Microsoft has admitted it deleted data belonging to nonprofit customers before the retention period had expired, that it cannot be recovered and that — this is the bad part — it cannot say what was deleted, or even whether a given customer lost anything at all. The Register has the story, with the email to one affected customer in hand and confirmation from the company itself.
What happened
The context is a change to a commercial programme. Microsoft used to grant eligible nonprofits ten free Microsoft 365 Business Premium licences. In May 2025 it announced the grant would not renew after 1 July that year, replacing it with up to three hundred free Business Basic licences plus discounted pricing on other plans, Business Premium included. You can see the current terms on its nonprofits page.
The notice said what these notices usually say: move your users onto another nonprofit plan before the subscription is cancelled, and export anything you don't intend to keep inside Microsoft 365. So far, a normal, well-communicated licensing change.
The trouble came after deactivation. According to the email Microsoft sent one affected customer, "due to an error" the remaining data was deleted before the retention and export window had closed. They looked into recovery options and found none. And on top of that:
We are currently unable to provide a list showing which data may have been deleted or whether any data was deleted at all.
Microsoft confirmed the premature deletion and said the affected content would have been data tied to expired Business Premium subscriptions. It has not said how many organisations were hit, how early the deletion happened, or what caused the error. By way of remedy it is offering a free concierge service: a meeting with a specialist to help set up the new environment and answer questions. Useful if what you need is a new environment. Rather less so if what you wanted was what was in the old one.
Why it matters
The retention period is not a backup
This is my takeaway. We have all leaned on the provider's grace window at some point: "if it gets cancelled there are ninety days to reactivate and export". That window is a commercial courtesy governed by billing processes, not a recovery guarantee. And billing processes get touched: a licensing programme changes, a grant is retired, a SKU catalogue gets migrated, and somewhere in the middle an automated job decides which tenants count as "terminated". An error there deletes for real.
The working rule: if a piece of data only still exists because the provider hasn't got round to deleting it, that data isn't backed up. It's queued for deletion.
The dangerous moment is the plan change, not the outage
I wrote recently about the AWS incident in Bahrain, and the lesson was similar: some data doesn't come back. But there the trigger was an infrastructure failure. Here the trigger is administrative, which is worse, because nobody puts it in the risk register. Nobody writes a contingency plan for "our licensing programme changed".
If you look after someone else's systems, these are the events that should trigger a full, verified copy:
- The end of a promotion, grant or discount.
- A downgrade or a reduction in seats.
- A change of partner or payment method.
- A tenant merger or migration.
- Any email from the provider containing the words "retirement" or "will not renew".
In every one of those cases an automated process is touching the lifecycle of your data. And that process has no idea who you are.
If you don't know what you had, nobody is going to tell you
The part that should sting most for anyone running systems isn't the deletion: it's that the provider can't enumerate what was lost. Which means that even if you wanted to complain, you don't have the list. The only way to know what's missing is to have kept the inventory yourself.
That is cheap to do and almost nobody does it. A periodic listing of mailboxes and their sizes, of SharePoint sites, of OneDrive libraries per user, of Teams and their channels, stored outside the tenant itself. It isn't the data: it's the index of the data. With that you can say "forty-one mailboxes and three sites are gone" instead of "we think something is missing".
What I'd do this week
- A real export, not faith in retention. Copy mailboxes, OneDrive, SharePoint and Teams to storage that doesn't depend on the same invoice or the same identity provider.
- A restore test. Pick a mailbox at random and bring it back. A copy that has never been restored is a hypothesis.
- A dated, signed inventory, kept outside.
- An alert on the billing inbox. Plan-change emails aren't administrative noise: they're technical risk notices. Make sure someone who understands what gets deleted reads them.
- If you manage small charities or nonprofits, check today whether any of them sat on an expired subscription instead of migrating it. That's where this landed.
What doesn't change
Let's be fair, because it's easy to overreach here. Microsoft gave notice well in advance, offered a free alternative with far more licences, and explicitly asked customers to migrate before cancellation. Anyone who moved their users in time has no problem. The failure is in the last stretch of the process, not in the communication.
We also don't know how big this is. There's no figure for affected organisations, none for how early the deletion happened. It could be a handful or a lot more; from what's been published you can't claim either, and anyone telling you "Microsoft deleted nonprofits' data" is saying more than the facts support.
And this is not an argument for going back to the server in the cupboard. The cloud still loses less data than an unmonitored NAS in the meeting room. What falls apart is a different idea, a more comfortable and more false one: that the provider is also your backup. It isn't, it never said it was, and this case proves it in the worst possible way — by not being able to tell you what you've lost.
Any questions, tell me and we'll go through it.
All the best, Vicente.
