Transition Exchange Online to Microsoft Graph

Use this procedure to transition eligible Exchange Online workloads from EWS to Microsoft Graph.

Before you begin, use the support information in Move Your Exchange Online Protection from EWS to Microsoft Graph to verify support for your Commvault deployment, release, and workloads.

Assign the Required Permissions and Roles

Assign the required permissions and roles to every Azure app associated with your Exchange Online client.

For the required Microsoft Graph application permissions, see Application Permissions for the Azure App for Exchange Online.

Grant admin consent for your tenant after you add the permissions.

Global Reader Role

Microsoft 365 Group mailbox protection requires the Global Reader role.

Assign the role to each app's service principal. For the exact commands, see Transitioning to the Microsoft Graph API for M365 - Exchange Online.

If You Are Still Using EWS

Keep the full_access_as_app and Exchange.ManageAsApp permissions on your apps until every workload has moved to Graph. Removing them early breaks any protection that still runs over EWS, including public folders.

Enable the Graph Toggle

Microsoft Graph is available in the supported releases, but it is off by default. You must enable the toggle. For instructions, see Transitioning to the Microsoft Graph API for M365 - Exchange Online.

Reauthorize Your Azure Apps

If your apps do not already have the required Microsoft Graph permissions, you must reauthorize all of them. Do this before your next backup.

  1. Reauthorize every app associated with your Exchange Online client.

  2. Sign in with an account that can grant tenant-wide admin consent, and then accept the permission request.

  3. Check the app status on your client configuration page. Reauthorize any app that does not show an authorized status.

Reauthorize every app, not just the first one. Commvault distributes mailboxes across all of your registered apps. Any app you leave unauthorized fails or skips its share of mailboxes.

Run a Backup and Check the Results

Run a backup and review the job's pending reason messages. Commvault records a pending reason for any missing permission, missing role, unauthorized app, or skipped mailbox.

×

Loading...