UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Backup & DR

Microsoft 365 Data Loss 2026: Nonprofit M365 Data Deleted Before Retention Ended

London · Servnet News Desk · IT infrastructure analysis5 min read
Share

Microsoft has told affected nonprofit customers it accidentally deleted their Microsoft 365 data before the retention window closed — and cannot say what was lost, or recover it. For UK tenants relying solely on Microsoft's own retention settings, the incident is a reminder for organisations to assess whether native retention meets their recovery requirements — starting with a look at how to compare Microsoft 365 backup solutions.

Native Microsoft 365 retention vs independent backup
Recycle Bin/NativeSoft-Delete WindowBackup Copy(Veeam)Exchange Online14 days default(up to 30)n/a52 weeks retainedSharePoint Online93-day recycle binup to ~90 days50 weeks weekly pointsOneDriveNot confirmedby cited sourcesup to ~90 days50 weeks weekly pointsDeleted user account30 days before purgen/aPreserved independentlyExpired nonprofitsubscriptionPremature deletiondue to errorn/an/a
View the data behind this chart
Native Microsoft 365 retention vs independent backup
Recycle Bin/NativeSoft-Delete WindowBackup Copy (Veeam)
Exchange Online14 days default (up to 30)n/a52 weeks retained
SharePoint Online93-day recycle binup to ~90 days50 weeks weekly points
OneDriveNot confirmed by cited sourcesup to ~90 days50 weeks weekly points
Deleted user account30 days before purgen/aPreserved independently
Expired nonprofit subscriptionPremature deletion due to errorn/an/a

What Microsoft actually admitted

The admission is unusually blunt for a hyperscaler. In an email to an affected customer, seen by The Register, Microsoft confirmed that "due to an error," it deleted remaining tenant data before the retention and export window had expired. A spokesperson later told the paper: "We have now investigated the recovery options, but unfortunately, the data cannot be recovered."

Just as troubling: Microsoft says it cannot even establish the scope of the damage. It told The Register it is "currently unable to provide a list showing which data may have been deleted or whether any data was deleted at all." The company has not disclosed how many nonprofits were affected, how far ahead of schedule the deletion happened, or what technical fault caused it.

How a licence change turned into a data-loss incident

The trigger was administrative, not malicious. Microsoft's Microsoft 365 Business Premium grant — which had given eligible nonprofits ten free licences — was retired. Microsoft announced in May 2025 that the grant would be discontinued, with licences expiring at the customer's next renewal date on or after 1 July 2025, and offered affected organisations up to 300 free Business Basic licences and discounted pricing on other plans, including Business Premium.

Nonprofits were told to migrate users to another plan before cancellation, and to export anything they wanted to keep. That guidance assumed the retention and export window would hold until subscriptions were formally terminated. Instead, an error deleted remaining data after subscriptions were deactivated but before that window had actually closed — precisely the scenario the migration advice was meant to prevent.

Retention settings are not a backup, and Microsoft's own numbers prove it

Even when Microsoft's native controls work as designed, they are time-limited safety nets rather than durable copies. According to Veeam's documentation, Exchange Online deleted items are typically retained for 14 days by default, extendable to 30. Veeam also documents that SharePoint Online keeps deleted content in its recycle bin for 93 days, and that a deleted user account's mailbox and files can be purged after 30 days unless already captured elsewhere. IBM's own recovery documentation confirms that a deleted Microsoft 365 group cannot be restored with native Microsoft 365 functionality after the 30-day retention window lapses.

This is the mechanism the incident exposed: a retention clock that is supposed to give administrators a fixed grace period, undone by an internal fault at the point of subscription termination. Industry guidance is consistent on this: these controls provide bounded recovery and retention capabilities, but are not necessarily an independent backup copy under the customer's control.

Illustration: Microsoft 365 Data Loss 2026: Nonprofit M365 Data Deleted Before Retention Ended

What this means for UK Microsoft 365 buyers

Microsoft and backup vendors describe Microsoft 365 as a shared-responsibility service: Microsoft operates the service, while customers remain responsible for data protection and recovery. This incident shows that assumption tested in the worst way — a Microsoft-side error, not a user mistake or attacker, and Microsoft's own admission that its recovery tooling failed. That distinction matters for UK IT and finance leaders benchmarking vendor SLAs: the incident shows that recovery may fail even when the reported deletion resulted from a Microsoft-side error.

UK organisations reviewing their own Microsoft 365 estate — nonprofits, SMEs on grant-funded plans, or any tenant that has recently changed licence tiers — should treat this as a prompt to check whether they'd know if the same thing happened to them. Guidance on do you need Microsoft 365 backup is a useful starting point for quantifying that exposure before a licence migration, not after one.

The 'concierge service' is not disaster recovery

Microsoft's remedy for affected nonprofits is a free concierge service — a meeting with a Microsoft specialist intended to help configure a new Microsoft 365 environment and answer questions. According to Microsoft's statement, the service cannot restore the deleted data, and the company has said recovery attempts have already failed.

This gap between remediation offered and remediation needed is exactly why independent backup exists as a category. Veeam warns that Microsoft will not recover data deleted by an attacker or rogue actor for the customer; the incident separately illustrates the risk of a provider-side deletion. Reading why back up Microsoft 365 makes the practical case for a copy that survives a subscription lifecycle event entirely.

Building resilience beyond Microsoft's SLA

The standard defensive posture recommended across the backup industry is the 3-2-1 rule: three copies of data, on two different storage systems, with at least one copy offsite and ideally immutable — a discipline covered under what is immutable backup. Applied to Microsoft 365, tools such as Veeam Microsoft 365 backup create restore points documented separately from Microsoft's native retention: Veeam documents 52-week retention for Exchange Online; for OneDrive and SharePoint Online, it documents two weeks of restore points plus weekly points retained for 50 weeks — durability that does not depend on Microsoft's subscription-termination logic holding up.

For UK boards weighing the cost of that extra layer against the cost of an incident like this one, running the numbers through a downtime cost calculator alongside a wider backup & disaster recovery review turns an abstract risk into a budget line — one considerably smaller than the cost of permanently losing donor records, case files or financial history with no list of what's gone.

Share
Key takeaways
  • ✓Microsoft has confirmed it deleted nonprofit customers' M365 data in error, before the retention window closed, and cannot recover it.
  • ✓Microsoft also cannot tell affected customers what, if anything, was deleted from their tenants.
  • ✓Native recovery windows vary by workload—for example, Exchange deleted items are commonly 14 days by default and SharePoint recycle-bin content is retained for 93 days under the cited guidance; these are rollback windows, not an independent backup.
  • ✓UK tenants undergoing licence or subscription changes should verify independent backup coverage before relying on export deadlines alone.
Frequently asked

FAQs — Microsoft 365 Data Loss 2026

What did Microsoft actually admit happened?

Microsoft told The Register that an internal error caused remaining Microsoft 365 data from expired Business Premium subscriptions to be deleted before the agreed retention period had ended, and that recovery attempts had since failed.

Can affected nonprofits find out what was deleted?

No. Microsoft said it is currently unable to provide a list of what data may have been deleted, or confirm whether any data was deleted at all, for the affected tenants.

Why did this happen to nonprofit customers specifically?

It followed Microsoft's retirement of the Microsoft 365 Business Premium nonprofit grant, announced in May 2025 and effective from 1 July that year, which required nonprofits to migrate off the free licences or export their data before cancellation.

Does this mean Microsoft 365 retention settings can't be trusted?

It means native retention and recycle-bin windows are administrative safety nets bound to Microsoft's own processes, not a substitute for an independent backup copy — see Microsoft 365 backup comparison for how third-party tools close that gap.

Related

Continue reading

More in Backup & DR →

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111