All pages
Powered by GitBook
1 of 4

Loading...

Loading...

Loading...

Loading...

Integration

Learn about integrating a Microsoft 365 tenant with Xopero ONE to protect its resources.

Cover
Required permissions

Permissions required for integrating Microsoft 365 with Xopero ONE.

Cover
Adding Microsoft 365 tenant to Xopero ONE

How to integrate a Microsoft 365 organization with Xopero ONE.

Cover
Enabling SharePoint protection in Xopero ONE

How to integrate a Microsoft 365 organization with Xopero ONE and include SharePoint protection.

Adding Microsoft 365 tenant to Xopero ONE

How to integrate a Microsoft 365 organization with Xopero ONE.

Adding a Microsoft 365 tenant to Xopero ONE connects your organization's environment and enables data protection for supported services. The integration requires proper authorization and tenant-level permissions to establish a secure connection between Microsoft 365 and Xopero ONE, allowing you to configure backup settings, manage protection policies, and perform recovery operations.


Important notice

The following documentation applies only to Microsoft 365 organizations with Xopero ONE licenses that include backup for Microsoft Exchange data (including individual mailboxes, shared mailboxes, calendars, and contacts) and OneDrive.

For instructions on enabling protection for SharePoint sites in new and existing Microsoft 365 organizations, refer to the Enabling SharePoint protection in Xopero ONE article.


Integration process

The below steps demonstrate how to integrate a Microsoft 365 organization with Xopero ONE using Xopero ONE Management Service.

1

Select Microsoft 365 from the left pane.

2

Click Connect under Microsoft 365.

3

After adding the organization, you may see the following message. Click Repair to configure permissions for shared mailbox protection.

To start the permission update process, click Continue at the bottom of the configuration pane. If prompted, sign in to your Microsoft 365 account and grant Xopero ONE the required permissions.

After the required permissions have been granted, you can configure a Microsoft 365 backup plan and start protecting your resources.


Copy the authentication code, then click Log in to Microsoft 365.

4

In the Microsoft authentication tab, paste the copied code and click Next.

5

Select your account and sign in if prompted. Next, click Continue to confirm your sign-in to Xopero Registrator.

6

If the registration is completed successfully, the following message will appear. Close the tab and return to Xopero ONE Management Service.

7

The Microsoft 365 organization has been successfully added to Xopero ONE. Click Custom policy to modify your backup policy settings, or click Run backup to start a backup using the current policy configuration.

If you already have a Microsoft 365 organization added, click the + Add new button in the top-left corner first.

Additional permissions for shared mailboxes protection

Useful links and items

Licensing overview
Required permissions
Enabling SharePoint protection in Xopero ONE

Required permissions

Permissions required for integrating Microsoft 365 with Xopero ONE.

The required Microsoft 365 permissions define the access levels Xopero ONE needs to securely back up and restore your data.


General requirements

To integrate a Microsoft 365 organization with Xopero ONE, ensure it uses a Microsoft 365 business license.

To back up a single Microsoft 365 account, the account must have a Microsoft 365 license assigned. This also applies to shared mailboxes. License assignments can be managed in the Microsoft 365 admin center.

Each Microsoft 365 account and shared mailbox requires one Xopero ONE license to back up its data.

The backup process requires a backup agent (worker), which communicates with the Microsoft 365 API, downloads the requested data, and performs the backup. You can use either a cloud or local worker. Any device with the Xopero ONE Backup&Recovery Agent installed can act as a worker.


To add your Microsoft 365 organization to Xopero ONE, you must use a global administrator account. Only a global administrator has the necessary permissions to back up data from all user accounts in the organization.


The following tables list Xopero apps and their permissions, which are automatically installed in the end user's Entra ID when integrating Microsoft 365 with Xopero ONE.

This application is used at the beginning of the integration to install and grant the necessary permissions for the Xopero ONE MS365 PRO app.

API name
Claim value
Permission
Type

This application is required to back up and recover data from Microsoft 365 tenants and is installed automatically in Entra ID by Xopero ONE Registrator.

API name
Claim value
Permission
Type
API name
Claim value
Permission
Type
API name
Claim value
Permission
Type

Maintain access to data you have granted access to.

delegated

Microsoft Graph

profile

View user's basic profile.

delegated

Microsoft Graph

openid

Sign users in.

delegated

Read and write all users' full profile information.

application

Microsoft Graph

Application.ReadWrite.All

Read and write all applications.

application

Microsoft Graph

Group.Read.All

Read all groups.

application

Microsoft Graph

Contacts.ReadWrite

Read and write contacts in all mailboxes.

application

Microsoft Graph

Group.Create

Create groups.

application

Microsoft Graph

Files.ReadWrite.All

Read and write files in all site collections.

application

Microsoft Graph

Calendars.ReadWrite

Read and write calendars in all mailboxes.

application

Microsoft Graph

Tasks.ReadWrite

Create, read, update, and delete user's tasks and task lists.

delegated

Microsoft Graph

Directory.ReadWrite.All

Read and write directory data.

delegated

Microsoft Graph

Group.ReadWrite.All

Read and write all groups.

delegated

Microsoft Graph

offline_access

Maintain access to data you have granted access to.

delegated

Read and write mail in all mailboxes.

application

Office 365 Exchange Online

Calendars.ReadWrite.All

Read and write calendars in all mailboxes.

application

Office 365 Exchange Online

delegated

Read and write mail in all mailboxes.

application

Office 365 Exchange Online

Calendars.ReadWrite.All

Read and write calendars in all mailboxes.

application

Office 365 Exchange Online

delegated

Microsoft Graph

Directory.AccessAsUser.All

Access directory as the signed-in user.

delegated

Microsoft Graph

Microsoft Graph

Mail.ReadWrite

Read and write mail in all mailboxes.

application

Microsoft Graph

Office 365 Exchange Online

full_access_as_app

Use Exchange Web Services (EWS) with full access to all mailboxes.

application

Office 365 Exchange Online

Office 365 Exchange Online

full_access_as_app

Use Exchange Web Services (EWS) with full access to all mailboxes.

application

Office 365 Exchange Online

You do not need to assign any licenses to cloud workers — the appropriate license is assigned automatically by the Xopero ONE system.

Account permissions

Learn more about Microsoft 365 administrator roles in the official Microsoft documentation.

Application permissions

Xopero ONE Registrator

Microsoft Graph

Xopero ONE MS365 PRO

Microsoft Graph

Exchange Online

Office 365 SharePoint Online

Useful links and items

offline_access

User.ReadWrite.All

Mail.ReadWrite

Mail.ReadWrite

About administrator roles in the Microsoft 365 admin center - Microsoft 365 adminMicrosoftLearn
Logo

Enabling SharePoint protection in Xopero ONE

How to integrate a Microsoft 365 organization with Xopero ONE and include SharePoint protection.

Enabling SharePoint protection in Xopero ONE allows SharePoint sites to be included in the Microsoft 365 backup scope. The setup follows the same tenant-based flow used for other Microsoft 365 resources and requires that the necessary prerequisites and permissions are in place before backup configuration is started.


Important notice

The following documentation applies only to Microsoft 365 organizations with Xopero ONE licenses (Microsoft 365 PRO) that include backup for Microsoft Exchange data (including individual mailboxes, shared mailboxes, calendars, and contacts), SharePoint, and OneDrive.

For instructions on adding Microsoft 365 tenants with only Microsoft Exchange and OneDrive protection to Xopero ONE, see this article.


The below steps demonstrate how to integrate a Microsoft 365 organization with Xopero ONE using Xopero ONE Management Service.

1

Select Microsoft 365 from the left pane.

2

Click Connect under Microsoft 365 Pro.

3

The following steps demonstrate how to enable SharePoint protection for existing Microsoft 365 organizations using Xopero ONE Management Service.

1

Select Microsoft 365 from the left pane.

2

Click Edit in the lower-left corner of the organization tile.

3

In the Add new organization pane, click Advanced configuration at the bottom of the pane.

4

In Advanced configuration, enable the Enable SharePoint protection switch, and specify whether Xopero ONE should automatically assign licenses to users.

5

Next, click the Add new or select certificate from (…) tile. In the Add certificate pane, select the certificate option that aligns with your deployment model: automatically generate a certificate, upload a custom certificate, or select an existing certificate from the list. Once done, click Save.

6

Set the synchronization interval (if needed), review your settings, and click Save to proceed.

7

Back in the Add new organization pane, copy the authentication code, and then click Log in to Microsoft 365.

8

In the Microsoft authentication tab, paste the copied code and click Next.

9

Select your account and sign in if prompted. Next, click Continue to confirm your sign-in to Xopero Registrator.

10

If the registration is completed successfully, the following message will appear. Close the tab and return to Xopero ONE Management Service.

11

The Microsoft 365 organization has been successfully added to Xopero ONE. Click Custom policy to modify your backup policy settings, or click Run backup to start a backup using the current policy configuration.

In Settings section, turn on the Enable SharePoint protection switch, and then click the Add new or select certificate from (…) tile.

4

In the Add certificate pane, select the certificate option that aligns with your deployment model: automatically generate a certificate, upload a custom certificate, or select an existing certificate from the list. Once done, click Save.

5

The system will automatically prompt you to create or run a default backup plan. You can skip this step and configure the SharePoint backup plan later.

6

Back in the Microsoft 365 organization dashboard, click Repair to configure permissions for SharePoint protection.

7

To start the permission update process, click Continue at the bottom of the Edit organization pane. If prompted, sign in to your Microsoft 365 account and grant Xopero ONE the required permissions.

8

After the required permissions have been granted, you can configure a SharePoint backup plan and start protecting your resources.

Adding new Microsoft 365 organization with SharePoint protection

If you already have a Microsoft 365 organization added, click the + Add new button in the top-left corner first.

Enabling SharePoint protection for existing organizations

To enable SharePoint protection for an existing Microsoft 365 organization, you must have the Microsoft 365 PRO license.

Useful links and items

Licensing overview
Required permissions
Adding Microsoft 365 tenant to Xopero ONE