Day 3: Mastering Microsoft 365 Backup

Welcome to Day 3 of your Magnus Box journey! Today you'll protect a client's Microsoft 365 data: mailboxes, OneDrive, SharePoint and Teams files. Microsoft keeps the service running, but it's still your job to be able to get back a deleted mailbox or an overwritten file. That's what this backup is for.

⏱️ Time to complete: 45 minutes

🎮 Achievement Unlocked: M365 Guardian

▶️ Prefer video? Watch the Day 3 guide to setting up Microsoft 365 backup.

What you can protect

  • Exchange Online: email, calendars and contacts for active users and shared mailboxes
  • SharePoint Online: sites, lists and pages
  • OneDrive for Business: documents and files
  • Microsoft Teams: files (they're stored in the team's SharePoint site)

Not included: Teams chats, meetings, calls and calendars; Outlook tasks; guest users, deleted users, archive mailboxes, journal mailboxes, Discovery mailboxes and Outlook group mailboxes. For the full list, see Office 365 - Overview.

Before you start

  • A Global Admin account for your client's Microsoft 365 tenant. You'll sign in with it once to approve access (see "What is admin consent?" below).
  • An endpoint that's always on, with the Magnus Box Application installed and signed in. The Microsoft 365 backup runs on this device: it downloads the data from Microsoft, then encrypts and uploads it. A server or dedicated machine works best.
  • A user account in the Magnus Box Web Portal for the client (see Day 2).

Set up Microsoft 365 backup

Step 1: Create the Protected Item

  1. Open the app on the endpoint, or in the Web Portal go to Users > [user] > Protected Items (the endpoint must be online).
  2. Create a new Protected Item.
  3. Select Microsoft Office 365 as the type.

Step 2: Connect to Microsoft 365

  1. Click the Azure Active Directory button. (Microsoft has since renamed Azure Active Directory to Microsoft Entra ID, but the button still uses the old name.)
  2. Sign in with your client's Global Admin account.
  3. Review the permissions and accept them. This is the admin consent step.
  4. Click Test Connection to confirm the credentials work.

💡 Pro Tip: Use a dedicated Global Admin account for backup purposes. It keeps your security tracking clean.

What is admin consent?

When you click Azure Active Directory, the app registers an application for the backup in your client's Microsoft Entra ID. That application needs permission to read every mailbox and site in the organization, not just your own. Microsoft only lets an administrator approve that level of access for the whole organization, which is why you have to sign in as a Global Admin and accept the permissions. Until consent is granted, the backup can't read any data.

If the automatic sign-in doesn't work, you can register the application by hand in Microsoft Entra ID and click Grant admin consent yourself. Office 365 - Authentication walks you through it and lists every permission.

Step 3: Choose what to back up

Mailboxes and sites are selected separately. Use the drop-down arrow next to the plus button to switch between them.

  • Back up everything: protects the whole Microsoft 365 domain, including accounts that are added later. This is the simplest choice for most clients.
  • Select specific items: pick individual users, sites or groups. If you pick a Microsoft Entra ID group, every member's mailbox is backed up. Use the Search field to find a user or site quickly.

To back up everyone except a few people, create a Microsoft 365 group that new accounts are added to automatically, remove the people you want to leave out, and select that group.

You can protect:

  • Active user mailboxes
  • Shared mailboxes (each one counts as a separate mailbox for billing, however many people can open it)
  • SharePoint sites
  • OneDrive content
  • Teams files

For more detail, see Office 365 - Configuring Selections.

Step 4: Set the schedule and retention

  1. Set a backup schedule (daily is recommended).
  2. Set the retention period (Day 5 covers retention in more detail).
  3. Start the backup.

💡 Pro Tip: The first backup downloads everything from Microsoft, so it can take a while for a large tenant. Microsoft limits how fast each mailbox can be read, and the biggest mailbox is usually the last to finish. See Office 365 - Performance Considerations.

Restore options

  • Restore to a local device: emails come back as .eml files that open in Outlook or any other mail app. Contacts and calendars come back as JSON files. OneDrive, SharePoint and Teams files come back as regular files and folders.
  • Restore to Microsoft 365: put items back in their original location or a different one. Existing emails aren't overwritten. If an email already exists, you'll get a duplicate.
  • Restore to a new user: if a user account was deleted and recreated, you can restore their Microsoft 365 data, including contacts, calendars, OneDrive and SharePoint data, to the new account. This is a big help in a disaster recovery.

See Office 365 - Restore for the details.

Best practices

  • Start with the most critical mailboxes, or use Back up everything so nobody gets missed.
  • Use search to find specific users quickly.
  • Watch the first backup until it completes.
  • Test a restore regularly, for example one email and one OneDrive file.
  • Keep Global Admin credentials secure.

Next steps

Tomorrow, we'll set up Disk Image protection. Here's what to expect:

  • Full-system protection for Windows and Linux
  • Bare-metal recovery options
  • Restoring straight into a virtual machine
  • Best practices for image backups

Common questions

How long will the first backup take?

It depends on the amount of data. After the first full backup, Magnus Box uses Microsoft's change tracking to back up only what's new or changed, so later backups are much faster.

Can I back up shared mailboxes?

Yes. Shared mailboxes are fully supported. Each shared mailbox counts as a separate mailbox for billing, no matter how many people have access to it. See How am I billed for an Office 365 backup?

What about Teams chats and meetings?

Teams files are backed up. Chats, meetings, calls and Teams calendars are not included.

Where did the "all except" option go?

It was replaced by Back up everything. To exclude people, use a Microsoft 365 group as described in Step 3.

Need help?

Our support team is here for you:

🏆 Achievement Summary

  • Portal Master ✓
  • Backup Initiate ✓
  • M365 Guardian ✓
  • Next achievement: System Shield (Day 4)
Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us