Setting up 365 Backup: connect and consent

How an administrator connects the Microsoft tenant to 365 Backup, which permissions the backing application requires, and what is not backed up without each of them.

Setup is done once per Microsoft organisation and takes a few minutes. You need an account with administrator rights in the Microsoft tenant.

Even if your mail flow already runs through Conbool: the backup is a different application with different permissions and requires its own consent. The existing connection is not enough.

You will find the route under Settings, tab Connections. Each application is listed separately there, with the access it needs and its own button.

The four applications

Backup. Read access to mailboxes, drives and Teams. Prerequisite for every backup run. This application can only read.

Restore. Write access to Microsoft 365. Without this consent, output is provided exclusively as a file.

Read state. Carries over whether a message had been read. Requires write access to individual messages.

Directory. Write access to the directory for restoring users and groups.

The last two are offered only if they are enabled for your tenant. Each application is consented separately per Microsoft organisation.

Which permission covers what

The backing application requests twelve permissions. What is lost without each:

PermissionWithout it you lose
User.Read.Alldiscovery itself: nothing is found
Group.Read.Alldiscovery itself: groups and teams stay invisible
Directory.Read.Allthe directory extract from Entra ID
Mail.Readmailbox and online archive
MailboxItem.Read.Allmailbox and online archive
Files.Read.AllOneDrive and SharePoint lists
Sites.Read.AllOneDrive and SharePoint lists
Chat.Read.AllTeams chat
ChannelMessage.Read.AllMicrosoft Teams
Tasks.Read.AllPlanner
Group-Conversation.Read.Allthe group mailbox
Calendars.Readthe group calendar

Calendars.Read is not Calendars.Read.All. In Microsoft's naming, the .All variant means working hours and locations, not calendar content.

Group mailbox and group calendar were added on 31 August 2026. Consent freezes the permission state at which it was granted: anyone who consented earlier does not receive those two permissions retroactively. The connection looks healthy meanwhile, and the affected source stays silently unprotected.

Whether this applies to you is visible under Connections: a missing permission is listed there by name, together with the data source that fails without it. The Renew consent button obtains it.

Connecting a second organisation

One account can hold several Microsoft organisations. Under Connect another organisation, enter the sign-in domain of the organisation you want, otherwise the consent lands in whichever organisation your browser is currently signed in to.

For an organisation to be connectable, one of its Microsoft-verified domains must either be your own sign-in domain or be verified in your Conbool account.

Next

Connected does not mean backed up. Select under Users and Groups what should be backed up: What gets backed up.