How to Connect to Your Microsoft Tenant

How to Connect to Your Microsoft Tenant

Your global administrator account credentials are only used during the initial connection and are not saved by Barracuda Cloud-to-Cloud Backup. The account must be explicitly granted the Global Administrator role; inherited privileges via group membership or Privileged Identity Management (PIM) are not supported. Once the connection is successful, the account can be changed back to a normal administrator role. For more information, see the Microsoft article About admin roles.

Choose your storage location

When setting up a new Cloud-to-Cloud Backup account, you are prompted to select a storage region. This is a one-time selection; once set, all connections on the account use the same region permanently and it cannot be changed. Barracuda Networks recommends selecting the region that best meets your organization's data residency and compliance requirements.

For Cloud-to-Cloud Backup available regions, see Available Locations.

Add a new connection

If necessary, you can create multiple connections for each available data source. To add Microsoft Planner to your existing connections, see How to Add Planner to Your Existing Connection.

  1. Log in to BarracudaONE. Click Apps at the bottom left. Select Cloud-to-Cloud Backup.

  2. Navigate to Backup > Backup sources from the side navigation menu, and then click Add source in the upper-right corner of the page.

    Note: The Add source button is only available to users with admin permissions. If you do not see this button, contact your account administrator.

  3. Select the connection you want to add:

    • Microsoft 365 – Backs up Exchange, OneDrive, SharePoint, Teams, and Planner data.

    • Microsoft Entra ID Basic – Backs up basic Entra ID (Azure AD) directory data.

    • Microsoft Entra ID Premium – Backs up premium Entra ID objects. Requires an active Entra ID Premium subscription.

      connectDataSources.png

    Note: If a subscription is not active for a data source, the option appears locked with a message to contact sales.

  4. Click Continue. You are redirected to Microsoft to sign in with a global administrator account.

  5. Sign in with your global administrator account to grant permissions to the application.

Note: If you have issues connecting, verify the account meets the requirements described at the top of this article.

  1. Review and click Accept to authorize Barracuda Networks to back up data.

    You are returned to the connection wizard.

  2. Optionally, click the pencil icon next to the connection name to give it a custom name. Click Save when done.

  3. Configure your data sources. Toggle on the data sources you want to back up. For Microsoft 365 connections, you can enable Exchange, OneDrive, Planner, SharePoint, and Teams individually. For Entra ID connections, the Entra data source is enabled automatically and cannot be turned off.

Note that the backup for a data source cannot be turned off once you enable it.

ccbConnectWizard.png
  1. Select a retention policy for each enabled data source.
    You can create new policies and assign data sources to policies from the Backup > Backup sources page. To manage retention policies, go to Backup > Retention Policies. See How to Configure Retention Policies.
    Note that assigning data sources to policies can only be done from the Backup sources page.

    ccbWizardRetentionPolicy.png
  2. Click Finish. Cloud-to-Cloud Backup provisions your selected data sources. This process may take some time; do not navigate away from the page while provisioning is in progress. Once complete, you are returned to the Backup sources page where your new connection and its data sources are displayed.

To configure and customize your data sources, see How to Configure Your Data Source. For an overview of the Backup sources page, see Backup Page.

Upgrade to Entra ID Backup Premium

After upgrading to Entra ID Premium, you must reauthorize the connection and accept the new permissions before premium objects are backed up. If you prefer to do this later, click Remind me later. For steps, see Reauthorize a Connection below.

entraUpgrade.png

Downgrade or subscription expiry

When your Entra ID Premium subscription expires and you choose not to renew:

  • If you have an active Entra ID Basic subscription, your account automatically switches to the Basic subscription. You will be prompted to reauthorize your Entra ID connections to avoid interruptions in your backups.

  • If you do not have an active Basic subscription, no automatic switch occurs and your backups will stop when the Premium subscription expires.

Managing your connections

You can view and manage all of your tenant connections from the Backup > Backup sources page. For an overview of the Backup menu, see Backup Page.

Note: The Backup sources page only displays multiple connections for the selected Azure region.

ccbBackupSources.png
Rename a connection
  1. On the Backup sources page, click the action menu (three dots) on the connection you want to rename.

  2. Click Rename connection.

    ccbReauthorize1.png
  3. Enter the new name and click Save.

A confirmation message appears, and the connection list updates to reflect the new name.

Reauthorize a connection

You may need to reauthorize a connection after a permission change, subscription upgrade, or subscription expiry.

You can start the reauthorization process in any of the following ways:

  • Click the Reauthorize button in the banner that appears on the Backup sources page when reauthorization is required.

    reauthorizeEntra1.png

     

  • Click the reauthorization prompt on the Dashboard page or the expiration popup.

    ccbExpired1.png

     

    ccbExpired.png

     

  • Use the action menu on the Backup sources page:

    1. Navigate to Backup > Backup sources.

    2. Click the action menu (three dots) on the connection you want to reauthorize.

    3. Click Reauthorize.

      ccbReauthorize1.png
    4. Follow the Microsoft sign-in prompts to complete the reauthorization. The same global administrator requirements described at the top of this article apply. Note that a connection can only be reauthorized using the same Microsoft tenant it was originally created with.
      A success message appears once the reauthorization is complete.

Remove a connection

To remove a connection, contact Barracuda Networks Technical Support.

 


We value your feedback.
If you have questions, suggestions, or feedback on our documentation, contact the Campus Product Documentation team.
For general product inquiries or technical support, please contact the global Barracuda Support team.