Setting up 365 Backup: connect and consent
How an administrator connects the Microsoft tenant to 365 Backup, which permissions the backing application requires, and what is not backed up without each of them.
Setup is done once per Microsoft organisation and takes a few minutes. You need an account with administrator rights in the Microsoft tenant.
The backup needs its own consent
Even if your mail flow already runs through Conbool: the backup is a different application with different permissions and requires its own consent. The existing connection is not enough.
You will find the route under Settings, tab Connections. Each application is listed separately there, with the access it needs and its own button.
The four applications
Backup. Read access to mailboxes, drives and Teams. Prerequisite for every backup run. This application can only read.
Restore. Write access to Microsoft 365. Without this consent, output is provided exclusively as a file.
Read state. Carries over whether a message had been read. Requires write access to individual messages.
Directory. Write access to the directory for restoring users and groups.
The last two are offered only if they are enabled for your tenant. Each application is consented separately per Microsoft organisation.
Which permission covers what
The backing application requests twelve permissions. What is lost without each:
| Permission | Without it you lose |
|---|---|
| User.Read.All | discovery itself: nothing is found |
| Group.Read.All | discovery itself: groups and teams stay invisible |
| Directory.Read.All | the directory extract from Entra ID |
| Mail.Read | mailbox and online archive |
| MailboxItem.Read.All | mailbox and online archive |
| Files.Read.All | OneDrive and SharePoint lists |
| Sites.Read.All | OneDrive and SharePoint lists |
| Chat.Read.All | Teams chat |
| ChannelMessage.Read.All | Microsoft Teams |
| Tasks.Read.All | Planner |
| Group-Conversation.Read.All | the group mailbox |
| Calendars.Read | the group calendar |
Calendars.Read is not Calendars.Read.All. In Microsoft's naming, the .All variant means working hours and locations, not calendar content.
Additional consent for existing customers
Group mailbox and group calendar were added on 31 August 2026. Consent freezes the permission state at which it was granted: anyone who consented earlier does not receive those two permissions retroactively. The connection looks healthy meanwhile, and the affected source stays silently unprotected.
Whether this applies to you is visible under Connections: a missing permission is listed there by name, together with the data source that fails without it. The Renew consent button obtains it.
Connecting a second organisation
One account can hold several Microsoft organisations. Under Connect another organisation, enter the sign-in domain of the organisation you want, otherwise the consent lands in whichever organisation your browser is currently signed in to.
For an organisation to be connectable, one of its Microsoft-verified domains must either be your own sign-in domain or be verified in your Conbool account.
Next
Connected does not mean backed up. Select under Users and Groups what should be backed up: What gets backed up.