- About Veeam Backup & Replication REST API
- Overview
- How To
- Changelog
- Global Changes
- New Features
- Users and Roles
- Malware Detection
- High Availability Cluster
- Bare Metal Recovery and Volume Restore
- Backup Move and Copy
- Unstructured Data
- Microsoft Entra ID
- Deduplication Appliance Repositories
- Veeam Data Cloud Vault Archive
- Instant Recovery to Microsoft Azure
- Instant Recovery to Another Platform
- Quick Backup
- Proxmox VE and Nutanix AHV
- General Options
- Inventory Browser
- Agent Management
- Backup Browser
- Application Items Restore
- Deprecated Requests
- Minor Non-Breaking Changes
- Breaking Changes
- Login
- Service
- Services
- Credentials
- getGet All Credentials
- postAdd Credentials Record
- getGet Credentials Record
- putEdit Credentials Record
- delRemove Credentials Record
- postChange Password
- postChange Linux Private Key
- postChange Linux Root Password
- getGet All Cloud Credentials
- postAdd Cloud Credentials Record
- postGet Microsoft Entra ID Verification Code
- postRegister Microsoft Entra ID Application
- postGet Google Authentication Information
- getGet Cloud Credentials Record
- putEdit Cloud Credentials Record
- delRemove Cloud Credentials Record
- postChange Secret Key
- postChange Google Service Account
- postChange Certificate
- getGet All Helper Appliances
- postAdd or Edit Helper Appliance
- getGet Helper Appliance
- delRemove Helper Appliance
- Encryption
- getGet All Encryption Passwords
- postAdd Encryption Password
- getGet Encryption Password
- putEdit Encryption Password Hint
- delRemove Encryption Password
- postChange Encryption Password
- postVerify Encryption Password
- getGet All KMS Servers
- postAdd KMS Server
- getGet KMS Server
- putEdit KMS Server
- delRemove KMS Server
- postChange KMS Server Certificate
- License
- postInstall License
- getGet Installed License
- postRemove License
- postCreate License Usage Report
- postRenew Installed License
- getGet Consumption of Socket Licenses
- postRevoke Socket License
- getGet Instance Licenses Consumption
- postAssign Instance License
- postRevoke Instance License
- postRemove Instance License
- getGet Capacity License Consumption
- postRevoke Capacity License from Unstructured Data Workload
- postUpdate License
- postEnable or Disable License Auto Update
- postEnable or Disable Instance Consumption for Unlicensed Agents
- Connection
- Cloud Browser
- Inventory Browser
- getGet All VMware vSphere Servers
- getGet VMware vSphere Server Objects
- postRescan Inventory Objects
- postGet All Servers
- postGet Inventory Objects
- postGet Inventory Object Details
- postGet All Protection Groups
- postGet All Physical Inventory
- postGet Inventory Objects for Specific Protection Group
- getGet All Unstructured Data Servers
- postAdd Unstructured Data Servers
- getGet Unstructured Data Server Defaults
- getGet Unstructured Data Server
- putEdit Unstructured Data Server
- delRemove Unstructured Data Server
- postStart Browsing Unstructured Data Server
- postBrowse Unstructured Data Server
- postStop Browsing Unstructured Data Server
- getGet All Unstructured Data Server Inventory Browse Sessions
- getGet Unstructured Data Server Inventory Browse Session
- getGet All Microsoft Entra ID Tenants
- postAdd Microsoft Entra ID Tenant
- getGet Microsoft Entra ID Tenant
- putEdit Microsoft Entra ID Tenant
- delRemove Microsoft Entra ID Tenant
- getGet Active Directory Objects from Domain
- getGet Available Disk Slots for Platform
- Traffic Rules
- General Options
- getGet General Options
- putEdit General Options
- getGet Email Settings
- putEdit Email Settings
- postSend Test Email
- postCheck SMTP Server Certificate
- getGet Host Authentication Settings
- putEdit Host Authentication Settings
- postExport Trusted Hosts List to a File
- postImport Trusted Hosts List from a File
- getGet Notification Settings
- putEdit Notification Settings
- getGet Event Forwarding Settings
- putEdit Event Forwarding Settings
- getGet Storage Latency Settings
- putEdit Storage Latency Settings
- postAdd Latency Settings for Specific Datastore
- getGet Latency Settings for Specific Datastore
- putEdit Latency Settings for Specific Datastore
- delRemove Latency Settings for Specific Datastore
- getGet VSA Event Forwarding Settings
- putEdit VSA Event Forwarding Settings
- getGet Daemon Settings for VSA Event Forwarding
- putEdit Daemon Settings for VSA Event Forwarding
- getGet Node Exporter Settings
- putUpdate Node Exporter Settings
- postSet Node Exporter Basic Authentication
- Users and Roles
- getGet All Users and Groups
- postAdd User or Group
- getGet User or Group
- delRemove User or Group
- getGet Roles Assigned to User or Group
- putEdit Roles Assigned to User or Group
- postChange Service Account Mode
- postReset MFA for Specific User
- getGet All Roles
- postCreate Custom Role
- getGet Role
- putEdit Custom Role
- delDelete Custom Role
- getGet Role Permissions
- getGet Custom Role Details
- postClone Custom Role
- getGet MFA Settings
- putEdit MFA Settings
- getGet All Restore Options
- ACL
- Global Exclusions
- Security
- postStart Security & Compliance Analyzer
- getGet Security & Compliance Analyzer Last Run
- getGet Security & Compliance Analyzer Schedule
- putModify Security & Compliance Analyzer Schedule
- postReset All Security & Compliance Analyzer Statuses
- getGet Security & Compliance Analyzer Results
- postSuppress Security & Compliance Analyzer Best Practice Status
- postReset Security & Compliance Analyzer Status
- getGet All Authorization Events
- getGet Authorization Event
- Malware Detection
- getGet All Malware Events
- postCreate Malware Event
- getGet Malware Event
- getGet All Malware Detection Settings
- putEdit Malware Detection Settings
- getGet Malware Suspicious File Masks Settings
- putEdit Malware Suspicious File Masks Settings
- getGet Malware Allowed Trusted Extensions
- getGet Malware File Detection Indicators of Compromise
- postEnable Monitoring of Indicators of Compromise
- postDisable Monitoring of Indicators of Compromise
- getGet Logs for SureBackup Scan Task Session
- postMark Backup Objects as Clean
- getGet All Malware Detection Objects
- getGet Malware Detection Object
- getGet All Malware Detection Exclusions
- postCreate or Update Malware Detection Exclusions
- postDelete Malware Detection Exclusions
- getGet YARA Rules
- postScan Backups with Antivirus or YARA Rules
- postStart Malware Encryption Analysis
- getDownload Malware Encryption Analysis Logs
- Configuration Backup
- Deployment
- Managed Servers
- getGet All Servers
- postAdd Server
- postGet vCenter Servers Attached to Cloud Director Server
- postGet Microsoft Hyper-V Servers Managed by Microsoft Hyper-V Cluster or SCVMM Server
- getGet Server
- putEdit Server
- delRemove Server
- postChange to Single-Use Credentials
- getGet Volumes for Microsoft Hyper-V Standalone Server
- putEdit Volumes on Microsoft Hyper-V Standalone Server
- postRescan All Managed Servers
- postRescan Managed Server
- getDefault Set of Optional Managed Server Components
- postUpdate Managed Server Components
- Repositories
- getGet All Repositories
- postAdd Repository
- postRescan Repositories
- getGet All Repository States
- getGet Repository
- putEdit Repository
- delRemove Repository
- getGet Repository Access Permissions
- putEdit Repository Access Permissions
- getGet All Scale-Out Backup Repositories
- postAdd Scale-Out Backup Repository
- getGet Scale-Out Backup Repository
- putEdit Scale-Out Backup Repository
- delRemove Scale-Out Backup Repository
- postEnable Sealed Mode
- postDisable Sealed Mode
- postEnable Maintenance Mode
- postDisable Maintenance Mode
- Mount Servers
- Proxies
- WAN Accelerators
- Helper Appliance Templates
- High Availability (HA) Cluster
- Jobs
- getGet All Jobs
- postCreate Job
- getGet All Job States
- getGet Job
- putEdit Job
- delDelete Job
- postStart Job
- postStop Job
- postRetry Job
- postDisable Job
- postEnable Job
- postApply Backup Policy Configuration
- postClear Backup Cache
- postClone Job
- postStart Quick Backup for VMware vSphere or VMware Cloud Director VM
- postStart Quick Backup for Hyper-V VM
- postStart Quick Backup for Agent-Managed Machine
- Backups
- getGet All Backups
- getGet Backup
- delDelete Backup
- postView Backup Details
- getGet Backup Objects
- delDelete Backup Object
- postDownload Backup Metadata
- getGet All Backup Files
- getGet Backup File
- postMark Backup File as Clean
- postMark Backup File as Infected
- postRun Health Check and Repair
- postCopy Backups to Another Repository
- postCopy Machine Backups to Another Repository or Folder
- postMove Backup to Another Repository
- postMove Backup Objects to Another Job
- getGet Move/Copy Backup Sessions Awaiting Action
- postManage a Move/Copy Backup Session Awaiting Action
- Backup Objects
- Restore Points
- Restore
- postRestore Entire File Share
- postRestore Entire Object Storage Bucket or Container
- getGet All Mount Points for Instant File Share Recovery
- postStart Instant File Share Recovery
- getGet Mount Point for Instant File Share Recovery
- postStop File Share Publishing
- postStart File Share Migration
- postStart File Share Switchover
- getGet File Share Switchover Settings
- putUpdate File Share Switchover Settings
- postStart File Restore from Unstructured Data Backup
- postUnmount Unstructured Data FLR Volumes
- postProlong a Retrieval Operation from Cold Object Storage
- getGet Cold Object Storage Retrieval Operations
- getGet All Mount Points for Instant Recovery to VMware vSphere
- postStart Instant Recovery to VMware vSphere
- getGet Mount Point for Instant Recovery to VMware vSphere
- postStop Publishing Machine to VMware vSphere
- postStart Migrating Machine to VMware vSphere
- getGet All Mount Points for Instant Recovery to Microsoft Hyper-V
- postStart Instant Recovery to Microsoft Hyper-V
- getGet Mount Point for Instant Recovery to Microsoft Hyper-V
- postStop Publishing Machine to Microsoft Hyper-V
- postStart Migrating Machine to Microsoft Hyper-V
- getGet All Mount Points for Instant Recovery to Microsoft Azure
- postStart Instant Recovery to Microsoft Azure
- getGet Mount Point for Instant Recovery to Microsoft Azure
- getGet All Mount Sessions for Instant Recovery to Microsoft Azure
- postStop Publishing Machine to Microsoft Azure
- postStart Migrating Machine to Microsoft Azure
- getGet Settings for Switchover to Microsoft Azure
- putUpdate Settings for Switchover to Microsoft Azure
- postStart Switchover to Microsoft Azure
- postRestore Entire VMware vSphere VM
- postRestore Entire VMware Cloud Director VM
- postRestore Entire Microsoft Hyper-V VM
- getGet All FCD Mount Points
- postStart Instant FCD Recovery
- getGet FCD Mount Point
- postStop FCD Publishing
- postStart FCD Migration
- postStart File Restore
- postUnmount File System
- postGet User Code for Delegated Restore of Microsoft Entra ID Items
- postGet Credentials for Delegated Restore of Microsoft Entra ID Items
- getGet Redirect URI for Delegated Restore of Microsoft Entra ID Items
- postPerform Authorization Code Exchange for Delegated Restore of Microsoft Entra ID Items
- postMount Microsoft Entra ID Tenant
- postStart Microsoft Entra ID Tenant Restore from Copy
- postUnmount Microsoft Entra ID Tenant
- postStart Microsoft Entra ID Audit Log Restore
- postUnmount Microsoft Entra ID Audit Logs
- postStarts Volume Restore for Agent or Recovery Appliance
- Application Items Restore
- DiskManagement
- postInitialize Disk Management
- postMap Backup Layout to Host Layout Automatically
- putKeep Disk Management Session Alive
- getGet Current Restore Layout of Host
- postApply Backup Layout
- postApply Disk Layout
- postErase Disk
- postRemove Partition
- postResize Partition
- postGet Partition Resize Options
- postRestore Partition
- putUnlock BitLocker-Protected Volume
- putCreate Disk Management Checkpoint
- putRevert to Disk Management Checkpoint
- Recovery Media
- Data Integration API
- Backup Browser
- postValidate Target Machine Credentials
- postValidate FLR Restore Item Target Path
- getGet All File Restore Mount Points
- getGet File Restore Mount Point
- getGet Restored Files Audit
- postBrowse File System
- postCompare Attributes
- postCompare Files and Folders
- postSearch for Files and Folders
- postBrowse Search Results
- postRestore Files and Folders to Original Location
- postRestore Files and Folders to Another Location
- postPrepare Files and Folders for Download
- postDownload Files and Folders
- getDownload Files and Folders
- getGet All Unstructured Data Mount Points
- getGet Unstructured Data Mount Point
- postBrowse Unstructured Data File System
- postGet Restore Points of Unstructured Data File System Item
- postSearch for Files and Folders in Unstructured Data Mount Point
- postBrowse Search Results in Unstructured Data Mount Point
- postCopy Files and Folders to Specific Folder
- postRestore Files and Folders from Unstructured Data Backup
- postPrepare Files and Folders for Download from Unstructured Data Backup
- getDownload Files and Folders
- postCompare Attributes of Unstructured Data Backup with Source
- postCompare Files and Folders of Unstructured Data Backup with Source
- getGet Mount Points of All Microsoft Entra ID Tenants
- getGet Mount Point of Microsoft Entra ID Tenant
- postGet Restore Points of Microsoft Entra ID Tenant
- getGet Protection Scope of Microsoft Entra ID Tenant
- postGet Microsoft Entra ID Items
- postGet Microsoft Entra ID Item
- postGet Restore Points of Microsoft Entra ID Item
- postValidate Microsoft Entra ID Items
- postCheck Microsoft Entra ID Items in Production
- postGenerate Microsoft Entra ID User Passwords
- postRestore Microsoft Entra ID Items
- postRestore Microsoft Entra ID Item Properties
- postCompare Microsoft Entra ID Item Properties
- postStart Comparing Microsoft Entra ID Item Properties
- getGet Comparison Results for Microsoft Entra ID Items
- postStart Comparing Microsoft Entra ID Conditional Access Policy
- getGet Comparison Results for Microsoft Entra ID Conditional Access Policy
- postStart Exporting Microsoft Entra ID Items to JSON
- getGet JSON Export Results for Microsoft Entra ID Items
- postExport Microsoft Entra ID Tenant Objects To JSON
- postExport Microsoft Entra ID Items
- postUpload Microsoft Entra ID Users
- postUpload Microsoft Entra ID Groups
- postUpload Microsoft Entra ID Administrative Units
- postUpload Microsoft Entra ID Roles
- postUpload Microsoft Entra ID Applications
- postUpload Microsoft Entra ID Conditional Access Policies
- postUpload Microsoft Entra ID Device Configurations
- postUpload Microsoft Entra ID Organization Contacts
- postUpload Microsoft Entra ID Devices
- getGet All Restore Sessions of Microsoft Entra ID Tenant
- getGet Restore Session of Microsoft Entra ID Tenant
- getGet Restore Session Logs of Microsoft Entra ID Tenant
- postStop Restore Session of Microsoft Entra ID Tenant
- postReveal Microsoft Entra ID BitLocker Recovery Key
- Tasks
- Replicas
- Replica Restore Points
- Failover
- Failback
- Sessions
- Agents
- getGet All Recovery Tokens
- postCreate Recovery Token
- getGet Recovery Token
- putEdit Recovery Token
- delDelete Recovery Token
- getGet All Protected Linux Computers
- getGet Protected Linux Computer
- getGet All Discovered Entities
- getGet All Agent States
- getGet Agent State
- getGet Agent Backups
- postAttach Backups to Agent
- postDetach Backups from Agent
- getGet Protection Groups
- postAdd Protection Group
- getGet Protection Group
- putEdit Protection Group
- delRemove Protection Group
- postRescan Protection Group
- postEnable Protection Group
- postDisable Protection Group
- postDownload Protection Group Packages
- getGet Discovered Entities
- postRescan Discovered Entities
- postReboot Discovered Entities
- postInstall Agent on Discovered Entities
- postUninstall Agent from Discovered Entities
- postUpgrade Agent on Discovered Entities
- postInstall CBT Driver on Discovered Entities
- postUninstall CBT Driver from Discovered Entities
- postUninstall All Components from Discovered Entities
- postAdd Discovered Entities to Trusted Hosts List
- postPrepare Agent Hosts for Remote Bare Metal Recovery
- postRecreate Embedded Recovery Media on Agent Hosts
- getGet Discovered Entity
- delRemove Discovered Entity
- postCreate Recovery Media Task for Discovered Entity
- getCreate Recovery Media for Discovered Entity
- getGet Linux Agent Packages
- getGet Unix Agent Packages
- getGet Agents Recovery Appliances
- getGet Agents Recovery Appliance
- postReboots Agents Recovery Appliances
- postReboots Agents Recovery Appliance
- Active Directory Domains
- Automation
- postImport Jobs
- postExport Jobs
- postImport Credentials
- postExport Credentials
- postImport Cloud Credentials
- postExport Cloud Credentials
- postImport Proxies
- postExport Proxies
- postImport Servers
- postExport Servers
- postImport Repositories
- postExport Repositories
- postImport Encryption Passwords
- postExport Encryption Passwords
- getGet All Automation Sessions
- getGet Automation Session
- getGet Automation Session Logs
- postStop Automation Session
- Log export
The Backup Browser section defines operations that allow you to:
- Browse the file system, compare files and folders, and perform file restore.
- Browse Microsoft Entra ID tenant backups, compare Microsoft Entra ID items, and restore entire items or their properties.
- Browse the Microsoft Entra ID log files, compare files and folders, and restore Microsoft Entra ID logs.
Validate Target Machine Credentials
The HTTP POST request to the /api/v1/restore/flr/{sessionId}/validateCredentials endpoint validates the target machine credentials in a restore session that has the specified sessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| restoreMode required | string (EFlrRestoreModeType) Restore mode for file-level restore. |
| credentialsId | string <uuid> ID of a credentials record used to connect to the target machine. If the ID is not specified, Veeam Backup & Replication will try to find credentials for the target machine in the stored credential records. |
object (FlrRestoreTargetHostModel) Target machine. To get an inventory object, run the Get Inventory Objects request. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "restoreMode": "OriginalLocation",
- "credentialsId": "a1b2c3d4-1111-2222-3333-444455556666"
}- 200
- 400
- 401
- 403
- 500
{- "isSuccessful": false,
- "message": "Failed to validate Windows FLR guest credentials for target machine. Error: Logon failure: unknown user name or bad password.",
- "credentialsId": "a1b2c3d4-1111-2222-3333-444455556666"
}Validate FLR Restore Item Target Path
The HTTP POST request to the /api/v1/restore/flr/{sessionId}/validateRestoreItemTargetPath endpoint checks whether a target path needs to be provided for the specified file-level restore item. Call this endpoint after the target machine credentials have been validated.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| itemPath required | string Path to the item to be restored. |
| isRestoreToOriginal required | boolean If |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "itemPath": "/data/share/reports/Q1.xlsx",
- "isRestoreToOriginal": true
}- 200
- 400
- 401
- 403
- 404
- 500
{- "isTargetPathNeeded": false,
- "targetPath": "/data/share/reports/Q1.xlsx"
}Get All File Restore Mount Points
The HTTP GET request to the /api/v1/backupBrowser/flr endpoint gets an array of all active file restore mount points.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
query Parameters
| skip | integer <int32> Number of mount points to skip. |
| limit | integer <int32> Default: 200 Maximum number of mount points to return. |
| orderColumn | string (EFlrBrowseMountFiltersOrderColumn) Sorts mount points by one of the mount point parameters. |
| orderAsc | boolean If |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "data": [
- {
- "type": "Linux",
- "sessionId": "1dc723e8-12a0-4480-bc34-6cb117d3d4a1",
- "restorePointId": "1e15c256-91fd-439e-a086-b27b1b389a2a",
- "mountErrors": [ ],
- "properties": {
- "pathSeparator": "/"
}, - "sourceProperties": {
- "machineName": "ubuntu88",
- "restorePointName": "ubuntu88"
}
}, - {
- "type": "Windows",
- "sessionId": "f031db1c-8294-4ace-b6f1-bb7e299e9e53",
- "restorePointId": "2b25d367-82ee-450f-b197-c38c2c490b3b",
- "mountErrors": [ ],
- "properties": {
- "pathSeparator": "\\"
}, - "sourceProperties": {
- "machineName": "winsp01",
- "restorePointName": "winsp01"
}
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 200
}
}Get File Restore Mount Point
The HTTP GET request to the /api/v1/backupBrowser/flr/{sessionId} endpoint gets a file restore mount point that was created by a restore session that has the specified sessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "type": "Linux",
- "sessionId": "1dc723e8-12a0-4480-bc34-6cb117d3d4a1",
- "restorePointId": "ab3361d3-df80-474d-b23f-ea9a498b9e8c",
- "mountErrors": [ ],
- "properties": {
- "pathSeparator": "/"
}, - "sourceProperties": {
- "machineName": "ubuntu88",
- "restorePointName": "ubuntu88"
}
}Get Restored Files Audit
The HTTP GET request to the /api/v1/backupBrowser/flr/{sessionId}/audit endpoint gets an aggregated view of items restored during a restore session that has the specified sessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "items": [
- {
- "itemType": "Folder",
- "restoreStatus": "Succeeded",
- "sourcePath": "C:\\Users\\Administrator\\",
- "targetPath": "C:\\Users\\Administrator\\",
- "targetHost": "localhost",
- "targetName": "localhost",
- "size": 3890,
- "jobName": "MS SQL backup - dlsql02",
- "restorePointId": "1e15c256-91fd-439e-a086-b27b1b389a2a",
- "restorePointDate": "2025-06-16T22:50:24.805063",
- "restoreStartTime": "2025-06-17T12:11:06.685788",
- "restoreFinishTime": "2025-06-17T12:11:07.970227",
- "restoreSessionId": "d6a83362-d2e4-4e7a-9ec4-dd7222731891",
- "initiatorName": "veeamadmin",
- "name": "Downloads"
}
], - "pagination": {
- "total": 1,
- "count": 1
}
}Browse File System
The HTTP POST request to the /api/v1/backupBrowser/flr/{sessionId}/browse endpoint browses file system items (drives, folders, files and links) available in a restore session that has the specified sessionId.
You can use this request in the following cases:
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| path required | string Browsing path. |
object (FlrBrowseFiltrationModel) Filter settings. | |
object (FlrBrowseOrderSpec) Sorting settings. | |
object (PaginationSpec) Pagination settings. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "path": ""
}- 200
- 400
- 401
- 403
- 500
{- "path": "C:\\Users",
- "items": [
- {
- "type": "File",
- "itemState": "NotAvailable",
- "location": "C:\\Users",
- "displayName": "desktop.ini",
- "name": "desktop.ini",
- "size": 174,
- "creationDate": "2023-09-15T09:16:48.5540496+02:00",
- "modifiedDate": "2023-09-15T09:16:48.5540496+02:00"
}, - {
- "type": "Folder",
- "itemState": "NotAvailable",
- "location": "C:\\Users",
- "displayName": "Public",
- "name": "Public",
- "size": 0,
- "creationDate": "2023-09-15T09:19:00.9562431+02:00",
- "modifiedDate": "2024-07-11T13:51:19.2515441+02:00"
}, - {
- "type": "Folder",
- "itemState": "NotAvailable",
- "location": "C:\\Users",
- "displayName": "sheila.d.cory",
- "name": "sheila.d.cory",
- "size": 0,
- "creationDate": "2023-07-25T20:31:51.6184821+02:00",
- "modifiedDate": "2023-07-27T18:19:45.0120786+02:00"
}
], - "pagination": {
- "total": 3,
- "count": 3,
- "skip": 0,
- "limit": 200
}
}Compare Attributes
The HTTP POST request to the /api/v1/backupBrowser/flr/{sessionId}/compareAttributes endpoint compares attributes of file system items (drives, folders, files and links) from a restore session that has the specified sessionId with attributes of original items.
The operation is allowed for Microsoft Windows machines only.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| path required | string Path to the item whose attributes you want to compare. |
| showUnchangedAttributes | boolean If |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Method not allowed. Indicates that the server knows the request method, but the target resource does not support this method.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "path": "C:\\Users\\sheila.d.cory\\Documents",
- "showUnchangedAttributes": true
}- 200
- 400
- 401
- 403
- 405
- 500
{- "path": "C:\\Users\\sheila.d.cory\\Documents",
- "attributes": [
- {
- "name": "Attributes",
- "valueBackup": "ReadOnly, Directory",
- "valueProduction": "ReadOnly, Directory",
- "isChanged": false
}, - {
- "name": "CreateDateUtc",
- "valueBackup": "7/25/2023 6:31:51 PM",
- "valueProduction": "7/25/2023 6:31:51 PM",
- "isChanged": false
}, - {
- "name": "ModifyDateUtc",
- "valueBackup": "11/7/2023 3:28:12 PM",
- "valueProduction": "11/7/2023 3:28:12 PM",
- "isChanged": false
}, - {
- "name": "IsArchived",
- "valueBackup": "False",
- "valueProduction": "False",
- "isChanged": false
}, - {
- "name": "IsCollected",
- "valueBackup": "True",
- "valueProduction": "True",
- "isChanged": false
}, - {
- "name": "IsEncrypted",
- "valueBackup": "False",
- "valueProduction": "False",
- "isChanged": false
}, - {
- "name": "IsHidden",
- "valueBackup": "False",
- "valueProduction": "False",
- "isChanged": false
}, - {
- "name": "IsReadonly",
- "valueBackup": "True",
- "valueProduction": "True",
- "isChanged": false
}
]
}Compare Files and Folders
The HTTP POST request to the /api/v1/backupBrowser/flr/{sessionId}/compareToProduction endpoint compares file system items (drives, folders, files and links) on the production machine with the items available in a restore session that has the specified sessionId. After the comparison completes, check the comparison results using the Browse File System request.
The operation is allowed for Microsoft Windows machines only.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| isEnabled required | boolean If |
| paths required | Array of strings Array of item paths that you want to compare. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Method not allowed. Indicates that the server knows the request method, but the target resource does not support this method.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "isEnabled": true,
- "paths": [
- "C:\\Users\\sheila.d.cory\\Documents",
- "C:\\Users\\sheila.d.cory\\Downloads"
]
}- 200
- 400
- 401
- 403
- 405
- 500
{ }Search for Files and Folders
The HTTP POST request to the /api/v1/backupBrowser/flr/{sessionId}/search endpoint creates a search task to find required file system items (drives, folders, files and links) available in a restore session that has the specified sessionId.
To get the search results, run the Browse Search Results request.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| path required | string Search path. |
| searchString required | string Search string. The following wildcard characters are supported: "*", "?" and "+". |
| disableRecursiveSearch | boolean If |
An FlrSearch task has been created to search for file system items. To check the progress, track the task state.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "path": "C:\\Users\\sheila.d.cory\\Documents",
- "searchString": "*docx"
}- 201
- 400
- 401
- 403
- 500
{- "type": "FlrSearch",
- "state": "Starting",
- "result": "None",
- "id": "32d764f7-18b0-47d9-8e34-1be27bc32d3b",
- "name": "Search files on VM winsp01",
- "progressPercent": 0,
- "creationTime": "2023-11-07T17:41:51.32221+01:00",
- "endTime": null
}Browse Search Results
The HTTP POST request to the /api/v1/backupBrowser/flr/{sessionId}/search/{taskId}/browse endpoint browses search results of a search task that has the specified taskId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
| taskId required | string <uuid> ID of the search task. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
object (PaginationSpec) Pagination settings. | |
object (FlrSearchForResultOrderSpec) Sorting settings. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "order": {
- "orderColumn": "Name"
}
}- 200
- 400
- 401
- 403
- 500
{- "path": "C:\\Users\\sheila.d.cory\\Documents",
- "searchString": "*docx",
- "items": [
- {
- "type": "File",
- "itemState": "Unchanged",
- "location": "C:\\Users\\sheila.d.cory\\Documents\\Documents for SharePoint",
- "displayName": "Document01.docx",
- "name": "Document01.docx",
- "size": 13712,
- "creationDate": "2023-11-07T16:28:12.5685143+01:00",
- "modifiedDate": "2023-07-26T20:56:32.6357349+02:00"
}, - {
- "type": "File",
- "itemState": "Unchanged",
- "location": "C:\\Users\\sheila.d.cory\\Documents\\Documents for SharePoint",
- "displayName": "Document02.docx",
- "name": "Document02.docx",
- "size": 19484,
- "creationDate": "2023-11-07T16:28:12.5685143+01:00",
- "modifiedDate": "2023-07-26T20:58:48.9404094+02:00"
}, - {
- "type": "File",
- "itemState": "Unchanged",
- "location": "C:\\Users\\sheila.d.cory\\Documents\\Documents for SharePoint",
- "displayName": "Document04.docx",
- "name": "Document04.docx",
- "size": 13712,
- "creationDate": "2023-11-07T16:28:12.7560357+01:00",
- "modifiedDate": "2023-07-26T20:56:32.6357349+02:00"
}, - {
- "type": "File",
- "itemState": "Unchanged",
- "location": "C:\\Users\\sheila.d.cory\\Documents\\Documents for SharePoint",
- "displayName": "Document06.docx",
- "name": "Document06.docx",
- "size": 4897,
- "creationDate": "2023-11-07T16:28:12.7872775+01:00",
- "modifiedDate": "2023-11-07T16:36:04.413056+01:00"
}, - {
- "type": "File",
- "itemState": "Unchanged",
- "location": "C:\\Users\\sheila.d.cory\\Documents\\Documents for SharePoint",
- "displayName": "Document07.docx",
- "name": "Document07.docx",
- "size": 18436,
- "creationDate": "2023-11-07T16:28:12.5841302+01:00",
- "modifiedDate": "2023-07-26T20:58:19.1911861+02:00"
}
], - "pagination": {
- "total": 5,
- "count": 5,
- "skip": 0,
- "limit": 200
}
}Restore Files and Folders to Original Location
The HTTP POST request to the /api/v1/backupBrowser/flr/{sessionId}/restore endpoint restores file system items (folders, files and links) to the original location.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| sourcePath required | Array of strings Array of paths to the items that you want to restore. |
| restoreType required | string (EFlrRestoreType) Restore type. |
| credentialsId | string <uuid> ID of a credentials record used to connect to the target machine. Allowed only for Linux machines. |
| targetPath | string Path to the target folder. |
An FlrRestore task has been created to restore the items. To check the progress, track the task state.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "sourcePath": [
- "C:\\Users\\sheila.d.cory\\Documents",
- "C:\\Users\\sheila.d.cory\\Downloads"
], - "restoreType": "Keep"
}- 201
- 400
- 401
- 403
- 500
{- "type": "FlrRestore",
- "state": "Starting",
- "result": "None",
- "id": "aabc5716-417b-4761-94a8-59ef21113ed2",
- "name": "winsp01",
- "progressPercent": 0,
- "creationTime": "2023-11-07T18:22:17.8433688+01:00",
- "endTime": null,
- "logs": {
- "data": [ ],
- "pagination": {
- "total": 0,
- "count": 0,
- "skip": 0,
- "limit": 100
}
}
}Restore Files and Folders to Another Location
The HTTP POST request to the /api/v1/backupBrowser/flr/{sessionId}/restoreTo endpoint restores file system items (folders, files and links) to another location.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| sourcePath required | Array of strings Array of paths to the items that you want to restore. |
| restoreType required | string (EFlrRestoreType) Restore type. |
required | object (FlrRestoreTargetHostModel) Target machine. To get an inventory object, run the Get Inventory Objects request. |
| targetPath required | string Path to the target folder. |
| credentialsId | string <uuid> ID of a credentials record used to connect to the target machine. |
An FlrRestore task has been created to restore the items. To check the progress, track the task state.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "sourcePath": [
- "C:\\Users\\sheila.d.cory\\Documents"
], - "restoreType": "Overwrite",
- "credentialsId": "c0940fba-7c6e-445e-bea3-c0fa20e9ef15",
- "targetHost": {
- "type": "VMware",
- "vmObject": {
- "type": "VirtualMachine",
- "hostName": "vcenter01.tech.local",
- "name": "enterprise03",
- "objectId": "vm-1086",
- "urn": "vc:vcenter01.tech.local;folder:group-d1;datacenter:datacenter-1001;folder:group-h1003;computeresource:domain-s1006;hostsystem:host-1008;resourcepool:resgroup-1023;virtualmachine:vm-1086",
- "platform": "VSphere",
- "size": "337.6 GB"
}
}, - "targetPath": "C:\\temp"
}- 201
- 400
- 401
- 403
- 500
{- "type": "FlrRestore",
- "state": "Starting",
- "result": "None",
- "id": "aabc5716-417b-4761-94a8-59ef21113ed2",
- "name": "winsp01",
- "progressPercent": 0,
- "creationTime": "2023-11-07T18:22:17.8433688+01:00",
- "endTime": null,
- "logs": {
- "data": [ ],
- "pagination": {
- "total": 0,
- "count": 0,
- "skip": 0,
- "limit": 100
}
}
}Prepare Files and Folders for Download
The HTTP POST request to the /api/v1/backupBrowser/flr/{sessionId}/prepareDownload endpoint prepares files and folders for download and packs them into a ZIP file. In response, a download task is created.
To download the ZIP file, specify the task ID in the Download Files and Folders request.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| sourcePath required | Array of strings Array of paths to the items that you want to download. |
An FlrDownload task has been created to download the items. To check the progress, track the task state.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "sourcePath": [
- "C:\\Users\\sheila.d.cory\\Documents",
- "C:\\Users\\sheila.d.cory\\Downloads"
]
}- 201
- 400
- 401
- 403
- 500
{- "type": "FlrDownload",
- "state": "Working",
- "result": "None",
- "id": "82ac5bd1-36bb-4980-b79e-0634f90c5754",
- "name": "FLR Download from VM winsp01",
- "progressPercent": 0,
- "creationTime": "2023-11-07T21:24:36.7715523+01:00",
- "endTime": null
}Download Files and Folders
The HTTP POST request to the /api/v1/backupBrowser/flr/{sessionId}/prepareDownload/{taskId}/download endpoint downloads a ZIP archive with files and folders of a download task that has the specified taskId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
| taskId required | string <uuid> Download task ID. To get the ID, run the Get All Tasks request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 400
- 401
- 403
- 500
{- "errorCode": "UnexpectedContent",
- "message": "One or more request parameters are not valid."
}Download Files and Folders
The HTTP GET request to the /api/v1/backupBrowser/flr/{sessionId}/prepareDownload/{taskId}/download endpoint downloads a ZIP archive with files and folders of a download task that has the specified taskId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All File Restore Mount Points request. |
| taskId required | string <uuid> Download task ID. To get the ID, run the Get All Tasks request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 400
- 401
- 403
- 500
{- "errorCode": "UnexpectedContent",
- "message": "One or more request parameters are not valid."
}Get All Unstructured Data Mount Points
The HTTP GET request to the /api/v1/backupBrowser/flr/unstructuredData endpoint gets all or specified active unstructured data mount points.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
query Parameters
| skip | integer <int32> Number of mount points to skip. |
| limit | integer <int32> Default: 200 Maximum number of mount points to return. |
| orderColumn | string (EUnstructuredDataFlrBrowseMountFiltersOrderColumn) Sorts mount points by one of the mount point parameters. |
| orderAsc | boolean If |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "data": [
- {
- "sessionId": "f7c1a9d2-8b34-4e21-9f0a-3c6d7e8b1a45"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 100
}
}Get Unstructured Data Mount Point
The HTTP GET request to the /api/v1/backupBrowser/flr/unstructuredData/{sessionId} endpoint gets an unstructured data mount point that was created by a restore session that has the specified sessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Unstructured Data Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "sessionId": "b7e1c2d3-4a5f-6789-abcd-ef0123456789",
- "properties": {
- "pathSeparator": "/"
}, - "sourceProperties": {
- "backupId": "c4d5e6f7-a8b9-0123-4567-89abcdef0123"
}
}Browse Unstructured Data File System
The HTTP POST request to the /api/v1/backupBrowser/flr/unstructuredData/{sessionId}/browse endpoint browses file system items (drives, folders, files and links) available in a restore session that has the specified sessionId.
You can use this request in the following cases:
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Unstructured Data Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| path required | string Browsing path. |
object (FlrBrowseFiltrationModel) Filter settings. | |
object (FlrBrowseOrderSpec) Sorting settings. | |
object (PaginationSpec) Pagination settings. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "path": "/data/share/reports"
}- 200
- 400
- 401
- 403
- 500
{- "path": "/data/share/reports",
- "items": [
- {
- "location": "/data/share/reports",
- "name": "Q1.xlsx",
- "type": "File",
- "size": 524288,
- "creationDate": "2026-05-20T10:30:00Z",
- "modifiedDate": "2026-05-20T10:30:00Z",
- "itemState": "Unchanged",
- "versionsCount": 1
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 100
}
}Get Restore Points of Unstructured Data File System Item
The HTTP POST request to the /api/v1/backupBrowser/flr/unstructuredData/{sessionId}/restorePoints endpoint gets an array of restore points available in a restore session that has the specified sessionId. This request helps you find the restore point from which you want to restore file system item.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Unstructured Data Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| path required | string Path to the item. |
object (UnstructuredDataFlrBrowseRestorePointsSortingSpec) Sorting options. | |
object (PaginationSpec) Pagination settings. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "path": "/data/share/reports/Q1.xlsx"
}- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "id": "0d6f1a23-4b56-4c78-9a01-b2c3d4e5f607",
- "name": "Q1.xlsx",
- "platformName": "VMware",
- "platformId": "8c2e4f10-3a5b-4d6c-8e9f-0a1b2c3d4e5f",
- "creationTime": "2026-05-20T10:30:00Z",
- "backupId": "1f2e3d4c-5b6a-7980-1a2b-3c4d5e6f7081",
- "type": "Increment",
- "allowedOperations": [
- "StartFlrRestore"
]
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 100
}
}Search for Files and Folders in Unstructured Data Mount Point
The HTTP POST request to the /api/v1/backupBrowser/flr/unstructuredData/{sessionId}/search endpoint creates a search task to find required file system items (drives, folders, files and links) available in a restore session that has the specified sessionId.
To get the search results, run the Browse Search Results in Unstructured Data Mount Point request.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Unstructured Data Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| path required | string Search path. |
| searchString required | string Search string. The following wildcard characters are supported: "*", "?" and "+". |
| disableRecursiveSearch | boolean If |
An FlrSearch task has been created to search for file system items. To check the progress, track the task state.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "path": "C:\\Users\\sheila.d.cory\\Documents",
- "searchString": "*docx"
}- 201
- 400
- 401
- 403
- 500
{- "type": "FlrSearch",
- "state": "Starting",
- "result": "None",
- "id": "32d764f7-18b0-47d9-8e34-1be27bc32d3b",
- "name": "Search files on VM winsp01",
- "progressPercent": 0,
- "creationTime": "2023-11-07T17:41:51.32221+01:00",
- "endTime": null
}Browse Search Results in Unstructured Data Mount Point
The HTTP POST request to the /api/v1/backupBrowser/flr/unstructuredData/{sessionId}/search/{taskId}/browse endpoint browses search results of a search task that has the specified taskId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Unstructured Data Mount Points request. |
| taskId required | string <uuid> Search task ID. To get the ID, run the Get All Tasks request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
object (PaginationSpec) Pagination settings. | |
object (FlrSearchForResultOrderSpec) Sorting settings. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "order": {
- "orderColumn": "Name"
}
}- 200
- 400
- 401
- 403
- 500
{- "path": "C:\\Users\\sheila.d.cory\\Documents",
- "searchString": "*docx",
- "items": [
- {
- "type": "File",
- "itemState": "Unchanged",
- "location": "C:\\Users\\sheila.d.cory\\Documents\\Documents for SharePoint",
- "displayName": "Document01.docx",
- "name": "Document01.docx",
- "size": 13712,
- "creationDate": "2023-11-07T16:28:12.5685143+01:00",
- "modifiedDate": "2023-07-26T20:56:32.6357349+02:00"
}, - {
- "type": "File",
- "itemState": "Unchanged",
- "location": "C:\\Users\\sheila.d.cory\\Documents\\Documents for SharePoint",
- "displayName": "Document02.docx",
- "name": "Document02.docx",
- "size": 19484,
- "creationDate": "2023-11-07T16:28:12.5685143+01:00",
- "modifiedDate": "2023-07-26T20:58:48.9404094+02:00"
}, - {
- "type": "File",
- "itemState": "Unchanged",
- "location": "C:\\Users\\sheila.d.cory\\Documents\\Documents for SharePoint",
- "displayName": "Document04.docx",
- "name": "Document04.docx",
- "size": 13712,
- "creationDate": "2023-11-07T16:28:12.7560357+01:00",
- "modifiedDate": "2023-07-26T20:56:32.6357349+02:00"
}, - {
- "type": "File",
- "itemState": "Unchanged",
- "location": "C:\\Users\\sheila.d.cory\\Documents\\Documents for SharePoint",
- "displayName": "Document06.docx",
- "name": "Document06.docx",
- "size": 4897,
- "creationDate": "2023-11-07T16:28:12.7872775+01:00",
- "modifiedDate": "2023-11-07T16:36:04.413056+01:00"
}, - {
- "type": "File",
- "itemState": "Unchanged",
- "location": "C:\\Users\\sheila.d.cory\\Documents\\Documents for SharePoint",
- "displayName": "Document07.docx",
- "name": "Document07.docx",
- "size": 18436,
- "creationDate": "2023-11-07T16:28:12.5841302+01:00",
- "modifiedDate": "2023-07-26T20:58:19.1911861+02:00"
}
], - "pagination": {
- "total": 5,
- "count": 5,
- "skip": 0,
- "limit": 200
}
}Copy Files and Folders to Specific Folder
The HTTP POST request to the /api/v1/backupBrowser/flr/unstructuredData/{sessionId}/copyTo endpoint copies file system items (folders, files and links) to the machine where the Veeam Backup & Replication console is installed or to a network shared folder.
When copying symbolic links, Veeam Backup & Replication copies the content that the links point to.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Unstructured Data Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| sourcePath required | Array of strings Array of paths to the items that you want to restore. |
| isRecursive | boolean If |
| restoreMode | string (EUnstructuredDataFLRRestoreMode) Restore point settings. Use this property if you have specified the Do not use this property if you have specified the |
| restoreType | string (EUnstructuredDataFLRRestoreType) Restore type. |
| toDateTime | string <date-time> Date when the restore point was created. Use this property when copying files and folders from an earlier restore point (the |
| unstructuredDataServerId | string <uuid> ID of a server where the target shared folder is located. Use this property when copying files and folders to a file share. To get the ID, run the Get All Unstructured Data Servers request. |
| path | string Path to the target folder. |
| copyToBackupServer | boolean If |
| restorePermissions | boolean If |
object (UnstructuredDataColdStorageRetrievalSettings) Settings for retrieving data from cold storage. |
An FlrRestore task has been created to restore the items. To check the progress, track the task state.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "sourcePath": [
- "/data/share/reports/Q1.xlsx"
], - "isRecursive": false,
- "restoreMode": "LatestPoint",
- "restoreType": "Overwrite",
- "unstructuredDataServerId": "2a3b4c5d-6e7f-8091-a2b3-c4d5e6f70819",
- "path": "/restore/reports",
- "copyToBackupServer": true,
- "restorePermissions": true
}- 201
- 400
- 401
- 403
- 500
{- "type": "FlrRestore",
- "state": "Starting",
- "result": "None",
- "id": "aabc5716-417b-4761-94a8-59ef21113ed2",
- "name": "winsp01",
- "progressPercent": 0,
- "creationTime": "2023-11-07T18:22:17.8433688+01:00",
- "endTime": null,
- "logs": {
- "data": [ ],
- "pagination": {
- "total": 0,
- "count": 0,
- "skip": 0,
- "limit": 100
}
}
}Restore Files and Folders from Unstructured Data Backup
The HTTP POST request to the /api/v1/backupBrowser/flr/unstructuredData/{sessionId}/restore endpoint restores unstructured data items.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Unstructured Data Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| sourcePath required | Array of strings Array of paths to the items that you want to restore. |
| restoreType required | string (EUnstructuredDataFLRRestoreType) Restore type. |
| isRecursive | boolean If |
| restoreMode | string (EUnstructuredDataFLRRestoreMode) Restore point settings. Use this property if you have specified the Do not use this property if you have specified the |
| toDateTime | string <date-time> Date when the restore point was created. Use this property when restoring files and folders from an earlier restore point (the |
| restorePermissions | boolean If |
object (UnstructuredDataColdStorageRetrievalSettings) Settings for retrieving data from cold storage. |
An FlrRestore task has been created to restore the items. To check the progress, track the task state.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "sourcePath": [
- "/data/share/reports/Q1.xlsx"
], - "isRecursive": false,
- "restoreType": "Overwrite",
- "restoreMode": "LatestPoint",
- "restorePermissions": true
}- 201
- 400
- 401
- 403
- 500
{- "type": "FlrRestore",
- "state": "Starting",
- "result": "None",
- "id": "aabc5716-417b-4761-94a8-59ef21113ed2",
- "name": "winsp01",
- "progressPercent": 0,
- "creationTime": "2023-11-07T18:22:17.8433688+01:00",
- "endTime": null,
- "logs": {
- "data": [ ],
- "pagination": {
- "total": 0,
- "count": 0,
- "skip": 0,
- "limit": 100
}
}
}Prepare Files and Folders for Download from Unstructured Data Backup
The HTTP POST request to the /api/v1/backupBrowser/flr/unstructuredData/{sessionId}/prepareDownload endpoint prepares files and folders for download and packs them into a ZIP file. In response, a download task is created.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Unstructured Data Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| sourcePath required | Array of strings Array of paths to the items that you want to download. |
| isRecursive | boolean If |
| restoreMode | string (EUnstructuredDataFLRRestoreMode) Restore point settings. Use this property if you have specified the Do not use this property if you have specified the |
| toDateTime | string <date-time> Date when the restore point was created. Use this property when download files and folders from an earlier restore point (the |
object (UnstructuredDataColdStorageRetrievalSettings) Settings for retrieving data from cold storage. |
An FlrDownload task has been created to download the items. To check the progress, track the task state.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "sourcePath": [
- "/data/share/reports/Q1.xlsx"
], - "isRecursive": false,
- "restoreMode": "LatestPoint"
}- 201
- 400
- 401
- 403
- 500
{- "type": "FlrDownload",
- "state": "Working",
- "result": "None",
- "id": "82ac5bd1-36bb-4980-b79e-0634f90c5754",
- "name": "FLR Download from VM winsp01",
- "progressPercent": 0,
- "creationTime": "2023-11-07T21:24:36.7715523+01:00",
- "endTime": null
}Download Files and Folders
The HTTP GET request to the /api/v1/backupBrowser/flr/unstructuredData/{sessionId}/prepareDownload/{taskId}/download endpoint downloads a ZIP archive with files and folders of a download task that has the specified taskId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Unstructured Data Mount Points request. |
| taskId required | string <uuid> Download task ID. To get the ID, run the Get All Tasks request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 400
- 401
- 403
- 500
{- "errorCode": "UnexpectedContent",
- "message": "One or more request parameters are not valid."
}Compare Attributes of Unstructured Data Backup with Source
The HTTP POST request to the /api/v1/backupBrowser/flr/unstructuredData/{sessionId}/compareAttributes endpoint compares attributes of unstructured data items from a restore session that has the specified sessionId with attributes of original items.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Unstructured Data Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| path required | string Path to the item whose attributes you want to compare. |
| showUnchangedAttributes | boolean If |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Method not allowed. Indicates that the server knows the request method, but the target resource does not support this method.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "path": "C:\\Users\\sheila.d.cory\\Documents",
- "showUnchangedAttributes": true
}- 200
- 400
- 401
- 403
- 405
- 500
{- "path": "C:\\Users\\sheila.d.cory\\Documents",
- "attributes": [
- {
- "name": "Attributes",
- "valueBackup": "ReadOnly, Directory",
- "valueProduction": "ReadOnly, Directory",
- "isChanged": false
}, - {
- "name": "CreateDateUtc",
- "valueBackup": "7/25/2023 6:31:51 PM",
- "valueProduction": "7/25/2023 6:31:51 PM",
- "isChanged": false
}, - {
- "name": "ModifyDateUtc",
- "valueBackup": "11/7/2023 3:28:12 PM",
- "valueProduction": "11/7/2023 3:28:12 PM",
- "isChanged": false
}, - {
- "name": "IsArchived",
- "valueBackup": "False",
- "valueProduction": "False",
- "isChanged": false
}, - {
- "name": "IsCollected",
- "valueBackup": "True",
- "valueProduction": "True",
- "isChanged": false
}, - {
- "name": "IsEncrypted",
- "valueBackup": "False",
- "valueProduction": "False",
- "isChanged": false
}, - {
- "name": "IsHidden",
- "valueBackup": "False",
- "valueProduction": "False",
- "isChanged": false
}, - {
- "name": "IsReadonly",
- "valueBackup": "True",
- "valueProduction": "True",
- "isChanged": false
}
]
}Compare Files and Folders of Unstructured Data Backup with Source
The HTTP POST request to the /api/v1/backupBrowser/flr/unstructuredData/{sessionId}/compareToProduction endpoint compares unstructured data items on the production share with the items available in a restore session that has the specified sessionId. After the comparison completes, check the comparison results using the Browse Unstructured Data File System request.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Unstructured Data Mount Points request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| isEnabled required | boolean If |
| paths required | Array of strings Array of item paths that you want to compare. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Method not allowed. Indicates that the server knows the request method, but the target resource does not support this method.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "isEnabled": true,
- "paths": [
- "C:\\Users\\sheila.d.cory\\Documents",
- "C:\\Users\\sheila.d.cory\\Downloads"
]
}- 200
- 400
- 401
- 403
- 405
- 500
{ }Get Mount Points of All Microsoft Entra ID Tenants
The HTTP GET request to the /api/v1/backupBrowser/entraIdTenant endpoint gets an array of all active mount points created for all Microsoft Entra ID tenants.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
query Parameters
| skip | integer <int32> Number of mount points to skip. |
| limit | integer <int32> Default: 200 Maximum number of mount points to return. |
| orderColumn | string (EFlrBrowseMountFiltersOrderColumn) Sorts mount points by one of the mount point parameters. |
| orderAsc | boolean If |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "data": [
- {
- "sessionId": "783241eb-5b56-4456-9736-379206ffc600",
- "sourceProperties": {
- "backupId": "61a85b62-41a9-4421-aa4f-568e3989fed8",
- "tenantId": "46101a50-1c07-4e11-a249-6dc349fbf909",
- "tenantName": "MSFT2"
}
}, - {
- "sessionId": "b3f568b0-88e0-4c3f-9a78-86ea4072976e",
- "sourceProperties": {
- "backupId": "61a85b62-41a9-4421-aa4f-568e3989fed8",
- "tenantId": "46101a50-1c07-4e11-a249-6dc349fbf909",
- "tenantName": "MSFT2"
}
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 200
}
}Get Mount Point of Microsoft Entra ID Tenant
The HTTP GET request to the /api/v1/backupBrowser/entraIdTenant/{sessionId} endpoint gets a Microsoft Entra ID tenant mount point created by a mount session that has the specified sessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "sessionId": "783241eb-5b56-4456-9736-379206ffc600",
- "sourceProperties": {
- "backupId": "61a85b62-41a9-4421-aa4f-568e3989fed8",
- "tenantId": "46101a50-1c07-4e11-a249-6dc349fbf909",
- "tenantName": "Tenant 1"
}
}Get Restore Points of Microsoft Entra ID Tenant
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/restorePoints endpoint gets an array of restore points available in a Microsoft Entra ID tenant backup that has the specified backupId. This request helps you find the restore point from which you want to restore tenant items.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| skip | integer >= 0 Number of restore points to skip. |
| limit | integer >= 1 Maximum number of restore points to return. |
object (EntraIdTenantRestorePointSortingSpec) Sorting options. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "limit": 5,
- "sorting": {
- "property": "CreationTime",
- "direction": "Ascending"
}
}- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "id": "8004f69b-c462-4412-bfd8-ea697052ea61",
- "creationTime": "2024-10-23T15:33:52.557121+02:00"
}, - {
- "id": "2add5743-0e45-43c1-afc3-85ed5f3a3071",
- "creationTime": "2024-10-23T22:01:36.529336+02:00"
}, - {
- "id": "8ffeea88-a439-4f27-8be8-8815ca1122f1",
- "creationTime": "2024-10-24T22:01:49.87691+02:00"
}, - {
- "id": "92b88093-f439-4e74-93ca-f736b66aab01",
- "creationTime": "2024-10-25T22:02:12.513235+02:00"
}, - {
- "id": "d67eabe0-c5f1-40d9-835b-954f9b7e4b9c",
- "creationTime": "2024-10-26T22:01:40.239859+02:00"
}
], - "pagination": {
- "total": 7,
- "count": 5,
- "skip": 0,
- "limit": 5
}
}Get Protection Scope of Microsoft Entra ID Tenant
The HTTP GET request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/protectionScope endpoint gets the protection scope of a Microsoft Entra ID tenant for a specific backup. The tenant protection scope defines the types of tenant resources that were backed up.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "tenantResources": [
- "Users",
- "Groups"
]
}Get Microsoft Entra ID Items
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/browse endpoint browses Microsoft Entra ID items available in a backup that has the specified backupId. Use this request to find the items that you want to restore. In the request body, you must specify the item type.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| type required | string (EEntraIdTenantItemType) Item type. |
| skip | integer >= 0 Number of items to skip. |
| limit | integer >= 1 Maximum number of items to return. |
object (EntraIdTenantUserFilterBrowseSpec) Filtering options. | |
object (EntraIdTenantUserSortingBrowseSpec) Sorting options. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "type": "User",
- "filter": {
- "department": "Marketing"
}, - "sorting": {
- "property": "userName",
- "direction": "ascending"
}
}- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "mailAddress": "test1@8bt3cp.onmicrosoft.com",
- "userName": "test1@8bt3cp.onmicrosoft.com",
- "userType": "Member",
- "employeeType": "Employee",
- "accountEnabled": true,
- "companyName": "Veeam Software",
- "creationType": null,
- "department": "Marketing",
- "country": "United States",
- "jobTitle": "Manager",
- "officeLocation": "Miami",
- "type": "User",
- "id": "fee6a1c9-6f07-4729-bf46-d3d4f45c7ad0",
- "displayName": "Test 1",
- "restorePointId": "e41b1345-a565-4db8-82f5-0632403630e8",
- "restorePointDate": "2024-10-15T22:11:26.218187+02:00"
}, - {
- "mailAddress": "test2@8bt3cp.onmicrosoft.com",
- "userName": "test2@8bt3cp.onmicrosoft.com",
- "userType": "Guest",
- "employeeType": "Contractor",
- "accountEnabled": true,
- "companyName": "Veeam Software",
- "creationType": null,
- "department": "Marketing",
- "country": "United States",
- "jobTitle": "Specialist",
- "officeLocation": null,
- "type": "User",
- "id": "8d9c14c9-822b-4b9d-ba1c-531275f1c6c6",
- "displayName": "Test 2",
- "restorePointId": "e41b1345-a565-4db8-82f5-0632403630e8",
- "restorePointDate": "2024-10-15T22:11:26.218187+02:00"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": null,
- "limit": null
}
}Get Microsoft Entra ID Item
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/browse/{itemId} endpoint gets a specific Microsoft Entra ID item available in a tenant backup that has the specified backupId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
| itemId required | string Item ID. To get the ID, run the Get Restore Points of Microsoft Entra ID Tenant request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| type required | string (EEntraIdTenantItemType) Item type. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "type": "User"
}- 200
- 400
- 401
- 403
- 500
{- "mailAddress": "test1@8bt3cp.onmicrosoft.com",
- "userName": "test1@8bt3cp.onmicrosoft.com",
- "userType": "Member",
- "employeeType": "Employee",
- "accountEnabled": true,
- "companyName": "Veeam Software",
- "creationType": null,
- "department": "Marketing",
- "country": "United States",
- "jobTitle": "Manager",
- "officeLocation": "Miami",
- "type": "User",
- "id": "fee6a1c9-6f07-4729-bf46-d3d4f45c7ad0",
- "displayName": "Test 1",
- "restorePointId": "e41b1345-a565-4db8-82f5-0632403630e8",
- "restorePointDate": "2024-10-15T22:11:26.218187+02:00"
}Get Restore Points of Microsoft Entra ID Item
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/browse/{itemId}/restorePoints endpoint gets restore points that were created for a Microsoft Entra ID item that has the specified itemId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
| itemId required | string Item ID. To get the ID, run the Get Restore Points of Microsoft Entra ID Tenant request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonoptional
| skip | integer >= 0 Number of restore points to skip. |
| limit | integer >= 1 Maximum number of restore points to return. |
object (EntraIdTenantRestorePointSortingSpec) Sorting options. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "limit": 5,
- "sorting": {
- "property": "CreationTime",
- "direction": "Ascending"
}
}- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "id": "8004f69b-c462-4412-bfd8-ea697052ea61",
- "creationTime": "2024-10-23T15:33:52.557121+02:00"
}, - {
- "id": "2add5743-0e45-43c1-afc3-85ed5f3a3071",
- "creationTime": "2024-10-23T22:01:36.529336+02:00"
}, - {
- "id": "8ffeea88-a439-4f27-8be8-8815ca1122f1",
- "creationTime": "2024-10-24T22:01:49.87691+02:00"
}, - {
- "id": "92b88093-f439-4e74-93ca-f736b66aab01",
- "creationTime": "2024-10-25T22:02:12.513235+02:00"
}, - {
- "id": "d67eabe0-c5f1-40d9-835b-954f9b7e4b9c",
- "creationTime": "2024-10-26T22:01:40.239859+02:00"
}
], - "pagination": {
- "total": 7,
- "count": 5,
- "skip": 0,
- "limit": 5
}
}Validate Microsoft Entra ID Items
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/validate endpoint validates that Microsoft Entra ID items specified in the request body are available in a specified restore point.
In the response body, you receive an array of items that are missing in the restore point. To browse restore points that are available for each of the missing items, run the Get Restore Points of Microsoft Entra ID Item request.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| restorePointId required | string <uuid> Restore point ID. |
| itemIds required | Array of strings Array of Microsoft Entra ID item IDs. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "restorePointId": "d67eabe0-c5f1-40d9-835b-954f9b7e4b9c",
- "itemIds": [
- "10b501ed-7f68-4b07-a62a-92b2d654623d",
- "dc6e5ce8-b6d2-49de-9d13-7c0eee3a419c",
- "492e3eec-ae57-4fab-898f-34c8bba4cc7b"
]
}- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "itemType": "Group",
- "itemId": "10b501ed-7f68-4b07-a62a-92b2d654623d",
- "displayName": "HR"
}
], - "pagination": {
- "total": 1,
- "count": 1,
- "skip": 0,
- "limit": 100
}
}Check Microsoft Entra ID Items in Production
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/checkProductionItems endpoint checks if the specified Microsoft Entra ID items from a mounted tenant backup are available in production.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
required | Array of objects (EntraIdTenantProductionItemSpec) Array of Microsoft Entra ID items that you want to check. |
| credentialId | string <uuid> ID of the credentials used to connect to the Microsoft Entra ID tenant. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "items": [
- {
- "itemId": "10b501ed-7f68-4b07-a620-92b2d654623d",
- "restorePointId": "8c843d10-6d0f-4abe-b898-e1ba18b94f68"
}, - {
- "itemId": "dc6e5ce8-b6d2-49de-9d13-7c0eee3a419c",
- "restorePointId": "8c843d10-6d0f-4abe-b898-e1ba18b94f68"
}, - {
- "itemId": "492e3eec-ae57-4fab-898f-34c8bba4cc7b",
- "restorePointId": "8c843d10-6d0f-4abe-b898-e1ba18b94f68"
}
]
}- 200
- 400
- 401
- 403
- 500
{- "items": [
- {
- "itemId": "user-9f0a3c6d",
- "displayName": "John Doe",
- "restorePointId": "5d6e7f80-1a2b-3c4d-5e6f-708192a3b4c5",
- "restorePointDate": "2026-05-20T10:30:00Z"
}
]
}Generate Microsoft Entra ID User Passwords
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/passwords/generate endpoint generates passwords for Microsoft Entra ID users that you want to restore.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| passwordsCount required | integer Number of passwords. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "passwordsCount": 5
}- 200
- 400
- 401
- 403
- 500
{- "passwords": [
- "JQ1Ir3z*?vt@",
- "=2z_q)Xvq#Rr",
- "{;%&x:rQ`x7k",
- "f3bQs'V(A>:V",
- "^&N79@-&pH Z"
]
}Restore Microsoft Entra ID Items
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/restoreItems endpoint restores Microsoft Entra ID items from a mount point with the specified sessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| credentialsId | string <uuid> ID of the credentials record used for connection to the target tenant. The property is used only for delegated restore by a restore operator that does not have access to pre-saved credentials. To obtain the credentials, use the following requests:
|
Array of objects (EntraIDItemIncludeRestoreSpec) Array of Microsoft Entra ID items. | |
| skipRelationships | boolean If |
| skipRecycleBinRestore | boolean If Otherwise, the items are restored from the Microsoft Entra ID recycle bin. If an item is not found in the recycle bin, it will not be restored. |
| skipObjectsIfExist | boolean If |
| requestPasswordChangeOnLogon | boolean If |
| defaultUserPassword | string Default password that will be set for all users. |
Array of objects (EntraIdTenantRestoreUserPasswordSpec) Array of custom user passwords. To generate the passwords, run the Generate Microsoft Entra ID User Passwords request. | |
Array of objects (EntraIdTenantRestoreApplicationCertificatesSpec) Array of application certificates. | |
| reason | string Reason for restoring Microsoft Entra ID items. |
| referenceRestoreMode | string (EEntraIdReferenceRestoreMode) Object relation restore mode. |
A RestoreTenant session has been created to restore tenant items. To check the progress, track the session state.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "items": [
- {
- "itemId": "6bc5249e-897b-4ba0-989e-2e273f5d0cd2",
- "restorePointId": "8c843d10-6d0f-4abe-b898-e1ba18b94f68"
}, - {
- "itemId": "a5943423-2255-469e-8270-ed91e35bd2ec",
- "restorePointId": "8c843d10-6d0f-4abe-b898-e1ba18b94f68"
}
], - "skipRelationships": false,
- "skipRecycleBinRestore": true,
- "skipObjectsIfExist": false,
- "requestPasswordChangeOnLogon": true,
- "usersPasswords": [
- {
- "userId": "6bc5249e-897b-4ba0-989e-2e273f5d0cd2",
- "password": "JQ1Ir3z*?vt@"
}, - {
- "userId": "a5943423-2255-469e-8270-ed91e35bd2ec",
- "password": "=2z_q)Xvq#Rr"
}
], - "reason": "Restore corrupted items"
}- 201
- 400
- 401
- 403
- 500
{- "state": "Running",
- "id": "0faf31e6-e6e8-43ea-95b4-1acacbe916c4",
- "name": "RestoreTenant",
- "creationTime": "2024-11-15T16:23:23.2885294+01:00",
- "endTime": "0001-01-01T00:00:00",
- "reason": "Restore corrupted users.",
- "parentSessionId": "b47e4f57-176f-4196-b6db-783c05729828"
}Restore Microsoft Entra ID Item Properties
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/restoreItemAttributes endpoint restores Microsoft Entra ID item properties from a mount point with the specified sessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| itemType required | string (EEntraIdTenantItemType) Item type. |
| restorePointId required | string <uuid> Restore point ID. |
| itemId required | string Item ID. |
| credentialsId | string <uuid> ID of the credentials record used for connection to the target tenant. The property is used only for delegated restore by a restore operator that does not have access to pre-saved credentials. To obtain the credentials, use the following requests:
|
Array of objects (EntraIdTenantItemIncludedPropertyModel) Array of item properties that you want to restore. | |
| skipRelationships | boolean If |
| skipRecycleBinRestore | boolean If Otherwise, the items are restored from the Microsoft Entra ID recycle bin. If an item is not found in the recycle bin, it will not be restored. |
| skipObjectsIfExist | boolean If |
| requestPasswordChangeOnLogon | boolean If |
| defaultUserPassword | string Default password that will be set for all users. |
Array of objects (EntraIdTenantRestoreUserPasswordSpec) Array of custom user passwords. To generate the passwords, run the Generate Microsoft Entra ID User Passwords request. | |
| reason | string Reason for restoring Microsoft Entra ID items. |
| referenceRestoreMode | string (EEntraIdReferenceRestoreMode) Object relation restore mode. |
A RestoreTenant session has been created to restore item properties. To check the progress, track the session state.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "credentialsId": "c4d5e6f7-0819-2a3b-4c5d-6e7f80912a3b",
- "restorePointId": "5d6e7f80-1a2b-3c4d-5e6f-708192a3b4c5",
- "itemId": "user-9f0a3c6d",
- "itemType": "User",
- "includedProperties": [
- {
- "id": "displayName"
}
], - "skipRelationships": false,
- "skipRecycleBinRestore": false,
- "skipObjectsIfExist": false,
- "requestPasswordChangeOnLogon": true,
- "reason": "Accidental deletion recovery.",
- "referenceRestoreMode": "Overwrite"
}- 201
- 400
- 401
- 403
- 500
{- "state": "Running",
- "id": "0faf31e6-e6e8-43ea-95b4-1acacbe916c4",
- "name": "RestoreTenant",
- "creationTime": "2024-11-15T16:23:23.2885294+01:00",
- "endTime": "0001-01-01T00:00:00",
- "reason": "Restore corrupted users.",
- "parentSessionId": "b47e4f57-176f-4196-b6db-783c05729828"
}Compare Microsoft Entra ID Item Properties
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/compare endpoint compares the properties of a Microsoft Entra ID item available in a mount session that has the specified sessionId.
You can compare item properties either between 2 restore points or between a restore point and production. To compare the item to production, do not specify newRestorePointId.
This request is synchronous, meaning that the client will wait until comparison results are ready. Alternatively, you can use an asynchronous request that returns a comparison session immediately so the client can continue execution, and you can process the comparison results later when the session changes its state to Success. For details on the asynchronous request, see Start Comparing Microsoft Entra ID Item Properties.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| itemId required | string ID of a Microsoft Entra ID item. |
| itemType required | string (EEntraIdTenantItemType) Item type. |
| oldRestorePointId required | string <uuid> ID of an earlier restore point. |
| newRestorePointId | string <uuid> ID of a later restore point. If you do not specify this property, the item from the earlier restore point will be compared to the item in production. |
| showUnchangedAttributes | boolean If |
| reloadCache | boolean This property is only used when comparing the item to production (
cacheTimestamp property in the response body.
|
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "itemId": "user-9f0a3c6d",
- "itemType": "User",
- "oldRestorePointId": "5d6e7f80-1a2b-3c4d-5e6f-708192a3b4c5",
- "newRestorePointId": "6e7f8091-2a3b-4c5d-6e7f-8091a2b3c4d5",
- "showUnchangedAttributes": false,
- "reloadCache": false
}- 200
- 400
- 401
- 403
- 500
{- "existsInOldRestorePoint": true,
- "existsInNewRestorePoint": true,
- "properties": [
- {
- "propertyName": "displayName",
- "oldValue": "John Doe",
- "newValue": "John A. Doe",
- "readOnly": false
}
], - "references": [
- {
- "referenceType": "memberOf",
- "referenceTypeDisplayName": "Member of",
- "values": [
- {
- "displayName": "Sales",
- "referenceId": "group-1a2b3c4d",
- "oldValue": true,
- "newValue": false,
- "readOnly": false
}
]
}
], - "cacheTimestamp": "2026-05-20T10:30:00Z"
}Start Comparing Microsoft Entra ID Item Properties
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/startCompare endpoint starts comparing the properties of a Microsoft Entra ID item available in a mount session that has the specified sessionId.
You can compare item properties either between 2 restore points or between a restore point and production. To compare the item to production, do not specify newRestorePointId.
This request is asynchronous, meaning that the request returns a comparison session immediately so the client can continue execution, and you can process the comparison results later when the session changes its state to Success. To get the comparison results, run the Get Comparison Results for Microsoft Entra ID Items request. For details on synchronous request, see Compare Microsoft Entra ID Item Properties.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| itemId required | string ID of a Microsoft Entra ID item. |
| itemType required | string (EEntraIdTenantItemType) Item type. |
| oldRestorePointId required | string <uuid> ID of an earlier restore point. |
| newRestorePointId | string <uuid> ID of a later restore point. If you do not specify this property, the item from the earlier restore point will be compared to the item in production. |
| showUnchangedAttributes | boolean If |
| reloadCache | boolean This property is only used when comparing the item to production (
cacheTimestamp property in the response body.
|
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "itemId": "user-9f0a3c6d",
- "itemType": "User",
- "oldRestorePointId": "5d6e7f80-1a2b-3c4d-5e6f-708192a3b4c5",
- "newRestorePointId": "6e7f8091-2a3b-4c5d-6e7f-8091a2b3c4d5",
- "showUnchangedAttributes": false,
- "reloadCache": false
}- 200
- 400
- 401
- 403
- 500
{- "compareSessionId": "7f809120-3a4b-5c6d-7e8f-90a1b2c3d4e5"
}Get Comparison Results for Microsoft Entra ID Items
The HTTP GET request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/compare/{compareSessionId}/result endpoint gets comparison results for Microsoft Entra ID items, initiated by a comparison session with the specified sessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
| compareSessionId required | string <uuid> Comparison session ID. To get the ID, run the Start Comparing Microsoft Entra ID Item Properties request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "status": "Success",
- "result": {
- "existsInOldRestorePoint": true,
- "existsInNewRestorePoint": true,
- "properties": [
- {
- "propertyName": "displayName",
- "oldValue": "John Doe",
- "newValue": "John A. Doe",
- "readOnly": false
}
], - "references": [ ],
- "cacheTimestamp": "2026-05-20T10:30:00Z"
}
}Start Comparing Microsoft Entra ID Conditional Access Policy
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/startRecursiveCompare endpoint starts a recursive comparison of the properties of a Microsoft Entra ID Conditional Access policy available in a mount session that has the specified sessionId.
You can compare item properties either between 2 restore points or between a restore point and production. To compare the item to production, do not specify newRestorePointId.
This request is asynchronous, meaning that the request returns a comparison session immediately so the client can continue execution, and you can process the comparison results later when the session changes its state to Success. To get the comparison results, run the Get Comparison Results for Microsoft Entra ID Conditional Access Policy request.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| itemId required | string ID of a Conditional Access policy. |
| oldRestorePointId required | string <uuid> ID of an earlier restore point. |
| newRestorePointId | string <uuid> ID of a later restore point. If you do not specify this property, the item from the earlier restore point will be compared to the item in production. |
| showUnchangedAttributes | boolean If |
| reloadCache | boolean This property is only used when comparing the item to production (
cacheTimestamp property in the response body.
|
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "itemId": "group-1a2b3c4d",
- "oldRestorePointId": "5d6e7f80-1a2b-3c4d-5e6f-708192a3b4c5",
- "newRestorePointId": "6e7f8091-2a3b-4c5d-6e7f-8091a2b3c4d5",
- "showUnchangedAttributes": false,
- "reloadCache": false
}- 200
- 400
- 401
- 403
- 500
{- "compareSessionId": "8091a2b3-4c5d-6e7f-8091-a2b3c4d5e6f7"
}Get Comparison Results for Microsoft Entra ID Conditional Access Policy
The HTTP GET request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/recursiveCompare/{compareSessionId}/result endpoint gets comparison results for a Microsoft Entra ID Conditional Access policy, initiated by a comparison session with the specified sessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
| compareSessionId required | string <uuid> Comparison session ID. To get the ID, run the Start Comparing Microsoft Entra ID Conditional Access Policy request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "status": "Success",
- "result": {
- "existsInOldRestorePoint": true,
- "existsInNewRestorePoint": true,
- "properties": [ ],
- "references": [ ],
- "cacheTimestamp": "2026-05-20T10:30:00Z"
}
}Start Exporting Microsoft Entra ID Items to JSON
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/exportToJson endpoint starts exporting Microsoft Entra ID items to JSON files in the mount session that has the specified sessionId. The request is asynchronous: it returns an export session immediately so the client can continue execution, and the export results can be retrieved later when the session changes its state to Success. To get the export results, send the Get JSON Export Results for Microsoft Entra ID Items request.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
required | Array of objects (StartEntraIdTenantExportToJsonRequestItem) Array of objects to export. |
| reason | string Reason for export. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "items": [
- {
- "itemId": "user-9f0a3c6d",
- "restorePointId": "5d6e7f80-1a2b-3c4d-5e6f-708192a3b4c5"
}
], - "reason": "Audit export."
}- 200
- 400
- 401
- 403
- 500
{- "exportSessionId": "a2b3c4d5-6e7f-8091-a2b3-c4d5e6f70819"
}Get JSON Export Results for Microsoft Entra ID Items
The HTTP GET request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/exportToJson/{exportSessionId}/result endpoint gets the JSON export results from an export session that has the specified exportSessionId within a mount session that has the specified sessionId. The response contains a SAS URI that you can use to download the exported JSON files.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. |
| exportSessionId required | string <uuid> Export session ID. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "status": "Success",
}Export Microsoft Entra ID Tenant Objects To JSON
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/exportToJsonDownload endpoint exports Microsoft Entra ID tenant objects to JSON.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
required | Array of objects (EntraIdTenantExportToJsonDownloadRequestItem) Array of Microsoft Entra ID items to export to JSON. |
| reason | string Reason for the export. |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "items": [
- {
- "itemId": "user-9f0a3c6d",
- "restorePointId": "5d6e7f80-1a2b-3c4d-5e6f-708192a3b4c5"
}
], - "reason": "Audit export."
}- 401
- 403
- 500
{- "errorCode": "AccessDenied",
- "message": "Unauthorized. Get bearer JWT token at /api/login"
}Export Microsoft Entra ID Items
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/export endpoint exports Microsoft Entra ID items from a backup that has the specified backupId to an XML or CSV file. The exported file contains all item properties that are available in the backup.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
query Parameters
| toXml | boolean If |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| type required | string (EEntraIdTenantItemType) Item type. |
| skip | integer >= 0 Number of items to skip. |
| limit | integer >= 1 Maximum number of items to return. |
object (EntraIdTenantUserFilterBrowseSpec) Filtering options. | |
object (EntraIdTenantUserSortingBrowseSpec) Sorting options. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "type": "User",
- "filter": {
- "department": "Marketing"
}, - "sorting": {
- "property": "userName",
- "direction": "ascending"
}
}- 400
- 401
- 403
- 500
{- "errorCode": "UnexpectedContent",
- "message": "One or more request parameters are not valid."
}Upload Microsoft Entra ID Users
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/uploadUser endpoint uploads a CSV file and gets an array of users, which is ready to be specified in the body of the restore request. The CSV file must contain a list of IDs or user principal names of Microsoft Entra ID users.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/octet-streamrequired
Comma-separated list of user IDs. For users, you can also specify a list of user principal names.
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "mailAddress": "test1@8bt3cp.onmicrosoft.com",
- "userName": "test1@8bt3cp.onmicrosoft.com",
- "userType": "Member",
- "employeeType": "Employee",
- "accountEnabled": true,
- "companyName": "Veeam Software",
- "creationType": null,
- "department": "Marketing",
- "country": "United States",
- "jobTitle": "Manager",
- "officeLocation": "Miami",
- "type": "User",
- "id": "fee6a1c9-6f07-4729-bf46-d3d4f45c7ad0",
- "displayName": "Test 1",
- "restorePointId": "e41b1345-a565-4db8-82f5-0632403630e8",
- "restorePointDate": "2024-10-15T22:11:26.218187+02:00"
}, - {
- "mailAddress": "test2@8bt3cp.onmicrosoft.com",
- "userName": "test2@8bt3cp.onmicrosoft.com",
- "userType": "Guest",
- "employeeType": "Contractor",
- "accountEnabled": true,
- "companyName": "Veeam Software",
- "creationType": null,
- "department": "Marketing",
- "country": "United States",
- "jobTitle": "Specialist",
- "officeLocation": null,
- "type": "User",
- "id": "8d9c14c9-822b-4b9d-ba1c-531275f1c6c6",
- "displayName": "Test 2",
- "restorePointId": "e41b1345-a565-4db8-82f5-0632403630e8",
- "restorePointDate": "2024-10-15T22:11:26.218187+02:00"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": null,
- "limit": null
}
}Upload Microsoft Entra ID Groups
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/uploadGroup endpoint uploads a CSV file and gets an array of groups, which is ready to be specified in the body of the restore request. The CSV file must contain a list of IDs of Microsoft Entra ID groups.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/octet-streamrequired
Comma-separated list of group IDs.
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "groupType": "SecurityGroup",
- "membershipType": "Assigned",
- "description": "Our first test group",
- "archived": null,
- "mailEnabled": true,
- "visibility": "Public",
- "type": "Group",
- "id": "5c923c24-effd-4e66-bc6f-cf0b9b9fba84",
- "displayName": "Test Group 1",
- "restorePointId": "34aa2791-09f4-432b-8c61-84080dc5e710",
- "restorePointDate": "2024-10-16T22:14:49.089469+02:00"
}, - {
- "groupType": "SecurityGroup",
- "membershipType": "Assigned",
- "description": "Our second test group",
- "archived": null,
- "mailEnabled": false,
- "visibility": "Private",
- "type": "Group",
- "id": "ad01d5df-a796-4781-81a1-37264cd6de0b",
- "displayName": "Test Group 2",
- "restorePointId": "34aa2791-09f4-432b-8c61-84080dc5e710",
- "restorePointDate": "2024-10-16T22:14:49.089469+02:00"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": null,
- "limit": null
}
}Upload Microsoft Entra ID Administrative Units
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/uploadAdministrativeUnit endpoint uploads a CSV file and gets an array of administrative units, which is ready to be specified in the body of the restore request. The CSV file must contain a list of IDs of Microsoft Entra ID administrative units.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/octet-streamrequired
Comma-separated list of administrative unit IDs.
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "visibility": "Public",
- "description": "Description 1",
- "type": "AdminUnit",
- "id": "f2143f59-6f46-40c5-ba00-6cc2be23a210",
- "displayName": "Unit 1",
- "restorePointId": "34aa2791-09f4-432b-8c61-84080dc5e710",
- "restorePointDate": "2024-10-16T22:14:49.089469+02:00"
}, - {
- "visibility": "Public",
- "description": "Description 2",
- "type": "AdminUnit",
- "id": "a9e01ce9-da91-455d-bf12-881ec1e420b7",
- "displayName": "Unit 2",
- "restorePointId": "34aa2791-09f4-432b-8c61-84080dc5e710",
- "restorePointDate": "2024-10-16T22:14:49.089469+02:00"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": null,
- "limit": null
}
}Upload Microsoft Entra ID Roles
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/uploadRole endpoint uploads a CSV file and gets an array of roles, which is ready to be specified in the body of the restore request. The CSV file must contain a list of IDs of Microsoft Entra ID roles.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/octet-streamrequired
Comma-separated list of role IDs.
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "isBuiltIn": false,
- "isEnabled": true,
- "description": "Update properties of application registrations",
- "type": "Role",
- "id": "11766790-99c7-486a-8d5b-58f45a3effde",
- "displayName": "Role 1",
- "restorePointId": "34aa2791-09f4-432b-8c61-84080dc5e710",
- "restorePointDate": "2024-10-16T22:14:49.089469+02:00"
}, - {
- "isBuiltIn": false,
- "isEnabled": false,
- "description": "Read custom security attribute keys and values",
- "type": "Role",
- "id": "7b0df540-1e7c-4c91-badd-095ce0ad055a",
- "displayName": "Role 2",
- "restorePointId": "34aa2791-09f4-432b-8c61-84080dc5e710",
- "restorePointDate": "2024-10-16T22:14:49.089469+02:00"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": null,
- "limit": null
}
}Upload Microsoft Entra ID Applications
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/uploadApplication endpoint allows you to upload a CSV file and get an array of applications, which is ready to be specified in the body of the restore request. The CSV file must contain a list of IDs of Microsoft Entra ID applications.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/octet-streamrequired
Comma-separated list of application IDs.
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "applicationType": "AppRegistration",
- "enabled": true,
- "tags": [ ],
- "description": null,
- "type": "Application",
- "id": "674b69a9-f288-46fd-babe-a172ddff0c6c",
- "displayName": "VeeamAzureApp5",
- "restorePointId": "cc5ada33-8c22-41d4-b559-87adcdabb2ee",
- "restorePointDate": "2024-10-17T22:11:50.974832+02:00"
}, - {
- "applicationType": "EnterpriseRegistration",
- "enabled": true,
- "tags": [ ],
- "description": null,
- "type": "Application",
- "id": "21147b36-913d-4e69-bf3c-924935bc72dc",
- "displayName": "VeeamAzureApp9",
- "restorePointId": "cc5ada33-8c22-41d4-b559-87adcdabb2ee",
- "restorePointDate": "2024-10-17T22:11:50.974832+02:00"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": null,
- "limit": null
}
}Upload Microsoft Entra ID Conditional Access Policies
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/uploadConditionalAccessPolicy endpoint allows you to upload a CSV file and get an array of conditional access policies, which is ready to be specified in the body of the restore request. The CSV file must contain a list of IDs of Microsoft Entra ID Conditional Access policies.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/octet-streamrequired
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "type": "ConditionalAccessPolicy",
- "id": "674b69a9-f288-46fd-babe-a172ddff0c6c",
- "displayName": "ConditionalAccessPolicy1",
- "restorePointId": "cc5ada33-8c22-41d4-b559-87adcdabb2ee",
- "restorePointDate": "2025-02-20T22:02:03.617717+01:00",
- "state": "Enabled"
}, - {
- "type": "ConditionalAccessPolicy",
- "id": "a014d6c1-8a26-4cda-85fb-ff71eefd0366",
- "displayName": "ConditionalAccessPolicy2",
- "restorePointId": "cc5ada33-8c22-41d4-b559-87adcdabb2ee",
- "restorePointDate": "2025-02-20T22:02:03.617717+01:00",
- "state": "EnabledForReportingButNotEnforced"
}
], - "pagination": {
- "total": 1,
- "count": 1,
- "skip": null,
- "limit": null
}
}Upload Microsoft Entra ID Device Configurations
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/uploadDeviceConfiguration endpoint uploads a CSV file and gets an array of device configurations, which is ready to be specified in the body of the restore request. The CSV file must contain a list of IDs of Microsoft Entra ID Device configurations.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/octet-streamrequired
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "type": "DeviceConfiguration",
- "id": "674b69a9-f288-46fd-babe-a172ddff0c6c",
- "displayName": "DeviceConfiguration1",
- "deviceConfigurationType": "DeviceConfigurationPolicy",
- "restorePointId": "cc5ada33-8c22-41d4-b559-87adcdabb2ee",
- "restorePointDate": "2025-02-20T22:02:03.617717+01:00",
- "description": "Device Configuration 1",
- "version": 1
}, - {
- "type": "DeviceConfiguration",
- "id": "a014d6c1-8a26-4cda-85fb-ff71eefd0366",
- "displayName": "DeviceConfiguration2",
- "deviceConfigurationType": "DeviceConfigurationPolicy",
- "restorePointId": "cc5ada33-8c22-41d4-b559-87adcdabb2ee",
- "restorePointDate": "2025-02-20T22:02:03.617717+01:00",
- "description": "Device Configuration 2",
- "version": 2
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": null,
- "limit": null
}
}Upload Microsoft Entra ID Organization Contacts
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/uploadOrgContact endpoint uploads a CSV file and gets an array of organization contacts that is ready to be specified in the body of the restore request. The CSV file must contain a list of IDs of Microsoft Entra ID organization contacts.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/octet-streamrequired
Comma-separated list of organization contact IDs.
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "type": "User",
- "id": "9f0a3c6d-7e8b-1a45-f7c1-a9d28b344e21",
- "displayName": "John Doe",
- "restorePointId": "5d6e7f80-1a2b-3c4d-5e6f-708192a3b4c5",
- "restorePointDate": "2026-05-20T10:30:00Z",
- "mailAddress": "john.doe@tech.local",
- "userName": "john.doe@tech.local",
- "userType": "Member",
- "accountEnabled": true,
- "companyName": "Tech Corp",
- "department": "Sales",
- "country": "United States",
- "jobTitle": "Account Manager",
- "officeLocation": "Building A"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 100
}
}Upload Microsoft Entra ID Devices
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{backupId}/uploadDevice endpoint uploads a CSV file and gets an array of devices that is ready to be specified in the body of the restore request. The CSV file must contain a list of IDs of Microsoft Entra ID devices.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| backupId required | string <uuid> Backup ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/octet-streamrequired
Comma-separated list of device IDs.
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{- "data": [
- {
- "type": "User",
- "id": "9f0a3c6d-7e8b-1a45-f7c1-a9d28b344e21",
- "displayName": "John Doe",
- "restorePointId": "5d6e7f80-1a2b-3c4d-5e6f-708192a3b4c5",
- "restorePointDate": "2026-05-20T10:30:00Z",
- "mailAddress": "john.doe@tech.local",
- "userName": "john.doe@tech.local",
- "userType": "Member",
- "accountEnabled": true,
- "companyName": "Tech Corp",
- "department": "Sales",
- "country": "United States",
- "jobTitle": "Account Manager",
- "officeLocation": "Building A"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 100
}
}Get All Restore Sessions of Microsoft Entra ID Tenant
The HTTP GET request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/restoreSessions endpoint gets an array of restore sessions that were started for a Microsoft Entra ID tenant mount point with the specified sessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
query Parameters
| skip | integer <int32> Number of items to skip. |
| limit | integer <int32> Default: 200 Maximum number of items to return. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "data": [
- {
- "id": "b3c4d5e6-7f80-9120-b3c4-d5e6f7081920",
- "name": "Entra ID Restore 2026-05-20",
- "creationTime": "2026-05-20T10:30:00Z",
- "endTime": "2026-05-20T10:45:00Z",
- "state": "Success",
- "reason": "Accidental deletion recovery."
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 100
}
}Get Restore Session of Microsoft Entra ID Tenant
The HTTP GET request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/restoreSessions/{restoreSessionId} endpoint gets a restore session that has the specified restoreSessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
| restoreSessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Restore Sessions of Microsoft Entra ID Tenant request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "state": "Running",
- "id": "0faf31e6-e6e8-43ea-95b4-1acacbe916c4",
- "name": "RestoreTenant",
- "creationTime": "2024-11-15T16:23:23.2885294+01:00",
- "endTime": "0001-01-01T00:00:00",
- "reason": "Restore corrupted users.",
- "parentSessionId": "b47e4f57-176f-4196-b6db-783c05729828"
}Get Restore Session Logs of Microsoft Entra ID Tenant
The HTTP GET request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/restoreSessions/{restoreSessionId}/logs endpoint gets restore session logs of a Microsoft Entra ID tenant.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
| restoreSessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Restore Sessions of Microsoft Entra ID Tenant request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "totalRecords": 1,
- "records": [
- {
- "id": "c4d5e6f7-8091-20b3-c4d5-e6f708192031",
- "title": "Restoring user John Doe",
- "description": "User account restored successfully.",
- "startTime": "2026-05-20T10:30:00Z",
- "updateTime": "2026-05-20T10:31:00Z",
- "status": "Success",
- "style": "None"
}
]
}Stop Restore Session of Microsoft Entra ID Tenant
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/restoreSessions/{restoreSessionId}/stop endpoint stops a restore session of a Microsoft Entra ID tenant.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
| restoreSessionId required | string <uuid> Restore session ID. To get the ID, run the Get All Restore Sessions of Microsoft Entra ID Tenant request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 400
- 401
- 403
- 500
{ }Reveal Microsoft Entra ID BitLocker Recovery Key
The HTTP POST request to the /api/v1/backupBrowser/entraIdTenant/{sessionId}/revealBitlockerRecoveryKey endpoint reveals the BitLocker recovery key for a device specified in the request body, in a mount session that has the specified sessionId.
Available to: Backup Administrator, Restore Operator. Also available to custom roles that have restore permissions.
path Parameters
| sessionId required | string <uuid> Mount session ID. To get the ID, run the Get Mount Points of All Microsoft Entra ID Tenants request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| deviceId required | string Infrastructure ID of the device. |
| restorePointId | string <uuid> Restore point ID. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "restorePointId": "5d6e7f80-1a2b-3c4d-5e6f-708192a3b4c5",
- "deviceId": "device-7e8b1a45"
}- 200
- 400
- 401
- 403
- 500
{- "bitlockerRecoveryKeys": [
- {
- "bitlockerRecoveryKeyId": "key-1a2b3c4d",
- "deviceId": "device-7e8b1a45",
- "recoveryKey": "123456-234567-345678-456789-567890-678901-789012-890123",
- "createdDateTime": "2026-05-20T10:30:00Z",
- "volumeType": "OperatingSystemVolume"
}
]
}