Help Center
Choose product document...
Veeam Backup for Microsoft Office 365 3.0
User Guide

Understanding Microsoft Graph

To access Azure Active Directory resources and retrieve information about your Microsoft Office 365 organizations, Veeam utilizes Microsoft Graph API. For more information about Microsoft Graph, see this Microsoft article.

Connecting to Microsoft Graph

To connect to Microsoft Graph, Veeam uses three different approaches involving three different application types:

To be used when selecting the Basic authentication option at the Specify Connection Settings step.

To be used when selecting the Basic authentication option at the Specify Connection Settings step for China and Germany regions.

To be used when selecting the Modern authentication option at the Specify Connection Settings step for organizations with enabled Multi-factor authentication (MFA).

Using Default Microsoft Application

The default application is installed by default by Microsoft and allows Veeam to connect to Microsoft Office 365 organizations that belong to any Microsoft Azure region except for China or Germany regions.

Using Veeam Backup for Microsoft Office 365 Application

To connect to Microsoft Office 365 organizations that belong to China or Germany regions, Veeam uses the proprietary application — Veeam Backup for Microsoft Office 365.

This application is installed automatically after you select the Basic authentication checkbox at the Specify Connection Settings step of the Add Organization wizard and provides Veeam with the appropriate permission set to work with your Microsoft Office 365 organizations data.

To install the application, Veeam requires either of the following roles to be assigned to your Microsoft Office 365 account:

To assign any of these roles, open your Azure Active Directory portal, go to Azure Active Directory > Users > %User% > Directory role and click Add role.

Once installed, the application can be found in the Enterprise applications - All applications section of your Azure Active Directory admin center.

To see what permissions were given to the application, click the Veeam Backup for Microsoft Office 365 application name and select Permissions.

Connecting to Microsoft Graph

Using Custom Application

If your Microsoft Office 365 organizations use Multi-factor authentication (MFA), you must create a custom application in your Azure Active Directory portal in advance. Such an application will be utilized by Veeam to access Microsoft Graph API and retrieve your Microsoft Office 365 organizations data.

The following mandatory API access and permissions must be granted to the application:

  • Use Exchange Web Services with full access to all mailboxes
  • Microsoft SharePoint Online API access (only required when using a certificate at the Specify Credentials step) with the following minimum required permissions:
  • Have full control of all site collections

See the following Microsoft documentation to learn more:

Veeam Large Logo

User Guide

RESTful API Reference

PowerShell Reference