TERRA CLOUD Veeam Data Protection/en: Unterschied zwischen den Versionen

Aus TERRA CLOUD WIKI
Die Seite wurde neu angelegt: „== '''Introduction''' ==“
 
Keine Bearbeitungszusammenfassung
 
(104 dazwischenliegende Versionen von 2 Benutzern werden nicht angezeigt)
Zeile 6: Zeile 6:
=== Product presentation TERRA CLOUD Veeam Data Protection ===
=== Product presentation TERRA CLOUD Veeam Data Protection ===


The Software-as-a-Service product TERRA CLOUD Veeam Data Protection offers you the opportunity to build or expand your own cloud backup platform.<br>
TERRA CLOUD Veeam Data Protection is a data backup platform from TERRA CLOUD powered by Veeam.<br>
At the heart of this platform is the multi-tenant portal [https://protection.terracloud.de protection.terracloud.de], which grants you access to various Veeam backup products.<br>
At the heart of this platform is the multi-tenant portal [https://protection.terracloud.de protection.terracloud.de], which grants you access to various backup products from Veeam.<br>
TERRA CLOUD provides you with the necessary resources, such as Veeam Backup for M365 servers or TERRA CLOUD S3 storage.<br>
<br>
At launch, you can operate a complete cloud backup solution for Microsoft 365 data for your end customers.<br>
'''What possibilities does the TERRA CLOUD Veeam Data Protection platform offer?'''<br>
Additional data backup products (Veeam Agents, Backup and Replication) and storage targets will be added later.
# A Software-as-a-Service backup solution for Microsoft 365, fully hosted in the TERRA CLOUD (Hüllhorst location)
# Licensing and centralized management of, for example, Veeam Backup & Replication Servers or Veeam Agents <span style="color:green">'''*NEW*'''</span>
<span id="Einrichtung"></span>
<span id="Einrichtung"></span>
== '''Facility''' ==
== '''Facility''' ==


<span id="Netzwerkkonfiguration"></span>
=== Network Configuration ===
{| class="wikitable" style="margin:left"
|+ style="text-align:left;"| Port Overview TERRA CLOUD Veeam Data Protection
|-
! Protocol !! Port !! Source !! Destination !! Function !! Note
|-
| HTTPS || 443 || Browser || protection.terracloud.de || TERRA CLOUD Veeam Data Protection Management Portal || 185.35.13.60
|-
| HTTPS || 4443 || Browser || Veeam Backup for Microsoft 365 Restore Portal || Restore from Microsoft 365 Backup || 185.35.13.240/28
|-
| TCP || 6180 || Management Agent || Cloud Gateways || Management of Veeam Backup Servers and Agents || 185.35.13.224/28
|}
<span id="Einrichtungsprozess_im_Überblick"></span>
<span id="Einrichtungsprozess_im_Überblick"></span>
=== Setup process overview ===
=== Setup process overview ===


Setting up the data backup consists of four steps, with steps 2-4 being repeated for each end customer.<br>
Setting up data backup consists of four steps in total, with steps 2-4 being repeated for each end customer.<br>
[[File:Einrichtung-overview-2025.png|1500px|without]]
[[Datei:Einrichtung-overview-2025.png|1500px|ohne]]
<span id="Bereitstellung_der_TERRA_CLOUD_Veeam_Data_Protection_Plattform"></span>
<span id="Bereitstellung_der_TERRA_CLOUD_Veeam_Data_Protection_Plattform"></span>
=== Deployment of the TERRA CLOUD Veeam Data Protection Platform ===
=== Deployment of the TERRA CLOUD Veeam Data Protection Platform ===
Zeile 32: Zeile 47:


'''First Login:'''<br>
'''First Login:'''<br>
You will receive a confirmation email after the deployment is complete.<br>
After the setup is complete, you will receive a confirmation email.<br>
You can retrieve your initial login credentials for protection.terracloud.de via the [https://manage.terracloud.de Technical Center].<br>
You can retrieve your initial login credentials for protection.terracloud.de via the [https://manage.terracloud.de Technical Center].<br>
<span style="color:#784D96">'''Note''': The user role "[[Technical_Center#Nutzerrollen|Reseller Admin]]" is required to access the login credentials.</span><br>
<span style="color:#784D96">'''Note''': Access to the login credentials requires the user role "[https://wiki.terracloud.de/index.php/Technical_Center/en#User_roles Reseller Admin]".</span><br>
<br>
<br>
The login is structured as follows: <br>
The login is structured as follows: <br>
Zeile 41: Zeile 56:
''111490\111490-Administrator''
''111490\111490-Administrator''
<br>
<br>
[[File:TC-TCVDP-Tab-new.png|1400px|without]]
[[Datei:TC-TCVDP-Tab-new.png|1200px|border|ohne]]
<br>
<br>
'''Changing the Initial login credentials and multi-factor authentication:
'''Change of the Initial access data and multi-factor authentication:'''<br>
'<br>
After your first login, we recommend the following adjustments to your initial administrator access (Service Provider Global Administrator):
We recommend making the following adjustments to your initial administrator access (Service Provider Global Administrator) after logging in for the first time:
# Change your password
# Changing the password
# Activate and configure multi-factor authentication
# Activating and configuring multi-factor authentication
# Verify the registered email address (using the "Forgot password" function)
# Verifying the stored email address ("Forgotten password" function)
<span id="Bearbeiten_eines_Benutzers"></span>
<br>
===== Editing a User =====
'''Editing a user''':<br>
 
'''Option 1:''' <br>
'''Option 1:'''<br>
Please go to the settings using the "Configuration" gear in the upper right corner. <br>
Please go to Settings via the gear icon "Configuration" in the upper right corner.<br>
In the "Roles & Users" section, select the Service Provider Global Administrator using the checkbox and edit it using the pencil icon. <br>
In the "Roles & Users" section, select the Service Provider Global Administrator using the checkbox and edit it using the pencil icon.<br>
[[File:Change Password.png|framed|without]]
[[Datei:Edit-User-new.jpg|1000px|ohne]]
'''Option 2''': <br>
'''Option 2''':<br>
The currently logged in user can also be edited using the drop-down menu next to the username.
The currently logged-in user can also be edited via the drop-down menu next to the username.
[[File:Edit-profile.png|framed|without]]
[[Datei:Edit-user-V9-2.png|600px|ohne]]
'''Adjusting the Administrator Profile:'''<br>
'''Administrator Profile Adjustment:'''<br>
Please assign a new password for this Service Provider Global Administrator user. <br>
Please assign a new password for this Service Provider Global Administrator user.<br>
Check the email address stored in the "User Info" section; this is required for the "Forgot Password" function. <br>
Check the email address in the "User Info" section; this is required for the "Forgot Password" function.<br>
The address of the Cloud Master Account is stored by default. Change the address stored there if necessary. <br>
The default email address is the Cloud Master Account address. Change the address listed there if necessary.<br>
[[File:Change Password 2.png|framed|without]]
[[Datei:Edit-Profile-1.png|700px|ohne]]
<span style="color:#008000"> We recommend enabling multi-factor authentication for all users in the Protection Portal.</span> <br>
<span style="color:#008000">We recommend enabling multi-factor authentication for all users in the Protection Portal.</span><br>
[[File:Change Password 3.png|framed|without]]
[[Datei:Edit-profile-2.png|700px|ohne]]
Further configuration will be performed the next time you log in. <br>
Further configuration will be completed upon your next login.<br>
In the final step, you will receive a summary of the configured changes.<br>
In the final step, you will receive a summary of the configured changes.<br>
<span id="E-Mail_Benachrichtigungen_konfigurieren"></span>
<span id="E-Mail_Benachrichtigungen_konfigurieren"></span>
==== Configure email notifications ====
==== Configure email notifications ====


Please follow the steps below to configure email notifications: <br>
Please follow these steps to configure email notifications:<br>
<br>
<br>
'''1. Configuring the TERRA CLOUD SMTP server''' <br>
'''1. Configuring the TERRA CLOUD SMTP Server'''<br>
Please open the portal settings using the "Configuration" gear and select the "Notifications" menu item. <br>
Please open the portal settings via the "Configuration" gear icon and select "Server Settings".<br>
Check whether an SMTP server has already been configured by TERRA CLOUD. If so, you can skip this step. <br>
Enter "mail.protection.terracloud.de" for the SMTP server and set the "Encryption protocol" to "None".<br>
If no SMTP server has been configured, please click "Configure." <br>
Since this SMTP server is located within the management infrastructure, encryption up to the SMTP server is not required. <br>
Please enter "mail.protection.terracloud.de" for the server and set the "Encryption protocol" to "None."<br>
Outgoing emails are encrypted if the receiving mail server requests it.<br>
Since this SMTP server is located in the management infrastructure, encryption up to the SMTP server is not required. <br>
[[Datei:SMTP-Settings-new.png|ohne]]
Outgoing emails are encrypted if the receiving mail server requests it. <br>
''' 2. Setting up notifications''' <br>
[[File:Mailserver-new.png|framed|without]]
First, change the "''Default sender''" to "''no-reply@protection.terracloud.de''". <br>
'''2. Setting up notifications''' <br>
Choose whether you want to be notified of every event or only receive summaries. <br>
First, change the "Default sender" to "no-reply@protection.terracloud.de". <br>
In the "Alarms" section, re-enter the sender address and the desired recipient address. <br>
Select whether you want to be notified of every event or only receive summaries.<br>
The "''Discovery Rules''" and "''Billing''" sections are not needed. <br>
Enter the sender address and the desired recipient address again in the "Alarms" section. <br>
[[Datei:SMTP-Settings-new_2.png|700px|ohne]]
The "Discovery Rules" and "Billing" sections are not required. <br>
[[File:Email-server-settings-new.png|framed|without]]
<span id="Konfiguration_des_„Alarms_Management&quot;"></span>
<span id="Konfiguration_des_„Alarms_Management&quot;"></span>
==== Configuration of Alarm Management ====
==== Configuration of Alarm Management ====


The Protection Portal offers its own monitoring function, which can be configured in the "Configuration --> Notifications --> Alarms Management" area. <br>
The Protection Portal offers its own monitoring function, which can be configured in the "Configuration --> Templates --> Predefined Alarms" section.<br>
[[File:Alarms-Management.png|750px|without]]
[[Datei:Predefinded Alarms.png|750px|ohne]]
<span id="Deaktivieren_des_Alarms_„Managed_companies_quota&quot;"></span>
<span id="Deaktivieren_des_Alarms_„Managed_tenants_quota&quot;"></span>
===== Deactivating the "Managed companies quota" alarm =====
===== Disabling the "Managed tenants quota" alarm =====


Please enter "Managed companies quota" in the search bar and disable this alarm. <br>
Please enter "Managed tenants quota" in the search bar and disable this alarm.<br>
TERRA CLOUD uses the Company Quota function to manage the provisioning of end customers via the TERRA CLOUD Technical Center. <br>
TERRA CLOUD uses the Company Quota function to manage the provisioning of end customers via the TERRA CLOUD Technical Center.<br>
For this purpose, the quota is set to the current number of managed end customers and only increased by +1 when a new end customer is provisioned automatically. <br>
For this purpose, the quota is set to the current number of managed end customers and only increased by 1 when a new end customer is automatically provisioned.<br>
This automation causes the "Managed companies quota" alarm to be triggered incorrectly and should be disabled beforehand.<br>
This automation incorrectly triggers the "Managed tenants quota" alarm, which should be disabled beforehand.<br>
[[File:Disable-alarm-managed-companies-quota.png|750px|without]]
[[Datei:Managed-tenants-quota.png|800px]] <br>
'''Email notification when a Managed companies quota alarm is triggered.'''<br>
'''Email notification when a Managed tenants quota alarm is triggered.'''<br>
If the alarm has not yet been deactivated, the following message will be displayed in the Protection Portal and/or sent to you via email. <br>
If the alarm has not yet been disabled, the following message will be displayed in the Protection Portal and/or sent to you by email.<br>
[[File:Managed-companies-quota.png|750px|without]]
[[Datei:Active-alarms.png|800px|ohne]]
<div lang="de" dir="ltr" class="mw-content-ltr">
=== Endkunden erstellen und verknüpfen ===
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
<span id="Endkunden_erstellen_und_verknüpfen"></span>
'''Allgemeines:'''<br>
=== Create and link end customers ===
Im Protection Portal werden Endkundenorganisationen über eine „Company" dargestellt. Ihre „Reseller" Organisation kann beliebig viele Companies und somit Endkunden verwalten.<br>
 
Companies können nur automatisiert über das [https://manage.terracloud.de/login TERRA CLOUD Technical Center] angelegt werden und nicht manuell im Protection Portal.<br>
'''General:'''<br>
Dies ermöglicht die eindeutige Zuordnung der Verbrauchsdaten von TERRA CLOUD Veeam Data Protection zu einem Endkunden aus dem TERRA CLOUD Center/Technical Center. <br>
In the Protection Portal, end-customer organizations are represented by a "Company." Your "Reseller" organization can manage any number of companies and thus end customers.<br>
<br>
Companies can only be created automatically via the [https://manage.terracloud.de/login TERRA CLOUD Technical Center] and not manually in the Protection Portal.<br>
'''TERRA CLOUD Veeam Data Protection für einen Endkunden bereitstellen'''<br>
This enables the clear assignment of TERRA CLOUD Veeam Data Protection usage data to an end customer from the TERRA CLOUD Center/Technical Center. <br>
# Bitte navigieren Sie im [https://manage.terracloud.de TERRA CLOUD Technical Center] in den Bereich der „Kundenverwaltung"
# Wählen Sie den gewünschten Endkunden aus und wechseln Sie auf den Reiter „DIENSTEINSTELLUNGEN"
# Starten Sie die Bereitstellung per „ENDKUNDEN ERSTELLEN UND VERKNÜPFEN" (s. Screenshot unten)
<br>
<br>
'''Deploy TERRA CLOUD Veeam Data Protection for an end customer'''<br>
# Please navigate to the "Customer Management" section in the [https://manage.terracloud.de TERRA CLOUD Technical Center]
# Select the desired end customer and go to the "SERVICE SETTINGS" tab
# Start the deployment by clicking "CREATE AND LINK END CUSTOMER" (see screenshot below)
[[Datei:TC-create-company-open2.png|1250px|ohne]]
[[Datei:TC-create-company-open2.png|1250px|ohne]]
Die automatisierte Bereitstellung führt im Hintergrund die folgenden Schritte aus:<br>
The automated deployment performs the following steps in the background:<br>
# Erstellen einer Company auf Basis der Endkundeninformationen aus dem Technical Center
# Create a company based on the end customer information from the Technical Center
# Zuweisung Ihrer Ressourcen für die Datensicherung (Veeam Backup für M365 Server und Repository)
# Assign your resources for data backup (Veeam Backup for M365 Server and Repository)
# Erstellen eines Benutzerzugangs für die Company
# Create a user account for the company
<br>
<br>
Nach erfolgreichem Abschluss wird Ihnen der erstellte Benutzerzugang und ein grüner Haken angezeigt.<br>
After successful completion, the created user account and a green check mark will be displayed.<br>
Der eingeblendete Benutzerzugang ist eine Vorgabe der Veeam Service Provider Console und wird für die Einrichtung und Verwaltung der Datensicherung nicht benötigt.<br>
The The displayed user access is a default of the Veeam Service Provider Console and is not required for setting up and managing data backups.<br>
Dieser ermöglicht einen Einblick in die Konfiguration der Datensicherung innerhalb der Company.<br>
This provides insight into the data backup configuration within the company.<br>
[[Datei:TC-create-company-ready.png|1250px|ohne]]
[[Datei:TC-create-company-ready.png|1250px|ohne]]
<!--
<!--
Wenn Sie im Portal protection.terracloud.de einen neuen Endkunden anlegen möchten, wählen Sie bitte zunächst den Reiter „Companies“ im linken Menüband aus.<br>
If you would like to create a new end customer in the protection.terracloud.de portal, please first select the "Companies" tab in the left menu bar.<br>
Nach Auswahl des „grünen Plussymbols“ oben links können Sie mit der Konfiguration des Benutzerkontos starten.<br>
After selecting the "green plus symbol" in the top left, you can start configuring the user account.<br>
[[Datei:New_Company_New.png|gerahmt|ohne|1000 px]]
[[Datei:New_Company_New.png|gerahmt|ohne|1000 px]]
Im ersten Schritt unter „Company Info“ können Sie die Kontaktdaten Ihres neuen Kunden hinterlegen.<br>
In the first step, under "Company Info," you can enter the contact details of your new customer.<br>
Hier wird als einziges Feld der „Company name“ vorausgesetzt. Alle weiteren Felder können optional befüllt werden.<br>
The only required field here is "Company name." All other fields can be filled in optionally.<br>
[[Datei:New_Company_Company_Info.png|gerahmt|ohne]]
[[Datei:New_Company_Company_Info.png|gerahmt|ohne]]
Bitte wählen Sie im zweiten Schritt „Company Type“ die Option „Native“ aus.<br>
Please select the "Native" option in the second step "Company Type."<br>
[[Datei:New_Company_Company_Type.png|gerahmt|ohne]]
[[Datei:New_Company_Company_Type.png|gerahmt|ohne]]
In dem Menü „User Info“ definieren Sie einen Portal Benutzer für den jeweiligen Kunden. Vergeben Sie hierfür einen Benutzernamen und ein Passwort.<br>
In the "User Info" menu, define a portal user for the respective customer. Assign a username and password.<br>
Bitte beachten Sie, dass ein Benutzername nur einmal vergeben sein darf.
Please note that a username can only be assigned once.
Weisen Sie dem Account zusätzlich die Site „TERRA CLOUD Hüllhorst“ zu.<br>
Additionally, assign the "TERRA CLOUD Hüllhorst" site to the account.<br>
[[Datei:New_Company_User_Info.png|gerahmt|ohne]]
[[Datei:New_Company_User_Info.png|gerahmt|ohne]]
Im nächsten Schritt „Services“ werden Ihre „Microsoft 365 managed backup“ Ressourcen für Ihren Endkunden hinterlegt.<br>
In the next step, "Services," your "Microsoft 365 managed backup" resources are stored for your end customer.<br>
Die Ressourcen bestehen dabei aus einem Veeam Backup für M365 Server und einem Zielspeicher (Repository).<br>
The resources consist of a Veeam backup for M365 servers and a target storage (repository).<br>
Nach einem Klick auf die Verlinkung „Configure“, gefolgt von einem Klick auf „Add“ lässt sich ein M365 Backup Server (Proxy Server) und ein Repository im Kontextmenü hinzufügen.<br>
After clicking the "Configure" link, followed by "Add," you can add an M365 backup server (proxy server) and a repository in the context menu.<br>
Es besteht die Möglichkeit Ihren Endkunden per Quota zu limitieren, in diesem Beispiel hat der Endkunde keine Limitierungen. <br>
You can limit your end customer using quotas; in this example, the end customer has no limits. <br>
[[Datei:Add Repository-new.png|gerahmt|ohne]]
[[Datei:Add Repository-new.png|gerahmt|ohne]]
Wenn Sie optional die Checkbox des „Job Scheduling“ selektieren, können Sie Ihrem Kunden die Möglichkeit geben, selbstständig Zeitpläne für Backup Jobs anzulegen.<br>
If you optionally select the "Job Scheduling" checkbox, you can give your customer the option to create their own backup job schedules.<br>
Zum Abschluss sollten die „Services" für Ihren Endkunden wie folgt aussehen:<br>
Finally, the "Services" for your end customer should look like this:<br>
[[Datei:Services overview.png|gerahmt|ohne]]
[[Datei:Services overview.png|gerahmt|ohne]]
Unter dem „Billing“-Reiter können Sie eine Preisliste für angebotene Leistungen definieren. Dieser Schritt ist vollständig optional.<br>
Under the "Billing" tab, you can define a price list for offered services. This step is entirely optional.<br>
Die „Bandwidth“-Einstellungen können Sie beim Standard belassen. Sie müssen die Leistung nicht einschränken.<br>
You can leave the "Bandwidth" settings at their default values. You do not need to limit the performance.<br>
[[Datei:New_Company_Billing.png|gerahmt|ohne]]
[[Datei:New_Company_Billing.png|gerahmt|ohne]]
Die Multi-Faktor-Authentifizierung lässt sich optional im nächsten Schritt aktivieren. Bitte beachten Sie den Hinweis bezüglich Drittanbieter-Programme.<br>
Multi-factor authentication can optionally be enabled in the next step. Please note the note regarding third-party programs.<br>
Zum Abschluss können Sie noch eine Willkommens-E-Mail verfassen, die Ihr Kunde nach Abschluss des Onboarding-Prozesses erhält.<br>
Finally, you can compose a welcome email that your customer will receive after completing the onboarding process.<br>
Für den Versand der E-Mails wird unser SMTP-Server einmal täglich automatisch in den Reseller-Einstellungen hinterlegt.<br>
Our SMTP server is automatically added to the reseller settings once a day to send the emails.<br>
[[Datei:New_Company_Notifications.png|gerahmt|ohne]]
[[Datei:New_Company_Notifications.png|gerahmt|ohne]]
-->
-->
</div>
<div lang="de" dir="ltr" class="mw-content-ltr">
=== Einrichtung einer Microsoft 365 Datensicherung ===
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
== '''Microsoft 365 Backup''' ==
==== Microsoft 365 Organisationen verbinden und verknüpfen ====
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
<span id="Einrichtung_einer_Microsoft_365_Datensicherung"></span>
Bitte wechseln Sie für die Konfiguration der Datensicherung in das [https://protection.terracloud.de Protection Portal].<br>
=== Setting up a Microsoft 365 data backup ===
<br>
Die Verknüpfung zwischen einer erstellen Company(Endkunde) und einem Microsoft 365 Mandanten kann im "Veeam Backup for Microsoft 365 Plugin" konfiguriert werden. <br>
Sie finden dieses in der Auflistung der Plugin Library im Bereich "Configuration". <br>
[[Datei:Connect-M365-1.png|frameless|1200px|border|ohne]]<br>
Wechseln Sie in den Menüpunkt „Organizations" und fügen Sie über „New" eine neue hinzu.
[[Datei:Connect-M365-2.png|frameless|1200px|border|ohne]]<br>
Zunächst wählen Sie bitte die zu verknüpfende Company aus und im nächsten Schritt die zu schütztenden Objekttypen („Protected Services"). <br>
Diese Auswahl legt fest welche Berechtigungen die Entra ID Applikation für Datensicherung des Mandanten benötigt. <br>
[[Datei:Connect-M365-3.png|frameless|1200px|border|ohne]]<br>
Anschließend muss die Microsoft 365 Region hinterlegt werden, falls diese vom Standard "Default" abweicht. <br>
[[Datei:Connect-M365-4.png|frameless|1200px|border|ohne]]<br>
Bitte registrieren Sie eine neue Entra ID application in den zu sichernenden Mandanten. <br>
Die Abkürzung TCVDP steht im Beispiel für TERRA CLOUD Veeam Data Protection und erleichtert die Identifizierung innerhalb von Entra ID. <br>
[[Datei:Connect-M365-5.png|frameless|1200px|border|ohne]]<br>
Um die Entra ID application zu erstellen und mit den benötigten Berechtigungen zu versehen, ist eine Anmeldung und Freigabe eines Globalen Administrators erforderlich. <br>
Bitte kopieren Sie den Code und melden Sie sich über den angezeigten Link in M365 an. <br>
[[Datei:Connect-M365-6.png|frameless|1200px|border|ohne]]<br>
Bestätigen Sie die Anmeldung bei der Microsoft Azure CLI, für die Erstellung und Berechtigung der Entra ID application.<br>
[[Datei:Connect-M365-9.png|frameless|1200px|border|ohne]]<br>
Nach der erfolgreichen Anmeldung und Bestätigung sollte der Status der „Verification" auf „Verified" gesprungen sein. <br>
Falls nicht, können Sie über „Refresh code" einen neuen Code generieren lassen und die Anmeldung erneut durchführen. <br>
[[Datei:Connect-M365-10.png|frameless|1200px|border|ohne]]<br>
Zum Abschluss sollte der Status der M365 Organization und der VSPC Company auf „Mapped" stehen. <br>
[[Datei:Connect-M365-11.png|frameless|1200px|border|ohne]]
</div>
<div lang="de" dir="ltr" class="mw-content-ltr">
==== Microsoft 365 Backup Job erstellen ====
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
<span id="Einrichtung_für_die_Microsoft_365_Organisation_des_Wortmann_Partners"></span>
Um einen Backup-Job zu konfigurieren, wählen Sie den Reiter „Backup Jobs“ im linken Menüband aus im Bereich „Management". <br>
==== Setting up data backup for the Wortmann partner's Microsoft 365 organization ====
Sie können über „Create Job“ einen neuen Backup Job anlegen. <br>
Zu Beginn vergeben Sie einen Namen für den Backup-Job und optional eine Beschreibung.<br>
Wir empfehlen Ihnen, wie in unserem Beispiel, einen Namen zu wählen, der auf die gesicherten Inhalte des Jobs schließen lässt.<br>
[[Datei:New Backup Job.png|gerahmt|ohne]]
Bitte wählen Sie den bereits [[TERRA_CLOUD_Veeam_Data_Protection#Microsoft_365_Organisationen_verbinden_und_verknüpfen|verknüpften Microsoft 365 Mandanten]] aus, der gesichert werden soll.<br>
Unter dem Backup Mode wird der Sicherungsumfang Ihres Jobs konfiguriert. Vorausgewählt ist die Sicherung der gesamten Organisation.<br>
[[Datei:Backup scope.png|gerahmt|ohne]]
Sie können den Umfang aber auch individuell verändern und granulare Exklusionen definieren. <br>
Im nächsten Schritt wird der Zeitplan ergänzt. Hier können Sie die Frequenzen, Tage und Wiederholungsversuche definieren. <br>
Optional können Sie die Datensicherung innerhalb eines Sicherungszeitfensters (backup window) erlauben oder verbieten (z. B. während der Geschäftszeiten).<br>
[[Datei:Schedule.png|gerahmt|ohne]]
In der abschließenden Zusammenfassung können Sie über die Option „Start the job when I click finish" die Datensicherung sofort ausführen.<br>
</div>
<div lang="de" dir="ltr" class="mw-content-ltr">
== '''Wiederherstellung von Microsoft 365 Daten''' ==
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
During the initial deployment of the TERRA CLOUD Veeam Data Protection platform, a company is automatically created for the Wortmann partner's company.<br>
=== Voraussetzungen ===
If you want to back up your own Microsoft 365 organization, you can skip the step [https://wiki.terracloud.de/index.php/TERRA_CLOUD_Veeam_Data_Protection/en#Create_and_link_end_customers Create and link end customers], as the company has already been created. <br>
</div>
Please start directly with the step [https://wiki.terracloud.de/index.php/TERRA_CLOUD_Veeam_Data_Protection/en#Setting_up_a_Microsoft_365_data_backup Setting up a Microsoft 365 data backup].
<span id="Microsoft_365_Organisationen_verbinden_und_verknüpfen"></span>
==== Connect and link Microsoft 365 organizations ====


<div lang="de" dir="ltr" class="mw-content-ltr">
'''Prerequisite:''' <br>
# Aktive Entra ID Backup Application, die bereits bei der [[TERRA_CLOUD_Veeam_Data_Protection#Microsoft_365_Organisationen_verbinden_und_verknüpfen|Einrichtung]] erstellt wird
* This guide assumes that you have already [https://wiki.terracloud.de/index.php/TERRA_CLOUD_Veeam_Data_Protection/en#Create_and_link_end_customers linked] your end customer to the Protection Portal via the Technical Center.
# Microsoft 365 Zugangsdaten (betroffener Benutzer oder Globaler Administrator)
'''Step 1:'''<br>
# TERRA CLOUD Veeam Data Protection Restore Portal Application im Mandanten hinzugefügt
To configure data protection, please switch to the [https://protection.terracloud.de Protection Portal].<br>
</div>
The link between a created Company (End Customer) and a Microsoft 365 tenant can be configured within the "Veeam Backup for Microsoft 365 Plugin." <br>
<div lang="de" dir="ltr" class="mw-content-ltr">
You can find this plugin in the Plugin Library list under the "''Configuration''" section. <br>
=== Restore Portal Application im Mandanten hinzugefügen ===
[[Datei:VB365-Plugin.png|1200px|rahmenlos|ohne]]
</div>
'''Step 2:'''<br>
Navigate to the "''Organizations''" menu item and add a new one by clicking "''New''."
[[Datei:New-organization.png|1200px|rahmenlos|ohne]]<br>
First, please select the Company/End Customer to be linked, and in the next step, select the object types to be protected ("Protected Services"). <br>
This selection determines the permissions that will be assigned to the Entra ID application used for data protection within the tenant. <br>
[[Datei:Protected-services.png|1200px|rahmenlos|ohne]]
Please leave the ''Region'' set to the default value of ''Default'' and click ''Next''. <br>
[[Datei:Region-setting.png|1200px|rahmenlos|ohne]]<br>
Please register a new Entra ID application within the tenant that is to be backed up. <br>
In this example, the abbreviation '''TCVDP''' within the new application's name stands for TERRA CLOUD Veeam Data Protection and facilitates its identification within Entra ID. <br>
Please note that the "export mode for [https://learn.microsoft.com/en-us/visualstudio/sharepoint/creating-web-parts-for-sharepoint?view=vs-2019 SharePoint Web Parts]" should only be enabled if this feature is utilized by SharePoint. <br>
[[Datei:Application-settings.png|1200px|rahmenlos|ohne]]
To create the Entra ID application and assign the necessary permissions, authentication and approval by a Global Administrator are required. <br>
Please copy the code and sign in to Microsoft 365 using the displayed link. <br>
[[Datei:New-organization-new.png|1200px|rahmenlos|ohne]] <br>
Confirm the sign-in to the Microsoft Azure CLI to authorize the creation and permissioning of the Entra ID application.<br>
[[Datei:Connect-M365-9.png|frameless|1200px|border|ohne]]<br>
Following a successful sign-in and confirmation, the "Verification" status should change to "Verified." <br>
If it does not, you can generate a new code by clicking "Refresh code" and attempt the sign-in process again. <br>
[[Datei:Verification.png|1200px|rahmenlos|ohne]]<br>
Finally, the status of both the M365 Organization and the VSPC Company should be listed as "Mapped." <br>
[[Datei:Mapped-organization.png|1200px|rahmenlos|ohne]]
<span id="Microsoft_365_Backup_Job_erstellen"></span>
==== Create a Microsoft 365 backup job ====


<div lang="de" dir="ltr" class="mw-content-ltr">
To configure a Microsoft365 backup job, select the "Backup Jobs" tab in the left-hand menu under "Management."<br>
Die TERRA CLOUD nutzt eine Microsoft Entra ID Enterprise Application um eine Wiederherstellung in den gesicherten Mandanten durchführen zu dürfen. <br>
You can create a new backup job using "Create Job."<br>
Um dies zu ermöglichen, muss die Application einmalig pro Mandant hinzugefügt und berechtigt werden. <br>
First, enter a name for the backup job and, optionally, a description.<br>
Bitte nutzen Sie dafür die Anwendung „Connect-VB365RestorePortal" die im Folgenden Abschnitt beschrieben wird.
We recommend choosing a name, as in our example, that reflects the content being backed up.<br>
</div>
[[Datei:New-m365-job.png|1000px|rahmenlos|ohne]] <br>
<div lang="de" dir="ltr" class="mw-content-ltr">
Please select the Microsoft 365 tenant that is already [https://wiki.terracloud.de/index.php/TERRA_CLOUD_Veeam_Data_Protection/en#Connect_and_link_Microsoft_365_organizations linked] to be backed up.<br>
==== Connect-VB365RestorePortal Anwendung ====
Under Backup Mode, you configure the scope of your job's backup. The backup of the entire organization is pre-selected.<br>
</div>
[[Datei:Backup-scope.png|1000px|rahmenlos|ohne]]
However, you can also customize the scope and define granular exclusions. <br>
'''Best Practice for Exclusions:'''<br>
We recommend backing up the entire organization and excluding specific objects (e.g., groups) instead of including only individual objects. <br>
In the next step, the schedule is added. Here you can define the frequencies, days, and retry attempts. <br>
Optionally, you can allow or disallow data backups within a backup window (e.g., during business hours).<br>
[[Datei:Schedule-new.png|1000px|rahmenlos|ohne]]
In the final summary, you can use the "Start the job when I click finish" option to run the data backup immediately.<br>
<span id="Wiederherstellung_von_Microsoft_365_Daten"></span>
=== '''Recovering Microsoft 365 data''' ===


<div lang="de" dir="ltr" class="mw-content-ltr">
<span id="Voraussetzungen"></span>
===== Download =====
==== Requirements ====
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
# Active Entra ID Backup Application, which is already created during [https://wiki.terracloud.de/index.php/TERRA_CLOUD_Veeam_Data_Protection/en#Connect_and_link_Microsoft_365_organizations setup]
Über diesen [https://drive.terracloud.de/dl/fi4zJgp5t58rYGK4cKQngZ/Connect-VB365RestorePortal.exe '''Link'''] können Sie die Anwendung „Connect-VB365RestorePortal" herunterladen. <br>
# Microsoft 365 credentials (affected user or global administrator)
</div>
# TERRA CLOUD Veeam Data Protection Restore Portal Application added to the tenant
<div lang="de" dir="ltr" class="mw-content-ltr">
<span id="Restore_Portal_Application_im_Mandanten_hinzugefügen"></span>
===== Wiederherstellungsberechtigung für einen Mandanten erteilen =====
==== Add Restore Portal Application in the tenant ====
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
TERRA CLOUD uses a Microsoft Entra ID Enterprise Application to perform a restore in the backed-up tenant. <br>
'''Schritt 1:''' Starten Sie die Anwendung „''Connect-VB365RestorePortal.exe''" auf einem administrativen System.<br>
To enable this, the application must be added and authorized once per Microsoft 365 tenant. <br>
Diese prüft in den Prozessschritten 1 und 2 ob die benötigten Azure AD (mittlerweile Entra ID) PowerShell Module installiert sind und installiert diese bei Bedarf automatisch. <br>
You can do this directly via the TERRA CLOUD Technical Center using the "SET RESTORE PERMISSIONS" function. <br>
'''Schritt 2:''' Nach der Überprüfung der PowerShell Module öffnet sich ein Microsoft 365 Anmeldedialog in einem neuen Fenster. <br>
Bitte melden Sie sich mit einem globalen Administrator Kontos des Mandanten an, für den Sie die Wiederherstellung durchführen möchten.<br>
[[Datei:Restore-Portal-Add-Tenant.png|300px|ohne]]
<br>
<br>
[[Datei:Connect-VB365RestorePortal-3.png|500px|ohne]]
'''Instructions:'''<br>
'''Schritt 3:''' Bitte bestätigen Sie die Autorisierung der Entra ID Restore Portal Application der TERRA CLOUD per Azure CLI über den zweiten Microsoft 365 Anmeldediaglog. <br>
'''Step 1:''' Log in to the [https://manage.terracloud.de TERRA CLOUD Technical Center] as a "Reseller Admin." <br>
Nach der erfolgreichen Konfiguration sollten Sie das folgende Ergebnis erhalten: <br>
'''Step 2:''' Navigate to the TERRA CLOUD Veeam Data Protection product in the menu under the "Products" category.<br>
''„The backup application 'TERRA CLOUD Veeam Data Protection - Restore Portal (V8.2)'[...] has been granted admin consent."''
'''Step 3:''' Click the "SET RESTORE PERMISSIONS" button.<br>
[[Datei:Add-Restore-Portalpermission.png|500px|ohne]]
'''Step 4:''' In the newly opened tab, log in with a Global Administrator user of the tenant for which you want to configure the restore.<br>
</div>
[[Datei:M365-Login.png|gerahmt|ohne]]
<div lang="de" dir="ltr" class="mw-content-ltr">
'''Step 5:''' Confirm the requested permissions for the "TERRA CLOUD Veeam Data Protection - Restore Portal" application by clicking "Accept." You will then be redirected to your Restore Portal.<br>
=== Wiederherstellung als Benutzer durchführen ===
[[Datei:Screenshot Restore Portal berechtigen.png|gerahmt|ohne]]
</div>
'''Functional test:''' Please log in to the Restore Portal with a Microsoft 365 user from the tenant or the Global Administrator used above.
<span id="Wiederherstellung_als_Benutzer_durchführen"></span>
==== Restore as user ====
 
'''Step 1:'''<br>
Under the "Protected Data" menu item, you can open a new tab with the "Restore Portal" link to access the Restore Portal.<br>
Please log in with the Microsoft 365 user for whom you want to restore something. <br>
[[Datei:Restore-portal-modern.png|750px|rahmenlos|ohne]]
'''Step 2:'''<br>
Select the desired restore point from the calendar.<br>
[[Datei:Restore-data1-modern.png|750px|rahmenlos|ohne]]
'''Step 3:'''<br>
Now assemble the recovery set from the required files or objects.<br>
You can navigate through the backup and the various object types, as well as use the search function.<br>
You can select individual files directly and restore them using the "Restore" function or add them to the restore set using "Add to Restore List."
[[Datei:Restore-data2-modern.png|850px|rahmenlos|ohne]]
'''Step 4:'''<br>
Please check whether all the desired files are included in the restore list under "Items." <br>
You can then specify the "Restore Mode" to determine whether the files should be overwritten or retained in their original location.<br>
Click the "Finish" button to start the restore. <br>
[[Datei:Restore-data3-modern.png|750px|rahmenlos|ohne]]


<div lang="de" dir="ltr" class="mw-content-ltr">
<span id="Wiederherstellung_als_Administrator_für_andere_oder_mehrere_Benutzer_durchführen"></span>
'''Schritt 1:'''<br>
==== Performing a restore as an administrator for other or multiple users ====
Über den Menüpunkt „Protected Data" können Sie mit dem Link „Restore Portal" einen neuen Tab öffen, um zum Restore Portal zu gelangen.<br>
Bitte melden Sie sich mit dem Microsoft 365 Benutzers an, für den Sie etwas wiederherstellen möchten. <br>
[[Datei:Restore_Portal.png|gerahmt|ohne]]
'''Schritt 2:'''<br>
Wählen Sie den gewünschten Wiederherstellungspunkt aus dem Kalender aus.<br>
[[Datei:Restore-data1.png|gerahmt|ohne]]
'''Schritt 3:'''<br>
Stellen Sie jetzt den Wiederherstellungssatz aus den benötigten Dateien zusammen.<br>
Sie können sowohl durch das Backup und die verschiedenen Objekttypen navigieren, als auch die Suchfunktion nutzen.<br>
Einzelne Dateien können Sie direkt auswählen und über die Funktion "Restore" wiederherstellen oder über "Add to Restore List" in den Wiederherstellungssatz aufnehmen.
[[Datei:Restore-data2.png|gerahmt|ohne]]
'''Schritt 4:'''<br>
Bitte prüfen Sie ob in der Wiederherstellungsliste unter "Items" alle gewünschten Dateien enthalten sind. <br>
Danach können Sie den „Restore Mode" festlegen, ob die Dateien am ursprünglichen Speicherort überschrieben werden oder beibehalten werden sollen .<br>
Über den „Finish" Button wird die Wiederherstellung gestartet. <br>
[[Datei:Restore-Data3.png|gerahmt|ohne]]
</div>
<div lang="de" dir="ltr" class="mw-content-ltr">
=== Wiederherstellung als Administrator für andere oder mehrere Benutzer durchführen ===
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
'''Prerequisite:'''<br>
'''Voraussetzung:'''<br>
You can authorize one or more users as "Restore Operators" through TERRA CLOUD Support. <br>
Sie können über den TERRA CLOUD Support einen oder mehrere Benutzer als „Restore Operator" berechtigen lassen. <br>
Please provide us with the desired tenant, e.g., ''contoso.onmicrosoft.com'', and the desired user, e.g., ''admin@contoso.onmicrosoft.com''. <br>
Bitte lassen Sie uns dazu den gewünschten Mandanten z. B: ''contoso.onmicrosoft.com'' und den gewünschten Benutzer z. B. ''admin@contoso.onmicrosoft.com'' zukommen. <br>
As a "Restore Operator," you can use the "Scope" to change your identity and perform the restore for other or multiple users. <br>
Als „Restore Operator" können Sie über den „Scope" einen Identitätswechsel vornehmen und die Wiederherstellung für andere oder mehrere Benutzer durchführen. <br>
The procedure is identical to restoring as a [https://wiki.terracloud.de/index.php/TERRA_CLOUD_Veeam_Data_Protection/en#Restore_as_user user].
Die Vorgehensweise ist dabei identisch zu Wiederherstellung als [[TERRA_CLOUD_Veeam_Data_Protection#Wiederherstellung_als_Benutzer_durchführen|Benutzer]].  
[[Datei:Restore Operator.png|frameless|1200px|border|ohne]]
[[Datei:Restore-with-RestoreOperator.png|frameless|1200px|border|ohne]]
----
----
</div>
<div lang="de" dir="ltr" class="mw-content-ltr">
== '''Verbauchsdaten''' ==
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
<span id="Verbauchsdaten"></span>
=== Verbrauchswerte über das TERRA CLOUD Technical Center ermitteln ===
== '''Consumption data''' ==
</div>
 
<span id="Verbrauchswerte_über_das_TERRA_CLOUD_Technical_Center_ermitteln"></span>
=== Determine consumption values ​​via the TERRA CLOUD Technical Center ===


<div lang="de" dir="ltr" class="mw-content-ltr">
The [https://manage.terracloud.de TERRA CLOUD Technical Center] provides you with an overview per end customer and a summary of usage data for the selected month.<br>
Das [https://manage.terracloud.de TERRA CLOUD Technical Center] bietet Ihnen eine Übersicht je Endkunde und ein Zusammenfassung der Verbrauchsdaten für den ausgewählten Monat. <br>
Within the table view, you can filter the values ​​as usual using the respective function and export them as a CSV file.<br>
Innerhalb der Tabellenansicht können Sie die Werte wie gewohnt über die jeweilige Funktion filtern und als CSV exportieren.<br>
The default selection "Current" shows you the license usage for the current month. However, only the usage reports for completed months are relevant for billing.<br>
Die Verbrauchsübersicht zeigt Ihnen die folgenden Werte an:
<span id="Verbrauchswerte_Microsoft_365_Backup"></span>
;Datum
=== Microsoft 365 Backup Usage Values ​​===
:*Gibt den abgeschlossenen und abrechnungsrelvanten Monat an der im Drop-Down Menü „Report Monat" ausgewählt wurde.
 
:*Sofern nichts ausgewählt wurde wird Ihnen der letzte abgeschlossene Monat angezeigt.
This tab displays the usage data for the TERRA CLOUD Veeam Data Protection Microsoft 365 Backup:<br>
;Endkunde
Date
:*Gibt den Endkunden an der mit dem gesicherten Microsoft 365 Mandanten verknüpft wurde.
*Indicates the completed and billable month selected in the "Report Month" drop-down menu.
;Anzahl gesicherte M365-Benutzer
*If nothing is selected, the current month is displayed.
:*Summe aus den neuen und berechneten M365-Benutzern.
End Customer
;Anzahl neue gesicherte M365-Benutzer
*Indicates the end customer associated with the backed-up Microsoft 365 tenant.
:* Benutzer die im ausgewählten Monat neu in die Sicherung aufgenommen wurden, werden nicht berechnet.
Number of Backed-Up M365 Users
:* Dies gilt sowohl für die Ersteinrichtung des Mandanten als auch für neu hinzugefügte Benutzer bei Bestandskunden.
*Total of new and billed M365 users.
;Anzahl berechnete M365-Benutzer
Number of New Backed-Up M365 Users
:* Benutzer die im ausgewählten Monat in Rechnung gestellt werden.
*Users newly added to the backup in the selected month are not billed.
Unter der Tabelle mit den Verbrauchswerten je Endkunde erhalten Sie noch Ihre summierten Verbrauchswerte als Partner. <br>
*This applies to both the initial tenant setup and newly added users for existing customers.
Number of Billed M365 Users
*Users billed in the selected month.
Below the table showing consumption figures per end customer, you will also find your total consumption figures as a partner.<br>
[[Datei:Verbrauchswerte-3.png|frameless|1200px|border|ohne]]<br>
[[Datei:Verbrauchswerte-3.png|frameless|1200px|border|ohne]]<br>
</div>
<span id="Wann_verbraucht_ein_Microsoft_365_Benutzer_eine_Lizenz_für_das_Backup?"></span>
<div lang="de" dir="ltr" class="mw-content-ltr">
=== When does a Microsoft 365 user consume a backup license? ===
=== Wann verbraucht ein Microsoft 365 Benutzer eine Lizenz für das Backup? ===
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
A Microsoft 365 user consumes one license for TERRA CLOUD Veeam Data Protection Microsoft 365 Backup in the billing month if the following criteria are met:
Ein Microsoft 365 Benutzer verbraucht im Abrechnungsmonat eine Lizenz für das TERRA CLOUD Veeam Data Protection Microsoft 365 Backup wenn die folgenden Kriterien erfüllt sind:  
<br>
<br>
#Die Onlinedienste Exchange Online und/oder SharePoint Online/OneDrive for Business werden verwendet und durch das Produkt gesichert <br>
#The online services Exchange Online and/or SharePoint Online/OneDrive for Business are used and backed up by the product. <br>
#Der Benutzer war Bestandteil mindestens einer Datensicherung innerhalb der letzten 31 Tage
#The user has been part of at least one backup within the last 31 days.
'''Important note:'''<br>
Restoration from previously created backups is also possible without an active license.<br>
<br>
<br>
'''Wichtiger Hinweis:'''<br>
When both criteria are met for the first time, the user is registered as "new." <br>
Die Wiederherstellung aus bereits erstellten Datensicherungen ist auch ohne aktive Lizenz möglich.<br>
If a user has not been backed up in the last 31 days, no more licenses are consumed. <br>
<span id="Was_verbraucht_keine_Lizenz_für_das_Microsoft_365_Backup?"></span>
=== What doesn't consume a license for Microsoft 365 Backup? ===
 
The following objects can be included in the backup, but they do not consume a license.
#Microsoft Teams objects
#Groups and non-personal SharePoint sites
#Shared mailboxes (unless a Microsoft 365 license has been assigned)
#Resource mailboxes (unless a Microsoft 365 license has been assigned)
#Public folders (unless a Microsoft 365 license has been assigned)
#External SharePoint users
#Microsoft Teams guest users
<span id="Lizenzierung:_Das_VCSP_Pulse_Plug-in"></span>
== '''Licensing: The VCSP Pulse Plug-in''' ==
 
The Protection Portal offers you the option to rent Veeam software licenses through Wortmann AG (Service Provider) via the "VCSP Pulse Plugin".<br>
The abbreviation "VCSP" stands for the  '''V'''eeam '''C'''loud & '''S'''ervice '''P'''rovider Program.
VCSP Pulse is a web-based license reporting platform for Service Providers operated by Veeam.<br>
To create a license, your end customer/company must be set up in VCSP Pulse and linked to the company in the Protection Portal.<br>
<span id="Aufbau_des_VCSP-Lizenzmodells"></span>
=== Structure of the VCSP Licensing Model ===
 
The Veeam VCSP licensing model is based on VCSP license points, which are billed uniformly according to the license size and feature set.<br>
A point value determined by Veeam is charged based on the workload and feature set.<br>
The workloads to be backed up are the determining factor for the license size. In this context, a '''''workload''''' refers, for example, to backing up a VM, a physical server, or a Microsoft 365 user, etc.<br>
In addition to the license size, the feature set and edition of the software product are also crucial.<br>
The core product, "Veeam Backup & Replication," is... B. Available individually in Standard, Enterprise, and Enterprise Plus versions, or bundled with the Veeam Data Platform.<br>
Some products are only available in one version, in which case only the license size or the number of workloads is relevant.<br>
<br>
<br>
Wenn beide Kriterien zum ersten Mal erfüllt sind, wird der Benutzer als „neu“ hinterlegt. <br>
When planning your license requirements, you can use these two questions as a guide:
Sofern ein Benutzer in den letzten 31 Tagen nicht gesichert wurde, wird keine Lizenz mehr verbraucht. <br>
# What feature set, and therefore which edition of Veeam Backup & Replication or the Veeam Data Platform, is required?
</div>
# Which workloads, and how many of them, need to be backed up? (VMs, network shares, S3 buckets, etc.)
<div lang="de" dir="ltr" class="mw-content-ltr">
<span id="Übersicht_der_Punktewerte_für_Veeam_Backup_&amp;_Replication"></span>
=== Was verbraucht keine Lizenz für das Microsoft 365 Backup? ===
==== Overview of score values ​​for Veeam Backup & Replication ====
</div>
 
{| class="wikitable sortable"
|-
! Workload!! Default!! Enterprise!! Enterprise Plus
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/virtual_machines.html Virtual Machine] || 5 || 9 || 11
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/veeam_agent_computers.html Server] || 11 || 11 || 11
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/veeam_agent_computers.html Workstation] || 4 || 4 || 4
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/public_cloud_workloads.html Public Cloud VM] || 11 || 11 || 11
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/public_cloud_workloads.html Public Cloud Database] || 11 || 11 || 11
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/public_cloud_workloads.html Public Cloud File Share] || 11 || 11 || 11
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/nas_file_shares.html Object Storage (500GB)] || 10 || 10 || 10
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/nas_file_shares.html File Shares (500 GB)] || 10 || 10 || 10
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/plugins_enterprise_apps.html Application] || 11 || 11 || 11


<div lang="de" dir="ltr" class="mw-content-ltr">
|-
Die folgenden Objekte können Teil der Sicherung sein, verbrauchen jedoch keine Lizenz.
| [https://helpcenter.veeam.com/docs/vcsp/refguide/vdp_entra_id.html Microsoft Entra ID (10 User Package)] || 10 || 10 || 10
#Microsoft Teams Objekte
|}
#Gruppen und nicht persönliche SharePoint Sites
<span id="Übersicht_der_Punktewerte_für_die_Veeam_Data_Platform"></span>
#Freigegebene Postfächer
==== Overview of score values ​​for the Veeam Data Platform ====
#Ressourcen Postfächer
#Öffentliche Ordner
#Externe SharePoint Benutzer
#Microsoft Teams Gastbenutzer
</div>
<div lang="de" dir="ltr" class="mw-content-ltr">
== '''FAQ''' ==
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
{| class="wikitable sortable"
=== Microsoft Teams ===
|-
</div>
! Workload!! Foundation Edition!! Advanced Edition!! Premium edition
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/virtual_machines.html Virtual Machine] || 11 || 13 || 16
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/veeam_agent_computers.html Server] || 11 || 13 || 16
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/veeam_agent_computers.html Workstation] || 4 || 5 || 5
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/public_cloud_workloads.html Public Cloud VM] || 11 || 13 || 16
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/public_cloud_workloads.html Public Cloud Database] || 11 || 13 || 16
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/public_cloud_workloads.html Public Cloud File Share] || 11 || 13 || 16
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/nas_file_shares.html Object Storage (500GB)] || 10 || 11 || 11
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/nas_file_shares.html File Shares (500 GB)] || 10 || 11 || 11
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/plugins_enterprise_apps.html Application] || 11 || 13 || 16
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/vdp_entra_id.html Microsoft Entra ID (10 User Package)] || 10 || 11 || 11
|}
<span id="Übersicht_der_Punktewerte_für_Veeam_Backup_for_Microsoft_365"></span>
==== Overview of the scores for Veeam Backup for Microsoft 365 ====


<div lang="de" dir="ltr" class="mw-content-ltr">
'''Note:''' Please note that you do not need to issue a Veeam Backup for Microsoft 365 license for [https://wiki.terracloud.de/index.php/TERRA_CLOUD_Veeam_Data_Protection/en#Microsoft_365_Backup TERRA CLOUD Veeam Data Protection Microsoft 365 Backup], as the Veeam license is already included in the product. <br>
==== Können Microsoft Teams Chats gesichert werden? ====
The point value per user is only relevant for licensing self-managed Veeam Backup for Microsoft 365 servers. <br>
</div>
{| class="wikitable"
|-
! Workload !! '''Veeam Backup for Microsoft 365'''
|-
| [https://helpcenter.veeam.com/docs/vcsp/refguide/vbo365.html User] || 1.5
|}
<span id="Lizenzierung_von_Veeam_Agents_direkt_über_das_Protection_Portal"></span>
==== Licensing Veeam Agents directly via the Protection Portal ====
 
All Veeam agents installed via Protection Portal are automatically licensed through TERRA CLOUD.<br>
You will be billed according to usage based on the following point values:<br>
{| class="wikitable sortable"
! Workload !! Workstation !! Server
|-
| Microsoft Windows || 4 || 11
|-
| Linux || 4 || 11
|-
| Mac || 4 || 11
|}
<span id="Voraussetzungen_für_das_Automatic_License_Reporting_und_die_Übermittlung_der_Verbrauchswerte"></span>
=== Prerequisites for Automatic License Reporting and the transmission of usage data ===
 
Veeam’s "Automatic License Reporting" feature allows for the creation of licenses that automatically expand on a regular basis. <br>
Additionally, usage data is transmitted directly to Veeam and recorded in the billing system of the respective service provider (Wortmann AG). <br>
To ensure smooth operation and accurate billing, please meet the following requirements:
# Create licenses exclusively with the "Automatic reporting on" option enabled.
# Activate the ''[https://helpcenter.veeam.com/docs/vcsp/refguide/license_key_update.html Automatic License Key Update]'' feature for your Veeam product (see example image below).
# The licensed Veeam products must be able to reach the Veeam license servers (see table below).
# The [https://wiki.terracloud.de/index.php/TERRA_CLOUD_Veeam_Data_Protection/en#Management_AgentVeeam Management Agent] is also required; it connects the licensed Veeam products to the Protection Portal (usage data is transmitted via the Management Agent).
{| class="wikitable"
|+ Veeam License Update Server
|-
! Product !! License Update Server !! Port
|-
| Veeam Backup & Replication || vbr.butler.veeam.com, autolk.veeam.com, vbrad.butler.veeam.com || 443
|-
| Veeam Backup Enterprise Manager || vbr.butler.veeam.com, autolk.veeam.com, vbrad.butler.veeam.com  || 443
|-
| Veeam ONE || one.butler.veeam.com || 443
|-
| Veeam Backup for Microsoft 365 || vbo.butler.veeam.com || 443
|-
| Veeam Recovery Orchestrator || vao.butler.veeam.com || 443
|-
| Veeam Backup for Salesforce || vbsf.butler.veeam.com || 443
|}
{| class="wikitable"
|+ Certificate Revocation List
|-
! Certificate Revocation List URLs !! Example !! Port
|-
| *.ss2.us || o.ss2.us || 80
|-
| *.amazontrust.com || ocsp.sca1b.amazontrust.com, ocsp.rootca1.amazontrust.com, ocsp.rootg2.amazontrust.com  || 80
|}
'''Example: '''Active ''Automatic License Key Update'' on a Veeam Backup for Microsoft 365 server:
[[File:ALK.png|500px|none]]
 
<span id="Einrichtung_des_VCSP_Pulse_Plug-ins"></span>
=== Setting up the VCSP Pulse Plug-in ===
 
You can find the VCSP Pulse plug-in in the "Configuration" section of the plug-in library.<br>
[[Datei:Vcsp-pulse-plugin-2.png|1200px|rahmenlos|ohne]]
First, activate the "Company creation in VCSP Pulse" option. This will automatically create all newly created companies as "VCSP Pulse Companies."<br>
If companies already exist, you can simply select them using the checkbox and create them via "Create Company" --> "In VCSP Pulse."<br>
The mapping between the company in the Protection Portal/Service Provider Console and VCSP Pulse is required so that licenses can be assigned to individual customers.<br>
[[Datei:VCSP-pulse-2-.png|1200px|rahmenlos|ohne]]
<span id="Erstellen,_Zuweisen_und_Herunterladen_eines_Lizenzschlüssels"></span>
=== Creating, assigning and downloading a license key ===
 
'''1.''' Start the license creation process via ''License Keys --> New License''<br>
''''2.''' Select a product from the range<br>
Please note that the ''Automatic Reporting'' option must remain active so that license usage is automatically reported to Wortmann AG.
[[File:New-license-1.png|frameless|800px|border|none]]
''''3.''' Equip your license with the required workloads, e.g. B. 5 VMs
Repeat this step for all other required workloads (e.g., for backing up a network share or Entra ID)<br>
[[File:Add-new-license2.png|frameless|800px|border|none]]
'''4.''' Create the license, provided all required workloads are included (you can also edit the license later)<br>
'''5.''' Select the new license from the list of ''License Keys'' and assign the license via ''License Actions --> Assign''<br>
[[File:Add-new-license-3.png|frameless|800px|border|none]]
'''6.''' Finally, you can download the license file via ''License Actions --> Download'' and install it in the respective product<br>
<span id="Verwaltung_von_Veeam_Backup_Servern_und_Agents"></span>
== '''Managing Veeam Backup Server and Agents''' ==
 
The TERRA CLOUD Veeam Data Protection Portal allows you to centrally manage the following Veeam software components:
* Veeam Backup & Replication Server
* Veeam Agents (Windows, Linux, and Mac)
* Veeam Backup for Microsoft 365
* Veeam ONE
* Veeam Cloud Connect
<span id="Voraussetzungen"></span>
=== Requirements ===
 
# The Veeam product is licensed via Wortmann AG's [https://wiki.terracloud.de/index.php/TERRA_CLOUD_Veeam_Data_Protection/en#Licensing:_The_VCSP_Pulse_Plug-in VCSP licensing model]
# The respective management agent (Windows, Linux, or Mac) is installed on the system to be managed (exception: no management agent is required for the Veeam software appliance)
# The management agents connect to the TERRA CLOUD cloud gateways via port 6180; see [https://wiki.terracloud.de/index.php/TERRA_CLOUD_Veeam_Data_Protection/en#Network_Configuration Network configuration]
# The "Backup agents management" option must be enabled for the company in the Protection Portal. In the current version (31.0) of the TERRA CLOUD Technical Center, this configuration does not yet happen automatically. In a future version, agent management will be automatically enabled when linking end customers in the Technical Center.
<br> "Backup agents management" option for the respective company:
[[Datei:Screen Backup agent management 2026 v2.png|800px|none]]
=== Management Agent ===
 
The Protection Portal Management Agent is the link between your Veeam software components (Veeam Backup Agents, Veeam Backup & Replication, Veeam Backup for Microsoft, etc.) and the Protection Portal.<br>
The Management Agent must be installed on each system to be managed. It is available in three versions for the Windows and Linux operating systems and for macOS.<br>
A list of all supported operating systems and system requirements can be found [https://helpcenter.veeam.com/rn/vspc_9_1_release_notes.html#system-requirements-veeam-management-agents here]. <br>
<br>
'''Tip:'''<br>
If you want to manage existing Veeam Backup & Replication servers, manual installation of the agent is not required.<br>
The Management Agent is installed automatically if [https://wiki.terracloud.de/index.php/TERRA_CLOUD_Veeam_Data_Protection/en#Windows_Veeam_Backup_&_Replication_Server Wortmann AG is specified as the service provider for this server]. <br>
<br>
'''Features:'''<br>
# Transfer of metadata, e.g., operating system version, product version, hostname, etc.
# Update management through the installation of upgrades and patches
# Remote installation of Veeam software (Veeam Agents, Backup & Replication, or Veeam One)
# Enables configuration of Veeam components via the Protection Portal (e.g., creating backup jobs, adjusting schedules, etc.)
<span id="Installation_für_Windows_Systeme"></span>
=== Installation for Windows systems ===


<div lang="de" dir="ltr" class="mw-content-ltr">
'''Step 1: Download'''<br>
Die Chats zwischen einzelnen Benutzern und Gruppenchats können nicht gesichert werden. <br>
You can download the Management Agent for Windows pre-configured for each of your end customers via the 'Discovery' section.<br>
Weitere Informationen zu den Einschränkungen der Veeam Backup für Microsoft 365 Teams Sicherung finden Sie [https://helpcenter.veeam.com/docs/vbo365/guide/vbo_considerations.html?zoom_highlight=does%20not%20back%20up%20the%20following%20objects&ver=80 hier].
Optionally, the validity period of the connection token can be extended to, for example, five years. <br>
</div>
[[Datei:Download-Management-Agent-new.png|1000px|rahmenlos|ohne]]
<div lang="de" dir="ltr" class="mw-content-ltr">
'''Step 2: Installation'''<br>
==== Was würde gesichert werden wenn unter den „Protected Services" die Option „Teams chats" ausgewählt wird? ====
Run the setup on the system to be managed and follow the installation process.<br>
</div>
The setup will install any necessary software packages (Microsoft ASP.NET Core 8.0.21 Shared Framework, Microsoft .NET Core Runtime 8.0.21, and Microsoft Windows Desktop Runtime 8.0.21).
[[Datei:Install-MGMT-Agent 2.png|1000px|rahmenlos|ohne]]<br>
In the next step, accept the license agreements.<br>
[[Datei:Install-MGMT-Agent 3.png|1000px|rahmenlos|ohne]]
Start the installation by clicking "Install"<br>
[[Datei:Install-MGMT-Agent 4.png|1000px|rahmenlos|ohne]]
'''Step 3: Adding the Agent to the Protection Portal'''<br>
After successful installation, a new computer should appear in the Protection Portal under "''Discovery --> Discovered Computers''".<br>
The Protection Portal is configured to automatically verify and authorize this new agent. This process may take a few minutes.<br>
[[Datei:Install-MGMT-Agent 6-neu.png||1500px|rahmenlos|ohne]]
Once the Management Agent has been verified, you can, for example, begin installing a product (Veeam Agent, Backup Server, or Veeam One). <br>
[[Datei:Install-MGMT-Agent 7-neu.png|1500px|rahmenlos|ohne]]
<span id="Die_Wortmann_AG_als_Service_Provider_hinzufügen"></span>
=== Add Wortmann AG as a service provider ===


<div lang="de" dir="ltr" class="mw-content-ltr">
==== Windows Veeam Backup & Replication Server ====
Die Option [[TERRA_CLOUD_Veeam_Data_Protection#Microsoft_365_Organisationen_verbinden_und_verknüpfen|„Teams chats"]] erfordert die kostenpflichtige Nutzung der Microsoft Teams Export APIs und sichert die Beiträge in öffentlichen Teams Kanälen. <br>
</div>
<div lang="de" dir="ltr" class="mw-content-ltr">
==== Welche Kosten entstehen für die Nutzung der Microsoft Teams Export APIs? ====
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
First, log in to the Veeam Backup & Replication Server via the Backup & Replication Console or the WebUI.<br>
Eine Übersicht über die Kosten finden Sie in diesem [https://learn.microsoft.com/en-us/graph/teams-licenses Microsoft Beitrag]. <br>
Please note that the Protection Portal Management Agent will be installed automatically during this process.<br>
Veeam wird als [https://learn.microsoft.com/en-us/microsoftteams/export-teams-content#general-usagemodel-b-scenarios zertifizierter Partner] in das Model B eingeordnet. <br>
In the Backup Infrastructure, navigate to the Service Provider menu item and click Add Service Provider.<br>
</div>
'''Note:'''
We recommend using Veeam Backup & Replication version ''''12.3.2.4465''' or higher.
Older versions exhibit connectivity issues and contain security vulnerabilities; see [https://www.veeam.com/kb4830 Veeam KB4830].
[[Datei:Add-Serviceprovider-2.png|1500px|rahmenlos|ohne]]
Please enter the following configuration:<br>
'''DNS name or IP address:''' <br>
    ''protection-gateway.terracloud.de''
'''Port:''' <br>
    ''6180''
'''Allow this Veeam Backup & Replication installation to be managed by the service provider --> Please enable'''<br>
Next, enter new access credentials via Add or Manage accounts. <br>
When a company is provisioned in the Protection Portal, a Cloud Connect user is also automatically provisioned. The username is an eight-digit ID (example in screenshot 966c77b6) <br>
'''Username:''' = The username is displayed in the Technical Center in your end customer's service settings under TERRA CLOUD Veeam Data Protection (please copy only the eight-digit ID) <br>
'''Password''' = The password is displayed in the Technical Center in your end customer's service settings under TERRA CLOUD Veeam Data Protection<br>
[[Datei:Add-Serviceprovider-3.png|1500px|rahmenlos|ohne]]
After successful completion, a new entry should appear in the Service Providers section. <br>
[[Datei:Add-Service-Provider-5.png|1500px|rahmenlos|ohne]]

Aktuelle Version vom 28. Juli 2026, 11:05 Uhr

Introduction

Product presentation TERRA CLOUD Veeam Data Protection

TERRA CLOUD Veeam Data Protection is a data backup platform from TERRA CLOUD powered by Veeam.
At the heart of this platform is the multi-tenant portal protection.terracloud.de, which grants you access to various backup products from Veeam.

What possibilities does the TERRA CLOUD Veeam Data Protection platform offer?

  1. A Software-as-a-Service backup solution for Microsoft 365, fully hosted in the TERRA CLOUD (Hüllhorst location)
  2. Licensing and centralized management of, for example, Veeam Backup & Replication Servers or Veeam Agents *NEW*

Facility

Network Configuration

Port Overview TERRA CLOUD Veeam Data Protection
Protocol Port Source Destination Function Note
HTTPS 443 Browser protection.terracloud.de TERRA CLOUD Veeam Data Protection Management Portal 185.35.13.60
HTTPS 4443 Browser Veeam Backup for Microsoft 365 Restore Portal Restore from Microsoft 365 Backup 185.35.13.240/28
TCP 6180 Management Agent Cloud Gateways Management of Veeam Backup Servers and Agents 185.35.13.224/28

Setup process overview

Setting up data backup consists of four steps in total, with steps 2-4 being repeated for each end customer.

Deployment of the TERRA CLOUD Veeam Data Protection Platform

You can have your TERRA CLOUD Veeam Data Protection Platform created with a one-time order in the TERRA CLOUD Center.
Upon completion of the deployment, you will receive a confirmation email. Your initial login credentials will be displayed in the TERRA CLOUD Technical Center.
Further setup of your customers and data backups is done in the technical administration portal protection.terracloud.de.

Establishment of the portal "protection.terracloud.de"

First login and change of initial access data

First Login:
After the setup is complete, you will receive a confirmation email.
You can retrieve your initial login credentials for protection.terracloud.de via the Technical Center.
Note: Access to the login credentials requires the user role "Reseller Admin".

The login is structured as follows:
(Wortmann Customer Number)\(Wortmann Customer Number-Administrator)
Example:
111490\111490-Administrator


Change of the Initial access data and multi-factor authentication:
After your first login, we recommend the following adjustments to your initial administrator access (Service Provider Global Administrator):

  1. Change your password
  2. Activate and configure multi-factor authentication
  3. Verify the registered email address (using the "Forgot password" function)

Editing a User

Option 1:
Please go to Settings via the gear icon "Configuration" in the upper right corner.
In the "Roles & Users" section, select the Service Provider Global Administrator using the checkbox and edit it using the pencil icon.

Option 2:
The currently logged-in user can also be edited via the drop-down menu next to the username.

Administrator Profile Adjustment:
Please assign a new password for this Service Provider Global Administrator user.
Check the email address in the "User Info" section; this is required for the "Forgot Password" function.
The default email address is the Cloud Master Account address. Change the address listed there if necessary.

We recommend enabling multi-factor authentication for all users in the Protection Portal.

Further configuration will be completed upon your next login.
In the final step, you will receive a summary of the configured changes.

Configure email notifications

Please follow these steps to configure email notifications:

1. Configuring the TERRA CLOUD SMTP Server
Please open the portal settings via the "Configuration" gear icon and select "Server Settings".
Enter "mail.protection.terracloud.de" for the SMTP server and set the "Encryption protocol" to "None".
Since this SMTP server is located within the management infrastructure, encryption up to the SMTP server is not required.
Outgoing emails are encrypted if the receiving mail server requests it.

2. Setting up notifications
First, change the "Default sender" to "no-reply@protection.terracloud.de".
Choose whether you want to be notified of every event or only receive summaries.
In the "Alarms" section, re-enter the sender address and the desired recipient address.
The "Discovery Rules" and "Billing" sections are not needed.

Configuration of Alarm Management

The Protection Portal offers its own monitoring function, which can be configured in the "Configuration --> Templates --> Predefined Alarms" section.

Disabling the "Managed tenants quota" alarm

Please enter "Managed tenants quota" in the search bar and disable this alarm.
TERRA CLOUD uses the Company Quota function to manage the provisioning of end customers via the TERRA CLOUD Technical Center.
For this purpose, the quota is set to the current number of managed end customers and only increased by 1 when a new end customer is automatically provisioned.
This automation incorrectly triggers the "Managed tenants quota" alarm, which should be disabled beforehand.

Email notification when a Managed tenants quota alarm is triggered.
If the alarm has not yet been disabled, the following message will be displayed in the Protection Portal and/or sent to you by email.

General:
In the Protection Portal, end-customer organizations are represented by a "Company." Your "Reseller" organization can manage any number of companies and thus end customers.
Companies can only be created automatically via the TERRA CLOUD Technical Center and not manually in the Protection Portal.
This enables the clear assignment of TERRA CLOUD Veeam Data Protection usage data to an end customer from the TERRA CLOUD Center/Technical Center.

Deploy TERRA CLOUD Veeam Data Protection for an end customer

  1. Please navigate to the "Customer Management" section in the TERRA CLOUD Technical Center
  2. Select the desired end customer and go to the "SERVICE SETTINGS" tab
  3. Start the deployment by clicking "CREATE AND LINK END CUSTOMER" (see screenshot below)

The automated deployment performs the following steps in the background:

  1. Create a company based on the end customer information from the Technical Center
  2. Assign your resources for data backup (Veeam Backup for M365 Server and Repository)
  3. Create a user account for the company


After successful completion, the created user account and a green check mark will be displayed.
The The displayed user access is a default of the Veeam Service Provider Console and is not required for setting up and managing data backups.
This provides insight into the data backup configuration within the company.

Microsoft 365 Backup

Setting up a Microsoft 365 data backup

Setting up data backup for the Wortmann partner's Microsoft 365 organization

During the initial deployment of the TERRA CLOUD Veeam Data Protection platform, a company is automatically created for the Wortmann partner's company.
If you want to back up your own Microsoft 365 organization, you can skip the step Create and link end customers, as the company has already been created.
Please start directly with the step Setting up a Microsoft 365 data backup.

Prerequisite:

  • This guide assumes that you have already linked your end customer to the Protection Portal via the Technical Center.

Step 1:
To configure data protection, please switch to the Protection Portal.
The link between a created Company (End Customer) and a Microsoft 365 tenant can be configured within the "Veeam Backup for Microsoft 365 Plugin."
You can find this plugin in the Plugin Library list under the "Configuration" section.

Step 2:
Navigate to the "Organizations" menu item and add a new one by clicking "New."


First, please select the Company/End Customer to be linked, and in the next step, select the object types to be protected ("Protected Services").
This selection determines the permissions that will be assigned to the Entra ID application used for data protection within the tenant.

Please leave the Region set to the default value of Default and click Next.


Please register a new Entra ID application within the tenant that is to be backed up.
In this example, the abbreviation TCVDP within the new application's name stands for TERRA CLOUD Veeam Data Protection and facilitates its identification within Entra ID.
Please note that the "export mode for SharePoint Web Parts" should only be enabled if this feature is utilized by SharePoint.

To create the Entra ID application and assign the necessary permissions, authentication and approval by a Global Administrator are required.
Please copy the code and sign in to Microsoft 365 using the displayed link.


Confirm the sign-in to the Microsoft Azure CLI to authorize the creation and permissioning of the Entra ID application.


Following a successful sign-in and confirmation, the "Verification" status should change to "Verified."
If it does not, you can generate a new code by clicking "Refresh code" and attempt the sign-in process again.


Finally, the status of both the M365 Organization and the VSPC Company should be listed as "Mapped."

Create a Microsoft 365 backup job

To configure a Microsoft365 backup job, select the "Backup Jobs" tab in the left-hand menu under "Management."
You can create a new backup job using "Create Job."
First, enter a name for the backup job and, optionally, a description.
We recommend choosing a name, as in our example, that reflects the content being backed up.


Please select the Microsoft 365 tenant that is already linked to be backed up.
Under Backup Mode, you configure the scope of your job's backup. The backup of the entire organization is pre-selected.

However, you can also customize the scope and define granular exclusions.
Best Practice for Exclusions:
We recommend backing up the entire organization and excluding specific objects (e.g., groups) instead of including only individual objects.
In the next step, the schedule is added. Here you can define the frequencies, days, and retry attempts.
Optionally, you can allow or disallow data backups within a backup window (e.g., during business hours).

In the final summary, you can use the "Start the job when I click finish" option to run the data backup immediately.

Recovering Microsoft 365 data

Requirements

  1. Active Entra ID Backup Application, which is already created during setup
  2. Microsoft 365 credentials (affected user or global administrator)
  3. TERRA CLOUD Veeam Data Protection Restore Portal Application added to the tenant

Add Restore Portal Application in the tenant

TERRA CLOUD uses a Microsoft Entra ID Enterprise Application to perform a restore in the backed-up tenant.
To enable this, the application must be added and authorized once per Microsoft 365 tenant.
You can do this directly via the TERRA CLOUD Technical Center using the "SET RESTORE PERMISSIONS" function.

Instructions:
Step 1: Log in to the TERRA CLOUD Technical Center as a "Reseller Admin."
Step 2: Navigate to the TERRA CLOUD Veeam Data Protection product in the menu under the "Products" category.
Step 3: Click the "SET RESTORE PERMISSIONS" button.
Step 4: In the newly opened tab, log in with a Global Administrator user of the tenant for which you want to configure the restore.

Step 5: Confirm the requested permissions for the "TERRA CLOUD Veeam Data Protection - Restore Portal" application by clicking "Accept." You will then be redirected to your Restore Portal.

Functional test: Please log in to the Restore Portal with a Microsoft 365 user from the tenant or the Global Administrator used above.

Restore as user

Step 1:
Under the "Protected Data" menu item, you can open a new tab with the "Restore Portal" link to access the Restore Portal.
Please log in with the Microsoft 365 user for whom you want to restore something.

Step 2:
Select the desired restore point from the calendar.

Step 3:
Now assemble the recovery set from the required files or objects.
You can navigate through the backup and the various object types, as well as use the search function.
You can select individual files directly and restore them using the "Restore" function or add them to the restore set using "Add to Restore List."

Step 4:
Please check whether all the desired files are included in the restore list under "Items."
You can then specify the "Restore Mode" to determine whether the files should be overwritten or retained in their original location.
Click the "Finish" button to start the restore.

Performing a restore as an administrator for other or multiple users

Prerequisite:
You can authorize one or more users as "Restore Operators" through TERRA CLOUD Support.
Please provide us with the desired tenant, e.g., contoso.onmicrosoft.com, and the desired user, e.g., admin@contoso.onmicrosoft.com.
As a "Restore Operator," you can use the "Scope" to change your identity and perform the restore for other or multiple users.
The procedure is identical to restoring as a user.


Consumption data

Determine consumption values ​​via the TERRA CLOUD Technical Center

The TERRA CLOUD Technical Center provides you with an overview per end customer and a summary of usage data for the selected month.
Within the table view, you can filter the values ​​as usual using the respective function and export them as a CSV file.
The default selection "Current" shows you the license usage for the current month. However, only the usage reports for completed months are relevant for billing.

Microsoft 365 Backup Usage Values ​​

This tab displays the usage data for the TERRA CLOUD Veeam Data Protection Microsoft 365 Backup:
Date

  • Indicates the completed and billable month selected in the "Report Month" drop-down menu.
  • If nothing is selected, the current month is displayed.

End Customer

  • Indicates the end customer associated with the backed-up Microsoft 365 tenant.

Number of Backed-Up M365 Users

  • Total of new and billed M365 users.

Number of New Backed-Up M365 Users

  • Users newly added to the backup in the selected month are not billed.
  • This applies to both the initial tenant setup and newly added users for existing customers.

Number of Billed M365 Users

  • Users billed in the selected month.

Below the table showing consumption figures per end customer, you will also find your total consumption figures as a partner.


When does a Microsoft 365 user consume a backup license?

A Microsoft 365 user consumes one license for TERRA CLOUD Veeam Data Protection Microsoft 365 Backup in the billing month if the following criteria are met:

  1. The online services Exchange Online and/or SharePoint Online/OneDrive for Business are used and backed up by the product.
  2. The user has been part of at least one backup within the last 31 days.

Important note:
Restoration from previously created backups is also possible without an active license.

When both criteria are met for the first time, the user is registered as "new."
If a user has not been backed up in the last 31 days, no more licenses are consumed.

What doesn't consume a license for Microsoft 365 Backup?

The following objects can be included in the backup, but they do not consume a license.

  1. Microsoft Teams objects
  2. Groups and non-personal SharePoint sites
  3. Shared mailboxes (unless a Microsoft 365 license has been assigned)
  4. Resource mailboxes (unless a Microsoft 365 license has been assigned)
  5. Public folders (unless a Microsoft 365 license has been assigned)
  6. External SharePoint users
  7. Microsoft Teams guest users

Licensing: The VCSP Pulse Plug-in

The Protection Portal offers you the option to rent Veeam software licenses through Wortmann AG (Service Provider) via the "VCSP Pulse Plugin".
The abbreviation "VCSP" stands for the Veeam Cloud & Service Provider Program. VCSP Pulse is a web-based license reporting platform for Service Providers operated by Veeam.
To create a license, your end customer/company must be set up in VCSP Pulse and linked to the company in the Protection Portal.

Structure of the VCSP Licensing Model

The Veeam VCSP licensing model is based on VCSP license points, which are billed uniformly according to the license size and feature set.
A point value determined by Veeam is charged based on the workload and feature set.
The workloads to be backed up are the determining factor for the license size. In this context, a workload refers, for example, to backing up a VM, a physical server, or a Microsoft 365 user, etc.
In addition to the license size, the feature set and edition of the software product are also crucial.
The core product, "Veeam Backup & Replication," is... B. Available individually in Standard, Enterprise, and Enterprise Plus versions, or bundled with the Veeam Data Platform.
Some products are only available in one version, in which case only the license size or the number of workloads is relevant.

When planning your license requirements, you can use these two questions as a guide:

  1. What feature set, and therefore which edition of Veeam Backup & Replication or the Veeam Data Platform, is required?
  2. Which workloads, and how many of them, need to be backed up? (VMs, network shares, S3 buckets, etc.)

Overview of score values ​​for Veeam Backup & Replication

Workload Default Enterprise Enterprise Plus
Virtual Machine 5 9 11
Server 11 11 11
Workstation 4 4 4
Public Cloud VM 11 11 11
Public Cloud Database 11 11 11
Public Cloud File Share 11 11 11
Object Storage (500GB) 10 10 10
File Shares (500 GB) 10 10 10
Application 11 11 11
Microsoft Entra ID (10 User Package) 10 10 10

Overview of score values ​​for the Veeam Data Platform

Workload Foundation Edition Advanced Edition Premium edition
Virtual Machine 11 13 16
Server 11 13 16
Workstation 4 5 5
Public Cloud VM 11 13 16
Public Cloud Database 11 13 16
Public Cloud File Share 11 13 16
Object Storage (500GB) 10 11 11
File Shares (500 GB) 10 11 11
Application 11 13 16
Microsoft Entra ID (10 User Package) 10 11 11

Overview of the scores for Veeam Backup for Microsoft 365

Note: Please note that you do not need to issue a Veeam Backup for Microsoft 365 license for TERRA CLOUD Veeam Data Protection Microsoft 365 Backup, as the Veeam license is already included in the product.
The point value per user is only relevant for licensing self-managed Veeam Backup for Microsoft 365 servers.

Workload Veeam Backup for Microsoft 365
User 1.5

Licensing Veeam Agents directly via the Protection Portal

All Veeam agents installed via Protection Portal are automatically licensed through TERRA CLOUD.
You will be billed according to usage based on the following point values:

Workload Workstation Server
Microsoft Windows 4 11
Linux 4 11
Mac 4 11

Prerequisites for Automatic License Reporting and the transmission of usage data

Veeam’s "Automatic License Reporting" feature allows for the creation of licenses that automatically expand on a regular basis.
Additionally, usage data is transmitted directly to Veeam and recorded in the billing system of the respective service provider (Wortmann AG).
To ensure smooth operation and accurate billing, please meet the following requirements:

  1. Create licenses exclusively with the "Automatic reporting on" option enabled.
  2. Activate the Automatic License Key Update feature for your Veeam product (see example image below).
  3. The licensed Veeam products must be able to reach the Veeam license servers (see table below).
  4. The Management Agent is also required; it connects the licensed Veeam products to the Protection Portal (usage data is transmitted via the Management Agent).
Veeam License Update Server
Product License Update Server Port
Veeam Backup & Replication vbr.butler.veeam.com, autolk.veeam.com, vbrad.butler.veeam.com 443
Veeam Backup Enterprise Manager vbr.butler.veeam.com, autolk.veeam.com, vbrad.butler.veeam.com 443
Veeam ONE one.butler.veeam.com 443
Veeam Backup for Microsoft 365 vbo.butler.veeam.com 443
Veeam Recovery Orchestrator vao.butler.veeam.com 443
Veeam Backup for Salesforce vbsf.butler.veeam.com 443
Certificate Revocation List
Certificate Revocation List URLs Example Port
*.ss2.us o.ss2.us 80
*.amazontrust.com ocsp.sca1b.amazontrust.com, ocsp.rootca1.amazontrust.com, ocsp.rootg2.amazontrust.com 80

Example: Active Automatic License Key Update on a Veeam Backup for Microsoft 365 server:

Setting up the VCSP Pulse Plug-in

You can find the VCSP Pulse plug-in in the "Configuration" section of the plug-in library.

First, activate the "Company creation in VCSP Pulse" option. This will automatically create all newly created companies as "VCSP Pulse Companies."
If companies already exist, you can simply select them using the checkbox and create them via "Create Company" --> "In VCSP Pulse."
The mapping between the company in the Protection Portal/Service Provider Console and VCSP Pulse is required so that licenses can be assigned to individual customers.

Creating, assigning and downloading a license key

1. Start the license creation process via License Keys --> New License
'2. Select a product from the range
Please note that the Automatic Reporting option must remain active so that license usage is automatically reported to Wortmann AG.

'3. Equip your license with the required workloads, e.g. B. 5 VMs Repeat this step for all other required workloads (e.g., for backing up a network share or Entra ID)

4. Create the license, provided all required workloads are included (you can also edit the license later)
5. Select the new license from the list of License Keys and assign the license via License Actions --> Assign

6. Finally, you can download the license file via License Actions --> Download and install it in the respective product

Managing Veeam Backup Server and Agents

The TERRA CLOUD Veeam Data Protection Portal allows you to centrally manage the following Veeam software components:

  • Veeam Backup & Replication Server
  • Veeam Agents (Windows, Linux, and Mac)
  • Veeam Backup for Microsoft 365
  • Veeam ONE
  • Veeam Cloud Connect

Requirements

  1. The Veeam product is licensed via Wortmann AG's VCSP licensing model
  2. The respective management agent (Windows, Linux, or Mac) is installed on the system to be managed (exception: no management agent is required for the Veeam software appliance)
  3. The management agents connect to the TERRA CLOUD cloud gateways via port 6180; see Network configuration
  4. The "Backup agents management" option must be enabled for the company in the Protection Portal. In the current version (31.0) of the TERRA CLOUD Technical Center, this configuration does not yet happen automatically. In a future version, agent management will be automatically enabled when linking end customers in the Technical Center.


"Backup agents management" option for the respective company:

Management Agent

The Protection Portal Management Agent is the link between your Veeam software components (Veeam Backup Agents, Veeam Backup & Replication, Veeam Backup for Microsoft, etc.) and the Protection Portal.
The Management Agent must be installed on each system to be managed. It is available in three versions for the Windows and Linux operating systems and for macOS.
A list of all supported operating systems and system requirements can be found here.

Tip:
If you want to manage existing Veeam Backup & Replication servers, manual installation of the agent is not required.
The Management Agent is installed automatically if Wortmann AG is specified as the service provider for this server.

Features:

  1. Transfer of metadata, e.g., operating system version, product version, hostname, etc.
  2. Update management through the installation of upgrades and patches
  3. Remote installation of Veeam software (Veeam Agents, Backup & Replication, or Veeam One)
  4. Enables configuration of Veeam components via the Protection Portal (e.g., creating backup jobs, adjusting schedules, etc.)

Installation for Windows systems

Step 1: Download
You can download the Management Agent for Windows pre-configured for each of your end customers via the 'Discovery' section.
Optionally, the validity period of the connection token can be extended to, for example, five years.

Step 2: Installation
Run the setup on the system to be managed and follow the installation process.
The setup will install any necessary software packages (Microsoft ASP.NET Core 8.0.21 Shared Framework, Microsoft .NET Core Runtime 8.0.21, and Microsoft Windows Desktop Runtime 8.0.21).


In the next step, accept the license agreements.

Start the installation by clicking "Install"

Step 3: Adding the Agent to the Protection Portal
After successful installation, a new computer should appear in the Protection Portal under "Discovery --> Discovered Computers".
The Protection Portal is configured to automatically verify and authorize this new agent. This process may take a few minutes.

Once the Management Agent has been verified, you can, for example, begin installing a product (Veeam Agent, Backup Server, or Veeam One).

Add Wortmann AG as a service provider

Windows Veeam Backup & Replication Server

First, log in to the Veeam Backup & Replication Server via the Backup & Replication Console or the WebUI.
Please note that the Protection Portal Management Agent will be installed automatically during this process.
In the Backup Infrastructure, navigate to the Service Provider menu item and click Add Service Provider.
Note: We recommend using Veeam Backup & Replication version '12.3.2.4465 or higher. Older versions exhibit connectivity issues and contain security vulnerabilities; see Veeam KB4830.

Please enter the following configuration:
DNS name or IP address:

   protection-gateway.terracloud.de

Port:

   6180

Allow this Veeam Backup & Replication installation to be managed by the service provider --> Please enable
Next, enter new access credentials via Add or Manage accounts.
When a company is provisioned in the Protection Portal, a Cloud Connect user is also automatically provisioned. The username is an eight-digit ID (example in screenshot 966c77b6)
Username: = The username is displayed in the Technical Center in your end customer's service settings under TERRA CLOUD Veeam Data Protection (please copy only the eight-digit ID)
Password = The password is displayed in the Technical Center in your end customer's service settings under TERRA CLOUD Veeam Data Protection

After successful completion, a new entry should appear in the Service Providers section.