Privileges required to backup using RecoveryManager Plus

ManageEngine RecoveryManager Plus provides administrators the ability to back up and restore their Active Directory, Azure Active Directory, Microsoft 365, Exchange, and Google Workspace environments.

This following table will explain the level of privileges required to backup and restore using RecoveryManager Plus.

ComponentPrivileges RequiredAdditional Remarks
Active Directory
  • A member of the Domain Administrators group.

If you wish to store the password of user accounts when the user account gets deleted, make sure that the account used is a member of the Schema Administrators group.

If you choose to save passwords of user accounts, RecoveryManager Plus will modify the AD schema to instruct AD to retain the Unicode-pwd attribute when a user is deleted. The Schema Administrator privilege is required to modify the schema accordingly.

Azure Active Directory and Microsoft 365A service account with Exchange administrator role.The user whose account is used to configure the product will be provided Site Admin Permission to all SharePoint Online and OneDrive for Business sites by the product during the initial full backup. To remove the user account’s access to particular SharePoint Online and OneDrive for Business sites, follow the steps listed here.
Exchange on-premisesA member of the Organization Management role group 
Google WorkspaceGoogle Workspace domain administrator 

In addition to the above privileges, the following roles and permissions are required by the Azure AD application to backup and restore Azure Active Directory and Microsoft 365 services.

ModuleRole NamePermissionScope
Exchange OnlineOffice 365 Exchange OnlineEWS.AccesAsUser.AllEWS.AccesAsUser.All
full_access_as_appUse Exchange Web Services to backup and restore mailboxes
SharePoint & OneDriveSharePointSites.FullControl.AllBackup and restore sites
User.ReadWrite.AllRead and write the full set of profile properties, reports, and managers of users
Azure ADAzure Active Directory GraphDomain.ReadWrite.AllRead and write all domain properties
Microsoft GraphAppRoleAssignment.ReadWrite.AllManage app permission grants and app role assignments

You're one step away from insuring your AD environment against disasters.

 Download a free trial now! Request demo

Couldn't find the feature you wanted? Raise a feature request

用于Active Directory和Exchange备份的统一解决方案