
OneDrive cloud deletions may no longer leave an additional copy in the Windows Recycle Bin. Users should check the online Microsoft 365 Recycle Bin first, understand SharePoint two-stage recovery, and confirm that synchronisation is not treated as backup.
You open File Explorer. A folder has gone. It could contain client contracts, finance spreadsheets, tender documents, project files, HR records, design work or management reports. The instinct is to open the Windows Recycle Bin.
Historically, where an online deletion was synchronised down to a Windows computer, the OneDrive sync client could place the locally held copy into the Windows Recycle Bin. Depending on when and how the file was deleted, it might appear there alongside the cloud recovery options. That additional local fallback is changing.
Microsoft announced through Message Centre notification MC1269861 that the OneDrive sync client would be updated so that cloud-originated deletions no longer place an additional copy in the Windows Recycle Bin or macOS Trash. The change began rolling out in May 2026. At the time of writing (July 2026), the notification is archived, indicating the rollout period has passed.
If a synchronised cloud file disappears, do not limit your search to the Windows Recycle Bin.
The recovery location is changing—not necessarily the ability to recover the file.
The Quick Answer
If a synchronised OneDrive or SharePoint file has disappeared, check the online Recycle Bin first.
For a OneDrive file: sign in to OneDrive on the web; open Recycle Bin; search for the missing file or folder; check the deletion date and original location; select Restore; confirm it returns to the expected location.
For a SharePoint or Teams file: open the relevant SharePoint site or Teams file location; open the site Recycle Bin; restore the item if it is present; ask an authorised site administrator to check the second-stage Recycle Bin if necessary.
- 1STOP — do not recreate, rename or move large numbers of files.
- 2CHECK ONLINE — open the relevant OneDrive or SharePoint location in a browser.
- 3CHECK THE CLOUD RECYCLE BIN — not only the Windows Recycle Bin.
- 4CHECK VERSION HISTORY — if the file still exists but its content is wrong.
- 5ESCALATE — if many files are affected, treat it as a security incident.
Do not empty any cloud or local Recycle Bin while recovery is being investigated.
What Microsoft Changed
When a file stored in OneDrive for Business or a synced SharePoint library was deleted from the cloud (for example, in a browser or by another user), the OneDrive sync client on a connected Windows computer would previously remove the locally synchronised copy. On many devices, that local copy was placed into the Windows Recycle Bin before it was removed from the synchronised folder.
This created several side-effects: duplicate recovery locations; large numbers of cloud files accumulating in the Windows Recycle Bin; additional local disk use; confusion about which copy was authoritative; and, most importantly, an impression that the Windows Recycle Bin held an independent backup copy.
Microsoft notified customers via Message Centre notification MC1269861 that this behaviour would change. When the update is applied, a cloud-originated deletion removes the local synchronised representation without placing it into the Windows Recycle Bin or macOS Trash. The deleted item continues to follow the Microsoft 365 online deletion and recovery process. The first-stage Recycle Bin in OneDrive or SharePoint remains the expected recovery location.
Microsoft is removing a duplicate local deletion artefact, not announcing the end of cloud file recovery.
The change applies to cloud-originated deletions synchronised to the local device. Local deletions initiated in File Explorer have historically behaved differently — those deletions generally send the local copy to the Windows Recycle Bin and synchronise the deletion to the cloud. The exact behaviour for local deletions may depend on client version and synchronisation state. Verify current Microsoft guidance if your organisation relies on that distinction.
The exact scope of the change — including which account types, platforms, sync-client versions and deletion scenarios are definitively affected — should be verified against current Microsoft release notes and your own tenant behaviour. The brief instruction in this area from Microsoft states that both Windows and macOS devices are affected for cloud-originated deletions.
Windows Recycle Bin Versus OneDrive Recycle Bin
The Windows Recycle Bin and OneDrive Recycle Bin are separate recovery systems.
| Windows Recycle Bin | OneDrive Recycle Bin | |
|---|---|---|
| Location | The Windows computer | Microsoft’s cloud service |
| Designed for | Supported deletions from local file-system volumes | Deleted OneDrive items |
| Access | Desktop or File Explorer | OneDrive on the web or supported controls |
| Scope | That computer and supported local volumes | The relevant OneDrive account or SharePoint site |
| Retention | Affected by local size limits, settings and manual emptying | Depends on account type, tenant settings and Microsoft service rules |
| Protection | Not an organisational backup | A temporary recovery mechanism, not a complete backup |
Following the MC1269861 change, a cloud-originated deletion may no longer create an additional entry in the Windows Recycle Bin. The Windows Recycle Bin should not be treated as a recovery location for cloud files.
What Happens When a OneDrive File Is Deleted
The outcome depends on where and how the deletion happens.
| Where the deletion starts | What synchronisation does | Likely recovery location | Important qualification |
|---|---|---|---|
| File Explorer on Windows (local deletion) | The local copy is typically placed into the Windows Recycle Bin; the deletion synchronises to the cloud and removes the item from OneDrive or SharePoint | Windows Recycle Bin (local); then OneDrive or SharePoint Recycle Bin (cloud) once the cloud deletion is processed | Behaviour may vary by sync-client version and configuration. Verify current client behaviour. |
| OneDrive on the web or SharePoint in a browser | The item enters the online Recycle Bin; the sync client receives the cloud deletion and removes the local representation — following MC1269861, without placing it in the Windows Recycle Bin | OneDrive or SharePoint online Recycle Bin | This is the scenario most clearly affected by the MC1269861 change. |
| SharePoint or Microsoft Teams (browser or app) | The item enters the SharePoint site Recycle Bin; connected sync clients receive the deletion | SharePoint first-stage Recycle Bin, then authorised second-stage | Recovery rights depend on permissions and role. |
| Another user deletes a shared file | The deletion may propagate to every user and device that syncs or shares that location | OneDrive or SharePoint Recycle Bin based on original storage location | Recovery rights depend on ownership and site permissions. The item may disappear for all users simultaneously. |
| Device is offline when deletion occurs | The deletion is applied when the device reconnects and synchronisation resumes | Online Recycle Bin at the time of deletion | Do not assume that an offline device preserves a protected local copy. |
| File is online-only through Files On-Demand | The file may have no complete local content copy; deletion in the cloud removes the placeholder | Online Recycle Bin | There may be no locally cached content to recover regardless of Recycle Bin location. |
| File marked ‘Always keep on this device’ | A full local content copy exists, but the file still belongs to the synchronised data set; a cloud deletion will synchronise and remove the local copy | Online Recycle Bin | Offline availability is not backup. |
Offline availability changes where content is cached. It does not change the fact that the file belongs to the synchronised data set.
How to Recover a Deleted OneDrive File
- 1Sign in to OneDrive on the web (onedrive.com or your Microsoft 365 portal).
- 2Select Recycle Bin from the left-hand navigation.
- 3Search or scroll for the missing item. Filter by date or file type where helpful.
- 4Select the item.
- 5Select Restore.
- 6Confirm that the item returns to its expected original location.
- 7Open the file and check its content.
- 8Check permissions and sharing links, particularly for items shared with others.
After restoring a business-critical item, confirm both its content and its access permissions.
Common complications to be aware of:
- If the original folder was also deleted, the restored file may appear in the root of OneDrive rather than its original location.
- If the file was shared and permissions were changed, sharing links may not work as expected after restore.
- If the file belonged to another user who has left, administrator access may be needed.
- If the Recycle Bin was emptied, or the retention period has expired, standard user recovery is no longer available.
- If a Microsoft Purview retention policy applies, a copy may be preserved in a compliance store but is generally not directly accessible to the end user.
- If the file is in Personal Vault, additional authentication may be required.
- If several files share the same name, check the deletion date and original location carefully.
How to Recover a Deleted SharePoint or Teams File
Files in Microsoft Teams channels are stored in SharePoint document libraries. Files shared in one-to-one or group chat conversations may be stored in the sender’s OneDrive, subject to current Teams behaviour — verify current Microsoft architecture for your Teams version.
The recovery process follows where Teams stored the file, not merely where the user last viewed it.
For channel files: identify the Team and channel; open the Files area; select Open in SharePoint; open the SharePoint site Recycle Bin; locate and restore the item.
- 1In Teams, open the channel where the file was stored.
- 2Select Files.
- 3Select Open in SharePoint (or follow the SharePoint link for the team site).
- 4In SharePoint, select the settings gear or Recycle Bin from the left navigation.
- 5Open Recycle Bin.
- 6Search for the file.
- 7Select Restore if it is present.
- 8If it is not present, ask an authorised site collection administrator to check the second-stage Recycle Bin.
Not every user has permission to restore items, particularly in shared libraries or team sites. Raising a request to the site owner or Microsoft 365 administrator may be needed.
SharePoint First-Stage and Second-Stage Recycle Bins
When an item is deleted from SharePoint or a SharePoint-backed Teams location, it enters the first-stage Recycle Bin. This is normally accessible to site members and owners depending on their permissions. After a period in the first-stage bin, or where it was emptied from that stage, the item moves to the second-stage Recycle Bin at the site-collection level.
The second-stage Recycle Bin is normally accessible to appropriately authorised site collection administrators. It provides an additional recovery window before the item is permanently deleted.
At the time of checking, Microsoft states that SharePoint Online deleted items are generally retained across both stages for up to 93 days from the initial deletion, subject to current Microsoft service rules, tenant configuration and storage quotas. The first and second stages share this overall period rather than each providing a separate full duration. Microsoft may update this behaviour — verify current documentation for your tenant. Your organisation’s retention, legal hold and backup configuration may provide different recovery options.
Important qualifications: retention time continues to pass while the incident is being investigated; manually emptying a Recycle Bin stage may restrict ordinary recovery; items close to expiry should be escalated immediately; permanent deletion may restrict Microsoft-supported recovery.
OneDrive for Business Retention
OneDrive for Business is built on SharePoint Online. At the time of checking, Microsoft states that deleted items in an OneDrive for Business Recycle Bin are generally retained for up to 93 days, subject to current Microsoft service rules and tenant configuration. This is broadly consistent with SharePoint Online behaviour.
Personal OneDrive (Microsoft account rather than work or school account) has separate retention rules. At the time of checking, Microsoft states that deleted items in a personal OneDrive Recycle Bin are retained for 30 days. This may differ from OneDrive for Business behaviour.
When Version History Can Help
Version history is useful when:
- The file still exists but its content is wrong
- Content was overwritten by a later save
- Another user made unwanted edits
- Synchronisation propagated a damaged or changed version
- Ransomware encrypted or modified a file that still exists
Version history generally does not replace the process of restoring a file that has been deleted. A deleted file is no longer present in the library — recover it from the Recycle Bin first. Version history applies to a file that still exists.
Deleted file: check the Recycle Bin. Existing but wrong file: check version history. Many files damaged or deleted: consider wider restore and backup options.
Related: How to Recover an Overwritten File in Google Workspace or Microsoft 365 →
OneDrive Restore
OneDrive Restore (also referred to as Files Restore) allows a user to roll their entire OneDrive back to a point within a recent window. It is accessed from OneDrive on the web: Settings → Options → Restore your OneDrive, or through the relevant Microsoft 365 admin centre tools for administrator-initiated restoration.
OneDrive Restore is most useful for:
- Widespread accidental deletion across many files
- Ransomware or malicious encryption of synced content
- Large-scale corruption or unwanted changes
- Events where identifying and restoring individual files would take too long
Restoring an entire OneDrive may reverse legitimate changes as well as unwanted ones.
The restore window, eligible subscriptions and available restore points are subject to current Microsoft requirements. Restoring to an earlier point may remove files created after that point and undo valid work. Review the result carefully after restoration. Do not present whole-OneDrive restoration as the first step for a single missing file.
For SharePoint Online, administrators may be able to use SharePoint library restore features to roll a document library back to an earlier state, subject to current Microsoft tools and licensing.
Recovering From Widespread Deletion
If many files have disappeared simultaneously, or if deletions are continuing, do not attempt recovery before understanding the cause. Synchronisation can propagate encryption, deletion, renaming, corruption and malicious changes across connected devices and accounts. Restoring files before the cause is identified and contained can allow the same damage to recur.
Recovery without containment can allow the same damaging change to synchronise again.
- 1ISOLATE — disconnect or isolate the affected device from the network where appropriate.
- 2SECURE — disable, revoke or contain the compromised account where appropriate, without destroying evidence.
- 3PRESERVE — preserve audit logs, event records and the current state for investigation.
- 4SCOPE — determine the scale of deletion or encryption. Identify affected accounts, sites, files and the responsible device or account.
- 5IDENTIFY — determine a clean recovery point in the Recycle Bin, version history, OneDrive Restore or backup.
- 6RESTORE — restore only after containment.
- 7MONITOR — confirm recovery is stable and monitor for recurrence.
Immediate Recovery Checklist
A OneDrive or SharePoint file has disappeared: what to do now
- 1STOP — do not recreate, rename or move large numbers of files yet.
- 2IDENTIFY THE LOCATION — was the file in personal OneDrive, OneDrive for Business, SharePoint, Teams, a local unsynchronised folder or a network drive?
- 3CHECK ONLINE — open the relevant OneDrive or SharePoint location in a browser.
- 4SEARCH — search by filename, file type, owner or modification date.
- 5CHECK THE CLOUD RECYCLE BIN — do not rely only on the Windows Recycle Bin.
- 6CHECK THE SECOND-STAGE RECYCLE BIN — for SharePoint content, ask an authorised administrator.
- 7CHECK VERSION HISTORY — use it only if the file still exists but its content is wrong.
- 8CHECK THE OWNER — did the content belong to another user or a departed employee?
- 9CHECK THE SCALE — if several files are affected, stop and escalate immediately.
- 10CONTAIN SECURITY INCIDENTS — disconnect or secure affected devices and accounts before restoring.
- 11CHECK RETENTION AND BACKUP — escalate before the ordinary recovery window expires.
- 12DOCUMENT THE RESULT — record what disappeared, where it was stored, who deleted it, when, how it was restored and what control needs improvement.
Where Did the File Go? A Decision Guide
- FILE IS MISSING → Was it stored in OneDrive, SharePoint or Teams?
- NO → Check local storage, Windows Recycle Bin, endpoint backup or network backup.
- YES → Does the file still exist but contain wrong content?
- WRONG CONTENT → Check version history.
- FILE GONE → Check the online Recycle Bin.
- SharePoint or Teams channel file? → Check first-stage, then authorised second-stage Recycle Bin.
- Many files affected? → Contain the incident first, then assess OneDrive Restore, retention and backup.
- Recycle Bin empty or retention expired? → Escalate immediately to administrator and backup provider.
Retention Versus Backup
Retention preserves information according to policy. Backup is designed to bring information back into use.
| Microsoft Purview Retention | Backup | |
|---|---|---|
| Primary purpose | Preserve or dispose of information according to policy or legal requirement | Maintain protected recovery points for operational restoration |
| Recovery interface | May require specialist permissions; not primarily an end-user restore interface | Typically designed for search, item-level restore, bulk restore and reporting |
| Point-in-time recovery | Not always available to the end user directly | Designed to support this where configured |
| Limitation | Configuration errors can affect coverage; preserved content may not restore directly to its original operational location | Requires a separate service, licensing and configuration; must be tested |
| Scope | Applied through retention labels and policies; affects items in scope | Depends on backup solution, configuration and retention periods |
Both retention and backup may be needed. They address different operational requirements and should not be treated as interchangeable.
Why Synchronisation Is Not Backup
Synchronisation keeps the same working files available across devices and services. Changes are propagated — including edits, renames, moves, deletions, corruption and encryption. A deletion is a change. Synchronisation distributes that change to every connected location.
A synchronised file is part of the same live data set. It is not a separate protected copy.
Sync copies the change. Backup preserves a recoverable state.
Backup maintains protected recovery points outside the ordinary live editing and synchronisation process. A suitable backup may provide independent retention, point-in-time recovery, wider restore options, protection from user deletion, protection from account compromise, documented recovery objectives and restore testing.
OneDrive protects availability and collaboration. It should not automatically be treated as the organisation’s complete backup strategy.
Deleted-User OneDrive
A user’s OneDrive may contain business-critical documents, correspondence, project files and client records. When a user leaves the organisation, the following apply:
- Licence removal and account deletion can trigger the retention timeline for the OneDrive.
- At the time of checking, Microsoft states that a deleted user’s OneDrive is retained for a default period, which administrators can configure — typically between 0 and 3,650 days. Verify current Microsoft guidance for your Microsoft 365 plan.
- Managers may be granted temporary access through a delegated-access process.
- Ownership of files and sharing links should be transferred as part of the leaver process.
- Links and permissions may break after the account is deleted.
- Backup coverage should be confirmed for the departing user’s data.
- The user’s personal OneDrive should not be the sole location for records that belong to the organisation.
A departed employee’s OneDrive should be handled through a documented leaver process, not discovered when somebody needs an old file.
Auditing Deletions
Authorised administrators may be able to investigate deletion incidents using Microsoft Purview audit capabilities. Depending on the Microsoft 365 licensing in place, the unified audit log may record: who deleted an item; when it was deleted; which workload stored it; how many items were affected; which device or application performed the action; and whether a permission change preceded the deletion.
Audit availability, event types and retention depend on licensing and configuration. Audit records do not themselves restore data. Timestamp accuracy and identity context matter for attributing actions. Logs should be preserved during an incident and not cleared before investigation. Not every deletion can always be conclusively attributed through available audit records.
What Businesses Should Review
- OneDrive sync-client versions deployed across the organisation
- Current Microsoft rollout status for MC1269861 in your tenant
- Documented deletion-recovery process for OneDrive and SharePoint
- Online Recycle Bin awareness and access among staff
- SharePoint site-administrator responsibilities and second-stage recovery access
- OneDrive Restore eligibility for current subscriptions
- Personal versus business OneDrive account use — business data should be in business accounts
- Known Folder Move configuration — confirm that redirected desktop and documents folders are in business OneDrive
- Files On-Demand settings and which files have no complete local content copy
- Departed-user OneDrive retention configuration
- SharePoint permissions and delete access
- Retention policies and labels
- Backup scope, retention and restore testing
- Mass-deletion alerting
- Ransomware response process
- Staff training on the difference between Windows and cloud Recycle Bins
- Recovery ownership and escalation routes
- Recovery time objectives and recovery point objectives
The change is a useful reminder to document the real recovery path rather than relying on a Recycle Bin somebody happened to find on one computer.
Warning Signs
Seek immediate technical assistance where: hundreds or thousands of files disappeared; file deletions are continuing; folders are being renamed; files have unfamiliar extensions; ransom messages appear; multiple users are affected; a departed user owned the content; OneDrive reports a large deletion; a synchronised device may be compromised; an administrator account may be compromised; the Recycle Bin has been emptied; the retention period is close to expiry; a SharePoint site was deleted; Teams files have disappeared; permissions changed unexpectedly; an unknown application made the changes; backup has not been tested; the user is about to reset or replace the computer; or legal or regulated information is involved.
One missing file may be accidental. Large or continuing deletions should be treated as a possible security incident.
Practical Business Implications
THE WINDOWS RECYCLE BIN IS NO LONGER A SAFE ASSUMPTION. Cloud-originated deletions may not leave an additional local fallback. The first recovery location for a deleted OneDrive or SharePoint file should now be the online Recycle Bin.
THE CLOUD RECYCLE BIN REMAINS IMPORTANT. Users need to know where it is, how to reach it and how long items remain there.
SHARED FILES CAN DISAPPEAR FOR EVERYONE. A deletion by one authorised user can remove the file for every person who shares or synchronises that location.
FILES ON-DEMAND CHANGES LOCAL EXPECTATIONS. An online-only file may never have had a complete local content copy to recover from locally.
ALWAYS KEEP ON THIS DEVICE IS NOT BACKUP. Offline availability still participates in synchronisation. A deletion synchronises regardless.
RECOVERY WINDOWS EXPIRE. Delayed reporting and investigation reduce available options. Escalate quickly.
WIDESPREAD DELETION NEEDS CONTAINMENT. Restoring before stopping the cause can repeat the damage.
RETENTION AND BACKUP SERVE DIFFERENT PURPOSES. Both may be needed. Neither automatically replaces the other.
RESTORE TESTING MATTERS. A recovery control should be demonstrated periodically, not merely assumed to work.
The IT Club View
The old behaviour could accidentally make a cloud deletion appear in two places: Microsoft 365’s online Recycle Bin and the Windows Recycle Bin of a synchronised computer. That additional local appearance was occasionally useful. It also encouraged a dangerous assumption.
“The files are synchronised to the computer, so there must be another safe copy.”
There may not be. The computer, OneDrive and SharePoint can all represent the same live working data. A file appearing in three places does not necessarily mean three independent copies exist.
IT Club recommends: identifying the authoritative file location for each type of content; teaching users to check the online Recycle Bin; documenting SharePoint second-stage recovery and who holds access; checking OneDrive Restore eligibility; controlling deletion permissions on sensitive libraries; monitoring mass deletions; maintaining independent backup; testing restoration periodically; reviewing departed-user data as part of a formal leaver process; treating widespread deletion as a security incident rather than a filing problem; and recording the Microsoft change in operational documentation.
The missing Windows fallback should not create the recovery problem. It should reveal whether the organisation had a proper recovery process in the first place.
Plain-English Takeaway
What to remember
If a synchronised OneDrive, SharePoint or Teams file disappears, check the online Microsoft 365 Recycle Bin rather than relying only on the Windows Recycle Bin. The OneDrive sync client may no longer place an additional local copy of a cloud-deleted file there. Act quickly, check version history and wider restore options where appropriate, and remember that synchronisation is not an independent backup.
Where do deleted OneDrive files go?
When a file is deleted from OneDrive, it normally goes to the OneDrive Recycle Bin online. Following Microsoft’s MC1269861 change, a cloud-originated deletion may no longer place an additional copy in the Windows Recycle Bin on a synchronised computer. Sign in to OneDrive on the web and open Recycle Bin to find and restore deleted items.
Do deleted OneDrive files go to the Windows Recycle Bin?
For local deletions from File Explorer, the local copy has typically gone to the Windows Recycle Bin and the deletion then synchronises to the cloud. For cloud-originated deletions, Microsoft’s MC1269861 change means the local synchronised representation may be removed without entering the Windows Recycle Bin. The primary recovery location for cloud files is the online Recycle Bin.
Has Microsoft removed the OneDrive Recycle Bin?
No. The OneDrive online Recycle Bin remains available. Microsoft changed how the sync client handles local copies of cloud-deleted files — the local fallback to the Windows Recycle Bin is being removed. The cloud Recycle Bin process continues as before.
Why is my deleted OneDrive file not in the Windows Recycle Bin?
Following Microsoft’s MC1269861 change, rolled out from May 2026, a file deleted from OneDrive online or from a synced SharePoint location may no longer appear in the Windows Recycle Bin on a synchronised computer. Check the online OneDrive or SharePoint Recycle Bin instead.
How do I open the OneDrive Recycle Bin?
Sign in to OneDrive on the web (onedrive.com or your Microsoft 365 portal). Select Recycle Bin from the left-hand navigation. You will see items that were recently deleted from your OneDrive. Select an item and choose Restore to return it to its original location.
How do I restore a deleted OneDrive file?
Sign in to OneDrive on the web. Open Recycle Bin. Find the file. Select it and choose Restore. Confirm it has returned to the expected location and that its content is correct. Check sharing permissions if the file was shared with others.
How long do files remain in the OneDrive Recycle Bin?
At the time of checking, Microsoft states that personal OneDrive Recycle Bin items are retained for 30 days. OneDrive for Business Recycle Bin items (which use SharePoint Online infrastructure) are generally retained for up to 93 days across both recovery stages. These periods are subject to current Microsoft service rules, tenant configuration, storage quotas and any applicable retention policies. Verify current Microsoft documentation for your account type.
Is OneDrive for Business retention different from personal OneDrive?
Yes. Personal OneDrive uses a Microsoft consumer account and has separate retention rules from OneDrive for Business. At the time of checking, the personal Recycle Bin retains items for 30 days, while OneDrive for Business retains items for up to 93 days. The recovery interfaces and administrative features also differ.
What is the SharePoint first-stage Recycle Bin?
When an item is deleted from a SharePoint site, it enters the first-stage Recycle Bin accessible to site members and owners with appropriate permissions. Items can be restored or permanently deleted from the first stage. After items leave the first stage, they move to the second-stage Recycle Bin.
What is the SharePoint second-stage Recycle Bin?
Items that have been removed from the first-stage SharePoint Recycle Bin (by emptying or expiry) move to the second-stage Recycle Bin at the site-collection level. The second stage is normally accessible to appropriately authorised site collection administrators. It provides an additional window to restore items that no longer appear in the first stage. The first and second stages together share the overall retention period.
How do I recover a deleted SharePoint file?
In SharePoint, go to the site where the file was stored. Open Recycle Bin from the site navigation or settings. If the file appears, select it and choose Restore. If it is not in the first-stage bin, ask an authorised site collection administrator to check the second-stage Recycle Bin. If neither stage has it, check retention, backup and escalate promptly.
How do I recover a deleted Teams file?
Teams channel files are stored in SharePoint. Go to the Teams channel, open Files, select Open in SharePoint, then check the SharePoint Recycle Bin. For files shared in Teams chat, they may be stored in the sender’s OneDrive — check the OneDrive Recycle Bin for that user. Recovery depends on the original storage location.
Where are Teams channel files stored?
Files shared in Microsoft Teams channels are stored in a SharePoint document library associated with the team. Each team has a SharePoint site. Files tab content in a channel corresponds to a folder in that SharePoint library. Recovery follows SharePoint Recycle Bin procedures.
Where are Teams chat files stored?
Files shared in one-to-one and group Teams chat conversations are typically stored in the sender’s OneDrive for Business. The exact location and recovery route depends on the current Microsoft Teams architecture. Verify current Microsoft documentation for your Teams version.
Can another user delete a shared OneDrive file?
Yes, if they have sufficient permissions. A collaborator with edit or delete permissions can delete a file that has been shared with them. The deletion removes it from the live location for all users and may synchronise to connected devices. Recovery from the Recycle Bin is normally possible within the retention period.
Can another user restore a shared file?
Restoration depends on permissions and account ownership. Only the owner of the OneDrive account can normally restore items from their own Recycle Bin. For SharePoint files, users with sufficient site permissions may be able to restore from the first-stage bin. Second-stage recovery requires site collection administrator access.
What happens when I delete a synced file in File Explorer?
Deleting a file from a OneDrive-synced folder in File Explorer typically places the local copy in the Windows Recycle Bin and then synchronises the deletion to the cloud, which removes the item from OneDrive or SharePoint online. The item then enters the online Recycle Bin. The exact behaviour can depend on the sync-client version, the file’s sync state and current Microsoft configuration. Verify current behaviour for your client version.
What happens when I delete a OneDrive file in a browser?
Deleting a file through OneDrive on the web or SharePoint in a browser sends it to the online Recycle Bin. The deletion then synchronises to connected devices. Following MC1269861, the sync client may remove the local representation without placing it in the Windows Recycle Bin. The online Recycle Bin is the recovery location.
Does Files On-Demand affect file recovery?
Yes. Files On-Demand allows OneDrive files to be visible in File Explorer without all content being downloaded locally. An online-only file (shown with a cloud icon) has no complete local content copy. If such a file is deleted from the cloud, there is no locally cached content to recover from Windows Recycle Bin — the online Recycle Bin is the only standard recovery location.
Does ‘Always keep on this device’ create a backup?
No. Marking a file or folder as ‘Always keep on this device’ downloads and maintains a full local content copy, making it available offline. However, it remains part of the synchronised data set. A deletion or change from the cloud will still synchronise to the local copy. Offline availability changes where content is cached — it does not create an independent protected backup.
Is OneDrive synchronisation a backup?
No. Synchronisation keeps working files consistent across devices and services. Changes including deletions, edits, renames and corruption are propagated. OneDrive has recovery features — Recycle Bin, version history and OneDrive Restore — but these have retention periods and limitations. A separate backup service provides independent recovery points not subject to the same synchronisation behaviour.
What is the difference between sync and backup?
Synchronisation keeps the same live data available across multiple locations. A change in one place is copied to others, including deletions and corruption. Backup creates protected copies at points in time, independent from the live editing process. The purpose of backup is recovery from a broader event; the purpose of sync is availability and collaboration.
What is OneDrive Restore?
OneDrive Restore (Files Restore) allows a user to roll their entire OneDrive back to a previous point in time within a recent window. It is accessible from OneDrive on the web under Settings. It is useful for widespread accidental deletion, ransomware or large-scale corruption. It is not designed for restoring a single missing file — use the Recycle Bin for that. Restoring an entire OneDrive also reverses legitimate changes made after the selected point.
Can OneDrive recover from ransomware?
Microsoft 365 provides features that may help, including version history, the Recycle Bin and OneDrive Restore. However, ransomware recovery requires isolating the affected device and account first, then identifying a clean restore point before recovering files. Restoring before containment can allow encrypted versions to overwrite recovered content. Independent backup provides recovery points outside the live synchronisation chain.
Can I restore my entire OneDrive?
Yes, through OneDrive Restore, subject to current Microsoft subscription requirements and available restore windows. The feature rolls back the entire OneDrive to an earlier point. It reverses all changes after that point, including valid work created after the selected restore date. Review the impact carefully before confirming a whole-OneDrive restoration.
What happens to newer files after a OneDrive Restore?
Files created after the selected restore point may be removed as part of the restoration. This is why identifying the correct restore point carefully is important before confirming the operation. Files that existed before the chosen point are rolled back to their state at that time. Review the result and confirm which changes need to be re-applied.
Can version history restore a deleted file?
Version history helps restore an earlier saved version of a file that still exists. It does not restore a file that has been deleted and is no longer present. To restore a deleted file, use the Recycle Bin. To restore an earlier version of an existing file, use version history.
What is the difference between version history and the Recycle Bin?
The Recycle Bin holds items that have been deleted and allows them to be restored before the retention period expires. Version history holds earlier saved states of a file that still exists, allowing the file’s content to be rolled back to a previous version without full deletion. Use the Recycle Bin for missing files; use version history for wrong or overwritten content.
What happens when a OneDrive user leaves the company?
When a Microsoft 365 account is deleted, the user’s OneDrive enters a retention period. Administrators can grant temporary access to a manager or successor. Ownership of files and sharing links should be transferred before the account is fully removed. At the time of checking, the default retention period for a deleted user’s OneDrive can be configured by administrators. After retention expires, the content may be permanently deleted. Verify current Microsoft guidance for your plan.
Can administrators recover permanently deleted OneDrive files?
Permanent deletion means the item is no longer in either Recycle Bin stage. Recovery options are then limited to Microsoft Purview retention holds (where configured), backup (where in scope), or a Microsoft support engagement (not guaranteed). Prompt escalation before permanent deletion occurs is always preferable.
Does Microsoft Purview retention replace backup?
No. Retention preserves information according to organisational or legal policy. Recovery from retention may require specialist permissions, compliance tools and is not primarily an end-user restore interface. Backup is designed for operational recovery — item-level restore, bulk restore, point-in-time recovery and reporting. Both may be needed for complete data protection.
Do I need a separate Microsoft 365 backup?
Microsoft’s own features — Recycle Bin, version history, OneDrive Restore and Purview retention — have retention limits, licensing requirements and do not provide every recovery scenario. A separate backup service provides independent recovery points, longer retention, item-level restore, reporting and testing. Whether it is needed depends on the organisation’s recovery requirements, risk tolerance and existing configuration.
What should I do if thousands of OneDrive files disappear?
Stop unnecessary activity. Isolate the affected device from the network. Contain the account if compromise is suspected. Preserve logs. Escalate to the Microsoft 365 administrator immediately. Assess the scale. Do not begin restoration before the cause is identified and contained. Consider OneDrive Restore, retention, backup and, if needed, Microsoft support. Treat it as a security incident.
How can a business test OneDrive recovery?
Test recovery by: creating a test file; deleting it; restoring it from the Recycle Bin; checking content and permissions. Also test version history restore and, where applicable, OneDrive Restore with a non-critical restore point. Test backup recovery with the backup provider’s restore process. Document the results and make testing a regular scheduled activity.
Administrator Technical Note
MC1269861 CHANGE: Microsoft announced via Message Centre MC1269861 that the OneDrive sync client would be updated so that cloud-originated deletions no longer place the local synchronised copy in the Windows Recycle Bin or macOS Trash. Rollout began in May 2026. At the time of writing (July 2026), the notification is archived. Verify current rollout status through the Microsoft 365 Message Centre and test current behaviour in your tenant, as the exact behaviour can depend on the sync-client version, release ring and affected scenario.
RELEASE RINGS: The OneDrive sync client uses Microsoft release rings (Insiders, Production, Deferred). Targeted release tenants typically receive changes earlier. Administrators can view and manage the sync-client update ring through Microsoft Intune, Group Policy (OneDrive ADM/ADMX templates) or the SharePoint admin centre. Administrators can also view the current sync-client build version reported by connected devices.
SCOPE: The change applies to OneDrive for Business and SharePoint Online synced libraries on Windows and macOS. Local File Explorer deletions have historically followed a different path (local copy to Windows Recycle Bin, deletion synchronises to cloud). Verify whether that distinction persists in current builds. Personal OneDrive behaviour should be verified separately from business account behaviour.
RECYCLE BIN RETENTION: SharePoint Online and OneDrive for Business Recycle Bin items are retained for up to 93 days across first and second stages. The second-stage Recycle Bin is accessible through the site collection administration. Site collection administrators can restore items from the second stage that are no longer visible to ordinary users. Verify current Microsoft guidance for your tenant’s storage and quota configuration.
DELETED-USER ONEDRIVE: When a Microsoft 365 user account is deleted, the OneDrive content retention period is configurable from 0 to 3,650 days in the SharePoint admin centre. The default period depends on the Microsoft 365 plan. Ownership can be delegated through the user management process. Administrators should review this configuration to ensure departed-user data is retained appropriately and that ownership transfer is part of the leaver process.
FILES ON-DEMAND: Online-only files have no locally cached content. An online-only file that is deleted from the cloud has no local content recovery path. Files marked ‘Always keep on this device’ have full local content copies but remain part of the synchronised data set. Storage Sense can automatically reclaim space by making locally downloaded files online-only again; verify that this does not interact with business recovery expectations.
KNOWN FOLDER MOVE: Where KFM redirects Desktop, Documents and Pictures to OneDrive for Business, files that appear local are actually in OneDrive. Staff and administrators should understand which folders are redirected. Recovery for KFM-redirected folders follows OneDrive recovery procedures, not local backup. Verify current KFM deployment status across the device estate.
ONEDRIVE RESTORE AND SHAREPOINT LIBRARY RESTORE: Administrators can initiate OneDrive Restore for a user account through the OneDrive admin centre. SharePoint library restore is available through SharePoint Online administration. Both operations have version-history limits and restore-window constraints. Test restoration in a non-production context before relying on it during an incident.
MICROSOFT PURVIEW RETENTION: Retention policies and labels applied to OneDrive and SharePoint can preserve content in a preservation hold library even after a user deletes it and the Recycle Bin retention expires. Recovery from the preservation hold library requires eDiscovery or compliance administrator permissions and is not a user-facing restore interface. Retention configuration errors can leave gaps in coverage. Retention is not a substitute for backup.
MICROSOFT 365 BACKUP: Microsoft 365 Backup (where licensed) provides an independent backup layer for OneDrive, SharePoint and Exchange Online. Third-party Microsoft 365 backup solutions also exist. Both extend retention beyond the standard Recycle Bin window and provide item-level and bulk restore capabilities. Verify current licensing, scope and configuration before assuming coverage. Test restoration regularly.
MASS-DELETION ALERTS: Microsoft Defender for Cloud Apps and Microsoft Purview can generate alerts on unusual file-deletion activity. Configure alert policies and thresholds appropriate to the organisation’s baseline activity. Enable the unified audit log to record file deletion events. Audit availability and retention depend on the Microsoft 365 licensing plan. Preserve audit logs during incidents.
RANSOMWARE CONTAINMENT: Ransomware encrypts and often deletes files. Recovery while the compromised device or account remains active risks the encrypted versions overwriting recovered content through synchronisation. Isolate the device. Suspend or contain the compromised account. Preserve evidence. Determine a clean restore point. Restore after containment. Microsoft Defender for Endpoint and Microsoft Entra risk-based conditional access can assist containment.
RECOVERY OBJECTIVES: Define and document recovery time objectives (RTO) and recovery point objectives (RPO) for OneDrive and SharePoint content. These should reflect the business impact of data loss and the available recovery tools. Test recovery against these objectives at least annually.
Operational Heartbeat
Cloud file recovery readiness changes as OneDrive clients update, sync behaviour changes, devices are replaced, Known Folder Move is deployed, Files On-Demand settings change, SharePoint sites are created, Teams are archived, staff join and leave, site owners change, retention policies change, backup licences lapse, storage limits are reached, permissions accumulate, mass-deletion alerts stop and restore knowledge is lost.
A recurring review should check: OneDrive sync-client health and current version; MC1269861 rollout status in the tenant; OneDrive account and SharePoint site ownership; Teams ownership; Recycle Bin recovery guidance provided to staff; second-stage recovery access; OneDrive Restore eligibility; deleted-user retention configuration; Known Folder Move status; Files On-Demand and Storage Sense settings; version history; retention policies and labels; legal holds; backup coverage, retention and restore success; audit availability; mass-deletion alerting; ransomware response process; staff guidance; previous incidents and corrective actions; and a next review date.
Cloud file recovery needs an operational heartbeat: synchronisation, ownership, Recycle Bins, retention, backup, alerting and restore procedures should be reviewed rather than assumed to remain available.
Related: How to Recover an Overwritten File in Google Workspace or Microsoft 365 →
Related: Microsoft Office Closed Before You Saved? How to Recover Unsaved Files →
Plain-English Takeaway
If a synchronised OneDrive, SharePoint or Teams file disappears, check the online Microsoft 365 Recycle Bin rather than relying only on the Windows Recycle Bin. The OneDrive sync client may no longer place an additional local copy of a cloud-deleted file there. Act quickly, check version history and wider restore options where appropriate, and remember that synchronisation is not an independent backup.
Need the practical steps?
A short, instruction-led version of this topic is available in the Knowledge Centre.
View the Knowledge Centre GuideRelated Articles
Can Someone Pretend to Email Your Customers?
A customer receives an email that looks exactly like it came from your business. It asks them to pay an invoice, click a link or reset a password. It did not come from you. This is email spoofing — and DMARC is one of the best tools available to stop it.
Read articleEmailing a Group? How to Use Bcc Without Exposing Everyone’s Address
Putting a group of unrelated contacts in the To or Cc field exposes every address to everyone. One field and one habit can prevent a common privacy mistake.
Read articlePasskeys: How to Protect Your Microsoft and Google Accounts
Passkeys let a trusted device approve sign-in with a fingerprint, face or PIN instead of a typed password. Here is how to set one up safely on a Microsoft or Google account — and what to check first.
Read article