Microsoft has been direct about a fact many Microsoft 365 customers still misunderstand: standard Microsoft 365 licences do not include a full backup solution. Versioning and recycle bins provide protection against minor accidents, not against ransomware, mass deletion, or a retention policy that quietly wipes an entire site. Microsoft’s answer is Microsoft 365 Backup, a native add-on with its own distinct, consumption-based pricing model that every organisation running a serious Microsoft 365 estate now needs to budget for separately.
How the Pricing Actually Works
Microsoft’s own documentation is precise about the mechanics. According to Microsoft Learn, Microsoft 365 Backup is a pay-as-you-go consumption-based service priced at $0.15 per GB per month of protected content, covering the summed size of protected OneDrive accounts, SharePoint sites, and mailboxes including online archives, plus any deleted or versioned data retained for recovery. Restores themselves are free, which shifts the cost conversation entirely toward how much data sits under protection at any given time, not how often it gets recovered.
One detail buried in that pricing model catches almost every organisation off guard the first time they encounter it: deleted content does not stop being billed the moment it is deleted. Because Microsoft 365 Backup retains deleted or versioned data for the length of the backup retention period, typically 365 days, an organisation continues paying for that data’s backup footprint for a full year after it disappears from the live environment, not just while it remains visible to end users.
Doing the Maths on a Real Tenant
The per-gigabyte rate sounds small in isolation, but it scales quickly once real tenant sizes are applied. Independent cost analysis walking through a typical mid-sized deployment found that protecting a modest 10-user tenant at 10 GB of data per user works out to fifteen dollars a month at Microsoft’s list rate, while a single terabyte of protected content runs one hundred and fifty dollars a month, a figure that compounds meaningfully once an organisation scales into hundreds or thousands of users with typical mailbox and SharePoint growth.
This is where the comparison against third-party backup vendors becomes genuinely useful rather than academic. Detailed vendor comparisons note that third-party Microsoft 365 backup tools typically price per user rather than per gigabyte, commonly landing in a two to seven dollar per user per month range depending on vendor, retention period, and feature set, meaning the two pricing models favour different tenant profiles. A lean tenant with aggressive data lifecycle management and low per-user storage volumes tends to do better on Microsoft’s native per-gigabyte model. A data-heavy tenant, particularly one in a consultancy or professional services environment with large SharePoint document libraries, often finds a per-user third-party price more predictable and, at scale, cheaper.
The Storage Economics Nobody Compares Directly
It is worth situating Microsoft 365 Backup’s per-gigabyte rate against how Microsoft prices storage elsewhere in the same ecosystem, because the gap is instructive. A breakdown of Microsoft 365’s built-in SharePoint storage economics found that Microsoft’s own Extra File Storage add-on for SharePoint runs at roughly twenty cents per gigabyte per month once an organisation exceeds its pooled allowance, a rate around twenty-five times higher than equivalent raw object storage sitting outside the Microsoft ecosystem. Microsoft 365 Backup’s $0.15 per gigabyte sits in a broadly similar premium tier, reflecting the convenience of staying inside the Microsoft compliance and security boundary rather than any inherent cost of the underlying storage itself.
None of this makes Microsoft 365 Backup the wrong choice. Speed of recovery, native integration with the existing Microsoft 365 admin experience, and staying inside the same compliance boundary as the rest of the tenant are real advantages that a cheaper third-party or raw-storage alternative does not automatically replicate. The point is that the premium being paid for those advantages should be a conscious decision, not an assumption nobody checked.
Why Restores Being Free Changes the Conversation
Most legacy backup pricing models charge something for the restore itself, whether through a support tier, a data egress fee, or a per-incident charge. Microsoft 365 Backup’s decision to make restores entirely free removes a cost variable that has historically made disaster recovery budgeting harder to predict, since organisations no longer need to factor in how many restore events a bad year might generate on top of the standard storage fee.
This matters most in a genuine incident scenario, where the instinct to minimise cost by restoring only the minimum necessary data can work against a faster, more complete recovery. Because the storage fee is already being paid regardless of how much gets restored, there is no cost argument for restoring conservatively during an actual ransomware or mass-deletion event. Speed and completeness of recovery should be the only considerations once an incident is underway, and the pricing model is structured to support exactly that.
The Shared Responsibility Point Most Buyers Miss
Underneath the pricing conversation sits a legal and operational point that Microsoft has been increasingly explicit about: under the Microsoft Services Agreement and the Shared Responsibility Model, the organisation, not Microsoft, owns its Microsoft 365 data. If a retention policy misfires, a user deletes a critical site, or an attacker encrypts a mailbox, Microsoft’s obligation to help recover that data is bounded by the built-in recycle bin and versioning windows, typically somewhere between thirty and ninety-three days, not an indefinite guarantee.
That gap is precisely the commercial rationale behind Microsoft 365 Backup’s existence, and it is worth stating plainly to any internal stakeholder who assumes Microsoft’s cloud infrastructure inherently protects against every form of data loss. It does not, by design, and the backup add-on is Microsoft’s own answer to a gap the base licence was never built to close.
Retention Policy as a Cost Control Lever
Because Microsoft 365 Backup bills based on the total protected footprint rather than a flat per-user fee, an organisation’s underlying data retention discipline has a direct and often underappreciated effect on the backup bill itself. A tenant that has never enforced retention limits on mailboxes, allowing years of accumulated email and attachments to sit indefinitely, will see a proportionally larger backup bill than one with active archiving and deletion policies, independent of how many users either tenant has.
This creates a genuine incentive to treat data lifecycle management and backup cost planning as connected disciplines rather than separate projects owned by different teams. Cleaning up genuinely obsolete data before expanding backup protection scope is often cheaper and faster than negotiating a better backup rate after the fact, and it reduces exposure on both the storage bill and the backup bill simultaneously.
Comparing Native Backup Against a Hybrid Approach
Not every organisation needs to choose exclusively between Microsoft’s native backup and a third-party alternative. A hybrid approach, using Microsoft 365 Backup for fast, native recovery of recent data while routing older or less business-critical content to a cheaper long-term archive outside the per-gigabyte backup rate, can capture most of the speed advantage while avoiding the full cost of protecting an entire multi-year data footprint at Microsoft’s premium rate indefinitely.
This kind of tiered approach requires more upfront design work than simply turning on Microsoft 365 Backup and protecting everything by default, but for data-heavy tenants it is often where the largest sustainable savings sit, particularly once an organisation’s SharePoint and mailbox footprint grows well beyond what it looked like when the backup policy was first configured.
Setting Expectations With End Users Before Rollout
A backup rollout that arrives without any communication to end users tends to generate its own quiet cost problem: employees who assume the new backup protection means old advice about clearing out unnecessary files and mailboxes no longer applies. The opposite is closer to true. Because protected storage volume drives the bill directly, a backup rollout is actually a good moment to reinforce good data hygiene practices, not abandon them, since every gigabyte of genuinely unnecessary data that gets cleaned up before backup protection is applied is a gigabyte that never needs to be paid for at all.
Framing the rollout that way, as an opportunity to pair better protection with better housekeeping rather than as a reason to stop caring about storage discipline, tends to produce a leaner and more cost-effective backup footprint from the outset than rolling out protection silently and hoping data volumes stay manageable on their own.
Right-Sizing Protection Instead of Backing Up Everything
Because Microsoft 365 Backup charges only for what is actively placed under a protection policy, the most direct lever available to control cost is being deliberate about what actually needs backup-grade protection versus what is adequately served by existing versioning and retention policies. Not every SharePoint site or shared mailbox in a large tenant carries the same business criticality, and treating them all identically for backup purposes is the fastest way to inflate the monthly bill unnecessarily.
A practical starting point is auditing which sites, mailboxes, and OneDrive accounts genuinely warrant backup-grade recovery guarantees, protecting those deliberately, and revisiting that list on a recurring basis as the organisation’s data footprint grows rather than protecting everything by default and never reviewing the scope again.
That review is also the right moment to check whether any sites or mailboxes currently under protection have become dormant since the policy was last set, since data belonging to a departed employee or a decommissioned project rarely needs the same backup-grade guarantee as active, business-critical content, yet frequently remains protected purely because nobody remembered to remove it from scope.
Conclusion
Microsoft 365 Backup closes a real gap in what standard Microsoft 365 licensing actually protects against, but its consumption-based pricing model rewards organisations that scope protection deliberately and punishes those that back up everything without a second look. The per-gigabyte rate is transparent. What it adds up to across a real tenant, and how it compares against third-party alternatives at that specific organisation’s data profile, is where the actual decision needs to be made.
Getting this right means running the numbers against real tenant storage data before committing, understanding that deleted content keeps billing for a full retention cycle, and treating backup scope as a deliberate, periodically reviewed decision rather than a default setting left untouched since deployment.