Backup M365 with Veeam and restore portal
Install Veeam Backup for Microsoft 365
The latest version of Veeam for Microsoft 365 contains many new features. In this post we will discuss the self-service restore via the restore portal.
Open an ISO file on the Server and click on Veeam.Setup.
A wizard appear, click on Install.
Few options is available, click on Veeam Backup for Microsoft 365.
Click on I accept for accept Licence agreement.
Verify the Data Location and click on Install.
Install is in progress…. Click on Finish when installation is finished.
Veeam for Microsoft 365 is now been configured.
Add Microsoft 365 Organization
From the Veeam console, click on Organizations then on Add Org on the ribbon.
Select Microsoft 365 and click on Next.
Select Modern Authentification and click on Next.
In case of a first time installation of Veeam Backup for Microsoft 365, leave the option Register a new Azure AD application automatically selected. Otherwise, you can use the application already present in Azure AD.
Enter the name of the Azure AD application and click on Install.
Select Generate a new self-signed certificate and click on Next.
Click on Next then on Finish. The certificate has been generated.
Click on Copy code then on the link to log in to Microsoft 365.
A web page appear, paste the code. Enter the username and password.
Application has been created on Azure AD Connect.
The connection with M365 platform has been verifying. If all connection has validated, click on Finish.
Organization is now been added on Veeam.
Configure Backup Repository
Before to create Backup Repository, we will create Object Storage Repositories. From the Veeam console, open Backup Infrastructure and click on Object Storage Repositories. Click on Add Object Storage in the ribbon.
A new Windows appear, enter the name of the Object Storage Repository and click on Next.
I use my azure subscription to externalize my backup file. Select Microsoft Azure Blob Storage or other Object storage type then click on Next.
Select Azure Blob Storage then click on Next.
The account credential must be configured. CLick on Add to add new account credential.
The account name and the shared key must be configured. You can retrieve this information in the properties of the blob storage.
Copy and paste the account name and the shared key then click on OK;
The Azure storage account has been added, click on Next.
Select the container and the folder then click on Finish.
Create local Backup Repository
From the Veeam consol, open Backup infrastructure then click on Backup Repositories. In the ribbon, click on Add Repository.
Enter the name of the repository and click on Next.
Select the desired folder. This repository is used only for cached (permit to restore the last backup object faster). All backup file is externalize on the Blob Storage.
Check Offload backup data to object storage and select the previously Object Storage Repository. Configure Encryption for secute the file transfer.
Configure the retention policy and click on Finish.
Create backup job
From the Veeam console, open Organizations tab and click on Backup.
Enter the name of the backup job and click on Next.
With Add button, select objects that you want backup.
Select the repository previously created and click on Next.
Scheduling the job as you want and click on Create.
THe job has been created.
Configure Restore portal
Restore portal permit to restore file with self-service portal. Delegated users can be restore one or more object backup ed by Veeam.
In the Veeam console, open the menu and click on General Options.
Select Restore Portal and check Enable Restore Portal. Click on Create for create Application ID.
Enter the name of Azure Ad Application registration then click on Install.
A new windows appear, select option : Select certificate for the Certificate Store of this server.
Select the certificate and click on Finish.
Enter restore portal web address (https://FQDNServeurVeeam:Port
Sign-in into the Azure AD portal. Copy the code and click on the URL. You need enter credential of administrator Azure AD Account. Click on Finish for close wizard.
Restore portal has been configured.
Click on REST API tab and check Enable REST service. Click on Install to select certificate used for HTTPS.
A wizard appear, select option : Select certificate from the Certificate Store of this server.
Select the certificate and click on Finish.
REST API tab is now configured.
Open Authentification tab and check Enable restore operator authentification with Microsoft credentials. Click on Install for select certificate.
Select option : Select certificate from the Certificate of this server and click on Next.
Select the certificate and click on Finsih
Select the certificate and click on Finsih. Click on Apply to valide all configuration.
configure Restore Operator Roles
In the Veeam console, open the menu and click on Restore Operator Roles.
Click on Add to assign resore operators role at users or groups.
Enter the name of the role and click on Next.
Select organization and click on Next.
Assign the restore operators roles at the users or groups.
It’s possible to delegate entire organization or some objects. I choose to allow manage entire organization.
Click on Create for create restore operator roles.
Restore with Self Service portal
Open web navigator and access to the following URL. Log in with the user account that has the Restore Operator Roles right.
https://FQDNServeur:Port
The user connected can restore his object. Click on the user then on Change Scope.
All object backup ed (the scope of the users is entire organization) appear. Select the desired users and click on Change scope.
Select the desired object and click on Restore.