Accounting firms run their entire practice through Microsoft 365. Client tax files are in SharePoint. Engagement letters and signed returns move through Exchange mailboxes. Working papers are in OneDrive. Because Microsoft hosts all of it, many firm owners assume Microsoft is also running backup for Microsoft 365. That assumption is wrong and the exposure lands on client tax records, engagement files, and the firm's own compliance position.
Microsoft has drawn the line itself: keeping the service running and protecting the data inside it are two different jobs, and only one of them is Microsoft's.
Microsoft is explicit about where its responsibility ends. Under the shared responsibility model that governs every Microsoft 365 subscription, Microsoft guarantees the availability and durability of the underlying infrastructure. Data management and protection are the customer's responsibility, according to Microsoft's own guidance on backup and recovery.
The recycle bins and retention windows built into Exchange, SharePoint, and OneDrive were designed to keep the service running smoothly. They were never built as a firm-wide backup and recovery system for a CPA practice handling client financial records.
The native protections inside Microsoft 365 backup tools are real but narrow, and they were never intended to replace a dedicated backup strategy.
Exchange Online keeps deleted mailbox items for a short window. Microsoft's documentation on the Recoverable Items folder sets the default deleted item retention period at 14 days, extendable by an administrator to a maximum of 30.
SharePoint and OneDrive run on a longer but still finite clock. Per Microsoft's guide to restoring deleted data in SharePoint Online, a deleted item stays in the site recycle bin for 93 days after it's removed. If someone deletes it from that first bin, it moves to a second-stage bin for the remainder of the same 93-day period. After that the content is permanently deleted.
Holds only work if they were already in place. Microsoft's Recoverable Items documentation is clear that once the deleted item retention period expires, the item leaves Exchange Online unless Litigation Hold, In-Place Hold, or single item recovery was turned on beforehand. SharePoint is harder still. Per Microsoft's Purview retention documentation, the recycle bin is not indexed, so an eDiscovery search cannot find recycle bin content to place a hold on. By the time a firm realizes a client folder is gone, the tool that would preserve it can no longer see it.
Microsoft has acknowledged the scale of the problem this creates. Its 365 Backup best practices white paper notes that as of its publication, more than 2.5 billion files were being created in Microsoft 365 every day, and that volume, paired with the complexity IT teams face managing data at that scale, is why organizations need dedicated backup and restore tools built for genuine recovery assurance. Microsoft's newer Backup add-on extends recovery past these defaults, but it's a separately licensed product. A firm that hasn't purchased and configured it is still operating inside the 14- to 93-day windows.
For a tax practice, those windows are shorter than the problems. A partner pulls a prior-year workpaper in October and finds the client folder was deleted back in March. A ransomware event goes unnoticed for weeks. A departing staff member clears a mailbox before the exit interview. None of these fall inside what native retention can fix.
Preparer recordkeeping requirements run well past 93 days. For any return claiming the EITC, the Child Tax Credit, the American Opportunity Tax Credit, or head of household status, IRC 6695(g) due diligence applies. The IRS's due diligence recordkeeping requirements call for a completed Form 8867, worksheets used to compute credit amounts, records of how and from whom information was obtained, and copies of client documents relied on. Under IRS audit guidance for due diligence compliance, those records must be kept for three years from the return's due date or filing date, whichever is later.
Employment tax records carry a longer clock still. The IRS's employment tax recordkeeping guidance states that employers must keep employment tax records for at least four years. Multiply that across a firm's full client roster, and the true retention obligation spans years for exactly the kind of documents that live in Exchange attachments and SharePoint client folders.
Data security carries its own separate mandate. The FTC's Safeguards Rule, part of the Gramm-Leach-Bliley Act, names tax preparation firms among the 13 examples of businesses the Rule treats as financial institutions. The Rule doesn't ask for informal precautions. A covered firm's security program must include administrative, technical, and physical safeguards tailored to its size, activities, and the sensitivity of the customer data it holds, and it must be built on a documented risk assessment.
The FTC's 2017 TaxSlayer settlement shows what that looks like in practice. Hackers accessed nearly 9,000 customer accounts over three months in late 2015. Tom Pahl, then Acting Director of the FTC's Bureau of Consumer Protection, said the company "didn't have an adequate risk assessment plan." The complaint listed failures many small firms would recognize in their own environment: no written comprehensive security program, no risk assessment identifying foreseeable threats, and no safeguards in place that would have helped prevent the attack. A recycle bin is not a security program.
Ransomware and business email compromise aren't abstract risks for firms holding financial data. The FBI's Internet Crime Complaint Center tracks both in its 2025 Annual Report, and the trend line points the wrong way. Business email compromise generated more than $3 billion in reported losses in 2025. Ransomware complaints climbed from 2,825 in 2023 to 3,156 in 2024 to 3,611 in 2025, with the ten most-reported variants accounting for more than half of all incidents.
The FBI identified 63 new ransomware variants in 2025, roughly 5.25 per month, with the top variants concentrated on critical infrastructure sectors including financial services and healthcare. Accounting firms are not in that reporting category, but they hold the same raw material: Social Security numbers, bank details, and prior-year returns for every client on the roster. A ransomware event that encrypts or deletes a firm's SharePoint libraries does not wait inside a 93-day recovery window. If it isn't caught right away, native retention may already have cycled past the point where a clean restore is possible.
Backup has to run as a function separate from the 365 platform itself.
Third-party backup, or Microsoft's own Backup add-on properly licensed and configured, gives a firm point-in-time recovery past 93 days without depending on a retention policy having been set up before the incident that caused the loss. It also creates a copy of the data that exists independently of the production environment, so a compromised admin account or ransomware spreading across a tenant doesn't take the backup down with everything else.
Firms should also adopt these practices:
Microsoft built a durable, reliable platform. Meeting an accounting firm's retention obligations and closing its exposure to ransomware and business email compromise is still the firm's job.
As a managed IT service provider, PK Tech brings nearly 17 years of experience serving CPA firms. PK Tech holds AICPA SOC 2 Type II attestation, verified through an independent third-party audit of its security and privacy controls. PK Tech builds each client's environment around the size of the firm, its compliance obligations, and the software the practice already runs on.
If you want a second set of eyes on how your firm's Microsoft 365 data is actually protected, schedule a chat.