Microsoft 365 Backup Costs: An SMB Budget Checklist

Budget beyond live storage. Understand Microsoft 365 Backup’s protected-data charges, recovery windows, preview policy scope, billing ownership, and exit costs before enabling pay-as-you-go protection.

Back to Blog
10 min read
ITECS illustration showing live content and retained history together under the instruction Budget both.

Microsoft 365 Backup looks simple to price: multiply protected storage by a monthly rate. The budget gets harder when an old mailbox has a large online archive, deleted files remain recoverable, or a policy automatically adds newly created sites.

Microsoft’s native service lists US$0.15 per GB per month of protected content, using pay-as-you-go billing rather than a flat charge per employee. Verify your applicable currency and commercial terms before approving spend. This guide concerns the native Microsoft 365 Backup service, not every third-party product with “Microsoft 365 backup” in its name. Microsoft’s product and pricing page describes that distinction.

The practical decision: approve a protection scope, recovery window, billing owner, and monitoring process together. A calculator estimate is a planning input—not a guaranteed invoice or proof that every important workload is recoverable.

Start with what Microsoft actually counts

Microsoft’s charge model includes these components:

  • SharePoint and OneDrive: protected site/account usage, including the first-stage recycle bin, plus deleted content in the second-stage recycle bin.
  • Exchange: protected user/shared mailboxes and associated online archives, plus deleted and versioned mailbox items retained for recovery.

Do not treat all “versions” as a separate identical charge across workloads, or multiply live storage by the number of restore points. Use Microsoft’s workload-specific accounting. Admin-center usage reports omit second-stage recycle bins and online archives; those need separate measurement. The native charge model adds no separate Azure API or storage fee.

When a unit leaves protection, its removal-time size becomes the ongoing live-size proxy. Retained deleted/versioned content stops contributing when its backup expires. Consequently, deleting live content is not an immediate equivalent reduction in the bill.

Microsoft also cautions that its calculator is an estimate; the basic twelve-month projection assumes no growth or churn. Do not interpret that output as a fixed annual quote.

Build a scope inventory before enabling protection

Our recommended worksheet has one row per mailbox, OneDrive account, or SharePoint site—not merely one row per employee. Record the business owner, department, live size, additional billable-content measurements, proposed policy, recovery need, and billing policy. Include shared mailboxes and former employees’ records in the review rather than assuming they disappear from the financial picture.

Use a consistent collection date and GB convention. Mark missing measurements as unknown, not zero. Ask the administrator to reconcile report exports with approved read-only measurements; finance should not need private mailbox content to understand aggregate costs.

For each proposed exclusion, write down the reason and who accepts the recovery risk. A smaller number on a spreadsheet is not a saving if it quietly removes the only practical recovery path for a customer-facing process. Review the plan alongside your broader backup and disaster recovery requirements.

Choose the recovery window deliberately

Microsoft now documents policy recovery windows of 3 months, 6 months, 1 year, or 2 years; existing policies retain the one-year default unless changed. Its September 18, 2026 feature update confirms these choices.

The policy documentation states that a shorter window deletes older recovery points after a 30-day grace period. Moving content into a shorter-window policy can also trigger that reduction. Removed units retain their last assigned recovery window.

Choose the window by asking how long an unnoticed deletion, overwrite, or compromised workflow might go undetected. Balance that need against retained-data cost and contractual obligations. Do not assume that doubling the window exactly doubles the invoice, or that shortening it creates an immediate proportional saving. Live protected data, historical changes, and expiration timing all matter.

Some Microsoft FAQ examples still describe one-year retention. For planning, use the specific configurable-window documentation and confirm the effective setting in your tenant, rather than applying a one-year example to every policy.

Treat Full Workload Backup as a scope change, not a free convenience

Full Workload Backup remains in preview. Microsoft says it can cover eligible SharePoint sites, OneDrive accounts, or Exchange mailboxes outside custom policies, checking for newly eligible items every 24 hours. That means onboarding more data can expand consumption without someone selecting each item manually. See the current feature status.

Under the Full Workload policy rules, custom policies take precedence, including paused ones. Exclusions apply only to Full Workload Backup; an excluded item can still be protected by a custom policy. Removing an exclusion makes the item eligible again. When removing an item from a custom policy, explicitly decide whether it should move into Full Workload Backup or be excluded.

Before enabling the preview, compare the eligible inventory with your approved scope, document exceptions, and nominate someone to review newly protected data. “Full workload” does not mean every Microsoft 365 service or every object type is supported. Microsoft lists room/group mailboxes, hybrid Exchange deployments, and certain SharePoint site templates among its current limitations. Inventory those gaps separately and confirm tenant availability before making the preview a dependency.

Assign the payer and the administrator separately

The Billing setup guide requires an Azure subscription in the Microsoft 365 tenant, a resource group, and Owner or Contributor permissions on both, alongside a supported Microsoft 365 administrator role. The setup flow also requires at least one SharePoint-containing license. Confirm the exact prerequisites for your tenant rather than granting broad rights by default.

Record the subscription, resource group, billing policy, invoice owner, cost-review owner, and operational backup administrator. Avoid a design in which one departing employee is the only person who can review charges or manage protection. Approve who may expand scope and who must sign off on destructive changes.

Microsoft’s Backup setup guidance distinguishes the newer Billing experience from older Setup/Org settings arrangements and documents migration for existing customers. Verify the actual tenant experience. Do not create duplicate billing arrangements simply because a screenshot uses a different menu.

Use departmental billing when it clarifies accountability

Departmental billing can associate backup policies with different Azure subscriptions. When its access restrictions are enabled, administrators need the applicable Azure Owner/Contributor rights to create or edit backup policies using that billing policy. This is a spending and administration boundary, not merely a report label.

For a small company, one centrally owned billing policy may be easier to operate. A multi-entity business may need separate financial responsibility. In either case, establish how shared sites and shared mailboxes are allocated; do not pretend every cost belongs neatly to one user.

Microsoft’s billing documentation supports cost analysis by tenant and workload, with protection-unit attribution. Exchange mailbox-level attribution requires explicit administrator consent; review that privacy decision before enabling it. Keep finance reports aggregated where individual identifiers are unnecessary.

Forecast a range, then reconcile it to actual consumption

Use a base case, a growth case, and an expansion case. The expansion case should include planned hiring, new collaboration sites, acquired data, archives, and any move from selected protection to Full Workload Backup. Assign assumptions to owners and dates so they can be challenged later.

Illustrative arithmetic, not a customer quote: suppose your reconciled billable amount remains 2,000 GB throughout a month. At the published list rate, the storage line would be approximately $300. At 2,500 GB it would be approximately $375. The additional 500 GB changes that simplified monthly estimate by $75.

Those figures assume a constant volume and rate. They exclude taxes, currency or commercial adjustments, and your organization’s administration, testing, support, and incident-labor costs. They are not a model of daily metering or a promise that today’s usage will persist for a year.

Do not add the same data twice: document which reported total already contains a recycle-bin or version component before adding another estimate. Likewise, do not count an assumed future deletion as an immediate saving. Keep a separate line for content removed from active protection but still within its recovery lifetime.

Set alerts—but do not mistake them for a spending cap

Microsoft’s billing-policy budget guidance says budgets apply at policy level, not per individual site or user. Consumption graphs can lag by up to four hours, and alert delivery can take up to 24 hours. Reaching 100% does not stop service or billing.

Route alerts to a monitored group with a named primary and backup owner. Choose warning thresholds early enough for a review, and document the response: check new scope, reconcile unusually large units, review growth, and authorize a deliberate change if needed. Avoid an automated “disconnect billing” reaction that could endanger recoverability.

During the first billing cycle, review usage more frequently than the eventual monthly meeting. Treat a blank or delayed chart as something to reconcile, not evidence that protection is free.

Budget for restoration, not just storage

Microsoft lists native restores as free, but that does not make the business recovery exercise costless. Its service overview also explains that backups remain within the Microsoft 365 data trust boundary. Do not describe the service as an independent off-platform copy.

Our recommended pilot uses representative Exchange, OneDrive, and SharePoint content with authorization and a safe test destination. Check what was recovered, permissions, version expectations, elapsed time, and business-owner acceptance. Avoid destructive in-place tests against live working data merely to complete a checklist.

Allow time for selecting a healthy recovery point, investigating an incident, coordinating users, validating restored work, and documenting exceptions. Record who can perform a restore and who approves it. A successful small-file test is useful evidence, but it does not establish the duration of a tenant-wide recovery.

Keep backup, retention, and exit planning distinct

Retention rules govern preservation and disposal requirements; backup addresses recovery to an earlier usable state. Microsoft states that Purview retention/deletion policies do not determine Backup’s recovery window. Its architecture guidance treats those policies separately. Review both with your records owner instead of assuming one setting satisfies every recovery and compliance obligation.

Removing a unit from protection without moving it into another policy stops new backups. Existing backups remain for their applicable lifetime and continue to incur charges. That is different from permanent offboarding. Microsoft’s offboarding guidance says disabling the tool—or an unhealthy billing account—can start the process of deleting policies and backed-up data. Specific-unit deletion has a separate workflow and recovery/undo safeguards.

Before changing providers, require a written exit plan: replacement coverage, an approved overlap budget, evidence that required records remain accessible, owner signoff, and confirmation of the remaining billable period. Do not assume old restore points transfer to another product. Check the current grace-period terms before approving deletion; do not use a grace period as your migration strategy.

The monthly budget review checklist

  • Finance: reconcile actual charges, forecast, invoice scope, and remaining budget.
  • IT: compare active, excluded, removed, and newly protected units with the approved inventory.
  • Business owners: explain new data, department moves, acquisitions, and changed recovery needs.
  • Records and risk owners: review proposed recovery-window reductions and deletion decisions.
  • Backup administrator: present restore-test results, unresolved gaps, and the next test date.
  • Service owner: approve any policy expansion, cost allocation, or exit action and retain the decision record.

The objective is not the cheapest-looking calculator result. It is a defensible budget for a protection scope your business understands and a recovery process it has actually tested.

ITECS can help frame the planning discussion across Microsoft 365 administration, recovery requirements, and operational ownership. Contact ITECS to discuss your backup budget and coverage needs; share aggregate inventory and requirements, not passwords or sensitive mailbox content.

Research checked September 30, 2026. Prepared by ITECS Team with AI-assisted research and drafting. Product facts are linked to Microsoft documentation; worksheets, scenarios, and review practices are ITECS editorial recommendations. Prices, preview availability, and tenant interfaces can change. Confirm current terms and effective settings before enabling protection or deleting recovery data.

continue reading

More ITECS blog articles

Browse all articles

About ITECS Team

The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.

View full profile and articles

Share This Article

Continue Reading

Explore more insights and technology trends from ITECS

View All Articles