How to set up and manage an automatic backup of your Microsoft 365 mailbox using a third-party tool
Summary
This guide helps you troubleshoot and resolve: How to set up and manage an automatic backup of your Microsoft 365 mailbox using a third-party tool. Follow the steps below to fix the issue.
Quick Tip: Need immediate assistance? 💻 Open a Ticket
Common Causes
Why third-party backup matters: Microsoft 365 includes basic retention for deleted items and versioning, but it does not provide a true point-in-time backup that protects against accidental deletion, ransomware, or malicious insider activity. A dedicated third-party backup tool gives you independent, restorable copies of your mailbox, contacts, and calendar data.
This guide walks you through choosing a suitable backup tool, connecting it to your Microsoft 365 tenancy, configuring an automatic backup schedule, and verifying that your data is being protected correctly. The steps are written for small business and home office users who may not have a dedicated IT administrator.
Before You Begin
- You need Global Administrator or Application Administrator rights on your Microsoft 365 tenancy to authorise a third-party backup application.
- Have your Microsoft 365 admin credentials ready (usually an account ending in
@yourdomain.com.auwith admin privileges). - Choose a backup tool. Popular options for Australian small businesses include Veeam Backup for Microsoft 365, Datto SaaS Protection, Spanning Backup, Afi.ai, and SkyKick. All offer free trials and similar setup flows.
- Decide where backup data will be stored. Most tools offer cloud storage (hosted by the vendor) or local storage (e.g., a NAS or server in your office). For home office users, cloud storage is usually simpler.
Important: Do not store your only backup copy in the same Microsoft 365 tenancy you are backing up. If your Microsoft account is compromised, both the original data and the backup could be affected. Choose a separate storage location.
Detailed Instructions
Step 1: Create an account with your chosen backup provider
- Visit the backup provider's website and sign up for a trial or paid account.
- Verify your email address and complete any initial onboarding steps.
- Note the data centre region option if available. For Australian customers, select an Australian or Asia-Pacific region to keep data within local jurisdiction and improve backup speed.
Step 2: Connect the backup tool to Microsoft 365
- Log in to your backup provider's dashboard.
- Look for a menu item such as Add Organisation, Connect Microsoft 365, or Add Tenant.
- Click the button to authorise the connection. You will be redirected to a Microsoft login page.
- Sign in with your Global Administrator account.
- Review the permissions the backup tool is requesting. These typically include
Mail.Read,Contacts.Read,Calendars.Read, andUser.Read.All. These are read-only permissions required to copy your data. - Click Accept or Consent to grant access.
- You will be redirected back to the backup provider's dashboard, where your Microsoft 365 organisation should now appear as connected.
Tip: Some backup tools offer a Modern Authentication option that does not require storing your password. Always choose this option if available. Avoid tools that ask you to enter your Microsoft 365 password directly into their interface — this is a red flag for poor security practices.
Step 3: Select which mailboxes to back up
- In the backup dashboard, navigate to Users, Mailboxes, or Protection.
- You will see a list of all licensed users in your Microsoft 365 tenancy.
- Select the mailboxes you want to protect. For most small businesses, select All Users.
- If you have shared mailboxes, archive mailboxes, or public folders, check whether your plan includes these and enable protection for them as well.
- Some tools let you apply protection policies that automatically include new users when they are added to Microsoft 365. Enable this if available — it prevents gaps in coverage.
Step 4: Configure the backup schedule and retention
- Navigate to Backup Schedule or Policy Settings.
- Set the backup frequency. For most small businesses, once per day is sufficient. If you handle high email volume, choose every 4–6 hours.
- Set the retention period. This determines how long deleted or changed items remain recoverable. Common choices:
- 30 days — minimal, suitable for very small mailboxes
- 1 year — recommended for most small businesses
- Unlimited or 7 years — for organisations with legal or compliance requirements
- Choose whether to back up deleted items and previous versions of emails and contacts. Enable these options for maximum protection.
- If the tool offers incremental backups (only copying changes since the last backup), leave this enabled. It reduces storage usage and speeds up each backup run.
- Click Save or Apply Policy.
Step 5: Run the first backup and verify
- Most tools will start the first backup automatically after configuration. If not, look for a Back Up Now or Run Backup button and click it.
- The first full backup can take several hours, depending on mailbox size and internet speed. You can continue using Microsoft 365 normally during this time.
- Once the first backup completes, check the dashboard for a success status on each mailbox.
- Perform a test restore:
- Navigate to the Restore or Recovery section of the backup tool.
- Select a test mailbox and a specific email or contact.
- Choose Restore to Original Location or Export to PST.
- Confirm the item appears correctly in Microsoft 365 or in the exported file.
Tip: Schedule a test restore once a quarter. A backup is only useful if you know how to restore from it. Regular testing also verifies that the backup tool is still connected and functioning correctly.
Step 6: Set up monitoring and alerts
- Navigate to Notifications or Alerts in the backup dashboard.
- Enable email alerts for:
- Backup failures
- Backup successes (optional, but useful for weekly summaries)
- Storage quota warnings
- Licence expiry reminders
- Set the alert recipient to an email address that is monitored regularly — ideally not the same mailbox being backed up, in case that mailbox is compromised.
- If the tool supports daily or weekly summary reports, enable them. These provide a quick health check without logging in to the dashboard.
Troubleshooting
Backup fails with "Authentication expired" or "Token invalid"
- Microsoft 365 authorisation tokens expire periodically. Reconnect the backup tool by going to Settings → Microsoft 365 Connection and clicking Re-authenticate.
- Sign in again with your Global Administrator account and re-consent to the requested permissions.
- If the issue persists, remove the existing connection and set it up again from scratch.
Backup completes but some mailboxes show "Skipped" or "Failed"
- Check that the affected users have a valid Microsoft 365 licence. Unlicensed mailboxes cannot be backed up by most tools.
- Confirm that the users are still present in the tenancy and have not been deleted.
- Review the backup tool's error log for specific error codes and consult the vendor's support documentation.
Backup is taking too long
- The first full backup always takes the longest. Subsequent incremental backups should be much faster.
- Check your internet upload speed. Slow connections will extend backup times.
- If the tool supports throttling settings, ensure they are not set too low.
Still Having Issues?
Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.
💻 Open a Ticket
💻 Open a Ticket