How to set up and manage retention policies for automated cloud backups in Microsoft 365
Summary
This guide helps you troubleshoot and resolve: How to set up and manage retention policies for automated cloud backups in Microsoft 365. Follow the steps below to fix the issue.
Common Causes
Retention policies in Microsoft 365 control how long your automated cloud backups keep copies of emails, OneDrive files, SharePoint documents, and Teams conversations before they're permanently deleted. Setting these up correctly helps you stay within your storage quota, meet Australian compliance obligations (such as the Privacy Act record-keeping requirements), and ensure critical data isn't purged too early. This guide walks you through creating, editing, and monitoring retention policies through the Microsoft Purview compliance portal.
Before You Begin
You'll need a Microsoft 365 admin account with one of the following roles assigned:
- Compliance Administrator
- Compliance Data Administrator
- Organisation Management (Exchange administrators)
Have a clear idea of which workloads you want to cover (Exchange, SharePoint, OneDrive, Teams) and how long each data type must be retained. If you're unsure, check with your accountant, legal adviser, or industry body for minimum retention periods relevant to your business.
Retention policies and backup retention are different things. Your automated cloud backup (managed by 220) keeps a copy of your data for a set period. A retention policy controls when Microsoft 365 itself deletes items from mailboxes and sites. Both work together to keep your data safe.
Quick Fix Steps
- Sign in to the Microsoft Purview compliance portal at
https://compliance.microsoft.com. - Navigate to Data lifecycle management → Retention policies.
- Click + New retention policy to start the wizard.
- Name the policy, choose the scope (static or adaptive), pick the workloads (Exchange, SharePoint, OneDrive, Teams), and set a retention period.
- Review and submit, then publish the policy to your chosen users or groups.
Detailed Instructions
Step 1: Access the Microsoft Purview Compliance Portal
- Open a browser and go to
https://compliance.microsoft.com. - Sign in with your Microsoft 365 admin credentials.
- If prompted for MFA, complete the authentication on your device.
Step 2: Start the Retention Policy Wizard
- In the left-hand menu, click Data lifecycle management.
- Click Retention policies.
- Select + New retention policy from the top toolbar.
Step 3: Name Your Policy and Choose a Description
- Enter a descriptive Name, for example
7-Year Business Records Retention. - Optionally, add a Description so other admins understand the policy's purpose.
- Click Next.
Step 4: Choose the Policy Scope
You'll be asked whether the policy uses a Static or Adaptive scope.
- Static scope: You manually choose the specific users, sites, or groups the policy applies to.
- Adaptive scope: Membership is determined automatically by a query, such as all users in a particular department or location. Best for organisations with dynamic membership.
Select Static scope for most small business scenarios, then click Next.
Step 5: Select Workloads to Include
- Tick the boxes for the workloads you want to cover:
- Exchange email
- SharePoint sites
- OneDrive accounts
- Microsoft Teams chat and channel messages
- Microsoft Teams meeting recordings
- Click Next.
Step 6: Decide Whether to Retain or Delete
Choose what happens to items when the retention period ends:
- Retain items for a specific period, then delete: Items are kept for the chosen duration and then deleted automatically.
- Retain items for a specific period: Items are kept but not deleted at the end of the period.
- Delete items only when they reach a specific age: Items are removed once they hit the age threshold, with no prior retention.
Enter the retention period in days, months, or years. Common choices are 7 years for financial records or 5 years for tax-related correspondence under ATO guidance.
Once a retention policy deletes an item, it cannot be recovered from Microsoft 365. However, your 220 automated cloud backup will still hold a copy according to your backup retention schedule. Always confirm your backup retention window covers any compliance minimums before shortening a policy.
Step 7: Apply the Policy to Users, Sites, or Groups
- For Exchange: Choose All recipients, Specific recipients, or a distribution group.
- For SharePoint sites: Add site URLs individually or select All sites.
- For OneDrive: Choose All users or pick specific users.
- For Teams: Choose All teams or specific team names.
- Click Next.
Step 8: Review and Submit
- Review the summary of your selections on the final screen.
- Click Submit.
- Wait for the confirmation message. The policy can take up to 7 days to fully propagate across your tenant.
Step 9: Monitor Policy Status
- Return to Data lifecycle management → Retention policies.
- Find your policy in the list and check the Status column. It will show Pending, Success, or Error.
- Click the policy name to view deployment progress per workload.
Managing Existing Retention Policies
Edit a Policy
- In the Retention policies list, select the policy.
- Click Edit from the toolbar.
- Update the workload coverage, retention period, or scope as needed.
- Click Save. Changes apply within 24 hours to new items; existing items may take up to 7 days.
Disable or Delete a Policy
- Select the policy from the list.
- Click Disable to pause it without removing the configuration, or Delete to remove it permanently.
- Confirm the action when prompted.
Disabling a policy stops new items from being retained but does not delete items already held under it. If you want to release storage, you'll need to wait for the retention period to expire or manually purge items from the relevant mailboxes or sites.
Storage Quota Tips
- Keep an eye on your 220 backup dashboard for storage usage alerts.
- Set retention periods to match your actual compliance needs — over-retention is the most common cause of quota overruns.
- Use Adaptive scopes with query-based filters to exclude large mailboxes or inactive users from long-term retention.
- Review retention policies every six months as part of your normal compliance cycle.
Troubleshooting
Policy Won't Apply to a User
- Confirm the user is licensed for Exchange Online, SharePoint, or OneDrive as appropriate.
- Check that the user falls within the chosen scope (static recipients list or adaptive scope query).
- Allow up to 7 days for the policy to fully propagate before troubleshooting further.
- Verify the user isn't excluded by an Exchange retention hold or litigation hold.
Policy Shows 'Error' Status
- Click the policy name to view the specific error message per workload.
- Common causes include invalid site URLs, deleted users in a static scope, or insufficient admin permissions.
- Correct the underlying issue, then re-save the policy to retry deployment.
Items Deleted Too Early
- Check whether a second retention policy with a shorter period is also applying to the same content — only the longest retention wins.
- Confirm the retention period was set correctly (days, months, or years).
- Recover the item from your 220 automated cloud backup if it is still within the backup retention window.
Storage Quota Exceeded
- Review which policies are retaining the largest volumes of data.
- Shorten retention periods where compliance allows, or apply adaptive scopes to exclude inactive users.
- Check your 220 backup dashboard to confirm whether the quota relates to the backup or to Exchange Online mailbox storage.
Still Having Issues?
💻 Open a Ticket