Introduction
To protect your Exchange Online data, you need to register your Microsoft 365 domain as a source in Cohesity. After registering your Microsoft 365 domain as a source, you can:
- Update the Microsoft 365 source configuration.
- Refresh the source details.
- Unregister the Microsoft 365 domain from the Cohesity Platform.
Register Microsoft 365 as a Source
Before you register Microsoft 365 as a source on Cohesity Platform, ensure that you:
- Review the Considerations and Best Practices, Firewall and Port Requirements, User Roles and Application Permissions, Microsoft 365 User Account, and Custom Application Within Azure Portal requirements.
- Perform the prerequisite tasks detailed in those documents.
To register Microsoft 365 as a source:
- Login to the Cohesity Dashboard and select Data Protection > Sources.
- Click Register on the top-right of the page and then select Microsoft 365.
- In the Register Microsoft 365 Sourcepage, perform the following:
- Follow the prompts to configure the M365 Applications that Cohesity will discover as needed
- The options for Fetch Mailbox Info, Fetch OneDrive Info, Include Users Without MySite, and Enable Site Tagging is recommended to be disabled
- Input the user account that would the owner for the Cohesity Entra App
- Follow the document Cohesity - Remediation-M365 Azure ACS Retirement to configure certificate based
- We encourage that OAuth is enabled if possible
- Optional. To enable exporting and downloading mailboxes or email(s) in PST format, toggle on Use Windows Proxy and specify the hostname (FQDN) or server IP of the Windows Proxy added as a physical server.
- Click Register.
You can add multiple Azure apps for a Microsoft 365 source to load balance the backup and restore operations. Click + to add multiple Azure apps. Also, ensure that you provide the valid App ID and App Secret Key.
The security defaults are enabled by default on recently created Microsoft 365 domains. For more information, see Security defaults in Microsoft documentation. Registering the Microsoft 365 domain as a source fails if security defaults are enabled on the Microsoft 365 domain. Ensure that you toggle on Enable OAuth while registering the Microsoft 365 domain as a source.