Global Admin role requirements for Entra ID

A dedicated Microsoft service account with the Global Admin role is required for creating and reauthenticating Entra ID connectors. Other roles are sufficient for backup and restore, depending on your configuration.

Connector creation

A Global Admin role is required to create an Entra ID connector and start the initial backup. This ensures Keepit has the necessary permissions to access and back up your data.

Connector reauthentication

You may need to reauthenticate your connector in these cases:

  • Your Microsoft 365 session expires, making the authentication between Microsoft and Keepit invalid.
  • You used the wrong Global Admin account when authorizing the connector. Reauthenticate using the Reauthenticate key icon in the configuration window.
  • Keepit updates the product to use new Microsoft capabilities, requiring updated permissions.

Backup

The Global Admin role isn't required for backup.

  • If the Devices entity is enabled in the backup configuration, the service account needs the Global Reader or Security Reader role.
  • If the Devices entity isn't enabled, the service account doesn't need a specific role to run backup jobs.

Restore

The Global Admin role isn't required for restore, but it remains fully supported. If your service account already uses Global Admin, no action is needed.

For customers who prefer a least-privilege approach, the table below lists the minimum roles needed, based on what you're restoring:h

Restoring Roles required
Users Privileged Authentication Administrator
Groups Groups Administrator and Privileged Role Administrator