Troubleshooting

The six connection error states with cause and remedy, the three most common cases that produce no error at all, and what support needs from you.

Connection errors

Consent was revoked in the Microsoft tenant. An administrator has to grant it again, otherwise nothing is backed up. Route: Settings, tab Connections, Grant consent on the affected application.

This application no longer exists in the Microsoft tenant. Somebody deleted the enterprise application in Entra. Renewing credentials does not help; new consent is required, by the same route as above.

The credentials have expired. The Microsoft tenant has to be connected again.

Microsoft denied access. Check whether consent still covers all mailboxes and drives. A common cause is an application access policy restricting access to particular mailboxes.

Microsoft temporarily throttled the requests. No action needed. The next run catches up on the outstanding data.

Microsoft answered with a service error. The connection stands; renewing consent changes nothing. The next run tries again. If the error persists, contact support.

The three cases without an error message

These are the most common and the most treacherous, because the module looks healthy meanwhile.

Consent freezes the permission state. If a permission is added later, existing customers do not receive it retroactively. The connection stays green, and the affected source stays silently unprotected. Since 31 August 2026 this concerns the group mailbox and group calendar. Visible under Connections: a missing permission is listed there by name.

A discovered source is never backed up. Discovery does not replace selection. A newly created mailbox that nobody selects under Users or Groups stays unprotected. Visible among the unprotected units with the reason Not yet selected for backup.

A unit above the seat count is skipped. If more billable accounts exist than seats ordered, the surplus is left behind. Reason: Above the seat count, unlicensed.

All three are visible in the breakdown of unprotected units. A regular look there pays off, rather than only when damage is done.

What support needs

  • The name of the affected protection unit
  • The time of the failed run
  • The technical detail from the error box under Connections, if one is shown
  • For a restore: the audit log entry of the operation

The error box has an expander labelled Technical detail for support. Send its contents in full, even if they look unintelligible — they contain the identifiers Microsoft uses to locate a single call.