> For the complete documentation index, see [llms.txt](https://helpdesk.augmentt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://helpdesk.augmentt.com/back-up/microsoft-365-backup.md).

# Microsoft 365 Backup

Microsoft 365 doesn't give you a real backup. The recycle bin and native retention tools have short windows and gaps — they aren't built to recover from ransomware, a bad admin action, an offboarding mistake, or a retention policy nobody remembered to set. Augmentt's Back-Up module (delivered through our backup partner, CloudAlly) automates a daily, independent backup of your M365 mailboxes so you can go back to a specific point in time.

{% hint style="info" %}
Backup tasks are managed in the dedicated backup portal, reached from the **Backup** link in the Augmentt navigation — it's a separate login from the main Augmentt console.
{% endhint %}

## What's backed up

The Microsoft 365 Exchange backup task covers, per mailbox:

* Mail
* Calendar
* Contacts
* Tasks
* Notes

{% hint style="warning" %}
Augmentt also sells broader "MS 365 Bundle" backup plans (billed per user) that are referenced on invoices and in sales material as covering "comprehensive Microsoft 365 backup" — which typically implies OneDrive and SharePoint alongside Exchange in a CloudAlly-style bundle. The source documentation pulled for this page only detailed the **Exchange** backup task specifically. If a customer is on a bundle plan and asks what's covered beyond mail/calendar/contacts/tasks/notes, confirm the exact scope with support or the account's plan details rather than assuming — don't state OneDrive/SharePoint/Teams coverage as fact until it's verified against the actual task types available in the portal.
{% endhint %}

## Setting up a backup task

1. In the backup portal, click **+ Add Backup Task**.
2. Choose **Microsoft Exchange**.
3. Name the task.
4. Click **Authenticate**, then sign in with a **Global Admin** account when redirected to the Microsoft sign-in page.
5. You'll land on the Backup Settings page to configure indexing, retention, and activation (below).

{% hint style="warning" %}
The account used to authenticate must have Global Admin permissions. A lower-privileged admin role will not complete setup.
{% endhint %}

Credential-based authorization (as opposed to OAuth) exists but is off by default and isn't recommended — only use it if support has specifically set it up for you.

## Activating mailboxes

You don't have to activate every mailbox manually. Options, from the Bulk Activation and Management screen:

* **Activate by directory property** — set a condition (e.g. a specific department or license type) and either activate the matching accounts once, or set a standing rule that auto-activates any *new* account matching that condition going forward.
* **Activate by Microsoft 365 Groups** — select specific groups to back up.
* **Import a list of accounts** — upload a CSV with an `Account Email` column.
* **Automatically activate new mailboxes** — a task-level toggle that detects and starts backing up new mailboxes as they're created, with no rule needed.

By default, **Unlicensed** Microsoft 365 accounts (external guest accounts, auto-generated shared-storage accounts, etc.) are not backed up. You can opt them in via **Backup Unlicensed accounts**, but be cautious about using an unlicensed *admin* account for anything — unlicensed accounts carry limited permissions.

## Backup frequency and schedule

| Setting          | Options                     |
| ---------------- | --------------------------- |
| Backup hour      | Any hour, in UTC            |
| Backup frequency | Daily, Every 3 Days, Weekly |

More frequent backups than the standard options are possible — this requires a support request, not a self-service setting.

## Retention

* Default retention is **unlimited for as long as the subscription is active**.
* You can request a **defined retention period** (in days, months, or years) instead, via a support ticket — backups older than the configured window are then automatically deleted. This is not adjustable directly in the task settings UI.
* When an entire mailbox/site is deleted upstream, its backups are auto-archived rather than dropped immediately. You can set **Retain auto-archived backups** to a specific number of days, after which they're deleted — or leave them retained indefinitely.

{% hint style="info" %}
Your backup storage region is fixed once set during account signup and can't be self-service changed. If you need to move regions, or want to explore Bring Your Own Storage (BYOS), contact support.
{% endhint %}

## Restoring data

{% hint style="warning" %}
Step-by-step restore instructions (single item vs. full mailbox restore, restore-to-original vs. restore-to-a-different-mailbox) weren't confirmed in the source material for this page. Confirm the current restore flow in the backup portal, or with support, before walking a customer through a live recovery.
{% endhint %}

What is confirmed:

* **Index all data for search** (on by default) is what enables granular, item-level search and restore. Disabling it limits you to browsing backups by date rather than searching within them. Indexing briefly decrypts data to build the search index, then re-encrypts both the data and index — if that's a policy concern, disable indexing and rely on date-based browsing instead.
* **Public Folders** have a distinct restore behavior: a restore creates a *sub-folder* of restored content, which you then have to manually add back as a Public Folder through the normal Exchange Online Public Folder creation process (including any nested sub-folders that came along with the restore). It doesn't restore in place automatically.
* To back up a Public Folder at all, the admin account used for the backup connection needs a mail-enabled Microsoft 365 license and read/write permission on that Public Folder's root permissions (set from the Exchange Admin Center).

## Common limitations

* Unlicensed accounts are excluded from backup by default.
* Public Folder restores land in a new sub-folder, not back in their original location automatically.
* Once the backup storage region is chosen, changing it isn't self-service.

### Microsoft's EWS-to-Graph API migration (2026)

This is a real, dated platform change worth knowing if you support Exchange backup customers:

{% hint style="warning" %}
Microsoft is retiring the Exchange Web Services (EWS) API that older Exchange/Groups/Teams backup tasks were built on. EWS deprecation began gradually on **June 30, 2026**, with full retirement on **October 1, 2026**. Backup tasks are being migrated to the Microsoft Graph API in this window, and tasks flagged for migration need to be **reauthorized** (Backup Task Settings > reauthorize) to grant the new Graph permissions.
{% endhint %}

What this means in practice:

* Backups **keep running on EWS** while a task shows the reauthorization prompt — the prompt itself doesn't mean backups have stopped. Reauthorization status is tracked independently of backup health status.
* After reauthorization, migration to Graph happens gradually in the background — no further action needed.
* Customers on **Kiosk, F1, or F3** Microsoft licenses are affected earlier, since Microsoft disables EWS for those license types on June 30, 2026, ahead of the general October 1 cutoff.
* **Coverage gap to flag:** the Microsoft Graph API does not yet support all Exchange data types. Once a task is migrated to Graph, **Exchange Online Archive** and **Public Folders** are no longer included in *new* backups going forward. Backups taken previously under EWS remain accessible — this only affects what gets captured after the migration.
* Customers who don't reauthorize promptly continue to be protected under EWS until Microsoft's hard October 1, 2026 cutoff — but should not wait, since EWS won't exist as a fallback after that date.

If a customer reports "my Exchange Archive or Public Folder stopped showing up in new backups," check whether that mailbox's task has already migrated to Graph — this is the expected (if disruptive) behavior of the migration, not a bug.

## Troubleshooting

| Symptom                                                                                          | Likely cause                                                                                                                                                                                          | What to do                                                                                                                                                                                                                                                                                                                                                                                                      |
| ------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Task shows **Disconnected**                                                                      | Auth token expired, often after a long pause                                                                                                                                                          | Reauthorize via the connection status indicator on the task                                                                                                                                                                                                                                                                                                                                                     |
| Reauthorization banner appears on a task                                                         | Part of the EWS → Graph API migration (see above)                                                                                                                                                     | Reauthorize promptly; backups continue on EWS in the meantime                                                                                                                                                                                                                                                                                                                                                   |
| Exchange Online Archive or Public Folder content missing from *new* backups after a certain date | Task has migrated to Graph API, which doesn't yet cover those data types                                                                                                                              | Confirm this is expected per the migration notice; historical EWS-era backups of that data remain accessible                                                                                                                                                                                                                                                                                                    |
| "Can Augmentt alert us before a mailbox fills up?"                                               | This is a monitoring/alerting question distinct from backup itself                                                                                                                                    | <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p>Whether mailbox-storage or SharePoint-storage threshold alerting exists as a feature (inside Back-Up or elsewhere in Augmentt) wasn't confirmed in the material available for this page — this has come up as a customer feature request. Check current product capability before answering definitively.</p></div> |
| Backup billed as a "Bundle Plan" per user but customer disputes scope/seat count                 | Per-user bundle billing (e.g. "MS 365 Bundle Plan — Comprehensive Microsoft 365 Backup Billed Per User") is invoiced separately from core Augmentt billing and can arrive as its own proforma invoice | Confirm active seat/user count on the backup task directly rather than assuming the invoice numbers already match the current tenant headcount                                                                                                                                                                                                                                                                  |
| Can't log in to the backup portal via the link in Augmentt                                       | Backup portal login is separate from Augmentt credentials; partner vs. customer login sections are easy to mix up when managing multiple client tenants                                               | Confirm which login role was provisioned and reset the backup-portal password directly                                                                                                                                                                                                                                                                                                                          |

{% hint style="warning" %}
Exact numeric limits — mailbox size ceilings, hard item-count caps, or an SLA-backed restore turnaround time — are not confirmed in the source material and should be checked with support for large or unusual tenants.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://helpdesk.augmentt.com/back-up/microsoft-365-backup.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
