Australian small businesses typically need more protection than Microsoft 365 provides by default — because what matters most isn't catching an obvious spam email, it's being able to recover the business's data when something goes wrong, whether that's an accidental deletion or a genuine cyberattack. That's the gap worth understanding before deciding what else, if anything, needs to be added.
What Is Exchange Online Protection (and What Does It Actually Catch)?
The baseline filtering built into every plan is a Microsoft service called Exchange Online Protection (EOP). It scans every incoming message for known spam patterns, known malware signatures, and senders already flagged as fraudulent. It's genuinely useful — it catches the obvious stuff, the bulk spam runs and the attachments that match a known virus.
What EOP isn't built to catch reliably is a convincing, targeted phishing email: one written specifically to look like it's from a real supplier, a real colleague, or the business's own bank, with no obvious red flags like a dodgy attachment or a misspelled sender address. That's a different, more advanced category of protection — and it's not included on every plan.
Microsoft Defender for Office 365: What's Included, and What Isn't
The advanced layer is called Microsoft Defender for Office 365 (Plan 1), and it adds the things EOP doesn't do: checking links at the moment someone clicks them rather than only when the email arrives (Safe Links), opening attachments in an isolated environment to see what they actually do before delivering them (Safe Attachments), and more sophisticated anti-phishing and impersonation detection.
Here's the part that catches people out: Defender for Office 365 Plan 1 is only bundled into Business Premium. On Business Basic and Business Standard — the two plans most small businesses on 1–20 seats actually choose — it's a separate add-on, at an extra cost, that has to be deliberately switched on. A business can be paying for Microsoft 365 in good faith, assuming "security" is a single box that's already ticked, and still be running on the baseline-only tier without realising it.
Does Microsoft 365 Back Up Your Email Automatically?
This is where the biggest misunderstanding sits, and it has nothing to do with Defender at all. Deleted items in an Exchange Online mailbox are kept in a recoverable folder for 14 days by default — configurable up to a maximum of 30 — before they're purged for good (Microsoft Learn: Recoverable Items folder). After that window closes, the item is gone, full stop, unless the mailbox happens to be on a litigation hold or an active retention policy for other reasons.
Microsoft's own documentation goes further than just stating the time limit — it's explicit that native tools like version history and retention holds "aren't designed or optimised to work as a backup and mass-recovery tool" (Microsoft 365 Backup FAQ). In other words, Microsoft itself draws the line between what it provides and what a dedicated backup is supposed to do.
It's Not Just Mailboxes — OneDrive Has Its Own Clock Too
The same pattern shows up outside the inbox. When a staff member leaves and their account is removed, their OneDrive files don't vanish immediately — but they're not kept forever either. By default, a departed staff member's OneDrive stays accessible to a manager or delegated owner for 30 days, after which it moves into a recycle bin for a further 93 days before being permanently removed (Microsoft Learn: OneDrive retention and deletion). That's a longer window than the mailbox's 14 days, but it's still a clock, still finite, and still something nobody tends to notice is ticking until well after someone's moved on and the files that mattered have already gone quiet.
Microsoft 365 Backup vs. Retention: What's the Difference?
It's easy to assume retention and backup are the same thing with different names, but they solve different problems. Retention policies and recoverable-items windows exist for everyday content lifecycle and compliance — holding onto things for a defined period in case they're needed for a legal or regulatory reason. A real backup exists for a different scenario entirely: being able to restore a mailbox, a folder, or an entire account to exactly how it looked at a specific point in time, regardless of how long ago that was or what caused the loss.
The gap shows up clearly with ransomware. If an attacker encrypts mailbox content and that gets synced or replicated before anyone notices, Microsoft's native tools can only roll back as far as their own retention window allows — and if the damage isn't discovered until after that window closes, there's nothing left to roll back to. A proper backup, taken on an independent schedule and stored separately, isn't bound by that same clock.
The Microsoft 365 Shared Responsibility Model, Explained
None of this is Microsoft doing something wrong. It's a shared responsibility model, and it's the same structure used across almost every major cloud platform, not something unique to Microsoft 365: the provider is responsible for the infrastructure staying up, patched, and physically secure, while the customer is responsible for the things specific to their own data — who has access to it, how long it needs to be kept, and what happens if it's deleted, corrupted, or encrypted.
The problem isn't the model itself. It's that very few small business owners have ever heard the phrase "shared responsibility model," let alone realised they're the "customer" half of it. Nobody hands a new Microsoft 365 subscriber a checklist of what they're now personally on the hook for.
Why "It's Covered by Microsoft" Is an Expensive Assumption
This matters more than it sounds like it should, because the cost of discovering the gap tends to land at the worst possible moment — after something's already gone. Small businesses that reported a cybercrime incident in FY2024–25 lost an average of $56,600, up 14% on the year before (ACSC Annual Cyber Threat Report 2024–25). Some portion of that figure, across the businesses it represents, is almost certainly the gap between "we assumed Microsoft had this" and "it turns out we needed something else as well."
The assumption is understandable — Microsoft 365 is a serious, capable, well-built product, and it would be reasonable to expect it to just handle everything. But "well-built" and "handles your specific recovery scenario by default" aren't the same claim, and the fine print is where the difference lives.
How to Actually Close the Gap
Closing this gap is a mix of a setting and a separate service, not just one or the other. The security half can, for some businesses, be switched on within Microsoft 365 itself — upgrading to Business Premium, or adding Defender for Office 365 Plan 1 to an existing Basic or Standard subscription. The backup half can't be solved the same way, because Microsoft's own retention tools aren't designed to be stretched into that role; genuine long-term, point-in-time recoverable backup has to come from a separate service layered on top, running on its own independent schedule.
Treated as two separate purchasing decisions, both are manageable on their own. The risk is in not knowing they're two separate decisions in the first place.
Tips for SMBs
What is Exchange Online Protection? It's the baseline email filtering service built into every Microsoft 365 plan, catching bulk spam, known malware attachments, and clearly fraudulent senders automatically, with no setup required. Don't assume this baseline filter is the whole security picture — treat it as a useful first layer, not the finish line.
Does Microsoft back up my email automatically? Not in the way most people assume. Deleted items in an Exchange Online mailbox are recoverable for 14 days by default (up to 30 if extended) before they're permanently purged, and there's no built-in, long-term version history for a mailbox the way a dedicated backup provides. If a deleted email or folder matters to the business, don't wait and hope — check it's recoverable within that window, and ensure your M365 provider includes backup by default that will let you recover your emails even if your M365 account is deleted.
Does Microsoft 365 protect against ransomware? Partially. Its native tools can help within their own retention window, but Microsoft's own documentation is explicit that these tools aren't designed to work as a full backup and mass-recovery solution — if an attack isn't caught before that window closes, native recovery options run out. Treat ransomware recovery as a backup problem, not a security-settings problem — the real fix is an independent copy of your data, not a stronger filter.
Does the same short recovery window apply to OneDrive files, or just email? Both, with slightly different timing. A departed staff member's OneDrive stays accessible for 30 days by default, then moves to a recycle bin for a further 93 days before it's gone for good — longer than a mailbox's 14 days, but still a fixed, finite window rather than permanent storage. Build an offboarding checklist that includes saving anything important from a departing staff member's OneDrive well before these windows close.
What's the actual gap between what Microsoft includes and what a small business usually needs? Two things: stronger phishing and targeted-attack protection on the lower-cost plans, and a real, independent backup that keeps data recoverable for longer than Microsoft's short default retention window. Check both boxes separately — fixing one (upgrading security) doesn't automatically fix the other (backup).
Do I need to buy something extra to close this gap, or is it just a setting to turn on? Traditionally, additional email security and backup are purchased as separate, stand-alone services layered on top of a Microsoft 365 subscription. Managed providers like SafeSMB include both as standard across every plan, so there's nothing extra to buy or configure — it's already there from day one, for peace of mind. If you'd rather not manage two separate purchases and renewal dates, a bundled plan removes that admin entirely.
Where to Next
Closing this gap doesn't require becoming a security expert, or juggling two separate subscriptions and renewal dates. The simplest path is choosing a business email provider that already builds the right things in from day one. When comparing providers, look for:
- Email security and backup included by default — not sold as separate add-ons you have to remember to switch on later.
- Guided configuration, so the provider sets things up correctly for your business, rather than leaving you to work out the right settings yourself.
- Local-language support when you need it — a real person to talk to, not a ticket queue in a different time zone.
- Transparent pricing, since traditional, stand-alone email security and backup services can get expensive once add-ons and per-user fees start stacking up.
- An easy-to-use management console, so you can see what's actually being blocked and adjust your protection level, without needing an IT background to make sense of it.