |
| Former employee data handling | Requires ongoing licensing or Inactive Mailbox configuration | Retains data automatically without active M365 licenses |
Data retention should offer both flexibility and security—after all, it is about safe, long-term storage paired with reliable recoverability. Instead of investing in expensive additional storage within the Microsoft 365 cloud or upgrading to higher-tier Microsoft Purview portal plans that still fail to provide data isolation, consider a dedicated backup&recovery solution like Xopero ONE.
It delivers far greater granular control over how long data is stored and how it is recovered, while ensuring significantly stronger security. This is essential in an era dominated by widespread ransomware and AI-driven cyberattacks.
You can try Xopero ONE for free, no credit card required. Use the 14-day unlimited trial to explore our solution and see how it protects your entire infrastructure, maximizing copy security and ensuring reliable data retention.





