How to configure the impersonation role on Microsoft Exchange Online for M365 backup powered by Veeam
Having the “Global Administrator” or “Exchange Administrator” role alone is not enough to allow all restore options using the “Veeam Explorer for Microsoft Exchange”. The impersonation role is also required to allow your Microsoft 365 user account to perform some operations by using permissions that are associated to the impersonated account.
- Navigate to https://admin.exchange.microsoft.com/ and log in to your Microsoft 365 tenant with a user having the “Global Administrator” or the “Exchange Administrator” role.
- Go to the Roles section, then to the Admin roles sub-section.
Finally, click on Discovery Management
- Click on the Permissions tab
- Enable the ApplicationImpersonation role and click on Save.
Then, make sure changes are applied to the role group.
- Click on the Assigned tab and click on the + Add button
- Add your users with the “Global Administrator” or “Exchange Administrator” role to be used for M365 restores, then click on Add.
Then, make sure users were added to the role group.
Users with the "Global Administrator" or “Exchange Administrator” role while being a member of the "Discovery Management" role group should now have the necessary permissions to perform additional restore options using "Veeam Explorer for Microsoft Exchange".