Microsoft has told affected nonprofit customers it accidentally deleted their Microsoft 365 data before the retention window closed — and cannot say what was lost, or recover it. For UK tenants relying solely on Microsoft's own retention settings, the incident is a reminder for organisations to assess whether native retention meets their recovery requirements — starting with a look at how to compare Microsoft 365 backup solutions.
View the data behind this chart
| Recycle Bin/Native | Soft-Delete Window | Backup Copy (Veeam) | |
|---|---|---|---|
| Exchange Online | 14 days default (up to 30) | n/a | 52 weeks retained |
| SharePoint Online | 93-day recycle bin | up to ~90 days | 50 weeks weekly points |
| OneDrive | Not confirmed by cited sources | up to ~90 days | 50 weeks weekly points |
| Deleted user account | 30 days before purge | n/a | Preserved independently |
| Expired nonprofit subscription | Premature deletion due to error | n/a | n/a |
What Microsoft actually admitted
The admission is unusually blunt for a hyperscaler. In an email to an affected customer, seen by The Register, Microsoft confirmed that "due to an error," it deleted remaining tenant data before the retention and export window had expired. A spokesperson later told the paper: "We have now investigated the recovery options, but unfortunately, the data cannot be recovered."
Just as troubling: Microsoft says it cannot even establish the scope of the damage. It told The Register it is "currently unable to provide a list showing which data may have been deleted or whether any data was deleted at all." The company has not disclosed how many nonprofits were affected, how far ahead of schedule the deletion happened, or what technical fault caused it.
How a licence change turned into a data-loss incident
The trigger was administrative, not malicious. Microsoft's Microsoft 365 Business Premium grant — which had given eligible nonprofits ten free licences — was retired. Microsoft announced in May 2025 that the grant would be discontinued, with licences expiring at the customer's next renewal date on or after 1 July 2025, and offered affected organisations up to 300 free Business Basic licences and discounted pricing on other plans, including Business Premium.
Nonprofits were told to migrate users to another plan before cancellation, and to export anything they wanted to keep. That guidance assumed the retention and export window would hold until subscriptions were formally terminated. Instead, an error deleted remaining data after subscriptions were deactivated but before that window had actually closed — precisely the scenario the migration advice was meant to prevent.
Retention settings are not a backup, and Microsoft's own numbers prove it
Even when Microsoft's native controls work as designed, they are time-limited safety nets rather than durable copies. According to Veeam's documentation, Exchange Online deleted items are typically retained for 14 days by default, extendable to 30. Veeam also documents that SharePoint Online keeps deleted content in its recycle bin for 93 days, and that a deleted user account's mailbox and files can be purged after 30 days unless already captured elsewhere. IBM's own recovery documentation confirms that a deleted Microsoft 365 group cannot be restored with native Microsoft 365 functionality after the 30-day retention window lapses.
This is the mechanism the incident exposed: a retention clock that is supposed to give administrators a fixed grace period, undone by an internal fault at the point of subscription termination. Industry guidance is consistent on this: these controls provide bounded recovery and retention capabilities, but are not necessarily an independent backup copy under the customer's control.

What this means for UK Microsoft 365 buyers
Microsoft and backup vendors describe Microsoft 365 as a shared-responsibility service: Microsoft operates the service, while customers remain responsible for data protection and recovery. This incident shows that assumption tested in the worst way — a Microsoft-side error, not a user mistake or attacker, and Microsoft's own admission that its recovery tooling failed. That distinction matters for UK IT and finance leaders benchmarking vendor SLAs: the incident shows that recovery may fail even when the reported deletion resulted from a Microsoft-side error.
UK organisations reviewing their own Microsoft 365 estate — nonprofits, SMEs on grant-funded plans, or any tenant that has recently changed licence tiers — should treat this as a prompt to check whether they'd know if the same thing happened to them. Guidance on do you need Microsoft 365 backup is a useful starting point for quantifying that exposure before a licence migration, not after one.
The 'concierge service' is not disaster recovery
Microsoft's remedy for affected nonprofits is a free concierge service — a meeting with a Microsoft specialist intended to help configure a new Microsoft 365 environment and answer questions. According to Microsoft's statement, the service cannot restore the deleted data, and the company has said recovery attempts have already failed.
This gap between remediation offered and remediation needed is exactly why independent backup exists as a category. Veeam warns that Microsoft will not recover data deleted by an attacker or rogue actor for the customer; the incident separately illustrates the risk of a provider-side deletion. Reading why back up Microsoft 365 makes the practical case for a copy that survives a subscription lifecycle event entirely.
Building resilience beyond Microsoft's SLA
The standard defensive posture recommended across the backup industry is the 3-2-1 rule: three copies of data, on two different storage systems, with at least one copy offsite and ideally immutable — a discipline covered under what is immutable backup. Applied to Microsoft 365, tools such as Veeam Microsoft 365 backup create restore points documented separately from Microsoft's native retention: Veeam documents 52-week retention for Exchange Online; for OneDrive and SharePoint Online, it documents two weeks of restore points plus weekly points retained for 50 weeks — durability that does not depend on Microsoft's subscription-termination logic holding up.
For UK boards weighing the cost of that extra layer against the cost of an incident like this one, running the numbers through a downtime cost calculator alongside a wider backup & disaster recovery review turns an abstract risk into a budget line — one considerably smaller than the cost of permanently losing donor records, case files or financial history with no list of what's gone.
- 01The Register — Microsoft tells nonprofits their deleted M365 data isn't coming back · 28 September 2026
- 02The Register — The backup Microsoft never promised you (sponsored) · 13 August 2026
- 03Veeam — Microsoft 365 backup gaps · 28 September 2026
- 04Veeam Help Center — M365 considerations and limitations · 28 September 2026
- 05IBM Docs — Restore Microsoft 365 Groups data · 28 September 2026
- 06BleepingComputer — 5 reasons Microsoft 365 backup isn't enough · 28 September 2026
- 07Veeam — Microsoft 365 backup and the 3-2-1 rule (Veeam Data Cloud)
- 08Veeam — Backup for Microsoft 365 (product overview)
