Permissions

This section lists permissions required for Veeam Backup for Microsoft 365 in the AWS environment.

For the detailed description of all permissions required for Veeam Backup for Microsoft 365 operation, see the Permissions section of the Veeam Backup for Microsoft 365 User Guide.

Microsoft Organizations

To protect Microsoft 365 data, Veeam Backup for Microsoft 365 uses Veeam Backup accounts and Azure AD applications. Accounts and applications are used to establish and maintain connection between Veeam Backup for Microsoft 365 and Microsoft 365 organizations, and to perform backup and restore operations. Depending on configuration of Microsoft 365 organizations and the restrictions on using legacy authentication protocols, you can add organizations using either modern app-only authentication, or modern authentication method with legacy protocols allowed, or basic authentication. For more information, see the Microsoft 365 Organizations section of the Veeam Backup for Microsoft 365 User Guide.

Depending on authentication methods you use, you must grant permissions to Veeam Backup account or Azure AD application, or both accounts.

For more information, see the Veeam Backup Account Permissions and Azure AD Application Permissions sections of the Veeam Backup for Microsoft 365 User Guide.

Amazon S3 Storage

If you store Microsoft 365 and on-premises Microsoft organization backups in Amazon S3 object storage, you must grant permissions to a user account that you use to access Amazon buckets and folders. For more information, see Amazon S3 Storage Permissions.