Maintain control of your Microsoft 365 data
Post Reply
matteu
Veeam Legend
Posts: 802
Liked: 126 times
Joined: May 11, 2018 8:42 am
Contact:

Account used to add organization

Post by matteu »

Hello,

I would like to know if the account used to add the Azure organization can be deleted or if I will have issue with VB365 product ?
I can see it on the Organization settings and want to be sure there are no problem if I remove it from Azure account

Thanks.
Mildur
Product Manager
Posts: 9452
Liked: 2513 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: Account used to add organization

Post by Mildur »

Hi Matteu

The account used for adding the M365 organization can be deleted. Just make sure to update the username in the organization settings to another valid mail address. We use this mail address to resolve the tenant name and impersonation.
And if you want to protect Public Folder, this account must have a valid Exchange Online license and an active mailbox.

Best,
Fabian
Product Management Analyst @ Veeam Software
matteu
Veeam Legend
Posts: 802
Liked: 126 times
Joined: May 11, 2018 8:42 am
Contact:

Re: Account used to add organization

Post by matteu »

Hello,

Thanks for your answer. This mail address must be global admin right ?
It's something strange.
Today If I authenticate and try to restaure an exchange item with an other account than the one I used to add the organization, if this other account is not ApplicationImperssonation role member, I can't perform a restauration. I guess that means the account used to add the organization is not used to perform this task right ?

I don't know if it's different with restore portal, but I'm using Exchange explorer to perform this task.
Mildur
Product Manager
Posts: 9452
Liked: 2513 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: Account used to add organization

Post by Mildur »

No, the account doesn't have to be a global admin. It can be any account from your M365 organization.
I even tested it with a shared mailbox once.
Today If I authenticate and try to restaure an exchange item with an other account than the one I used to add the organization, if this other account is not ApplicationImperssonation role member, I can't perform a restauration. I guess that means the account used to add the organization is not used to perform this task right ?
Restore does not use the account which you have provided in the username field.

When you do the restore with our Veeam Explorer for Microsoft Exchange, you need to authenticate your restore session through device logon:
https://helpcenter.veeam.com/docs/vbo36 ... tml?ver=70

Make sure that the user you use for this device login authentication have one of the following roles assigned:
- ApplicationImpersonation
- Global Administrator or Exchange Administrator

Source: https://helpcenter.veeam.com/docs/vbo36 ... =70#modern

Best,
Fabian
Product Management Analyst @ Veeam Software
matteu
Veeam Legend
Posts: 802
Liked: 126 times
Joined: May 11, 2018 8:42 am
Contact:

Re: Account used to add organization

Post by matteu »

Thanks for your answer.

OK, So, I will use a "service user account" on the organization account.
And to restore exchange item, you need both permission : (global admin or exchange admin ) AND applicationImpersonnation.
If you don't have impersonnationApplication role -> impossible to restore mailbox . (I lost some time on it these days :p )
matteu
Veeam Legend
Posts: 802
Liked: 126 times
Joined: May 11, 2018 8:42 am
Contact:

Re: Account used to add organization

Post by matteu »

Sorry to ask again but I'm not sure to understand.
The account in Microsoft 365 Connection settings on the organization is used to get datas ?

If I don't backup public folder, do I need to give this user impersonnation role or not ? Not sure to understand the documentation about it :
https://helpcenter.veeam.com/docs/vbo36 ... tml?ver=70
"In the Username field, enter a user account that you want to use for impersonation. "
Post Reply

Who is online

Users browsing this forum: Bing [Bot] and 29 guests