AvePoint Cloud Backup

AvePoint Cloud Backup supports backup for all Microsoft 365 instances, such as Exchange Online, OneDrive, SharePoint Online, Microsoft 365 Groups, Teams, Microsoft Teams Chat, Project Online, Public Folders, Viva Engage, Power BI, Power Automate, and Power Apps to protect your data.

Once the backup is enabled, AvePoint Cloud Backup will perform a full backup to cover all contents within the backup scope. Subsequent incremental backups will follow the configured frequency to capture changes based on the corresponding timestamps.

*Note: AvePoint cannot guarantee the completion of four backups per day, even if the backup frequency is set to four times daily. Various factors, such as data size, can impact job performance and are beyond our control. If a scheduled backup is due to start but the previous one is still in progress, the new job will be skipped.

For site collections (of SharePoint Online, Microsoft 365 Groups, Teams, or Viva Engage), the hybrid mode is now provided. In the hybrid mode, Cloud Backup for Microsoft 365 jobs will, by default, use an app profile in backup and restore. For the data types that are unsupported in the app context, service account authentication will be used automatically. Note that the use of service accounts is not the recommended method as it attracts an increased potential for throttling issues. To learn more and enable the mode, contact the AvePoint support team.

For the authentication method and permission requirements for Auto Discovery and Backup & Restore, continue with the following instructions.

Exchange Online

To protect Exchange Online mailboxes with AvePoint Cloud Backup, ensure you have at least one of the following apps configured for your tenant for the Auto discovery and data protection:

- Cloud Backup for Microsoft 365 (Exchange Online) service app - Microsoft 365 default app with at least the Exchange Online permissions - Custom app profile with the required permissions.

For details on creating an app profile, refer to . For the app permissions, refer to Required Permissions of Microsoft 365 App Profile.

Note the following for Exchange Online service using AvePoint Cloud Backup:

- You can now choose to protect the **Recoverable** **Items** folder in the user’s primary mailbox for the Exchange Online service. If you want to enable this feature, contact support for assistance. Note that an additional cost is required. Currently, we support the **Deletions**, **Purges**, **Versions**, and **DiscoveryHolders** subfolders in the **Recoverable Items**. For more information about Recoverable Items, refer to this Microsoft article: . On the backup data tree, you can find the data in the following directory: *mailbox address/Recoverable Items folder (**S**ystem)*. This folder cannot be a destination for an out of place restore, and the backup data of this folder being restored to its original mailbox will use the following name: **Recovery Items folder (System) _ Restored**. Note that due to the API limitation, this folder directory will always be displayed in English regardless of the preferred display language of Microsoft 365. - The hidden folders in the mailboxes (including Exchange Online mailboxes, Group mailboxes, and Teams group mailboxes) will be excluded from the backup for better performance. If you want to include the hidden folders in your backup, contact AvePoint support for assistance. - By default, the **Deleted Items** folder and the **Junk Emails** folder will be excluded from the backup for better performance. If you want to include the folders in your backup, contact AvePoint support for assistance - In , you can select the option to scan the **In-Place Archived Mailboxes**. By default, the **Scan in-place archived mailboxes** option is deselected, as there may be performance issues due to API limitations. - If you would like to filter the folders to protect for **Exchange Online** or **OneDrive** service, or filter the folders or lists/libraries within the site collections of **SharePoint Online** service, **Project Online** services, **Microsoft 365 Groups** services, or **Teams** service, you can contact the AvePoint Support team for assistance. Note that if your subscription to Cloud Backup for Microsoft 365 is based on the protected data size, the total consumed data size in your subscription will not be affected by the filter policy. AvePoint will not exclude the size of the filtered items from the total consumed data size. - Use Object ID instead of mailbox address as the unique identifier for Exchange Online mailboxes and Public Folders. This change has been made to both the Cloud Backup for Microsoft 365 service and the Standalone tool. Due to this change, the mailboxes that have been re-created with the same address will no longer be regarded as the same one. This might require a broader search to ensure you find all the backup data for restoring, exporting, or deleting; the mailbox being renamed can only be found by the new name with the former backup data associated, and its former name will be displayed in its row. - The Exchange Online service does not support protecting the **Search Folders**.

After your app profile is ready, navigate to Auto Discovery in the AvePoint Online Services interface to configure a scan profile for the Exchange Online mailboxes that you want to protect in Cloud Backup for Microsoft 365. For details, refer to .

Then, you can navigate to the Cloud Backup for Microsoft 365 interface to enable the backup service of Exchange Online after the Auto Discovery scan job completes.

- Refer to [Set Up the Backup Wizard](#missing-link) for details, if this is your first time signing into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)

SharePoint Online

To protect SharePoint Online site collections with AvePoint Cloud Backup, you must have at least one of the following apps configured for your tenant for Auto discovery and data protection:

- Cloud Backup for Microsoft 365 (SharePoint Online) service app - Microsoft 365 default app with at least the SharePoint Online permissions - Custom Azure app with the required permissions

For details on creating an app profile, refer to . For the app permissions, refer to Required Permissions of Microsoft 365 App Profile.

Note the following for the SharePoint Online service:

- The hidden lists in SharePoint sites (including SharePoint Online sites, Teams team sites, Group team sites, Viva Engage community sites, and Project Online sites) are now excluded from the backup scope for better performance. If you want to include the hidden lists in your backup, contact AvePoint support for assistance. For the hidden lists that you can include in the backup, refer to [Hidden Lists](#missing-link). - If a SharePoint site is connected to a Microsoft 365 Group (a ), AOS will keep it in both the **SharePoint** **Sites** container and the **Microsoft 365** **Groups** container. Cloud Backup for Microsoft 365 will protect this site in the corresponding container separately, as you selected. - It is possible to change the SharePoint domain name for your organization in Microsoft 365 as introduced in the Microsoft article: . This change affects only the SharePoint and OneDrive URLs. It doesn’t impact email addresses. After the domain name is changed and updated into Auto Discovery, Cloud Backup for Microsoft 365 will run a full backup for SharePoint Online sites and OneDrive objects with new URLs. - If you would like to filter the folders to protect for **OneDrive** service or **Exchange Online** service, or filter the folders or lists/libraries within the site collections of **SharePoint Online** service, **Project Online** services, **Microsoft 365 Groups** services, or **Teams** service, you can contact the AvePoint Support team for assistance. Note that if your subscription to Cloud Backup for Microsoft 365 is based on the protected data size, the total consumed data size in your subscription will not be affected by the filter policy. AvePoint will not exclude the size of the filtered items from the total consumed data size. - AvePoint Cloud Backup for SharePoint Online also supports protecting **Communication Sites**. When restoring a deleted Communication Site to its original location, AvePoint Cloud Backup supports restoring the custom design of the Communication Site in the backup. If the Communication Site is registered through App Profile, the Communication Site can only be restored with the default design. Note that the comments in Communication Sites are not currently supported. - As the locked site collections are inaccessible, the backup job will check the lock status and skip backing up the locked site collections, which will be recorded in the job report; For read-only site collections, only the full backup job that runs once every year will back them up. Since no changes can be made to read-only site collections, the incremental backup jobs will skip them. - The files in the SharePoint site and the mailbox items in Exchange Online that are applied with the labels created via **AIP (Azure Information Protection)** can be protected by AvePoint Cloud Backup, as well as the applied [Label](#missing-link). The documents applied with the sensitivity labels of DKE () are also supported, but only the user who has permission can access them. - By default, the **Preservation Hold** library is not protected by AvePoint Cloud Backup for Microsoft 365. An additional cost is required to enable the feature. - As Microsoft API has a 2 GB size limit to download **OneNote notebooks** saved in OneDrive or SharePoint, backup jobs will skip the OneNote files that are larger than 2 GB. In addition, due to API limitations, Cloud Backup cannot protect the history versions of OneNote files.

After your app profile is ready, navigate to Auto Discovery in the AvePoint Online Services interface to configure a scan profile for the SharePoint Online site collections that you want to protect in Cloud Backup for Microsoft 365. For details, refer to .

Then, you can navigate to the Cloud Backup for Microsoft 365 interface to enable the backup service after the Auto Discovery scan job completes.

- Refer to [Set Up the Backup Wizard](#missing-link) for details if this is your first time to sign into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)

OneDrive

To protect OneDrive with AvePoint Cloud Backup, you must have at least one of the following apps configured for your tenant for Auto discovery and data protection:

- Cloud Backup for Microsoft 365 (SharePoint Online) service app - Microsoft 365 default app with at least the SharePoint Online permissions - Custom Azure app with the required permissions

For details on creating an app profile, refer to . For the app permissions, refer to Required Permissions of Microsoft 365 App Profile.

Note the following for the OneDrive service usingAvePoint Cloud Backup:

- Backup for OneDrive now uses Microsoft Graph API for improved performance. Graph API has been more focused on protecting OneDrive content, and it has some limitations, such as it cannot protect the file versions. The file version number cannot be kept either after being restored to the destination. The restored file will use version: **1.0**. You can refer to [OneDrive Data Types](#missing-link) for additional details. If you require any additional assistance, contact AvePoint Support. - AvePoint Cloud Backup service for OneDrive will protect the **Documents** library and protect the **Site Assets** library if the site feature **Site** **NoteBook** is activated. The service only protects content and permissions for OneDrive since OneDrive is the cloud service used to securely store, share, and access your files. - As Microsoft API has a 2 GB size limit to download OneNote notebooks saved in OneDrive or SharePoint, backup jobs will skip the OneNote files that are larger than 2 GB. In addition, due to API limitations, Cloud Backup cannot protect the history versions of OneNote files. - If there are security changes but no changes on the content in the sites, the scheduled incremental backup jobs will not back up the securities. Moving forward, the changes on the securities in the sites (including the SharePoint Online sites, OneDrive, and Microsoft 365 Groups/Teams team sites) that have not yet been backed up, in this case, will be included in an incremental backup once a week. - If some items in a site encounter errors in a backup but there are no changes on the content in the site for the next backup, the scheduled incremental backup jobs will not back up these items with errors. Moving forward, they will be included in an incremental backup once a week. - If you would like to filter the folders to protect for **OneDrive** service or **Exchange Online** service, or filter the folders or lists/libraries within the site collections of **SharePoint Online** service, **Project Online** services, **Microsoft 365 Groups** services, or **Teams** service, you can contact the AvePoint Support team for assistance. Note that if your subscription to Cloud Backup for Microsoft 365 is based on the protected data size, the total consumed data size in your subscription will not be affected by the filter policy. AvePoint will not exclude the size of the filtered items from the total consumed data size. - AvePoint Online Services Auto discovery now supports including orphaned OneDrive in scan profiles of OneDrive but the objects cannot be synchronized to Cloud Backup for Microsoft 365.

After your app profile is ready, navigate to Auto discovery in the AvePoint Online Services interface to configure a scan profile for the OneDrive users that you want to protect in Cloud Backup for Microsoft 365. For details, refer to .

Then, you can navigate to Cloud Backup for Microsoft 365 interface to enable the backup service of OneDrive after the Auto Discovery scan job completes.

- Refer to [Set Up the Backup Wizard](#missing-link) for details, if this is your first time to sign into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)

Microsoft 365 Groups

Microsoft 365 Groups service will protect the group team site, group mailbox, and planner data. For a detailed list of data types supported and unsupported by Cloud Backup for Microsoft 365, refer to Microsoft 365 Groups Data Types.

For Auto discovery and data protection of Microsoft 365 Groups, you must have at least one of the following apps configured for your tenant:

- Cloud Backup for Microsoft 365 (All permissions) service app - Microsoft 365 default app with all permissions - Custom Azure app with the required permissions

For details on creating an app profile, refer to . For the app permissions, refer to Required Permissions of Microsoft 365 App Profile.

If you are using a Multi-geo tenant, ensure the app profile has the Exchange Administrator role. This role is required to restore the region information for Microsoft 365 Groups and Teams. Otherwise, your group or team backed up from a specific region will be restored to the default region. For details on how to assign the role to an app, refer to .

Before you perform the Auto Discovery scan job for Microsoft 365 Groups, consider the following for your own condition:

- If a SharePoint site is connected to a Microsoft 365 Group (a ), AOS will keep it in both the **SharePoint** **Sites** container and the **Microsoft 365** **Groups** container. Cloud Backup for Microsoft 365 will protect this site in the corresponding container separately, as selected. - The hidden folders in the mailboxes (including Exchange Online mailboxes, Group mailboxes, and Teams group mailboxes) will be excluded from the backup for better performance. If you want to include the hidden folders in your backup, contact AvePoint support for assistance.

After your authentication method is ready, navigate to Auto Discovery in the AvePoint Online Services interface to configure a scan profile for the Microsoft 365 Groups that you want to protect in Cloud Backup for Microsoft 365. For details, refer to .

Then, you can navigate to the Cloud Backup for Microsoft 365 interface to enable the backup service after the Auto Discovery scan job completes.

- Refer to [Set Up the Backup Wizard](#missing-link) for details, if this is your first time signing into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)

Teams

Teams service can protect all the Teams channels, Teams settings and permissions, channel conversations and files, primary team site, private or shared channel sites, planner data, etc. For a full list of the supported data types, refer to Teams Data Types. To protect Teams mailboxes, at least one owner/member in the team should have the Exchange Online product license.

The Teams service is now available for customers using Microsoft 365 operated by 21Vianet in China. Note that hosted content is unsupported and will be skipped in the backup.

For Auto discovery and data protection of Microsoft 365 Teams, you must have at least one of the following apps configured for your tenant:

- Cloud Backup for Microsoft 365 (All permissions) service app - Microsoft 365 default app with all permissions - Custom Azure app with the required permissions

For details on creating an app profile, refer to . For the app permissions, refer to Required Permissions of Microsoft 365 App Profile.

If you are using a Multi-geo tenant, ensure the app profile has the Exchange Administrator role. This role is required to restore the region information for Microsoft 365 Groups and Teams. Otherwise, your group or team backed up from a specific region will be restored to the default region. For details on how to assign the role to an app, refer to .

After your authentication method is ready, navigate to Auto Discovery in the AvePoint Online Services interface to configure a scan profile for the Teams that you want to protect in Cloud Backup for Microsoft 365. For details, refer to .

Then, you can navigate to Cloud Backup for Microsoft 365 interface to enable the backup service after the Auto Discovery scan job completes.

- Refer to [Set Up the Backup Wizard](#missing-link) for details, if this is your first time to sign into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)

Teams Chat

The Teams Chat service can protect 1:1 chats and group chats in Teams.

For the default Microsoft Graph API, the backup of chats started by external users is not supported, but chats started by internal users and including external users can be protected. For the Teams Export API model B, only plain text can be protected.

For customers using Microsoft 365 operated by 21Vianet in China, the Teams Chat backup service using the Microsoft Graph API is currently available in Cloud Backup for Microsoft 365. Due to API limitations, the backup of hosted content is not supported.

Follow the steps to enable the Teams Chat backup

  1. Configure a custom app profile in the AvePoint Online Services interface and add required permissions to it. Teams Chat service only supports using Custom app profile authentication. For details on how to create a custom app, refer to . For details on the required permissions for a custom app, refer to Required Permissions of Microsoft 365 App Profile.

  2. Navigate to Auto Discovery in the AvePoint Online Services interface to configure a scan profile for the Microsoft 365 Users that you want to protect in Cloud Backup for Microsoft 365 after your app profile is ready. For details, refer to .

  3. Navigate to the Cloud Backup for Microsoft 365 interface to enable the backup service after the Auto Discovery scan job completes.

Note the following:

- To protect the Teams chats, you must have access to the default Microsoft Graph API or Microsoft Graph Teams Export API. Note that starting May 18, 2023, the online form and the protected API approval process are no longer needed. You can call the protected APIs as long as the requirements for accessing without a user () are met. Since the API requires payment for use, you must follow the steps described in to set up an active Azure subscription for your application for billing purposes. - Microsoft Teams Chat service in Cloud Backup for Microsoft 365 supports using the **default Microsoft Graph API** or **Microsoft Graph** **Teams Export API model B** to retrieve Teams chat messages from Microsoft Teams Chat for backup. Note that the will charge the app creator $ 0.00075 per message and that it may cost a lot if you have a large scale of chat messages to protect. You can follow this to estimate the number of Teams chat messages that may be backed up. - The number of messages in the M365 Admin Center is just for the specific duration you define when exporting the report, not the full total amount. Additionally, the Microsoft Export API only supports export at a user level, so if there is a group chat with multiple users, the same message will be exported multiple times if all these users are included in the scope, which means the number of messages which will be backed up by Cloud Backup has the potential to be higher than the number of messages in the Microsoft admin center report. For confirmation, you can check the job report after the job has finished for the backup chat messages count to compare with the bill from Microsoft. If necessary, you can also limit the user scope for the export. - Here is an example: In the report in the Microsoft 365 admin center shows the last 180 days’ number of Teams chat messages are 1000. Then for the whole year, the number of messages will be approximately 2000. Because there is no deduplication logic for the Microsoft 365 export API, the same message will be exported multiple times if all these users are included in the scope. So let’s say that all are 1V1 chats, then the message number charge by export API will be doubled to approximately 4000 messages. If most of chats are group chats with multiple users, the cost will be even higher. - Only the default Microsoft Graph API can be used to protect Teams Chat in GCC/GCCH environment. - The group chat messages cannot be protected if the user has been removed from the group. - For additional details on the supported data types, refer to [Teams Chat Data Types](#missing-link). Note that it may cost a lot if there are a large number of chat messages in your tenant. - For details about the format and content of exported Teams Chat messages, refer to the FAQ: . - For more information: - Refer to [Set Up the Backup Wizard](#missing-link) for details, if this is your first time to sign into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)

Project Online

Project Online service cannot protect the Project for the web data and cannot fully support the data added through Microsoft 365 subscription Project Online desktop client, for example, custom fields.

If you would like to filter the folders within the site collections of Project Online services, you can contact the AvePoint Support team for assistance. Note that if your subscription to Cloud Backup for Microsoft 365 is based on the protected data size, the total consumed data size in your subscription will not be affected by the filter policy. AvePoint will not exclude the size of the filtered items from the total consumed data size.

You can now use an app profile to scan the Project Online site collections. In this way, the service account does not require the Site Collection Administrator role. However, the Project Online data cannot be protected in the app context (using app profile authentication). Therefore, a service account with enough permissions is still required for the backup and restore for Project Online. For the required permissions of a service account, refer to Service Account Authentication.

Once the app profile and the service account is ready, you can navigate to the Auto discovery page to create a scan profile for Project Online site collections. After the Auto discovery scan job is completed, you can navigate to Cloud Backup for Microsoft 365 interface to enable the backup service.

- Refer to [Set Up the Backup Wizard](#missing-link) for details, if this is your first time to sign into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)

Public Folder

The service for Public Folders only supports restoring content and permissions of Public Folder to the original location and you must use impersonation accounts to protect the Public Folders data.

Cloud Backup for Microsoft 365 now supports the backup of Public Folder metadata via app profile authentication. To protect Public Folder metadata, ensure your backup for Public Folder metadata is enabled and the Exchange Administrator role is assigned to the app in Microsoft Entra ID.

The Public Folders backup will perform operations by using the permissions that are associated with the impersonation accounts. To configure impersonation accounts, refer to Configure Backup Settings. We recommend a 1:500 ratio for the impersonation accounts and the Public Folders. For more information about impersonation technology, see . The impersonation accounts configured must meet the following conditions:

- The impersonation account must have the Exchange Online product license. - This user must also have the **Owner** permission to the Public Folders.

If you have configured impersonation accounts for Public Folder in the AvePoint Online Services interface, the impersonation accounts will be synchronized to Cloud Backup for Microsoft 365 after June 2023 release. You can check and configure the impersonation accounts through Settings > Backup page on the Cloud Backup for Microsoft 365 interface.

For the Auto discovery of Public Folders, ensure you have at least one of the following apps configured for your tenant:

- Cloud Backup for Microsoft 365 (Exchange Online) service app - Microsoft 365 default app with at least the Exchange Online permissions - Custom app profile with the required permissions.

For details on creating an app profile, refer to . For the app permissions, refer to Required Permissions of Microsoft 365 App Profile.

Note the following for the Public Folder service:

- Use Object ID instead of mailbox address as the unique identifier for Exchange Online mailboxes and Public Folders. This change has been made to both the Cloud Backup for Microsoft 365 service and the Standalone tool. Due to this change, the mailboxes that have been re-created with the same address will no longer be regarded as the same one. This might require a broader search to ensure you find all the backup data for restoring, exporting, or deleting; the mailbox being renamed can only be found by the new name with the former backup data associated, and its former name will be displayed in its row. - For subscriptions with Multi-Geo enabled, the public folders can only be protected in the Central AOS Location.

After your app profile is ready, navigate to Auto Discovery in the AvePoint Online Services interface to configure a scan profile for the Public Folders that you want to protect in Cloud Backup for Microsoft 365. For details, refer to .

Then, you can navigate to Cloud Backup for Microsoft 365 interface to enable the backup service after the Auto Discovery scan job completes.

- Refer to [Set Up the Backup Wizard](#missing-link) for details, if this is your first time to sign into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)

Viva Engage

For Auto discovery of Viva Engage communities, you must have at least one of the following app configurations. For details on creating an app profile, refer to .

- Microsoft 365 app (All permissions) or Cloud Backup for Microsoft 365 app (All permissions), and the Viva Engage app. - For the required permissions for the Microsoft 365 app, refer to [Required Permissions of Microsoft 365 App Profile](#missing-link). - For the required permissions for the Viva Engage app, refer to [Required Permissions of Viva Engage App](#missing-link). - When consenting to the Viva Engage app profile, the consent user must be a **Microsoft 365 Global Administrator** with the Viva Engage product license. To re-authorize the Viva Engage app, the authentication user of this Viva Engage app must have the **Verified Admin** role and the **Yammer administrator** role with the Viva Engage product license. Cloud Backup will use the Viva Engage app for the backup and restore. - Custom Azure app with delegated permissions. - To use custom Azure app with delegated permissions, you must grant at least all permissions listed in [Required Permissions of Microsoft 365 App Profile](#missing-link) and [Required Permissions of Viva Engage App](#missing-link) to the app.

*Note: The Microsoft 365 services in the GCC High data center and the data center operated by 21Vianet in China do not support Viva Engage, as such, the Viva Engage backup service is not supported in these data centers.

After your authentication method is ready, navigate to Auto Discovery in the AvePoint Online Services interface to configure a scan profile for the Viva Engage communities that you want to protect in Cloud Backup for Microsoft 365. For details, refer to .

Note the following for the Viva Engage service:

- If you have Microsoft 365-connected Viva Engage communities protected under Microsoft 365 Groups service, once the Viva Engage service is enabled, the connected groups will be removed from Microsoft 365 Groups service and can only be protected in Viva Engage even if you disable the Viva Engage service again. Cloud Backup job will start a new backup cycle for these Viva Engage communities, but their former backup data as Microsoft Groups will not be deleted until the data expires retention period.

Then, you can navigate to the Cloud Backup for Microsoft 365 interface to enable the backup service after the Auto Discovery scan job completes.

- Refer to [Set Up the Backup Wizard](#missing-link) for details, if this is your first time signing into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)

Power BI

Power BI service can only protect the Power BI content in the new workspace experience. (The personal workspace is the classic workspace, which is not supported.)

To use Cloud Backup for Microsoft 365 to protect the Power BI data, you must configure an app profile for the Microsoft Delegated app or a custom Azure app with delegated permissions.

*Note: If you have been using a scan profile with service account authentication for Power Platform object types, the Auto discovery scan jobs and the Cloud Backup jobs can continue using the service account authentication.

- For the list of the required permissions added to the Delegated app for Power BI, refer to [App Profile Authentication](#missing-link). - If you use service account authentication or the Delegated app to protect the Power BI data, the service account or the authentication user of the Delegated app must have a **Power BI** **Pro** license or a **Premium** **Per** **User** license, and have the **Fabric Administrator** role (the **former** **Power BI** admin role).

Before you enable the Power BI service, ensure the feature in the tenant settings has been enabled. This feature was enabled by default.

Note the following for Power BI service.

- If you use the service account authentication to protect Power BI data or use the Delegated app to scan Power BI workspaces in AOS, the Auto Discovery scan job will automatically add the service account or the authentication user of the Delegated app as the workspace admin. - Power BI service can now only protect the Power BI files that can be downloaded. For the limitations on downloading reports from Power BI, refer to . The exported .pbix file includes both the report you're downloading and the dataset (the data on which the report is based), the same as the “” download mode in Power BI. If a Power BI report is created using data from Dataverse, neither the report nor the data in Dataverse will be protected. - Due to the , the backup job of Power BI can back up at most 200 workspaces per hour. - Power BI service can now protect Power BI reports larger than 1 GB in the small semantic model storage format.

After your authentication method is ready, navigate to Auto Discovery in the AvePoint Online Services interface to configure a scan profile for the Power BI workspaces that you want to protect in Cloud Backup for Microsoft 365. For details, refer to .

Then, you can navigate to the Cloud Backup for Microsoft 365 interface to enable the backup service after the Auto Discovery scan job completes.

- Refer to [Set Up the Backup Wizard](#missing-link) for details, if this is your first time signing into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)

Power Automate

Power Automate service can only protect the cloud flows.

For subscriptions with Multi-Geo enabled, flows can only be protected in the Central AOS Location due to API limitations.

To use Cloud Backup for Microsoft 365 to protect the Power Automate flow data, you must configure an app profile for the Microsoft Delegated app or a custom Azure app with delegated permissions.

*Note: If you have been using a scan profile with service account authentication for Power Platform object types, the Auto discovery scan jobs and the Cloud Backup jobs can continue using the service account authentication.

- For the list of the required permissions added to the Delegated app for Power Automate, refer to [Required Permissions of Microsoft Delegated App](#missing-link). - If you use the Delegated app to protect the Power Automate data, the authentication user of the Delegated app must be the **Global Administrator** and the **Environment** **Admin/System** **Administrator**. If you use service account authentication to protect the Power Automate data, the service account must be the **Global Administrator**. > ***Note**: The backup job will automatically add the service account or the authentication user of the Delegated app (the user who consents the app permissions) as the flow owner. Due to the Microsoft native logic, after the authentication user is added as the flow owner, the corresponding flows will be listed under the **My flows** > **Shared with me** tab for the existing flow owners.

After your authentication method is ready, navigate to Auto Discovery in the AvePoint Online Services interface to configure a scan profile for the Power Automate flows that you want to protect in Cloud Backup for Microsoft 365. For details, refer to .

Then, you can navigate to the Cloud Backup for Microsoft 365 interface to enable the backup service after the Auto Discovery scan job completes.

- Refer to [Set Up the Backup Wizard](#missing-link) for details, if this is your first time signing into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)

Power Apps

Power Apps service can only protect standard Canvas apps which have been published and component libraries.

For subscriptions with Multi-Geo enabled, apps can only be protected in the Central AOS Location due to API limitations.

To use Cloud Backup for Microsoft 365 to protect the Power Apps data, you must configure an app profile for the Microsoft Delegated app or a custom Azure app with delegated permissions.

*Note: If you have been using a scan profile with service account authentication for Power Platform object types, the Auto discovery scan jobs and the Cloud Backup jobs can continue using the service account authentication.

- For the list of the required permissions added to the Delegated app for Power Apps, refer to the [Required Permissions of Microsoft Delegated App](#missing-link). - If you use service account authentication or the Delegated app to protect the Power Apps data, the service account or the authentication user of the Delegated app must be the **Global** **Administrator** and the **Environment Admin**/**System** **Administrator**, and have the **Power Apps for Microsoft 365** license to proceed. > ***Note**: The backup job will automatically add the service account or the authentication user of the Delegated app as the apps’ co-owner and flow owner (if the app has an associated flow).

After your authentication method is ready, navigate to Auto Discovery in the AvePoint Online Services interface to configure a scan profile for the standard Canvas apps and component libraries in Power Apps that you want to protect in Cloud Backup for Microsoft 365. For details, refer to .

Then, you can navigate to the Cloud Backup for Microsoft 365 interface to enable the backup service after the Auto Discovery scan job completes.

- Refer to [Set Up the Backup Wizard](#missing-link) for details, if this is your first time signing into Cloud Backup for Microsoft 365. - To enable and manage a backup service, refer to the following instructions: - [Monitor and Manage Your Backup](#missing-link) - [Change the Backup Scope](#missing-link) - [Change the Backup Frequency](#missing-link) - [Configure Settings for AvePoint Cloud Backup](#missing-link) - [Configure Notifications](#missing-link) - [Disable a Backup](#missing-link)