Permissions

The following table lists the user account permissions necessary to launch Veeam Explorer for Microsoft SharePoint and restore Microsoft SharePoint data.

Operation

Required Roles and Permissions

Veeam Explorer for Microsoft SharePoint launch

The account used to run Veeam Explorer for Microsoft SharePoint must meet the following requirements:

  • The account must be a member of the local Administrators group.
  • The account must have the Veeam Backup Administrator or Veeam Restore Operator role on the backup server.

Restore to on-premises Microsoft SharePoint

To restore data to on-premises Microsoft SharePoint organizations, you must grant the following roles and permissions to user accounts:

  • The account must be granted Full Control to connect to the target SharePoint server.
  • The account must be assigned either the Site Administrator or System Account role to restore user permissions.
  • If permissions of items being restored are inherited from the parent one, the account must be granted Full Control.
  • If permissions of items being restored are not inherited from the parent one and items being restored replace the existing ones, the account must be granted Contribute and Full Control.

Restore to Microsoft Office 365

To restore data to SharePoint Online organizations, you must grant the following roles and permissions to user accounts:

Restore Using Basic Authentication Method

  • The account used to log in to Microsoft Office 365 must have the Global Administrator or SharePoint Administrator role assigned.
  • For restore of personal SharePoint sites, make sure to select the Allow users to run custom script on personal sites option in the SharePoint admin center. For more information, see this Microsoft article.
  • During restore, Veeam Backup for Microsoft 365 automatically assigns the Site Collection Administrator role to the user account.

Restore Using Modern Authentication Method

  • The account used to log in to Microsoft Office 365 must have the Global Administrator or SharePoint Administrator role assigned.
  • For restore of personal SharePoint sites, make sure to select the Allow users to run custom script on personal sites option in the SharePoint admin center. For more information, see this Microsoft article.
  • During restore, Veeam Backup for Microsoft 365 automatically assigns the Site Collection Administrator role to the user account.
  • Make sure that the required settings are specified for the Azure AD application used for restore. For more information, see the Configuring Azure AD Application Settings section of the Veeam Backup for Microsoft 365 User Guide.
  • If you restore data with Azure AD applications using a certificate, make sure that your Azure AD application is granted the required permissions. For more information, see the Permissions for Modern App-Only Authentication section of the Veeam Backup for Microsoft 365 User Guide.

Consider the following:

  • The current account can only be used to access a local staging server. To connect to a remote server, use appropriate authentication credentials to access that server.
  • The account requires the sysadmin fixed server role on a staging Microsoft SQL server.
  • For ADFS as an authentication provider:
  • When using Windows Authentication, you can use both your current account or provide another account.
  • When using Forms Authentication, the current account cannot be used.

Page updated 6/13/2024

Page content applies to build 12.1.2.172