Cloud Backup User Guide
Complete guide for configuring automated backup and point-in-time restore of your Microsoft 365 and Google Workspace data, including Exchange, Gmail, OneDrive, Google Drive, SharePoint, and Teams.
Overview
Cloudiway Backup provides comprehensive, automated backup and point-in-time restore for your Microsoft 365 and Google Workspace environments. Protect your organization's critical data — emails, files, sites, and collaboration content — against accidental deletion, ransomware, and data loss.
Key capabilities of Cloudiway Backup:
Supported Workloads
Microsoft 365
Exchange Online
Back up and restore email, calendar, and contacts for:
- User Mailboxes — Personal mailboxes assigned to individual users
- (Coming Soon) Shared Mailboxes — Shared mailboxes accessible by multiple users
- (Coming Soon) Archive Mailboxes — In-Place Archive mailboxes for compliance and retention
OneDrive for Business
Back up and restore all files, folders, and metadata stored in each user's OneDrive. Full file versioning is preserved across backup snapshots.
SharePoint Online
Back up SharePoint site collections and document libraries, including site structure, documents, and metadata.
Microsoft Teams (Coming Soon)
Back up Teams content including channels, conversations, and shared files.
Copilot Sessions (Coming Soon)
Back up Microsoft Copilot conversation history and session data for compliance and audit purposes.
Google Workspace
Gmail
Back up and restore all emails, labels, and metadata for user mailboxes across your Google Workspace domain.
Google Drive
Back up and restore all files, folders, and sharing permissions stored in each user's Google Drive, including Google Docs, Sheets, and Slides.
Google Sites
Back up Google Sites content and structure for preservation and disaster recovery.
Prerequisites
Before configuring Cloudiway Backup, ensure the following requirements are met for your platform.
For Microsoft 365
Microsoft 365 Tenant
An active Microsoft 365 tenant with Exchange Online and/or OneDrive for Business
Global Administrator
A Global Administrator account to grant admin consent for backup permissions
API Permissions
Mail.ReadWrite, Files.ReadWrite.All, Sites.ReadWrite.All, User.Read.All, Group.Read.All, Directory.Read.All
For Google Workspace
Google Workspace Domain
An active Google Workspace domain with Gmail and/or Google Drive
Super Admin Account
A Google Workspace Super Admin account to configure Domain-Wide Delegation
Domain-Wide Delegation
API access via Domain-Wide Delegation with OAuth scopes for Gmail, Drive, Calendar, and Contacts
Cloudiway Account
A Cloudiway account with an active backup license (required for both platforms)
Getting Started
Setting up Cloudiway Backup is a six-step process guided by an onboarding wizard:
Step 1: Add Organization
The first step is to connect your cloud tenant to Cloudiway Backup. Navigate to Organizations and click Add Organization.
The Organizations page lists all protected tenants, available backup licenses, and provides the Add Organization action. Click the screenshot to view full size.
Select Cloud Platform
Choose your cloud platform and datacenter location:
The Select Cloud Platform dialog lets you pick Microsoft 365 or Google Workspace, set the datacenter region, and name the organization. Click the screenshot to view full size.
- Cloud Platform: Select Microsoft 365 (Exchange, OneDrive) or Google Workspace (Gmail, Drive, Calendar, Contacts)
- Datacenter Location: Choose East US or North Europe based on your data residency requirements
- Organization Name: Enter a friendly name to identify this tenant (e.g., "My Company")
The next step depends on the platform you selected. See the relevant section below.
Setup: Microsoft 365
After selecting Microsoft 365 as your platform, you will be redirected to Microsoft to authenticate and grant admin consent.
Microsoft 365 connection settings with tenant credentials, required API permissions, and storage location configuration.
Admin Consent
Click Sign in with Microsoft and log in with a Global Administrator account. The following permissions will be requested:
Mail.ReadWrite— Read and write access to mailbox dataFiles.ReadWrite.All— Read and write access to OneDrive filesSites.ReadWrite.All— Read and write access to SharePoint sitesUser.Read.All— Read user profiles for discoveryGroup.Read.All— Read group information for Teams backupDirectory.Read.All— Read directory data for tenant discovery
Setup: Google Workspace
After selecting Google Workspace as your platform, you need to configure Domain-Wide Delegation and provide your admin email.
Google Workspace connection settings with backup account, domain management, and Domain-Wide Delegation configuration.
Backup Account
Enter the Google Workspace admin email that will be used for backup operations (e.g., [email protected]). This must be a Super Admin account.
Domain-Wide Delegation Setup
Before Cloudiway can access your Google Workspace data, you must configure Domain-Wide Delegation in your Google Admin Console:
Sign in to Google Admin Console
Go to admin.google.com and sign in with a Super Admin account.
Navigate to API Controls
Go to Security > Access and data control > API Controls.
Manage Domain Wide Delegation
Click on Manage Domain Wide Delegation.
Add a New Client ID
Click Add new and enter Cloudiway's Client ID:
114818336788408865729Paste OAuth Scopes
In the OAuth Scopes field, paste the following scopes:
https://www.googleapis.com/auth/admin.directory.user.readonly, https://www.googleapis.com/auth/admin.directory.group.readonly, https://www.googleapis.com/auth/gmail.readonly, https://www.googleapis.com/auth/gmail.imap_admin, https://www.googleapis.com/auth/calendar, https://www.googleapis.com/auth/contacts.readonly, https://www.googleapis.com/auth/drive.readonly, https://www.googleapis.com/auth/drive, https://www.googleapis.com/auth/tasks.readonlyAuthorize
Click Authorize to save the configuration.
Once configured, click Test Connection & Continue in the Cloudiway wizard to validate the connection.
Step 2: Storage Configuration
Choose where your backup data will be stored. Cloudiway offers three storage options:
Option 1: Cloudiway Datacenter (Recommended)
Fully managed, secure storage hosted by Cloudiway. No additional configuration required.
- Fully managed infrastructure with automatic scaling
- Geo-replicated for disaster recovery
- GDPR and SOC 2 compliant
- Recommended for most organizations
Option 2: Azure Blob Storage
Bring your own Azure storage account for full data sovereignty. You will need:
- Storage Account Name — Your Azure storage account name
- Access Key — Primary or secondary access key from the Azure portal
- Container Name (optional) — A specific container for backups. If not specified, Cloudiway will create one automatically.
Option 3: Amazon S3
Store backups in your own AWS S3 bucket. You will need:
- Bucket Name — Your S3 bucket name
- Region — US East (N. Virginia), US West (Oregon), EU (Ireland), or EU (Frankfurt)
- Access Key ID — Your AWS IAM access key ID
- Secret Access Key — Your AWS IAM secret access key
For Azure Blob Storage and Amazon S3, click Test Connection & Continue to validate your credentials before proceeding.
Step 3: Encryption Setup
Before any backup can run, Cloudiway generates a unique encryption key pair for the organization, protected by a password you define. This password is required for every restore operation, so it must be set up at the very beginning of the onboarding process.
- The public key is used to encrypt all backup data written to your storage
- The private key is used to decrypt data during restore and is itself protected by your encryption password
- The encryption password is defined by you in this step and is required for all restore operations
For full details on key management and security architecture, see Encryption & Security.
Step 4: Discover Sources
Once your organization is created, the next step is to discover the resources available for backup in your tenant.
Navigate to Backup Configuration and click the Discover button. Cloudiway will scan your tenant and detect:
Microsoft 365
- All user mailboxes (user, shared, and archive)
- All OneDrive for Business accounts
- SharePoint site collections
- Microsoft Teams
Google Workspace
- All Gmail mailboxes
- All Google Drive accounts
- Google Sites
The discovery process runs in the background. You can monitor its progress from the Jobs page. Once complete, all discovered resources will appear in the Backup Configuration page, organized by workload type.
Step 5: Configure Backup
After discovery, configure which resources to include in your backup. Navigate to Backup Configuration to see all discovered items organized in tabs:
The Backup Configuration page lets you enable or disable backup for individual mailboxes and drives, with Discover and Backup Now actions.
Mailboxes Tab
Lists all mailboxes discovered in your tenant (Exchange or Gmail). For each mailbox, you can see:
- Backup toggle — Enable or disable backup for each mailbox
- Mailbox name — Display name and email address
- Type — User, Shared, or Archive mailbox (Microsoft 365)
- User Status — Active or Archived
- Last Backup — Timestamp of the last successful backup
- Size — Current backup data size
Drives Tab
Lists all drive accounts (OneDrive or Google Drive). For each drive, you can see:
- Backup toggle — Enable or disable backup
- User — Display name and email of the drive owner
- User Status — Active or Archived
- Files — Total number of items in the drive
- Last Backup — Timestamp of the last successful backup
- Size — Current backup data size
Bulk Operations
Use the Enable All or Disable All buttons for quick bulk operations. You can also use the search bar to filter items and enable/disable specific subsets.
Step 6: Schedule Backups
Configure automated backup schedules to ensure your data is continuously protected. Navigate to Settings > Schedules.
For each workload, you can configure:
- Enable/Disable schedule — Turn automatic backups on or off
- Backups per day — Number of backup runs per day
- First backup time — The time of day for the first backup
- Timezone — The timezone for scheduling (based on your datacenter location)
The dashboard will display the Next Backup time based on your schedule configuration. Scheduled jobs appear in the Jobs > Scheduled tab.
Running Backups
In addition to scheduled backups, you can run backups on demand at any time.
Backup Now
To start an immediate backup:
- Navigate to Backup Configuration
- Select the workload tab (Mailboxes or Drives)
- Click the Backup Now button
This triggers an immediate backup for all enabled items in the selected workload. You can also launch a backup from the Organizations page by clicking the play icon on an organization, or from the Dashboard using the Run Backup quick action.
Full vs. Incremental Backups
The first backup for each item is always a full backup. All subsequent backups are incremental, meaning only changed data since the last backup is transferred. This ensures fast, bandwidth-efficient backup operations.
Monitoring Jobs
The Jobs page provides comprehensive visibility into all backup and restore operations. Jobs are organized into three tabs:
Scheduled Tab
Displays jobs waiting to run based on your configured schedules. Each scheduled job shows the source, workload type, and planned start time.
Running Tab
Shows all currently executing jobs with real-time progress tracking:
- Progress bar — Visual progress indicator with percentage
- Duration — Elapsed time since job started
You can Stop a running job if needed by clicking the stop button in the job detail view.
History Tab
Lists all completed, failed, and cancelled jobs. Use the filters to narrow results:
- Status: Completed, Failed, Cancelled
- Workload: Mailboxes, Drives
- Job Type: Backup Mailbox, Restore Mailbox, Backup Drive, Restore Drive
- Time Range: Today, Last 7 Days, Last 30 Days
Job Detail View
Click on any job to see detailed information:
- Job summary — Source, status, start/end time, duration
- Job logs — Timestamped log entries with severity levels (Info, Success, Warning, Error)
- Error details — Detailed error messages for failed items
For failed jobs, you can click Retry to re-run the job.
Restoring Data
Cloudiway Backup provides granular, point-in-time restore capabilities. You can restore individual items or entire workloads to their original location or an alternate destination.
To start a restore operation:
- Navigate to the Restore page
- Select the workload tab (Mailboxes or Drives)
- Select the items you want to restore (individual or multiple via checkboxes)
- Click Restore to open the restore configuration dialog
The restore dialog has two panels:
- Restore Point (left panel) — Choose which backup snapshot to restore from
- Restore Destination (right panel) — Choose where to restore the data
Selecting a Restore Point
You can restore from:
- Latest Version — The most recent backup (selected by default)
- Historical backups — Any previous backup point, listed by date and time, with indication of whether it was a full or incremental backup
Restore: Mailboxes
When restoring mailboxes (Exchange or Gmail), you can choose from the following destinations:
Single Mailbox Restore
- Original Mailbox — Restore emails to the original mailbox location
- New Folder — Restore emails to a subfolder in the mailbox (e.g., "Restored Items"). You specify the target folder name.
- Different Mailbox — Restore emails to another user's mailbox (coming soon)
- Download as PST — Export mailbox data as a PST file (coming soon)
Multiple Mailbox Restore
When restoring multiple mailboxes at once:
- Original Mailboxes — Restore each mailbox to its original location
- New Folder — Restore emails to a subfolder in each mailbox (default: "Restored Items")
- Download as PST — Export each mailbox as a separate PST file (coming soon)
Restore: Files
When restoring files (OneDrive or Google Drive), you can choose from the following destinations:
Single User Restore
- Original Location — Restore files to their original drive location
- Restore to Subfolder — Restore to a subfolder in the same drive
Multiple User Restore
When restoring multiple drives at once:
- Original Locations — Restore each drive to its original location
- Restore to Subfolder — Restore each drive to a subfolder (default: "Restored Files")
Encryption Password
All restore operations require the encryption password used to protect your encryption key. Enter this password in the restore dialog before launching the restore job.
Settings & Configuration
The Settings page provides centralized management for all backup configuration options. Settings are organized into the following tabs:
Connection
Manage the connection to your cloud tenant. View the platform credentials, domain configuration, and test the connection to ensure it is active.
Credentials
View and manage the account details used for backup operations:
- Microsoft 365: Tenant ID, migration account, certificate authentication
- Google Workspace: Admin email (backup account), Domain-Wide Delegation status
Encryption Key
Manage your encryption keys for backup data protection. Cloudiway uses public/private key pairs to encrypt your backup data. You can:
- Generate a new encryption key pair
- Set or change the encryption password
- Download your encryption keys for safekeeping
Policies
Configure backup retention and data management policies:
- Retention Days — How long backup data is retained
- Retention Versions — Number of backup versions to keep
- Grace Period — What happens after retention expires
- Auto-Discovery — Automatically detect new users, mailboxes, sites, and teams
Schedules
Create, modify, and delete backup schedules for each workload. See Step 6: Schedule Backups for details.
Notifications
Configure email alerts. See Notifications for details.
Storage
View and update your storage account configuration. You can change your storage provider or credentials after initial setup. See Step 2: Storage Configuration for available options.
Notifications
Cloudiway Backup can send email notifications to keep you informed of backup and restore activity. Navigate to Settings > Notifications to configure alerts.
Available notification triggers:
- Backup Success — Notification when a backup job completes successfully
- Backup Failure — Notification when a backup job fails
- Restore Success — Notification when a restore job completes successfully
- Restore Failure — Notification when a restore job fails
- Storage Quota Warning — Notification when storage usage approaches the quota limit
You can also enable a Daily Digest email that provides a summary of all backup activity. Configure the delivery time for the daily digest in the notification settings.
Add one or more email addresses to receive notifications. You can enable or disable individual notification types independently.
Encryption & Security
Cloudiway Backup implements multiple layers of security to protect your data:
Encryption Key Management
Each organization has its own encryption key pair. When you first set up an organization, Cloudiway generates a public/private key pair protected by a password you define.
- The public key is used to encrypt backup data
- The private key is used to decrypt data during restore
- The encryption password protects the private key and is required for all restore operations
License Management
Cloudiway Backup uses a per-tenant licensing model. Licenses are managed from the Organizations page.
Viewing Licenses
The Backup Licenses section at the top of the Organizations page shows your license summary:
- Purchased Date — When the license was acquired
- Available Licenses — Licenses not yet assigned
- Assigned Licenses — Licenses currently assigned to organizations
- Total Licenses — Total licenses in your account
- Status — Active or Expired
- Valid Until — License expiration date
Assigning Licenses
To assign licenses to an organization:
- Click the Assign button on a license row
- Select the target organization from the dropdown
- Enter the quantity of licenses to assign
- Click Assign Licenses to confirm
Revoking Licenses
To revoke licenses from an organization:
- Click the Revoke button on a license row
- Select the organization from the dropdown
- Enter the quantity of licenses to revoke
- Click Revoke Licenses to confirm
Need more licenses? Click the Buy More button to purchase additional backup licenses.
Dashboard
The Backup Dashboard provides an at-a-glance overview of your backup environment:
The Dashboard provides an overview with user count, total data size, last backup time, recent jobs, and backup summary per workload.
- Users Count — Total number of users in the selected organization
- Data Size — Total backup data size across all workloads
- Last Backup — Timestamp of the most recent backup job
- Recent Backup Jobs — The last 5 backup jobs with source, type, status, and duration
- Backup Summary — Number of completed jobs per workload (Mail and Drive)
The dashboard also provides Quick Actions for common operations:
- Run Backup — Start an immediate backup
- Restore Data — Navigate to the restore page
- View Jobs — Navigate to the jobs page
- Settings — Navigate to the settings page
Managing Organizations
The Organizations page lets you manage all your backup tenants across both Microsoft 365 and Google Workspace. For each organization, you can:
The Organizations page displays your backup licenses and all protected organizations with their platform, users, and data size.
- View details — Name, domain, platform, datacenter, data size, last backup
- Edit — Update the organization name, domain, or status
- Launch backup — Start an immediate backup
- Restore — Navigate to the restore page for this organization
- Settings — Open the settings page for this organization
Deleting an Organization
When deleting an organization, you have two options:
- Delete Immediately — All backup data is permanently removed. This action cannot be undone.
- Deactivate Organization (recommended) — The organization is deactivated and automatically deleted after 30 days. You can reactivate it during this period.
Frequently Asked Questions
What cloud platforms does Cloudiway Backup support?
Cloudiway Backup supports both Microsoft 365 (Exchange, OneDrive, SharePoint, Teams, Copilot) and Google Workspace (Gmail, Google Drive, Google Sites). You can back up and restore data from both platforms using a single interface.
How does point-in-time restore work?
Cloudiway maintains a history of all backup snapshots. When restoring, you can select any previous backup point and restore data from that exact moment. This allows you to recover from accidental deletions, ransomware attacks, or data corruption by selecting a clean backup point from before the incident.
Can I bring my own storage for backups?
Yes. In addition to Cloudiway's managed datacenter storage, you can use your own Azure Blob Storage account or Amazon S3 bucket. This gives you full data sovereignty and control over where your backup data is stored. You configure storage during the initial setup wizard and can change it later in Settings.
Is backup data encrypted?
Yes. All backup data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. Each organization has its own encryption key pair, and restore operations require the encryption password. You can manage your encryption keys in Settings > Encryption Key.
How often can I schedule backups?
You can configure multiple backups per day for each workload. Set the first backup time, the number of daily backups, and the timezone. Cloudiway automatically distributes backup times evenly throughout the day. After the initial full backup, all subsequent backups are incremental.
Can I restore to a different user or location?
Yes. For mailboxes, you can restore to the original mailbox or to a subfolder. For files (OneDrive/Google Drive), you can restore to the original location, a subfolder, a different user, or download as a ZIP archive. Additional restore destinations (different mailbox, PST export) are planned for future releases.
What happens if a backup job fails?
Failed jobs are displayed in the Jobs > History tab with an error status. You can click on the job to view detailed error information and job logs. Use the Retry button to re-run a failed job. You can also configure email notifications for backup failures in Settings > Notifications.
Do I need an admin account to run backups?
An admin account is only needed once during initial setup: a Global Administrator for Microsoft 365 (to grant consent) or a Super Admin for Google Workspace (to configure Domain-Wide Delegation). After that, backups run using app-only authentication.
What is the difference between full and incremental backups?
The first backup for each item is a full backup that copies all data. All subsequent backups are incremental, meaning only data that has changed since the last backup is transferred. This makes subsequent backups much faster and uses less bandwidth.
What happens to backup data when a user leaves the organization?
When a user is removed or disabled in your tenant, their status changes to "Archived" in Cloudiway. Existing backup data is preserved according to your retention policy. You can still restore their data as long as it is within the retention period.
Can I back up both Microsoft 365 and Google Workspace in the same account?
Yes. You can add multiple organizations to your Cloudiway account, each with a different platform. For example, you can back up one Microsoft 365 tenant and two Google Workspace domains from a single Cloudiway dashboard.
What happens if I lose my encryption password?
The encryption password cannot be recovered. Without it, backup data cannot be decrypted and restored. We strongly recommend storing the encryption password in a secure password manager or vault accessible to authorized administrators.
Related Guides
Ready to Protect Your Cloud Data?
Set up automated backup and recovery for your Microsoft 365 or Google Workspace environment in minutes.