Views:

TABLE OF CONTENTS

Description

New permissions and a role must be granted to the Microsoft Entra application to backup and restore data of your Microsoft 365 organization with M365 Backup powered by Veeam.


This procedure explains how to set the new required permissions and role in Microsoft Entra ID to ensure the continuity of your backup service after the upgrade of the infrastructure that occurred in Mid-August 2026.

 

Please refer following Veeam KB for more details: - https://www.veeam.com/kb4820

Requirements

The user to use must have one of the following roles to update permissions in Microsoft Entra ID:  Application Administrator, Cloud Application Administrator or Global Administrator.

 

The user to use must have one of the following roles to update roles in Microsoft Entra ID:   Privileged Role Administrator or Global Administrator.

Important Notes

Please note that the procedure below was automated for Microsoft tenants with a working GDAP (Granular Delegated Admin Privileges) relationship with Sherweb. For others, this procedure is mandatory. Tenants without a working GDAP relationship with Sherweb were contacted by email about this required change.

 

If required permissions are not properly configured before the upgrade of the infrastructure, you may receive warnings in your backup reports after the upgrade. Also, some backup and restore options may not be working properly.

 

Tenants' backups (Microsoft accounts) implemented after the infrastructure update will automatically receive the appropriate permissions and do not require to follow this procedure.

Procedure

  1. Sign in to the Microsoft Entra admin center

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 
       2. Browse to Identity > Applications > App registrations > All applications.

           Use the search field to filter the “M365 Backup powered by Veeam application. Then, click on the application named M365 backup powered by Veeam.

           Note: If multiple applications named “M365 backup powered by Veeam” are found, proceed with steps below for all of them.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

3. Click on API permissions.

 
  

First permission to add

  • Click on Add a permission
     

 

 

 

 

 

 

 

 

 

 

 

 

 

 



 

  • Click on Microsoft Graph.
     
     

 

 

 

 

 

 

 

 

 

 

  • Click on Delegated permissions

     

 

 

 

 

 


 

  • Browse to User, select User.Read.All and click on Add permissions



     




 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Second, Third and Fourth permission to add

  • Browse to MailboxFolder and MailboxItem, select Mailboxfolder.ReadWrite, MailboxItem.ImportExport and MailboxItem.ReadWrite and click on Add permissions
     


     

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Fifth permission to add

  • Click on Add a permission
     

     

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


 

  • Click on Microsoft Graph.

     
     

  • Click on Application permissions

     

 

 

 

 

 


  

 

 

  • Browse to User, select User.Read.All and click on Add permissions
     
      



     

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Sixth, Seventh and Eighth permission to add

  • Browse to MailboxFolder and MailboxItem, select Mailboxfolder.ReadWrite.All, MailboxItem.ImportExport.All and MailboxItem.Read.All and click on Add permissions
     




 



 

 


 





 

  • Once all permissions are added on the application, click on Grant admin consent


     

 

 

 

 

 

 

 

 

 

 

 

 

 

 



 

  • Select Yes and click on Save and continue.





     

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 



 

 

 

 

 

 

 

 

 

 

 

 

 

 

  • Confirm that all permissions are granted.





     

 

 

 

 

 

 

 

 

 

 

 

 


 

Granting Global Reader Role to Microsoft Entra Application

 

  • Browse to Identity > Roles & admins > Roles & admins.

    Use the search field to get the “Global Reader” role. Then, click on Global Reader.

      
     

 

 

 

 

 

 

 

 

 

 

 

 


 

 

  • Click on Add assignments

      
     

     

  • In the search field, type M365 Backup powered by Veeam. Select all applications named M365 Backup powered by Veeam and click on Add.

      

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

References