Back to Blog

Microsoft deleted data before the window closed, and cannot say which

Microsoft deleted data before the window closed, and cannot say which

What cannot be recovered is serious. What cannot even be listed is something else. On 28 September 2026, The Register reported that Microsoft had deleted data from expired subscriptions under its nonprofit programme before the retention window had closed, that recovery attempts had failed, and that it was currently unable to tell each organisation which data may have been deleted — not even whether anything of theirs had been.

The context is an ordinary product retirement. The Microsoft 365 Business Premium grant for nonprofits —ten free licences— was announced as discontinued at the next renewal on or after 1 July 2025, with the usual advice: move users onto another plan before cancellation, or export whatever you want to keep. Nothing controversial. What failed was the clock. In an email to one affected organisation, Microsoft acknowledged that, "due to an error", it had deleted the remaining data before the retention and export window closed. The compensation on offer is a free session with a specialist to set up the new environment.

That window which failed is, for a great many small companies, the only safety net they have when a subscription ends. And for years now it has been shorter and more conditional than people assume. Let us read it in full.

The official countdown, and its asterisk

The Microsoft Learn page describing what happens when a business subscription ends (revision of 8 June 2026) defines four states and chains them like this: Active > Expired > Disabled > Deleted. For most offers and countries, 30 days in Expired and 90 days in Disabled. In Expired everyone carries on working as normal. In Disabled, users stop signing in and data becomes accessible "to admins only": the administrator can still get it out. Then Deleted, which the same table describes as "Data is deleted and Microsoft Entra ID is removed, if not in use by other services".

A hundred and twenty days. That is the number most people in the industry carry in their heads, and it is a fair one. What tends to go unread is the asterisk the table itself puts on Expired and Disabled: "For most offers, in most countries/regions". It is not a service commitment with a penalty behind it. It is a description of the product's usual behaviour, with the margin declared in writing.

And the same page, in its first paragraph, before any table, says this: "If you're leaving Microsoft 365, we recommend that you back up your data before it gets deleted". Whoever writes the product documentation already knows what the counter is for. The counter is the time you have to get things out, not a warehouse.

The counter had already been shortened, and the table never found out

On that same page there is a short note, the kind you read in ten seconds and that changes a figure many people treat as fixed: "As of February 9, 2026, the Expired lifecycle state no longer applies to license-based subscriptions bought directly through a Microsoft Customer Agreement (MCA)".

If you buy by licence, direct from Microsoft under a Customer Agreement, that state no longer exists for you. The note does not say what chain is left, nor how many days: the duration table on the same page still says 30 plus 90 for "all subscription terms", with no written exception. Read literally, the 30 days of Expired disappear and the 90 of Disabled remain — that subtraction is our reading, not a figure Microsoft publishes. And the thirty that go are precisely the ones during which users were still signing in normally, which is to say the ones during which somebody in the organisation would have noticed that something was happening. What remains is the stretch only the administrator can enter. The same administrator who, in a small organisation, is very often the person who has already left.

And let us be fair about the nuance, which is on the same page and to which the note itself points: for subscriptions bought under an MCA billing account there is the Extended Service Term, which gives additional time at the end of the term "without any service disruption" until you cancel or convert. Put another way: the cushion does not disappear, it stops being automatic. What used to be there by default now has to be asked for, and whoever does not ask is left with the short chain.

The counter, besides, is not one counter but several. Buy through a volume licensing programme on a multi-year term and you get 90 days of Expired plus 90 of Inactive, not 30 plus 90. Buy through a CSP and you are governed by the Partner Center lifecycle states, which are different again. The documentation itself warns that durations "might differ" and that you should confirm them with your partner or account team. Which means the question "how many days do I have?" has no general answer. It has a per-contract answer, and it is worth knowing before you need it.

There is a button that zeroes it

The countdown is fragile for a reason that predates the September error: the product itself offers documented shortcuts around it, and every one of them is triggered from the admin centre as easily as changing a plan:

  • ·Deleting the subscription by hand. "If you explicitly delete a subscription, it skips the Expired and Disabled statuses and SharePoint Online data and content, including OneDrive, is immediately deleted". No 30, no 90. It is immediate, and it takes the SharePoint sites and the OneDrives with it.
  • ·Cancelling inside the cancellation window. The subscription "moves directly to the Disabled status". You skip the first 30 days. And whatever is left inside "might be deleted after 90 days and will be deleted no later than 180 days after cancellation".
  • ·Letting a trial die. "After the trial ends, your trial account information and data are permanently deleted". If somebody spun up a trial of something and put real documents in it —which happens more than you would think— there is no counter there at all.
  • ·Re-subscribing undoes nothing. "If a subscription is deleted, adding a new subscription of the same type doesn't restore the data that was associated with the deleted subscription". The reflex of "I will just pay again" does not work.

None of these four points is a defect. They are written down, they are coherent, and they are probably what most customers want most of the time. The problem is of a different order: four separate roads lead to "the data is gone", and all four are travelled without anyone signing anything. We already wrote about what happens when the clock depends on a specific licence staying alive in the tenant when we covered the Project Online retirement, which had a deletion counter of its own; this post is about something else, the generic counter sitting underneath every subscription.

The damage nobody counts: there is no list

Back to the case. What should really cost you sleep, beyond the data not being recoverable, is that Microsoft said it is currently unable to provide a list of which data may have been deleted, nor to confirm to any given organisation whether it lost anything at all. The wording matters: this is not a refusal, it is a "right now we cannot", and at this point that is still where things stand.

If those mailboxes and OneDrives held personal data —and in an organisation with members, donors or service users, they did— then we are looking at what article 4(12) of the GDPR defines as a breach: "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed". Accidental destruction. It is literally in the definition. There does not need to be an attacker: losing the data is a breach just as leaking it is.

And then two obligations arrive pointing in awkward directions. Article 33(1) requires notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to people's rights and freedoms. And there is the joke: to decide whether it is unlikely, you have to know what was lost. Article 33(5) is the one that hurts here: the controller "shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken". The facts and their effects. Which is to say: what was lost, whose it was and how much of it. That is the sentence that turns "I have no copy" into a legal problem and not merely an operational one, because without a source of your own there is no way to reconstruct the scope. The controller is you; the processor is the provider. And the processor has just said it does not have the list.

Which produces the idea we repeat every time we hand over a tenant, and that this case teaches better than any sales deck: an external copy is not only the ability to restore; it is the only inventory of what you had. Last night's backup catalogue —mailboxes, sites, item counts, dates— is the document you answer article 33(5) with. Without it, your answer to the supervisory authority starts with "we do not know", and that sentence does not improve with time.

Deleting at the end of service is the clause

It is worth saying plainly, because the headline invites the opposite. A provider deleting your data when the service ends is not negligence: it is exactly what article 28(3)(g) of the GDPR requires of a processor, which shall "at the choice of the controller, delete or return all the personal data after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage". A provider that kept departed customers' data indefinitely would be in breach.

What failed in September was the when, not the what. And that distinction matters for deciding what you do on Monday. If the problem were "Microsoft is careless", the answer would be to switch providers, and it is not: any serious processor has the same clause and the same button. If the problem is "my only copy lives inside the system that is contractually obliged to delete it", the answer is to put a copy outside. A far less epic conclusion, and a considerably more useful one.

Five questions we ask when we come into a tenant

This is what we review in a tenant when we come in, and what we leave written in the handover. Five questions with a concrete answer or no answer, and the ones without get recorded as such.

What gets asked Why, and what happens if there is no answer
Purchase channel and end date of each subscriptionDirect under MCA, CSP or volume licensing: each has a different counter. Without this you do not know whether you have 90 days or 180.
Which mailbox the renewal notices reachAlmost always an admin account nobody reads. And that account lives inside the tenant being switched off: the warning that you are losing access arrives somewhere you no longer go.
Which workloads the copy coversExchange, SharePoint, OneDrive and Teams do not travel together by default; with the native backup it is a separate checkbox per workload. "We have 365 backup" is not an answer.
Where the copy lands and who can delete itIf it lives in the same tenant, it shares that tenant's fate. And if it is "immutable", you have to look at the mode, the retention period and who can override it, which is what that word actually means.
Can you print today the list of what you hold?Mailboxes, sites, item counts and a date. It is the check almost nobody asks for and the only one that lets you answer article 33(5) on the bad day.

The limits of what we have just said

We do not know how many organisations were affected: no figure has been published; what the coverage does report is that Microsoft cannot determine exactly which information was involved. As of 4 October 2026 we are not aware of any public incident report from the vendor itself on this case; what is known comes from correspondence with affected organisations reported in the press, and we treat it as such. This concerns one specific nonprofit grant programme, it is not a general Microsoft 365 failure, and it would be dishonest to sell it as one. The day counts we have quoted come from the documentation as revised on 8 June 2026 and can change: the page that governs is the one for your contract, not this post.

And the conflict of interest up front: everyWAN sells managed Microsoft 365 backup. A post that ends by saying "get an external copy", written by the people who sell it, should be read with that caveat. The verifiable part is what we have quoted; the rest is our judgement, and you can apply it with us or without us.

Sources (verified on 4 October 2026): the early deletion of data from expired subscriptions under the nonprofit programme, Microsoft's acknowledgement that it happened "due to an error", the impossibility of recovering the data and the statement that it is currently unable to provide a list of which data may have been deleted, and the free "concierge" session offered — original reporting by The Register (28 September 2026), picked up by TechRadar Pro (1 October 2026) and ITdaily (29 September 2026). The lifecycle statuses (Active > Expired > Disabled > Deleted), the 30 and 90 day durations with their "For most offers, in most countries/regions" note, the 9 February 2026 note on the Expired state and Customer Agreements, the Extended Service Term for MCA billing accounts, the volume licensing durations, the immediate deletion of SharePoint and OneDrive when a subscription is explicitly deleted, the 90/180 day window after cancellation, the permanent deletion when a trial ends and the sentence "we recommend that you back up your data before it gets deleted" — "What happens to my data and access when my Microsoft 365 for business subscription ends?", Microsoft Learn, revised 8 June 2026. Articles 4(12), 28(3)(g), 33(1) and 33(5) — Regulation (EU) 2016/679 (GDPR). Cover photograph: "LTO-6 tape drive & IBM TS3500 slots", by vaxomatic, Wikimedia Commons, licensed CC BY 2.0.

Can you say today what is inside your tenant?

Not how many gigabytes: which mailboxes, which sites and how many items, with a date. That list is not produced by a dashboard on the day you need it; it is produced by a scheduled copy that runs outside the tenant — which is what we do in Backup 365. And writing down who looks at it, how often a restore gets tested and which document you answer with inside 72 hours is compliance and continuity, not paperwork.

Talk to everyWAN

Tags:

Share:

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN