Retention scope
Map mailbox, SharePoint, OneDrive, and Teams retention settings against their actual recovery windows, not an assumed default.
Independent IT security review
Microsoft 365 keeps data available so the business can keep running, not as a substitute for backup. The review clarifies what native retention actually covers and where a deliberate recovery decision is still needed.
Recycle bins, versioning, and retention policies protect against some loss scenarios and not others. The review states plainly which scenarios each native control actually addresses.
Map mailbox, SharePoint, OneDrive, and Teams retention settings against their actual recovery windows, not an assumed default.
Distinguish accidental deletion, malicious deletion, retention-policy expiry, and account offboarding, since native tools respond differently to each.
Confirm how retention and hold settings interact so recovery expectations match what is actually preserved.
A third-party backup product is a decision, not a default. The review connects that decision to actual risk and recovery requirements instead of a blanket recommendation.
Compare how much data loss is acceptable against what native retention windows and any backup product actually provide.
Assess how quickly a mailbox, site, or Teams workspace needs to be usable again after a loss event.
Document who would operate a third-party backup product, and what compensating process exists if one is not adopted.
A backup or retention setting that has never been exercised is an untested assumption. The review looks for evidence of an actual recovery attempt.
Confirm whether a real restoration-of a mailbox item, a document, or a Teams channel-has been performed and verified.
Distinguish a full-item restore test from simply confirming a backup job completed without errors.
Record what worked, what took longer than expected, and what the test revealed about the real recovery time.
The review’s output is a decision record, not a product recommendation delivered in isolation from ownership and process.
Assign who monitors backup job health and who is authorized to initiate a recovery.
Reconcile backup retention length with regulatory, contractual, or internal data-retention expectations.
Set a sensible interval to revisit recovery objectives as the organization’s data and risk tolerance change.
Next step
Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.