If recent work is missing from a former employee’s OneDrive, first determine what was restored: the user account, a deleted OneDrive site, or the contents of an existing OneDrive. These are different recovery operations. Missing edits do not establish that Microsoft restored an old periodic snapshot.
This guide is for an authorized Microsoft 365 administrator recovering business records. Keep the account’s security restrictions and applicable retention controls intact while investigating. Do not remove a legal hold to make a restore operation succeed.
Identify the recovery problem before changing anything
- The OneDrive opens, but a document is outdated: investigate that file and its available versions before considering a drive-wide rollback.
- The entire OneDrive is unavailable: check whether the site is retained, deleted, or archived. An access-denied message alone does not identify which state applies.
- The user no longer appears under Deleted users: do not conclude that their OneDrive has been permanently erased.
- A recent local edit never reached the cloud: preserve authorized device copies before resetting, unlinking, or reconnecting the sync client.
Create a recovery inventory with each required file’s name, original location, expected content, last known editor, and evidence of the missing change. Keep copies of important current files outside the OneDrive being investigated. A second folder within that same OneDrive is not an independent recovery copy.
Check the user and OneDrive separately
Microsoft documents a 30-day window for restoring a deleted user through the Microsoft 365 admin center. The OneDrive lifecycle is separate: its deleted-user retention period is configurable, and a deleted OneDrive can remain recoverable after the user disappears from that list. Retention policies and holds can alter the normal lifecycle. See Microsoft’s OneDrive retention and deletion guidance.
Ask the administrator responsible for offboarding to confirm the deletion date, the actual OneDrive URL, and any prior recovery actions. Do not restore the former employee’s sign-in access merely to inspect business files without the appropriate authorization.
Find out whether a deleted OneDrive is recoverable
A SharePoint Administrator connected through the SharePoint Online Management Shell can check a known site URL with Get-SPODeletedSite -Identity <URL>. This is an inspection step, not a restore. Replace the placeholder with the verified OneDrive URL; do not run commands against a guessed account.
If the site is listed, Microsoft documents restoring it with Restore-SPODeletedSite -Identity <URL> and separately granting an authorized administrator access. Review the scope and approval before either change. Follow the current deleted-OneDrive recovery procedure. Do not run permanent-deletion commands as part of diagnosing missing edits.
If the site is not listed, record the result and investigate its actual state. Do not keep retrying a content rollback on an inaccessible site. Unlicensed accounts also have an archive lifecycle; check Microsoft’s unlicensed OneDrive account guidance before assuming deletion or authorizing any paid reactivation.
Recover the required content, not an assumed snapshot
For an accessible OneDrive, distinguish a deleted file from an existing file containing the wrong content. Use the relevant recycle-bin recovery or file-version path. Verify the candidate document’s contents, not only its date: an apparently recent version might still lack the required edit.
Restore OneDrive is a broader operation for undoing unwanted activity within the available 30-day window. It is not a way to import unsynced device changes. Review the activity list and preserve current work before using it. Files created after the selected restore point are moved to the recycle bin; a rollback can therefore make recent work disappear from its previous location.
Do not select a date simply because it precedes the employee’s departure or license removal. The recovery point should relate to a verified unwanted content change, not an employment event.
Escalate without weakening retention protections
If a hold, retention policy, access restriction, or archive state complicates recovery, involve the responsible administrator and compliance owner. Record the exact error, site URL, operation, and timestamp. Keep recovery evidence in an approved location. Do not disable protections temporarily and assume that re-enabling them later makes the operation safe.
Where approved backups or retained content may help, have their owner check coverage and recovery options. Do not promise that eDiscovery or another search will contain every missing version. Close the recovery only after the business owner has checked the required files against the inventory, and document any remaining gaps.