This article contains information on prerequisites for setting up Backup & Recovery, including required Exchange deployment, Directory Sync, admin access, group structure, and setup expectations.
Prerequisites
- Exchange Online deployment confirmed.
- Ensure that Directory Sync is configured and recently synced.
- Microsoft 365 Global Administrator available to grant admin consent.
- Relevant Mimecast role and permissions assigned.
- Target groups identified (if using scoped policies).
Requirements
The following are the requirements for setting up Backup & Recovery:
Exchange Deployment
The customer must have an Exchange Online instance for Backup & Recovery to work.
Exchange On-Premises is not supported; if any part of the customer’s mail environment is on-premises, setup will not complete for those mailboxes.
Directory Sync
Directory Sync must be configured using an Azure AD/Entra ID connector, and must have synced at least once before setup begins. On-Premises Active Directory connectors are not supported for mailbox discovery and subsequent backup operations. Backup & Recovery does not maintain its own independent directory; it sources every mailbox and every group it can target from Directory Sync.
If Directory Sync has never run, or is stale, the mailbox list inside Backup & Recovery will be empty or incomplete, and no policy will find anything to protect.
Administrative Access Required
Microsoft 365
A Microsoft 365 Global Administrator (or an equivalent role with sufficient rights) is required to authenticate the Exchange Online integration and grant admin consent to the Mimecast Backup & Recovery application during setup.
Mimecast
The admin performing setup must have a Mimecast role that grants access to the Backup & Recovery permission set.
- The following permissions are available:
- Read: View policies, the dashboard, the mailbox list, backup status, and export history.
- Manage: Everything in Read, plus create and edit policies, and create or cancel exports.
- Recover: A distinct, separate permission specifically for downloading completed export part files.
At minimum, the admin performing setup needs the Manage permission. The Recover permission is required separately to download export files.
Group Structure (Optional but Recommended)
While a single tenant-wide policy is fully supported, most customers use Active Directory groups or Mimecast local profile groups as an alternative where Active Directory groups are not available, to scope different retention or content rules to different populations.
If group-based targeting is planned, confirm the relevant groups exist and are populated correctly in Directory Sync before starting policy configuration.
Comments
Please sign in to leave a comment.