Ready to migrate?
Admin Guide

Cloud Backup User Guide

Complete guide for configuring automated backup and point-in-time restore of your Microsoft 365 and Google Workspace data, including Exchange, Gmail, OneDrive, Google Drive, SharePoint, and Teams.

30 min read Updated: 2026-03-17 Backup & Recovery

Overview

Cloudiway Backup provides comprehensive, automated backup and point-in-time restore for your Microsoft 365 and Google Workspace environments. Protect your organization's critical data — emails, files, sites, and collaboration content — against accidental deletion, ransomware, and data loss.

SaaS Data Protection: Both Microsoft and Google follow a Shared Responsibility Model: they secure the infrastructure, but you are responsible for protecting your data. Cloudiway Backup fills this gap with automated, policy-driven backup and granular recovery.

Key capabilities of Cloudiway Backup:

Automated scheduled backups
Point-in-time restore
AES-256 encryption at rest
Exchange & Gmail backup
OneDrive & Google Drive backup
Flexible restore destinations
Bring your own storage
Email notifications & alerts

Supported Workloads

Microsoft 365

Exchange Online

Back up and restore email, calendar, and contacts for:

  • User Mailboxes — Personal mailboxes assigned to individual users
  • (Coming Soon) Shared Mailboxes — Shared mailboxes accessible by multiple users
  • (Coming Soon) Archive Mailboxes — In-Place Archive mailboxes for compliance and retention

OneDrive for Business

Back up and restore all files, folders, and metadata stored in each user's OneDrive. Full file versioning is preserved across backup snapshots.

SharePoint Online

Back up SharePoint site collections and document libraries, including site structure, documents, and metadata.

Microsoft Teams (Coming Soon)

Back up Teams content including channels, conversations, and shared files.

Copilot Sessions (Coming Soon)

Back up Microsoft Copilot conversation history and session data for compliance and audit purposes.

Google Workspace

Gmail

Back up and restore all emails, labels, and metadata for user mailboxes across your Google Workspace domain.

Google Drive

Back up and restore all files, folders, and sharing permissions stored in each user's Google Drive, including Google Docs, Sheets, and Slides.

Google Sites

Back up Google Sites content and structure for preservation and disaster recovery.

Incremental Backups: After the initial full backup, all subsequent backups are incremental — only changed data is transferred. This minimizes bandwidth usage and reduces backup duration significantly.

Prerequisites

Before configuring Cloudiway Backup, ensure the following requirements are met for your platform.

For Microsoft 365

Microsoft 365 Tenant

An active Microsoft 365 tenant with Exchange Online and/or OneDrive for Business

Global Administrator

A Global Administrator account to grant admin consent for backup permissions

API Permissions

Mail.ReadWrite, Files.ReadWrite.All, Sites.ReadWrite.All, User.Read.All, Group.Read.All, Directory.Read.All

For Google Workspace

Google Workspace Domain

An active Google Workspace domain with Gmail and/or Google Drive

Super Admin Account

A Google Workspace Super Admin account to configure Domain-Wide Delegation

Domain-Wide Delegation

API access via Domain-Wide Delegation with OAuth scopes for Gmail, Drive, Calendar, and Contacts

Cloudiway Account

A Cloudiway account with an active backup license (required for both platforms)

Getting Started

Setting up Cloudiway Backup is a six-step process guided by an onboarding wizard:

1
Add Organization
2
Configure Storage
3
Encryption Setup
4
Discover Sources
5
Configure Backup
6
Schedule Backups

Step 1: Add Organization

The first step is to connect your cloud tenant to Cloudiway Backup. Navigate to Organizations and click Add Organization.

Cloudiway Backup Organizations page showing the list of protected tenants, backup licenses summary, and the Add Organization button

The Organizations page lists all protected tenants, available backup licenses, and provides the Add Organization action. Click the screenshot to view full size.

Select Cloud Platform

Choose your cloud platform and datacenter location:

Select Cloud Platform dialog with Microsoft 365 and Google Workspace options, datacenter location selector, and organization name field

The Select Cloud Platform dialog lets you pick Microsoft 365 or Google Workspace, set the datacenter region, and name the organization. Click the screenshot to view full size.

  • Cloud Platform: Select Microsoft 365 (Exchange, OneDrive) or Google Workspace (Gmail, Drive, Calendar, Contacts)
  • Datacenter Location: Choose East US or North Europe based on your data residency requirements
  • Organization Name: Enter a friendly name to identify this tenant (e.g., "My Company")

The next step depends on the platform you selected. See the relevant section below.

Setup: Microsoft 365

After selecting Microsoft 365 as your platform, you will be redirected to Microsoft to authenticate and grant admin consent.

Cloudiway Backup - Microsoft 365 settings showing tenant credentials, required permissions, and storage location options

Microsoft 365 connection settings with tenant credentials, required API permissions, and storage location configuration.

Admin Consent

Click Sign in with Microsoft and log in with a Global Administrator account. The following permissions will be requested:

  • Mail.ReadWrite — Read and write access to mailbox data
  • Files.ReadWrite.All — Read and write access to OneDrive files
  • Sites.ReadWrite.All — Read and write access to SharePoint sites
  • User.Read.All — Read user profiles for discovery
  • Group.Read.All — Read group information for Teams backup
  • Directory.Read.All — Read directory data for tenant discovery
Secure Authentication: After granting consent, you are redirected back to Cloudiway. The platform uses OAuth 2.0 client credentials flow to access your data securely. No passwords are stored.

Setup: Google Workspace

After selecting Google Workspace as your platform, you need to configure Domain-Wide Delegation and provide your admin email.

Cloudiway Backup - Google Workspace settings showing service account configuration, Domain-Wide Delegation notice, backup account, and domain management

Google Workspace connection settings with backup account, domain management, and Domain-Wide Delegation configuration.

Backup Account

Enter the Google Workspace admin email that will be used for backup operations (e.g., [email protected]). This must be a Super Admin account.

Domain-Wide Delegation Setup

Before Cloudiway can access your Google Workspace data, you must configure Domain-Wide Delegation in your Google Admin Console:

1

Sign in to Google Admin Console

Go to admin.google.com and sign in with a Super Admin account.

2

Navigate to API Controls

Go to Security > Access and data control > API Controls.

3

Manage Domain Wide Delegation

Click on Manage Domain Wide Delegation.

4

Add a New Client ID

Click Add new and enter Cloudiway's Client ID:

114818336788408865729
5

Paste OAuth Scopes

In the OAuth Scopes field, paste the following scopes:

https://www.googleapis.com/auth/admin.directory.user.readonly, https://www.googleapis.com/auth/admin.directory.group.readonly, https://www.googleapis.com/auth/gmail.readonly, https://www.googleapis.com/auth/gmail.imap_admin, https://www.googleapis.com/auth/calendar, https://www.googleapis.com/auth/contacts.readonly, https://www.googleapis.com/auth/drive.readonly, https://www.googleapis.com/auth/drive, https://www.googleapis.com/auth/tasks.readonly
6

Authorize

Click Authorize to save the configuration.

Propagation Time: Domain-Wide Delegation changes can take up to 24 hours to propagate, though they usually apply within a few minutes.

Once configured, click Test Connection & Continue in the Cloudiway wizard to validate the connection.

Step 2: Storage Configuration

Choose where your backup data will be stored. Cloudiway offers three storage options:

Option 1: Cloudiway Datacenter (Recommended)

Fully managed, secure storage hosted by Cloudiway. No additional configuration required.

  • Fully managed infrastructure with automatic scaling
  • Geo-replicated for disaster recovery
  • GDPR and SOC 2 compliant
  • Recommended for most organizations

Option 2: Azure Blob Storage

Bring your own Azure storage account for full data sovereignty. You will need:

  • Storage Account Name — Your Azure storage account name
  • Access Key — Primary or secondary access key from the Azure portal
  • Container Name (optional) — A specific container for backups. If not specified, Cloudiway will create one automatically.

Option 3: Amazon S3

Store backups in your own AWS S3 bucket. You will need:

  • Bucket Name — Your S3 bucket name
  • Region — US East (N. Virginia), US West (Oregon), EU (Ireland), or EU (Frankfurt)
  • Access Key ID — Your AWS IAM access key ID
  • Secret Access Key — Your AWS IAM secret access key
Enterprise Security: All data is encrypted at rest (AES-256) and in transit (TLS 1.3), regardless of the storage option you choose.

For Azure Blob Storage and Amazon S3, click Test Connection & Continue to validate your credentials before proceeding.

Step 3: Encryption Setup

Before any backup can run, Cloudiway generates a unique encryption key pair for the organization, protected by a password you define. This password is required for every restore operation, so it must be set up at the very beginning of the onboarding process.

  • The public key is used to encrypt all backup data written to your storage
  • The private key is used to decrypt data during restore and is itself protected by your encryption password
  • The encryption password is defined by you in this step and is required for all restore operations
Critical: The encryption password cannot be recovered if lost. Store it in a secure location (e.g., a password manager or a secure vault). Without it, your backup data cannot be decrypted and restored.

For full details on key management and security architecture, see Encryption & Security.

Step 4: Discover Sources

Once your organization is created, the next step is to discover the resources available for backup in your tenant.

Navigate to Backup Configuration and click the Discover button. Cloudiway will scan your tenant and detect:

Microsoft 365

  • All user mailboxes (user, shared, and archive)
  • All OneDrive for Business accounts
  • SharePoint site collections
  • Microsoft Teams

Google Workspace

  • All Gmail mailboxes
  • All Google Drive accounts
  • Google Sites
Auto-Discovery: You can configure auto-discovery policies in Settings to automatically detect new users and resources added to your tenant. This ensures that newly onboarded employees are automatically included in your backup scope.

The discovery process runs in the background. You can monitor its progress from the Jobs page. Once complete, all discovered resources will appear in the Backup Configuration page, organized by workload type.

Step 5: Configure Backup

After discovery, configure which resources to include in your backup. Navigate to Backup Configuration to see all discovered items organized in tabs:

Cloudiway Backup - Backup Configuration page showing mailbox list with backup toggles, type, user status, and action buttons

The Backup Configuration page lets you enable or disable backup for individual mailboxes and drives, with Discover and Backup Now actions.

Mailboxes Tab

Lists all mailboxes discovered in your tenant (Exchange or Gmail). For each mailbox, you can see:

  • Backup toggle — Enable or disable backup for each mailbox
  • Mailbox name — Display name and email address
  • Type — User, Shared, or Archive mailbox (Microsoft 365)
  • User Status — Active or Archived
  • Last Backup — Timestamp of the last successful backup
  • Size — Current backup data size

Drives Tab

Lists all drive accounts (OneDrive or Google Drive). For each drive, you can see:

  • Backup toggle — Enable or disable backup
  • User — Display name and email of the drive owner
  • User Status — Active or Archived
  • Files — Total number of items in the drive
  • Last Backup — Timestamp of the last successful backup
  • Size — Current backup data size

Bulk Operations

Use the Enable All or Disable All buttons for quick bulk operations. You can also use the search bar to filter items and enable/disable specific subsets.

Important: Disabling backup for an item only excludes it from future scheduled jobs. Existing backup data is preserved according to your retention policy. Click Save Configuration to apply your changes.

Step 6: Schedule Backups

Configure automated backup schedules to ensure your data is continuously protected. Navigate to Settings > Schedules.

For each workload, you can configure:

  • Enable/Disable schedule — Turn automatic backups on or off
  • Backups per day — Number of backup runs per day
  • First backup time — The time of day for the first backup
  • Timezone — The timezone for scheduling (based on your datacenter location)
Multiple Daily Backups: If you set 3 backups per day with a first backup time of 06:00, Cloudiway will automatically schedule backups at 06:00, 14:00, and 22:00 (evenly distributed across 24 hours).

The dashboard will display the Next Backup time based on your schedule configuration. Scheduled jobs appear in the Jobs > Scheduled tab.

Running Backups

In addition to scheduled backups, you can run backups on demand at any time.

Backup Now

To start an immediate backup:

  1. Navigate to Backup Configuration
  2. Select the workload tab (Mailboxes or Drives)
  3. Click the Backup Now button

This triggers an immediate backup for all enabled items in the selected workload. You can also launch a backup from the Organizations page by clicking the play icon on an organization, or from the Dashboard using the Run Backup quick action.

Note: The Backup Now button is disabled when an automatic backup schedule is currently active for that workload, to prevent conflicts between manual and scheduled jobs.

Full vs. Incremental Backups

The first backup for each item is always a full backup. All subsequent backups are incremental, meaning only changed data since the last backup is transferred. This ensures fast, bandwidth-efficient backup operations.

Monitoring Jobs

The Jobs page provides comprehensive visibility into all backup and restore operations. Jobs are organized into three tabs:

Cloudiway Backup - Jobs page showing running backup jobs with progress bars, status, and duration

The Jobs page displays running backup jobs with real-time progress tracking, status, and duration.

Scheduled Tab

Displays jobs waiting to run based on your configured schedules. Each scheduled job shows the source, workload type, and planned start time.

Running Tab

Shows all currently executing jobs with real-time progress tracking:

  • Progress bar — Visual progress indicator with percentage
  • Duration — Elapsed time since job started

You can Stop a running job if needed by clicking the stop button in the job detail view.

History Tab

Lists all completed, failed, and cancelled jobs. Use the filters to narrow results:

  • Status: Completed, Failed, Cancelled
  • Workload: Mailboxes, Drives
  • Job Type: Backup Mailbox, Restore Mailbox, Backup Drive, Restore Drive
  • Time Range: Today, Last 7 Days, Last 30 Days

Job Detail View

Click on any job to see detailed information:

  • Job summary — Source, status, start/end time, duration
  • Job logs — Timestamped log entries with severity levels (Info, Success, Warning, Error)
  • Error details — Detailed error messages for failed items

For failed jobs, you can click Retry to re-run the job.

Real-Time Updates: Job progress is updated in real-time using push notifications. You don't need to refresh the page to see the latest status.

Restoring Data

Cloudiway Backup provides granular, point-in-time restore capabilities. You can restore individual items or entire workloads to their original location or an alternate destination.

Cloudiway Backup - Restore page showing mailbox selection with workload tabs and item list

The Restore page lets you select individual mailboxes or drives to restore from your backups.

To start a restore operation:

  1. Navigate to the Restore page
  2. Select the workload tab (Mailboxes or Drives)
  3. Select the items you want to restore (individual or multiple via checkboxes)
  4. Click Restore to open the restore configuration dialog

The restore dialog has two panels:

  • Restore Point (left panel) — Choose which backup snapshot to restore from
  • Restore Destination (right panel) — Choose where to restore the data

Selecting a Restore Point

You can restore from:

  • Latest Version — The most recent backup (selected by default)
  • Historical backups — Any previous backup point, listed by date and time, with indication of whether it was a full or incremental backup

Restore: Mailboxes

When restoring mailboxes (Exchange or Gmail), you can choose from the following destinations:

Single Mailbox Restore

  • Original Mailbox — Restore emails to the original mailbox location
  • New Folder — Restore emails to a subfolder in the mailbox (e.g., "Restored Items"). You specify the target folder name.
  • Different Mailbox — Restore emails to another user's mailbox (coming soon)
  • Download as PST — Export mailbox data as a PST file (coming soon)

Multiple Mailbox Restore

When restoring multiple mailboxes at once:

  • Original Mailboxes — Restore each mailbox to its original location
  • New Folder — Restore emails to a subfolder in each mailbox (default: "Restored Items")
  • Download as PST — Export each mailbox as a separate PST file (coming soon)
What is Restored: Mailbox restore includes emails, calendar items, contacts, tasks, notes, and archive data — all the content that was included in the original backup.

Restore: Files

When restoring files (OneDrive or Google Drive), you can choose from the following destinations:

Single User Restore

  • Original Location — Restore files to their original drive location
  • Restore to Subfolder — Restore to a subfolder in the same drive

Multiple User Restore

When restoring multiple drives at once:

  • Original Locations — Restore each drive to its original location
  • Restore to Subfolder — Restore each drive to a subfolder (default: "Restored Files")

Encryption Password

All restore operations require the encryption password used to protect your encryption key. Enter this password in the restore dialog before launching the restore job.

Keep your encryption password safe: Without the encryption password, you will not be able to restore your backup data. Store it securely and ensure it is accessible by authorized administrators.

Settings & Configuration

The Settings page provides centralized management for all backup configuration options. Settings are organized into the following tabs:

Connection

Manage the connection to your cloud tenant. View the platform credentials, domain configuration, and test the connection to ensure it is active.

Credentials

View and manage the account details used for backup operations:

  • Microsoft 365: Tenant ID, migration account, certificate authentication
  • Google Workspace: Admin email (backup account), Domain-Wide Delegation status

Encryption Key

Manage your encryption keys for backup data protection. Cloudiway uses public/private key pairs to encrypt your backup data. You can:

  • Generate a new encryption key pair
  • Set or change the encryption password
  • Download your encryption keys for safekeeping

Policies

Configure backup retention and data management policies:

  • Retention Days — How long backup data is retained
  • Retention Versions — Number of backup versions to keep
  • Grace Period — What happens after retention expires
  • Auto-Discovery — Automatically detect new users, mailboxes, sites, and teams

Schedules

Create, modify, and delete backup schedules for each workload. See Step 6: Schedule Backups for details.

Notifications

Configure email alerts. See Notifications for details.

Storage

View and update your storage account configuration. You can change your storage provider or credentials after initial setup. See Step 2: Storage Configuration for available options.

Save Settings: After making changes on any tab, click the green Save Settings button in the page header to apply your changes.

Notifications

Cloudiway Backup can send email notifications to keep you informed of backup and restore activity. Navigate to Settings > Notifications to configure alerts.

Available notification triggers:

  • Backup Success — Notification when a backup job completes successfully
  • Backup Failure — Notification when a backup job fails
  • Restore Success — Notification when a restore job completes successfully
  • Restore Failure — Notification when a restore job fails
  • Storage Quota Warning — Notification when storage usage approaches the quota limit

You can also enable a Daily Digest email that provides a summary of all backup activity. Configure the delivery time for the daily digest in the notification settings.

Add one or more email addresses to receive notifications. You can enable or disable individual notification types independently.

Encryption & Security

Cloudiway Backup implements multiple layers of security to protect your data:

AES-256 encryption at rest
TLS 1.3 encryption in transit
Customer-managed encryption keys
Password-protected restore
OAuth 2.0 app-only authentication
Multi-tenant isolation

Encryption Key Management

Each organization has its own encryption key pair. When you first set up an organization, Cloudiway generates a public/private key pair protected by a password you define.

  • The public key is used to encrypt backup data
  • The private key is used to decrypt data during restore
  • The encryption password protects the private key and is required for all restore operations
Critical: The encryption password cannot be recovered if lost. Store it in a secure location (e.g., a password manager or a secure vault). Without it, your backup data cannot be decrypted and restored.

License Management

Cloudiway Backup uses a per-tenant licensing model. Licenses are managed from the Organizations page.

Viewing Licenses

The Backup Licenses section at the top of the Organizations page shows your license summary:

  • Purchased Date — When the license was acquired
  • Available Licenses — Licenses not yet assigned
  • Assigned Licenses — Licenses currently assigned to organizations
  • Total Licenses — Total licenses in your account
  • Status — Active or Expired
  • Valid Until — License expiration date

Assigning Licenses

To assign licenses to an organization:

  1. Click the Assign button on a license row
  2. Select the target organization from the dropdown
  3. Enter the quantity of licenses to assign
  4. Click Assign Licenses to confirm

Revoking Licenses

To revoke licenses from an organization:

  1. Click the Revoke button on a license row
  2. Select the organization from the dropdown
  3. Enter the quantity of licenses to revoke
  4. Click Revoke Licenses to confirm

Need more licenses? Click the Buy More button to purchase additional backup licenses.

Dashboard

The Backup Dashboard provides an at-a-glance overview of your backup environment:

Cloudiway Backup - Dashboard showing user count, data size, last backup timestamp, recent jobs, and backup summary

The Dashboard provides an overview with user count, total data size, last backup time, recent jobs, and backup summary per workload.

  • Users Count — Total number of users in the selected organization
  • Data Size — Total backup data size across all workloads
  • Last Backup — Timestamp of the most recent backup job
  • Recent Backup Jobs — The last 5 backup jobs with source, type, status, and duration
  • Backup Summary — Number of completed jobs per workload (Mail and Drive)

The dashboard also provides Quick Actions for common operations:

  • Run Backup — Start an immediate backup
  • Restore Data — Navigate to the restore page
  • View Jobs — Navigate to the jobs page
  • Settings — Navigate to the settings page

Managing Organizations

The Organizations page lets you manage all your backup tenants across both Microsoft 365 and Google Workspace. For each organization, you can:

Cloudiway Backup - Organizations page showing backup licenses, organization list with platform badges, users, data size, and action buttons

The Organizations page displays your backup licenses and all protected organizations with their platform, users, and data size.

  • View details — Name, domain, platform, datacenter, data size, last backup
  • Edit — Update the organization name, domain, or status
  • Launch backup — Start an immediate backup
  • Restore — Navigate to the restore page for this organization
  • Settings — Open the settings page for this organization

Deleting an Organization

When deleting an organization, you have two options:

  • Delete Immediately — All backup data is permanently removed. This action cannot be undone.
  • Deactivate Organization (recommended) — The organization is deactivated and automatically deleted after 30 days. You can reactivate it during this period.
Caution: Immediate deletion permanently removes all backup data. We recommend using the Deactivate option, which gives you a 30-day grace period to reactivate if needed.

Frequently Asked Questions

What cloud platforms does Cloudiway Backup support?

Cloudiway Backup supports both Microsoft 365 (Exchange, OneDrive, SharePoint, Teams, Copilot) and Google Workspace (Gmail, Google Drive, Google Sites). You can back up and restore data from both platforms using a single interface.

How does point-in-time restore work?

Cloudiway maintains a history of all backup snapshots. When restoring, you can select any previous backup point and restore data from that exact moment. This allows you to recover from accidental deletions, ransomware attacks, or data corruption by selecting a clean backup point from before the incident.

Can I bring my own storage for backups?

Yes. In addition to Cloudiway's managed datacenter storage, you can use your own Azure Blob Storage account or Amazon S3 bucket. This gives you full data sovereignty and control over where your backup data is stored. You configure storage during the initial setup wizard and can change it later in Settings.

Is backup data encrypted?

Yes. All backup data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. Each organization has its own encryption key pair, and restore operations require the encryption password. You can manage your encryption keys in Settings > Encryption Key.

How often can I schedule backups?

You can configure multiple backups per day for each workload. Set the first backup time, the number of daily backups, and the timezone. Cloudiway automatically distributes backup times evenly throughout the day. After the initial full backup, all subsequent backups are incremental.

Can I restore to a different user or location?

Yes. For mailboxes, you can restore to the original mailbox or to a subfolder. For files (OneDrive/Google Drive), you can restore to the original location, a subfolder, a different user, or download as a ZIP archive. Additional restore destinations (different mailbox, PST export) are planned for future releases.

What happens if a backup job fails?

Failed jobs are displayed in the Jobs > History tab with an error status. You can click on the job to view detailed error information and job logs. Use the Retry button to re-run a failed job. You can also configure email notifications for backup failures in Settings > Notifications.

Do I need an admin account to run backups?

An admin account is only needed once during initial setup: a Global Administrator for Microsoft 365 (to grant consent) or a Super Admin for Google Workspace (to configure Domain-Wide Delegation). After that, backups run using app-only authentication.

What is the difference between full and incremental backups?

The first backup for each item is a full backup that copies all data. All subsequent backups are incremental, meaning only data that has changed since the last backup is transferred. This makes subsequent backups much faster and uses less bandwidth.

What happens to backup data when a user leaves the organization?

When a user is removed or disabled in your tenant, their status changes to "Archived" in Cloudiway. Existing backup data is preserved according to your retention policy. You can still restore their data as long as it is within the retention period.

Can I back up both Microsoft 365 and Google Workspace in the same account?

Yes. You can add multiple organizations to your Cloudiway account, each with a different platform. For example, you can back up one Microsoft 365 tenant and two Google Workspace domains from a single Cloudiway dashboard.

What happens if I lose my encryption password?

The encryption password cannot be recovered. Without it, backup data cannot be decrypted and restored. We strongly recommend storing the encryption password in a secure password manager or vault accessible to authorized administrators.

Related Guides

Ready to Protect Your Cloud Data?

Set up automated backup and recovery for your Microsoft 365 or Google Workspace environment in minutes.