Deleted content in OneDrive and SharePoint passes through two stages before it is
unrecoverable. Knowing which stage an item is in tells you how much time you have.
The two stages
| Stage | Where | Default retention |
|---|---|---|
| First stage | The user's or site's recycle bin | 93 days from deletion |
| Second stage | Site collection recycle bin (admin) | The remainder of the same 93 days |
The 93 days is counted from the original deletion, not from when the item moved
to the second stage. Emptying the first-stage bin moves items to the second; it does
not restart the clock, and it does not buy more time.
After 93 days the item is gone as far as the service desk is concerned.
Files nobody deleted
Not everything in a recycle bin was deleted by a person. Check the Deleted by
column:
- Meeting expiration service — a Teams recording reached its auto-expiry date.
- Retention policy — a compliance policy acted on the item.
- Sync client — a local delete propagated from a device, sometimes long after
the user forgot doing it.
- A named user — an actual deletion, which may or may not have been intended.
That column frequently answers the ticket on its own.
Restoring
- Restore returns the item to its original path with its original URL, so links
in chats, documents and emails start working again. Copying the file out instead
produces a new URL and leaves every existing link broken.
- Permissions restore with the item.
- Restoring a folder restores its contents.
- If something already occupies the original path, resolve that first — a restore
into an occupied path produces a duplicate, not a merge.
Version history is a separate lifeline
A file that still exists but has been damaged, overwritten, or encrypted does not
need the recycle bin — it needs version history. Every library keeps previous
versions by default. This is the fastest route back for "someone saved over my work"
and for the early stages of a ransomware event, where the files are present but
their contents are not.
Restore this library
For bulk damage — a mass delete, or a sync client that removed a large tree —
Restore this library rolls a whole library back to a point in time within the
last 30 days. Prefer it to restoring thousands of items individually.
Related
- Where Teams meeting recordings are stored
- OneDrive Files On-Demand and local disk space