Backup & Recovery - Configuration

This article contains information on configuring Backup & Recovery, including setup prerequisites, integration, policy creation, enabling, validation, and confirming successful backups and recoveries.

How to Configure Backup & Recovery

The steps below are a step-by-step guide to setting up Backup & Recovery. Follow each stage in order. Before you begin, confirm that all prerequisites are in place; see Backup & Recovery - Prerequisites.

Step 1: Confirm the Service Is Provisioned

  1. Confirm that Backup & Recovery is active and available on the account.
  2. Confirm that the Administrator account being used has a role that includes Backup & Recovery permissions. At minimum, the Read permission is required to view the product; Manage and Recover are needed to complete the remaining stages below.

Step 2: Verify Directory Synchronization

 

Ensure that Directory Synchronization is configured and running using an Azure AD/Entra ID connector. On-premises Active Directory connectors are not supported.

 

To verify your Directory Synchronization follow the steps below:

  1. Log in to the Mimecast Administration Console.
  2. Click on the Users & Groups | Directory Synchronization menu item
  3. Confirm that Directory Synchronization shows a healthy, recently-synced status for the target Azure Active Directory tenant.
  4. If Directory Synchronization has not run recently, trigger or wait for a synchronization before continuing. The mailbox list in the next stage will otherwise be empty.

Step 3: Create the Microsoft Exchange Online Integration

To set up the Microsoft Exchange Online Integration, follow the steps below:

  1. Navigate to Integrations Hub.
  2. Scroll down to Microsoft Exchange Online and select Configure New.
  3. Enter the Name and Description and select Authorize.

You will receive the pop-up below; ensure that your browser has pop-ups enabled on your browser and select Authorize again.

  1. You will need to grant the following permissions to complete setup:
  2. Once the setup is complete you will be redirected to this page:

Step 4: Confirm the Mailbox List

  1. Navigate to the Backups view within Backup & Recovery.
  2. Confirm that mailboxes are gradually appearing, sourced from Directory Synchronization.

 

It may take up to 12 hours for mailboxes to appear once the product is activated and Directory Synchronization is running successfully.

 

  1. Every mailbox will initially show as Unprotected. This is expected and simply means no policy has been assigned yet.
  2. Confirm that alias addresses are not appearing as separate entries; only primary addresses should be listed.

Step 5: Create a Backup & Recovery Policy

  1. Log in to the Mimecast Administration Console.
  2. Navigate to Policies | Backup & Recovery Policy |Create Policy.
  3. Enter a unique Name and a short Description of the policy.
  4. Select the Integration data source for this backup policy.
  5. Choose the Target Selection:
Field / Option Description
All Mailboxes This includes all mailboxes within the Exchange environment.
Select Groups This scopes the policy to one or more specific groups. If a mailbox belongs to multiple selected groups, it is automatically de-duplicated and is not backed up twice.

You can select up to 20 groups from your Directory.
  1. You can set the retention period in years and months, ranging from a minimum of 1 month to a maximum of 99 years.

Mailbox Backup & Recovery customers

 Retention for Mailbox Backup & Recovery is configurable up to a maximum of 1 year for Plan customers.

  1. Choose whether to include or exclude sensitive items, content marked Private, Personal, or Confidential in Microsoft Outlook.
  2. Select Save. The policy is created but remains disabled and appears at the top of the policy list.

Step 6: Enable the Policy

  1. Open Manage Policies and locate the newly created policy.
  2. Change Status to Enabled. Enabling is always a deliberate, manual action; no policy is ever enabled automatically.
  3. On enablement, the system immediately begins a one-time initial backup of every in-scope mailbox, prioritizing the most recently created or modified content first.
  4. Initial backup and incremental backup of new incoming messages run concurrently from this point forward. Any policy changes made while initial backup is still running do not interrupt or restart that process.
  5. Mailboxes will move from Unprotected to Initializing during this phase, and to Healthy once the initial backup finishes and incremental backups are running successfully.

Step 7: Set Policy Priority (Multiple Policies Only)

 

This is only relevant if more than one policy exists.

 

 

  1. Open Manage Policies and set the priority order for your active policies.
  2. When a mailbox matches more than one active policy; for example, because it belongs to groups covered by two different policies, the highest-ranked policy in this order is the one that applies.
  3. Any change to policy priority triggers an immediate re-evaluation of every mailbox's policy assignment across the tenant.

Step 8: Validate the Setup

  1. Allow approximately five minutes for dashboard metrics to refresh after activation.
  2. Open the Backup & Recovery overview and confirm that total mailbox counts and the state breakdown are populating.
  3. Check individual mailboxes to confirm they have moved from Unprotected through Initializing toward Healthy.
  4. As a final validation step, perform a test recovery:
  • Open a Healthy mailbox.
  • Browse or search its content.
  • Select a small item or folder and run an export.
  • Confirm the completion notification arrives and the download link works.

 

 A successful test export is confirmation that setup is complete. A Healthy status alone only confirms that backup is running, not that recovery works end-to-end.

 

See Also...

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.