Category: BACKUP RECOVERY

BACKUP & RECOVERY

  • How to Create Account Wasabi S3 Bucket blob storage

    How to Create Account Wasabi S3 Bucket blob storage

    Create Account Wasabi S3 Bucket

    In this guide series, the focus is to create a trial account that will be used in combination with Veeam Backup and Replication to store long term backup. In this case how to sigh up a Wasabi S3 free account for a trial. Later on also the ability to explain content directly from the cloud for granular restores. Wasabi S3 offers enterprise cloud blob storage at a reasonable price.
    They offer an interesting option for that entire customer who wants to benefit from cloud resources and in particular for object or blob storage. Wasabi offered for a fraction of the price when compared to other solutions in the market.

    How to Create Wasabi S3 Account

    To create a trial account is a straight forward process and requires no credit card. The trial gives access for 30 days for a maximum of 1 TB.
    1- Browse the Wasabi website for sign up and then click Try or BUY Now.

    wasabi cloud

    2- Click Create Account

    welcome to wasabi cloud

    3- Enter details and then click start your free trial

    wasabi start your free trial

    4- You will receive an email from Wasabi for confirmation. Type your email address, password and then click signup

    wasabi cloud sign up

    Create Account Wasabi S3 Bucket

    5- Once the Wasabi account is created the next step is to create a bucket.
    Click create bucket

    wasabi create bucket

    6- Enter a name for the bucket and the region and then click next

    wasabi select bucket name

    7- Click next.

    wasabi bucket versioning

    8- Review the settings and then click create bucket

    wasabi create bucket review

    9- Select your bucket

    wasabi create bucket

    10- Here you can create folder

    wasabi create bucket

    11- Select settings

    wasabi create bucket

    12- In the bucket settings we can edit settings for example enable Logging and Versioning or you can enable while creating the bucket.

    wasabi bucket settings

    13- The last step is to create the Access Key. Select create new access key

    wasabi access key

    The status and creation of the keys can be controlled by the wasabi S3 console.
    The wizard will create an Access & Secret Key. This information is to provide when configuring client apps to access the pertinent bucket. In addition, it’s necessary to also provide the correct name of the region where the bucket is located.
    14- Click create

    wasabi create new access key

    15- Here you can get your access key and secret key

    wasabi create new access key
  • File Restore from Tape in Veeam Backup

    File Restore from Tape in Veeam Backup

    In this blog, I am going to restore files and folders from the tape backup. Please follow the below steps to restore files form tape.

    1- Open the Veeam Backup & Replication console, select Home tab, and click on the Restore tab and select Tape

    veeam console

    2- Select Restore files.

    restore from tape wizard

    3- Restore from tape wizard, Objects to Restore option and then click Add.

    restore from tape object

    4- Expand the server, browse to the file or folder or volume you need to restore. Select them and then click ok

    veeam restore choose file and folder

    5- Select Backup Set button

    restore from tape object

    6- If you need to restore files from other restore points, so select them and click ok
    By default, Veeam Backup & Replication will restore the latest version of files and folders are available on the tape.

    veeam restore select backup set

    7- If you want to remove a file or folder from the list, select it and then click Remove.
    Click next

    restore from tape object

    8- Restore from tape destination option, select an original location if you want to restore files and folder to its original server.
    This server option. If you want to restore files to another server. You can restore files to the Veeam backup server shared folder or to any other machine the one is added to Veeam Backup & Replication.
    Now select the browse button and select the folder where you need to restore files

    veeam restore from tape destination

    9- Select the overwrite the existing files option and then click next

    veeam restore from tape options

    10- Review the restore from tape settings and then click Finish.

    veeam restore from tape summary

    11- Files form tape successfully restored

    veeam restore progress

    12- Now you can see the files in restoration folder

    windows explorer

    For more details please Veeam

  • How to Restore Virtual Machine Veeam Backup

    How to Restore Virtual Machine Veeam Backup

    Restore Virtual Machine Veeam

    In this blog, I will explain how to restore Virtual Machine in Veeam Backup & Replication.

    1- Open Veeam Backup and Replication Console, click on Inventory options and click on VMware vSphere you can see the following virtual machine.

    veeam backup inventory

    2- Here you need to select the vCenter server, after that select the virtual machine which you want to restore and click on restore option and then restore entire VM

    veeam restore entire vm

    3- Full Virtual Machine Restore wizard will open, so just select the Virtual Machine and click on next.

    veeam full vm restore wizard

    4- Here you can select restore location you can select any one option in these two so I am restoring the Virtual Machine to different locations so just select the location and click on the Next button.

    veeam full vm restore mode

    5- Here it’s showing the Virtual Machine and original location here so we need to change the host location so just select the Host button and select the different Host where you need to restore the virtual machine.

    veeam full vm restore host

    6- Here you can select the available host where you need to restore and click on the OK button.

    veeam vm restore select host

    7- After selecting host so just click on next button.

    veeam full vm restore host

    8- Here you can select resources like Datastore or you can leave it default and click on the next button.

    veeam vm restore resource pool

    9- Now select the Database button if you want to change the datastore.

    veeam vm restore datastore

    10- Select a Datastore and then click OK.

    veeam vm restore select datastore

    11- Select disk type

    veeam vm restore datastore

    12- Select disk type and then click OK.

    veeam restore disk type option

    13- Now you can see the virtual machine hard disk and datastore size so verify the details and click on the Next button.

    veeam vm restore datastore

    14- Select the name button.

    veeam vm restore folder

    15- Type a virtual machine name and click OK.

    veeam vm restore change name

    16- Click next.

    veeam vm restore folder

    17- Virtual Machine Network and click on next button.

    veeam vm restore network

    18- Click next

    veeam full vm secure restore

    19- Now you can type the reason why you are restoring the Virtual Machine and click on the Next button.

    veeam full vm restore reason

    20- Choose the Power on target VM after the restoring option and then click on the Finish button.

    veeam full vm restore summary

    21- Virtual Machine successfully restored so just click on close button.

    veeam restoring vm

    22- Virtual Machine successfully restored

    veeam virtual machine

    Related: How to use Extract Utility in Veeam Backup & Replication

    For more details, please visit Veeam

    Watch Video: How to Restore Virtual Machine Files.

  • Extract Utility Veeam Backup & Replication

    Extract Utility Veeam Backup & Replication

    Extract Utility Veeam Backup & Replication with an extract utility that can be used to restore virtual machines from Veeam backup files. The Veeam extract utility does not need any communication with Veeam. You can use it as an independent tool on Linux & Microsoft Windows virtual machines.

    Extract Utility Veeam Backup

    Veeam extract utility can be use in two interfaces (Graphic user interface (GUI) and command line)
    I am using an extract utility Graphic user interface (GUI) interface
    The Veeam extract utility is located in the installation folder of Veeam, by default C:\Program Files\Veeam\Backup and Replication\Backup The folder includes three files for the extract utility:
    Veeam.Backup.Extractor.exe working in GUI (can be use on Microsoft Windows machines only)
    extract.exe: Veeam utility working in the command prompt interface, a version for Microsoft Windows
    extract: Veeam utility working in the command prompt interface, a version for Linux

    veeam backup extractor

    Extract Utility GUI

    Restore VM data using Veeam extract utility GUI
    Run the Veeam.Backup.Extractor.exe setup file extract utility file from the installation folder of Veeam Backup & Replication.
    Veeam Backup Extraction Utility wizard next to Backup file option and then click on the browse button

    veeam backup extractor utility

    Specify a Veeam backup .vbk path.
    If the backup file is encrypted, the utility will require you to provide a credential to unlock the backup file.

    windows folder .vbk

    Under the Target folder field, specify a path to the destination folder where you want to restore virtual machine data.

    From the Virtual Machines list, select a virtual machine whose data you need to restore.

    Click on Extract button, Machine data will be restored to the specified folder.

    veeam backup extractor utility

    The Veeam extract utility can be start on Microsoft Windows machines only.
    If you plan to start the Veeam extract utility on that machine where Veeam backup not installed.
    You need to copy the Veeam.Backup.Extractor.exe and extract.exe file from the Veeam installation folder and store these 2 files to the same folder on the destination machine.
    Restoring files please wait

    please wait restoring files

    Veeam .vbk extraction completed successfully

    vbk extract successfully

    After extracting Veeam .vbk backup

    windows folder .vmdk

    For more details please visit Veeam

  • How to Create File to Tape Jobs Veeam

    How to Create File to Tape Jobs Veeam

    Create File to Tape Job

    In this article, I will create a file to tape the job using the Veeam new file to Tape Job wizard.

    1- Select the Home tab, right-click the Jobs tab, and select Tape Job and then Select Files to Tape.

    veeam console

    2- New file to tape job wizard, under the Name field, type a name for the file to tape job. Under the Description option, type a description of the file to tape the job and then click next.

    new file to tape wizard veeam

    3- File to tape, (Files and Folders) step of the wizard, click the Add button.

    new file to tape add file and folder

    4- Select file or folder windows pop up, From the Server drop-down list; select a Windows Server the one you want to backup files or folders. Select files & folders that you need to backup and then click on ok.

    new file to tape select file and folder

    5- If you want to back up files and folders from a Windows server or Linux server, first make sure you have added as a managed server to the Veeam backup infrastructure.
    If you want to back up files and folders from an SMB server or NFS share, and then make sure you have added as a file share to the inventory.
    Now in the Files and Folders windows, you use the Up and Down buttons on your right side menu to move sources up or down.

    new file to tape add file and folder

    6- Select Include masks & Exclude masks fields to filter the file & folder contents and then click ok

    new file to tape include exclude

    7- Select Next.

    new file to tape add file and folder

    Media pool for full backup

    8- New file to tape job wizard, Full Backup options. Select a media pool that you want to use for full backups.
    If you need to create a new media pool click here.
    Backup schedule option select the Run the full backup automatically checkbox to specify the full backup schedule and click next

    new file to tape media pool

    9- Incremental Backup option, Select a media pool that will use for incremental backups.
    Backup schedule, select the Run incremental backup automatically checkbox and specify the schedule for the incremental backup.

    new file to tape incremental

    10- Select Microsoft volume shadow copy (VSS) to enable backup of files with the help of Microsoft shadow volume copies.
    Select Eject media upon job completion option if you want tape automatically eject from the drive.
    Select Advanced

    new file to tape wizard options

    11- At the advanced settings. Then select the Notifications tab, Configure e-mail notification and then click ok

    file to tape wizard advanced

    12- Select the Run the job when I click Finish option if you need to start file to tape job right and then click the Finish button.

    new file to tape wizard summary

    13- Now files and folder job has been created and running

    veeam console file to tap

    14- Veeam files and folder to tape successfully completed

    veeam job progress completed

    15- After the file and folder to tape job completes. Select Tape Infrastructure, select Media Pool and then click properties.

    veeam console

    16- Select the Files tab, expand the Tape node and locate the files archive.

    veeam tape properties

    For more details please visit Veeam

  • Archive Veeam Backup to AWS S3

    Archive Veeam Backup to AWS S3

    Archive Veeam Backup to AWS S3, The Veeam Backup & Replication solution offers backup, restore, and replication functionality for physical servers, virtual machines, and workstations as well as cloud-based workloads.

    A native S3 interface for Veeam Backup & Replication is part of the Veeam Availability. It will allow us to push backups to an S3 compatible service to maximize backup capacity.

    The following below steps will represent the functionality of Veeam Backup and Restore which acts as an intermediate agent to manage primary data storage and secondary & archival storage:

    Archive Veeam Backup to AWS S3

    1- How to Create an S3 Bucket Amazon

    2- Configuring an Object Storage Repository

    3- Configure a Scale-Out repository

    4- Create a new Backup Job

    5- Move backups to the Cloud Tier Immutability

    Configure Veeam Cloud Tier Immutability

    1- Step is to Create an S3 Bucket Amazon

    The AWS S3 bucket has been successfully created.

    2- Configuring an Object Storage Repository

    1- Open Veeam backup and click connect.

    veeam windows click connect

    2- Backup Infrastructure tab, click on Backup Repositories, and then click Add Repository.

    veeam backup repository

    3- Select the Object storage as repository type.

    veeam add backup repository

    4- Choose Amazon S3 as object storage type.

    veeam add object storage type

    5- Type repository name, Description and then click next.

    new object storage repository name

    6- Select Add

    new object storage repository account

    7- To access Amazon S3 bucket type credentials and then click OK.

    veeam credentials

    8- Select Data center region and then click Next.

    new object storage repository account

    9- Select the Datacenter region to use and the Bucket. Click the Browse button to specify the correct folder to use to store the backups.

    new object storage repository bucket

    10- Click New Folder and specify the folder name. Click OK.

    archive veeam backup to aws

    11- You can enable the Limit object storage consumption option to keep storage costs under control. Choose Make recent backups immutable for days to use native object storage capabilities and specify the retention in days. Click Next.

    new object storage repository bucket

    12- Click Finish to save the configuration.

    new object storage repository summary

    13- The new S3 Repository has been created successfully.

    veeam console backup repository

    3- Configure a Scale-Out repository

    Veeam Scale-out Backup Repository is a key technology for many/various additional competencies for managing backup data.

    1- From the Backup Infrastructure tab, click on the Scale-out Repositories and then click Add Scale-out Repository to create a new one.

    veeam console scale-out repository

    2- Enter a Name, a Description and then click next.

    new scale-out repository name

    3- Click the Add button to specify the Performance Tier Extent.

    “Configuring a Local Backup Repository” I have already configured a local backup repository name (Backup Repository Cloud).

    scale-out repository performance tier

    4- Select the Repository to use then and then click OK.

    select backup repository to exclude

    5- After selecting the Performance Tier click next.

    scale-out repository performance tier

    6- Choose Data locality option as Placement Policy then click next.

    scale-out repository performance policy

    7- Enable the Extend Scale-out repository capacity with object storage option and select the S3 Repository previously created. This default value is set as 30 days. Click Apply.

    scale-out repository capacity tier

    8- Click Finish to create the Scale-out Repository.

    new scale-out repository summary

    9- Scale-out Repository created.

    veeam scale-out repository

    4- Create a Backup Job Veeam

    Now we need to create a new Backup Job to take advantage of the Immutability feature.

    1- Select Home, select backup job and then virtual machine.

    veeam console backup

    2- Enter job name and click next.

    veeam new backup job name

    3- Click add

    veeam backup job virtual machine

    4- Select virtual machine and then click OK.

    veeam backup add object

    5- Select from the Backup repository drop-down menu the just we have created Scale-out Repository and then click next.

    veeam new backup job storage

    6- Guest processing click next.

    veeam new backup job guest

    7- Backup schedule click next.

    veeam new backup job schedule

    8- Summary click finish

    veeam new backup job summary

    9- Right click the created Backup Job and then select Start to start the backup immediately.

    veeam console backup

    During the first execution, an Active Full Backup is being performed.
    If you are willing to test the archival process to the protected bucket, after the initial Full Backup you should perform some additional (incremental) backups. At least 3 additional Incremental Backups and one another Active Full Backup.

    veeam job progress

    2 Full active backup and 3 Incremental backup

    windows folder .vbk

    5- Move backups to the Cloud Tier Immutability

    To move backups immediately to the selected Object Storage (Amazon S3).

    1- Select the Backup Infrastructure option and expand the Scale-out Repositories. Select the Repository previously configured and then select Edit the Scale-out Repository.

    veeam console

    2- Select Capacity Ties, set the Move backup files older than the field to 0, and then click Finish to save the configuration.

    scale-out repository capacity tier

    3- Hold CTRL & right-click on the Scale-out Backup Repository and then select Run tiering job now.

    scale-out backup repository

    4- The offload process is started and backups are moved to the S3 Object Storage.
    I am going to stop this process because I have free trial AWS with one GB storage capacity. Just testing in my lab.

    veeam job progress

    5- The backup will be also found in the AWS S3 bucket.

    amazon s3 bucket

    Watch Video: How to Archive Veeam Backup to AWS

    For more details please visit Veeam

  • How to Add New Disk Using Bootable Media Acronis

    How to Add New Disk Using Bootable Media Acronis

    Add New Disk, in this article, I am going to add a new hard drive using Acronis bootable media.

    1- Turn off your computer, and then insert the new drive.

    tools and utilities acronis media

    4- Select your new drive and then click next.
    Note:- Everything on the new drive will be erased.

    acronis add new hard disk

    5- Select the required disk initialization method, If the source drive was an MBR-disk, select Initialize drive is the MBR layout.

    acronis initialization option

    6- If you want to create a new partition then click create a new portion button, if you want to keep the original size then click next.

    acronis partition creation

    7- Review the summary and click the proceed button to start the process.

    acronis add new hard summary

    8- Click ok.

    acronis add new hard disk

    For more details visit Acrronis

  • Adding an organization fails 401: Unauthorized

    Adding an organization fails 401: Unauthorized

    Adding an organization fails within the 401: Unauthorized and Connect to PowerShell Access Denied errors in Office 365 tenants with enabled Security Defaults

    Require MFA (Multi-Factor Authentication) for all users, including administrators & Azure management. Require Azure MFA (Multi-Factor Authentication) registration
    Block legacy authentication

    Conditional Access: Require MFA for all users
    Create a Conditional Access policy

    The below steps will help you to create a Conditional Access policy to require All users to perform multi-factor authentication.

    Adding an organization fails 401:

    1- Signin Microsoft Azure as a security administrator, global administrator, or Conditional Access administrator. Select the Azure Active Directory

    azure active directory admin center

    2- Select Security under manage tab.

    azure active directory dashboard security

    3- Under protect tab select Conditional Access.

    azure security conditional access

    4- Click on + New policy.

    azure conditional access policy

    5- Type your policy a name. We recommend that institutional create a meaningful standard for the names of their policies.
    Select Users and groups Under Assignments

    azure conditional create access policy

    6- Select Include tab, and then select All users.

    azure conditional access new policy

    7- Select Exclude tab and then select Users and groups.

    azure new policy assignment

    8- Select your organization’s emergency access or break-glass accounts and then choose the select button.

    azure new policy assignment exclude

    9- Select Cloud apps or actions, select Include and select All cloud apps.

    azure new policy cloud apps

    10- Select the Exclude tab, select excluded cloud apps, choose any applications that do not require multi-factor authentication, and click on the create button.

    azure new policy cloud apps exclude

    11- Choose the Conditions tab, select Client apps (Preview), and then select Configure to Yes. Under Select the client apps this policy will apply to leave all defaults selected and then select Done.

    azure new policy conditions

    12- Under Access controls option select Grant, choose Grant access, select Require multi-factor authentication checkbox and select Select.

    azure new policy access control

    13- Confirm your settings and choose Enable policy to On. Select Save to create to enable your policy.

    azure new policy

    Modern Authentication with Veeam for office 365

    For more details adding an organization denied errors in Office 365 tenants, visit Veeam

  • How to Backup Office 365 Emails with Veeam Backup

    How to Backup Office 365 Emails with Veeam Backup

    Backup Office 365 Emails, In this article I am going to create a new backup job for Microsoft Office 365 emails with Veeam Backup.

    Download Veeam for Office 365

    1- Connect Veeam Backup for Microsoft Office 365 console, select the Organizations view.
    On the Home tab, click Backup on the ribbon.

    veeam backup for office 365 console

    2- Backup Office 365 Email, Specify job name and description page, enter a name for your backup job, and then click Next.

    veeam new backup job

    3- Veeam new backup job wizard, select objects to back up window, select Back up entire organization if you have enough users license for the entire organization if not, you need to select Back up the following objects. You can add by users, groups, sites, and organizations. Click the Add button.

    veeam select object to backup

    4- I am going to add a user for backup and then click add.

    veeam select object to backup

    5- After adding a user for backup click the next button.

    veeam select object to backup

    6- Select objects to exclude page, we can add by users, groups, sites & Organization. Click next after you add them.

    veeam select object to backup

    7- New Veeam Backup job wizard, specify backup proxy and repository window, select backup proxy and Azure Blob backup repository and then click next.

    veeam specify backup proxy and repository

    8- Select scheduling options page, enter your schedule information, and then click Create.

    veeam select scheduling options

    9- Select the new created office 365 email backup job and then click Start.

    veeam backup for office 365 console

    10- Now you can see the office 365 email job in progress.

    veeam job for office 365 in progress

    Create Storage account in Azure

    Add Object Storage Repository

    Add Azure Blob Storage Repository

    Modern Authentication Veeam for Office 365

    Watch Video: How to Backup Office 365 Emails with Veeam Backup

  • How to Add Office 365 Organization using Modern Authentication

    How to Add Office 365 Organization using Modern Authentication

    Add Office 365 Organization using modern authentication, after successfully configuring modern authentication now I am going to add organizations with veeam backup for office 365.

    How to add to the Veeam Backup for Microsoft Office 365 scope, an Office 365 organization using modern authentication

    Now I am ready to add our tenant to Veeam backup for Microsoft Office 365.

    1- Open Veeam Backup for Office 365 console, select organization and then Add Org.

    veeam backup office 365 console

    2- Select the Organizations deployment type, select the services you want to protect and then click next.

    veeam select organization deployment kit

    3- Select region of your tenant and which authentication you need to use. Of course we are going for the modern authentication now (allow for using legacy authentication protocols) and then click next.

    veeam office 365 connection settings

    4- Exchange Online Credentials setup we need to provide all our collected information. Meaning the application ID, the application secret, our username, the app password and then click next.

    veeam exchange online credentials

    5- Click the close button after verifying connection and organization parameters. The tenant will be added to your Veeam console successfully.

    veeam organization verifying connection

    6- Now you can see an Organization successfully added.

    veeam backup office 365 console

    For more details please visit Veeam

    Create Storage account in Azure

    Add Object Storage Repository

    Add Azure Blob Storage Repository

    Modern Authentication Veeam for Office 365

  • Modern Authentication with Veeam Backup for Office 365

    Modern Authentication with Veeam Backup for Office 365

    Modern Authentication with Veeam, In this article I will explain how to configure the modern authentication with Veeam Backup for Office 365.

    What is Modern Authentication visit Microsoft

    Veeam Office 365 Modern Authentication

    The release of version 4 of Veeam Backup for Office 365, now we are able to use the so-called modern authentication. This means using service accounts enabled for MFA (multi-factor authentication).

    We need an Azure Active Directory custom application and a service account that has MFA (Multi-Facture Authentication) enabled. The custom application (App application) registered in Azure Active Directory will allow Veeam Backup for Office 365 to access the Microsoft Graph API. With this access, we can pick up the data from the “Microsoft Office 365 organization tenant”.

    In this strategy, the service account will be used to connect to the EWS and PowerShell services.

    Preparation

    In instance, we want to use modern authentication with Veeam Backup for Office 365.

    The below steps should be done for using the modern authentication.

    Register a custom application in Azure Active Directory
    Collect your Application ID and Secret
    Create a new client secret
    Create a new service account in Azure Active Directory
    Enable Multi-Factor Authentication (MFA) on this service account
    Assign roles to the service account
    Grant a service account required roles and permissions
    Get App password for an MFA-enabled service account
    Add tenant to Veeam with the service account

    Create Storage account in Azure

    Add Object Storage Repository

    Add Azure Blob Storage Repository

    Create backup job

    Register a custom application in Azure Active Directory

    1- Open your Azure Active Directory admin center under the Manage tab and then select App registration.

    azure active directory admin center

    2- Click on + new registration Under App registrations tab.

    azure active directory app registration

    3- Enter new custom application a name; select the supported account type and then click on the register button.

    azure active directory register an app

    4- After creating a new custom application, we need to provide it with some permission. For that go to your newly created app application and then select the + API Permissions button.

    azure active directory app permissions

    5- Now we need to add Microsoft Graph permissions to our custom app application.
    In the request API permissions wizard and then select Microsoft Graph.

    azure active directory request api permissions

    6- Select Application permissions.

    azure active directory application permissions

    7- Expand Director Option and select Directory.Read.All. Expand Group option and select Group.Read.All from the list of available permissions, and then click Add permissions
    1- Directory.Read.All
    2- Group.Read.All

    These two permissions are needed to access the organization tenant.

    azure application permissions directory
    azure request api permissions group

    8- This type of permission requires administrator consent. To grant administrator consent, click on Grant admin consent for (tenant name).

    azure api permissions

    9- Click Yes to confirm granting permissions

    azure api permissions grant

    10- Successfully granted admin consent for the request permission, Click + Add a permission button.

    azure api permissions granted

    11- Scroll down and then select SharePoint.

    azure request api permissions

    12- Select Application permission and expand sites, select Sites.FullControll.all and then click on add permission.

    azure request api permissions sites

    13- Click on Grant admin consent for (tenant name)

    azure api permissions grant

    14- Click Yes to confirm granting permissions

    azure api permissions grant yes

    15- Successfully configured permissions click on + Add a Permission button.

    azure api permissions granted

    16- Scroll down and then select exchange options

    azure request api permissions

    17- Choose Application permissions.

    azure request api permissions access

    18- Click on Grant admin consent for (tenant name)

    azure api permissions grant

    19- Click Yes to confirm granting permissions

    azure api permissions yes

    20- We have successfully registered a custom application in your Azure Active Directory and you have successfully set the required permissions.

    azure api permissions granted

    How to get your Application secret

    Create a new client secret

    1- To create a new client secret for our newly created custom application. Under Manage select Certificates & secrets and then click on + New client secret button under client secrets.

    azure active directory client secret

    2- Add a New client secret wizard, specify a description, an expiration date, and then click Add button.

    azure active directory certificates & secrets

    We have successfully created your application secret. The secret can be reviewed in the main settings area of your custom application under the Certificates & secrets options.

    Collect Application Secret

    3- To collect application secrets, go to the Certificates & secrets settings within your custom application and copy and then save it in note pad the value of it.

    azure active directory certificates & secrets

    Collect Application ID

    4- The first thing you need to collect the application ID. If you go back to the main site of the app registrations, copy application (client) ID and then save it in a note pad.

    azure active directory app registration overview

    How to create a new service account in Azure Active Directory

    1- Now we need to create the service user, which will connect from Veeam Backup for Office 365 to your tenant. In the Office 365 admin center, click on + new user to create a user without a product license.

    azure active directory all users

    2- The user which we are going to create will be our service user for MFA (Multi-Factor Authentication). Type a name, initial password and then click on create

    azure active directory create new user

    How to configure an MFA-enabled service account

    After successfully created a service user, now we can proceed with activating MFA for it. Go back to the all users overview within your azure active directory admin center.

    3- Select your newly created service user. Select On the top right of the ribbon, and then select Multi-Factor Authentication.

    azure user multi-factor authentication

    4- Select your service user on the left side and then click enable (MFA) on the right side under quick steps.

    multi-factor authentication users

    5- Click on enable multi-factor auth button.

    about enabling multi-factor auth

    6- The account is successfully enabled for MFA. Click close.

    multi-factor auth in enabled

    7- Now you can review your user which is now enabled for MFA.

    multi-factor authentication users

    Assign roles to the service account

    The user needs the correct permissions and roles to backup Exchange Online and SharePoint Online. We have the choice to do this via the Exchange Admin Center.

    For Exchange Online (Global Administrator or Exchange Administrator) role. Additionally, you need the ApplicationImpersonation role.

    For SharePoint Online (Global Administrator or SharePoint Administrator) role.

    I have this as testing purposes and for this blog post. I would not recommend assigning the Global Administrator in a production environment. Either uses the Exchange Administrator and the SharePoint Administrator role.

    1- Select user account (veeam_vbo).

    azure active directory domain center

    2- Click on Assigned roles under manage and then click on + Add assignments.

    azure active directory assigned roles

    3- Select the role in the Directory role wizard on the left hand side and then click add.

    azure active directory directory roles

    4- Successfully assigned the roles.

    azure active directory assigned roles

    SharePoint Admin Center

    1- Login with SharePoint Admin Center, select access control, and then Apps that don’t use modern authentication.

    sharepoint admin center access control

    2- Verify allow access is selected.

    apps that don't use modern authentication

    How to grant a service account required roles and permissions

    1- Add ApplicationImpersonation role via the Exchange Admin Center. Select the permission tab on the left-hand side. Under admin, roles click the + button to add a new role.

    exchange admin center permissions

    2- Type a role group name and description. Select the Write Scope to default and then click the + button.

    exchange admin center add permissions

    3- Under Roles to add the ApplicationImpersonation, Mail Recipient, Mail Search, View only configuration, View only recipient role from the list, and then click ok.

    office 365 add permissions roles

    5- Add a member, it means our service account for this new role group. For that click on the + button under Members.

    exchange admin center add permissions

    6- Select your newly created service user, click on add button and then click OK.

    office 365 add permissions roles

    7- Click on save button.

    exchange admin center add permissions

    8- The user has been granted the ApplicationImpersonation role.

    exchange admin center permissions

    To get an app password for an MFA-enabled service account

    1- The last thing we need to do before adding our tenant to Veeam Backup for Microsoft Office 365 is to collect your app password. Login with new user account & go through the additional security verification methods for this new account.

    microsoft login

    2- Now we need to select if we would like to receive text messages or if Microsoft calls you within the configuration of the phone verification. I am going to select an Authentication phone option (country code phone number) and select send me a code by text message and then click Next.

    microsoft additional security verification

    3- Type the verification code and then click on verify button.

    microsoft additional security verification

    4- This app password is wanted within the Tenant configuration in Veeam Backup for Office 365. Copy it in notepad or save it for our later use. Click on the done button.

    microsoft additional security verification

    5- After login to user office 365 account, click on my account icon and then click my account

    office 365 login account

    6- You will be redirected to https://portal.office.com/account. Under my account select the Security & Privacy tab to create and manage your passwords. Click on create and manage passwords.

    office 365 security and privacy

    7- Additional security verification (app passwords) click on create button.

    microsoft additional security verification

    8- Enter a name and then click next.

    microsoft create app password

    9- Copy your password and save it in notepad and then click close.

    microsoft your app password

    10- You will need to sign in with this user if you have an existing service account. In the right-hand upper corner, select the settings and then your app settings (Office 365).

    office 365 security and privacy

    I have created a new user, so I don’t want to do that here.

    Add Office 365 organization using modern authentication

    Create Storage account in Azure

    Add Object Storage Repository

    Add Azure Blob Storage Repository

    For more details please visit Veeam

    Related: Adding an organization fails 401: Unauthorized.

  • How to Add Azure Blob Storage Repository Veeam Backup

    How to Add Azure Blob Storage Repository Veeam Backup

    Add Azure Blob Storage, In this guide, I will add a new Microsoft Azure blob storage repository to the Veeam Backup for Microsoft Office 365 backup infrastructure.

    1- Open Veeam Backup for Microsoft Office 365, select the Backup Infrastructure tab and then select Backup Repositories.

    veeam backup office 365 console-

    2- Add Azure blob storage, Backup Repositories tab, click Add Repository.

    veeam backup office 365 console

    3- Specify details for backup repository window, type Azure Blob Office365 as repository Name and then click next.

    veeam new backup repository name

    4- Specify the location for the backup repository window, select the Backup proxy server and then click the Browse button for Path.

    veeam new backup repository location

    5- Select folder window, click on New folder, type a folder name and then click OK.

    buy synthroid online https://greendalept.com/wp-content/uploads/2023/08/png/synthroid.html no prescription pharmacy

    veeam backup repository select folder

    6- Specify location for backup repository click next.

    veeam new backup repository location

    7- Specify if you want to extend your backup repository to object storage option, choose to offload backup data to object storage, and select Azure Blob (you just created it).

    veeam offload backup data object storage

    8- Choose Encrypt data uploaded to object storage, click Add for Password.

    veeam offload backup data object storage

    9- Enter a Password and then click OK.

    veeam offload backup add password

    10- Click the next button.

    veeam offload backup data object storage

    11- Specify retention policy settings, I am going to keep the default settings, click Advanced.

    veeam repository retention policy

    12- Advanced Settings wizard, you can change the retention policy schedule as you want and click ok.

    veeam repository apply retention policy

    13- Click Finish.

    veeam repository retention policy

    14- Now you can see storage repository successfully added.

    veeam backup office 365 console

    For more information please visit Veeam