Maintain control of your Microsoft 365 data
Post Reply
GianlucaCroci
Expert
Posts: 237
Liked: 25 times
Joined: Feb 26, 2019 12:08 pm
Full Name: Gianluca Croci
Contact:

After upgrade to 8.0.2.159

Post by GianlucaCroci » 1 person likes this post

Hello,

we've upgraded our Veeam Backup for Microsoft 365 to 8.0.2.159.

Now when we run the backup we've these warning

Code: Select all

Missing application permissions: Exchange.ManageAsApp. Missing application roles: Global Reader. Public folder and discovery search mailboxes will be skipped from processing, and a shared mailbox type will not be identified.

Missing application permissions: ChannelMember.Read.All. Private and shared team channels will be skipped from processing
We tried to look on the Microsoft website for the rights part, but it's very chaotic and we didn't understand what to change.

Also in the "App Registrations" part and we find 3 "VeeamBackup" and several "VeeamBackupApplication".
Should all of them be modified?


Thanks in advance for the reply.
pat_ren
Service Provider
Posts: 94
Liked: 16 times
Joined: Jan 02, 2024 9:13 am
Full Name: Pat
Contact:

Re: After upgrade to 8.0.2.159

Post by pat_ren »

I had this issue too, right click on the org with the problem and edit it, click next a few times to find the app ID

Check these permissions and add the ones that are missing, and add the global reader permission as per this KB
https://helpcenter.veeam.com/docs/vbo36 ... tml?ver=80
GianlucaCroci
Expert
Posts: 237
Liked: 25 times
Joined: Feb 26, 2019 12:08 pm
Full Name: Gianluca Croci
Contact:

Re: After upgrade to 8.0.2.159

Post by GianlucaCroci »

Thanks a lot.


Just a question that goes beyond this issue, but still related to Veeam Backup for Microsoft 365.

I printed a report with the list of users protected and not protected by Veeam (about 50% protected).
I was wondering why many were not protected, since the job is set to save everything (without filters).
In some cases I saw that the user has never connected.
In others, however, the last time he accessed was in 2023.
I think this is the discriminant of the save, but I wanted to have more details (for example how much time must pass since the last save to still be taken into consideration).


Thanks again for the precious help
Mike Resseler
Product Manager
Posts: 8221
Liked: 1333 times
Joined: Feb 08, 2013 3:08 pm
Full Name: Mike Resseler
Location: Belgium
Contact:

Re: After upgrade to 8.0.2.159

Post by Mike Resseler »

@GianlucaCroci

So you have a job with the setting of "Entire Organization" but not all users are protected? And the users that are not protected are still enabled in M365?
GianlucaCroci
Expert
Posts: 237
Liked: 25 times
Joined: Feb 26, 2019 12:08 pm
Full Name: Gianluca Croci
Contact:

Re: After upgrade to 8.0.2.159

Post by GianlucaCroci »

Hello,

yes, we save the "Entire Organization" and several users are not saved.
As I wrote, it seems because they've never logged in to MS365 (since they were created) or they've not connected for several months.
For this reason I'd like to know the logic that is applied for saving, such as if users who've not logged in in the last 6 months are filtered.

Thanks
ACrispiels
Influencer
Posts: 23
Liked: 3 times
Joined: Mar 27, 2009 4:57 pm
Full Name: Alain Crispiels
Location: Belgium
Contact:

Re: After upgrade to 8.0.2.200

Post by ACrispiels »

Hello,

I followed the url suggested by @pr_osit but there is still "Missing application roles: Global Reader. Public folder and discovery search mailboxes will be skipped from processing, and a shared mailbox type will not be identified.".

This error message makes sense since this tenant does not have any public folders !

What did I miss ? ;-)
ACrispiels
Influencer
Posts: 23
Liked: 3 times
Joined: Mar 27, 2009 4:57 pm
Full Name: Alain Crispiels
Location: Belgium
Contact:

Re: After upgrade to 8.0.2.159

Post by ACrispiels »

Hello,


No news since more than a week, the case id #07454261 has been opened today...
mjr.epicfail
Veeam Legend
Posts: 475
Liked: 128 times
Joined: Apr 22, 2022 12:14 pm
Full Name: Danny de Heer
Contact:

Re: After upgrade to 8.0.2.159

Post by mjr.epicfail »

There is a new CP:
Maybe this fixes your issues?

https://www.veeam.com/kb4656
VMCE / Veeam Legend 2*
ACrispiels
Influencer
Posts: 23
Liked: 3 times
Joined: Mar 27, 2009 4:57 pm
Full Name: Alain Crispiels
Location: Belgium
Contact:

RE: After upgrade to 8.0.2.200

Post by ACrispiels »

@mjr.epicfail, the suggested guide I read to check permissions from @pr_osit was not enough.
Following the tech support, I had to revalidate all organizations and it was ok after that.
But that revalidation brought the Global Reader permission/role to the Veeam 365 application, which I hadn't imagined and don't like too much by the way...
So it's currently resolved without the latest patch but thanks for the info.
mjr.epicfail
Veeam Legend
Posts: 475
Liked: 128 times
Joined: Apr 22, 2022 12:14 pm
Full Name: Danny de Heer
Contact:

Re: After upgrade to 8.0.2.159

Post by mjr.epicfail »

Hi Alain,

Good to hear you got it fixed, but you should install the patch too, as it fixes a lot and could prevent issues in the future :)
VMCE / Veeam Legend 2*
Mildur
Product Manager
Posts: 10289
Liked: 2747 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: After upgrade to 8.0.2.159

Post by Mildur » 1 person likes this post

Hi @ACrispiels

Yes, running the organization wizard again and selecting the option "Grant this application required permissions and register its certificate in Azure AD" will apply all the necessary permissions for you.
Danny is correct. We recommend deploying the patch he shared. The patch fixes the top known issues we observed in the first two months of the Veeam Backup for Microsoft 365 v8 release.

Best,
Fabian
Product Management Analyst @ Veeam Software
ACrispiels
Influencer
Posts: 23
Liked: 3 times
Joined: Mar 27, 2009 4:57 pm
Full Name: Alain Crispiels
Location: Belgium
Contact:

Re: After upgrade to 8.0.2.200

Post by ACrispiels » 1 person likes this post

Ok @Fabian, I'll do that upgrade soon.
troll@fixsys.nl
Lurker
Posts: 1
Liked: 1 time
Joined: Jan 08, 2025 12:14 pm
Full Name: Troll FS
Contact:

Re: After upgrade to 8.0.2.159

Post by troll@fixsys.nl » 1 person likes this post

We have resolved the issue with following:

Missing application permissions: Exchange.ManageAsApp.
Missing application roles: Global Reader. Public folder and discovery search mailboxes will be skipped from processing, and a shared mailbox type will not be identified.

Adding role:
- ExchangeManageAsApp
- GlobalReader
- ExchangeAdministrator

And also with:
" The easiest way to add the required Azure permissions is to revalidate the organization:
right click edit the organization.onmicrosoft.com, Next Next Next
Install the Application certificate that corresponds to the Application ID.
Under the Install button, there is this checkbox:
"Grant this application required permissions and register its certificate in Azure AD".
Please check it. Next Finish. Finish revalidating the organization, make sure that all components are green, check if the issue is resolved."
eyvindb
Service Provider
Posts: 20
Liked: 5 times
Joined: Mar 14, 2016 7:14 am
Full Name: Eyvind Baadnes
Location: Aalesund, Norway
Contact:

Re: After upgrade to 8.0.2.159

Post by eyvindb »

Same issue.. are there any way to reauthenticate through the service provider portal?

Regards,
Eyvind B
GianlucaCroci
Expert
Posts: 237
Liked: 25 times
Joined: Feb 26, 2019 12:08 pm
Full Name: Gianluca Croci
Contact:

Re: After upgrade to 8.0.2.159

Post by GianlucaCroci » 2 people like this post

we've installed the last version of Veeam (v.8.1.0.305), and then edited the "organization.onmicrosoft.com" to the end, and now the problem is solved.

thanks
mjr.epicfail
Veeam Legend
Posts: 475
Liked: 128 times
Joined: Apr 22, 2022 12:14 pm
Full Name: Danny de Heer
Contact:

Re: After upgrade to 8.0.2.159

Post by mjr.epicfail » 1 person likes this post

Thats great!

Thanks for sharing.
VMCE / Veeam Legend 2*
Post Reply

Who is online

Users browsing this forum: Amazon [Bot] and 68 guests