Office 365 - Authentication
Authentication
To enable backups, grant Magnus Box permission to access your Office 365 account data. These credentials provide significant organizational access, so handle them carefully. Access is granted by creating an "Application" in Azure Active Directory, either automatically or manually.
Automatic application registration
Select the Azure Active Directory button to open a registration wizard that automates the setup. You will need to authenticate with Azure as a top-level administrator.
Manual application registration
If automatic registration is not available, complete the following steps manually.
1. Register the application in Azure Active Directory
- Go to https://aad.portal.azure.com/
- Click Azure Active Directory
- Click App registrations, then New registration
- Enter an application name (for example, "My Office 365 Backup")
- Leave the other options at their defaults and click Register
- Copy the
Application (client) IDinto the Application ID field in Magnus Box - Copy the
Directory (tenant) IDinto the Tenant ID field in Magnus Box. Ensure there are no extra spaces after the value
2. Register an authentication secret
- Click the Certificates & secrets tab
- Under Client secrets, click New client secret
- Specify a name and an expiry. Selecting the longest available expiry avoids the secret lapsing and interrupting backups
- Copy the secret's
Valueinto the Application Secret field in Magnus Box. Copy it immediately, as Azure hides the value after you leave the page
3. Grant application permissions
- Click the API permissions tab
- Click Add a permission and add the permissions below
Office 365 Exchange Online, under Application permissions, then Other permissions:
full_access_as_app
Microsoft Graph, under Application permissions:
Application.Read.AllCalendars.ReadWriteChannelMessage.Read.AllContacts.ReadWriteDirectory.Read.AllFiles.ReadWrite.AllGroupMember.Read.AllMail.ReadWriteNotes.Read.AllSites.FullControl.AllTeamMember.ReadWrite.AllUser.Read.All
- Click Grant admin consent for (your organization name) at the top of the permissions list
Once the details are entered, the desktop app populates the authentication fields automatically. Use Test Connection to validate the credentials.