Veritas Alta™ Archiving : Folder Sync 1.14.0 Administration Guide
- About Folder Sync
- Requirements for Folder Sync
- Preparing the service and admin accounts for Folder Sync- Service account and administration account requirements for Folder Sync
- Creating the Folder Sync service account
- Preparing the administration account for Exchange 2016 or 2013
- Preparing the administration account for Exchange 2010
- Preparing the administration account for Exchange 2007
- Preparing an administration account for Office 365
 
- Installing or upgrading Folder Sync
- Configuring the Folder Sync task
- Running and scheduling Folder Sync synchronizations- About performing and scheduling Folder Sync synchronizations
- Performing a "Run Now" Folder Sync synchronization
- Configuring scheduled Folder Sync synchronizations
- About Folder Sync scheduling and choosing a scheduling strategy
- Creating scheduled Folder Sync synchronization events
- Selecting the mailboxes to target for scheduled Folder Sync synchronizations
- Changing the iterative restart period for scheduled Folder Sync synchronization events
 
- Monitoring and managing Folder Sync- About monitoring and managing Folder Sync
- Viewing the All Mailboxes table
- Viewing the Folder Sync job list
- Viewing the Folder Sync mailbox report
- Viewing the Folder Sync status report
- Disabling or enabling Folder Sync from the Veritas Alta View Compliance and Governance Management Console
- Viewing the Folder Sync synchronization status of an account from the Veritas Alta View Compliance and Governance Management Console
 
- Troubleshooting Folder Sync
Preparing an administration account for Office 365
When you configure Folder Sync for Office 365 folder synchronization you must provide the credentials of a Microsoft Office 365 account with the required permissions.
Note:
You must not use the account that Veritas Alta Archiving Office 365 Sync uses for Office 365 account synchronization.
If you install Folder Sync on multiple servers for load sharing or redundancy, each instance of Folder Sync requires its own Office 365 service account. Create a separate Office 365 service account for each installation.
The Office 365 account must have the following role assignments:
- The account must be assigned to the following Office 365 administrator roles: Exchange administrator, Service administrator, User management administrator. 
- In the Office 365 Exchange admin center, the account must be a member of an Exchange management role group that includes the management roles ApplicationImpersonation, View-Only Configuration, and . 
The following procedure describes how you can create an account with these required permissions from the Office 365 Admin center.
To prepare an administration account for Office 365
- Sign in to Microsoft Office 365 as a global administrator.
- Click the Admin app to open the Office 365 Admin center.
- Under Users > Active Users, click + Add a user.
- Complete the New user dialog, including  the following role assignment:Expand Roles, select Customized administrator, and then select the following roles: - Exchange administrator 
- Service administrator 
- User management administrator 
 Then click Add to add the new user. 
- In the left menu bar of the Office 365 Admin center, expand Admin centers (Admin in the old admin center), and select Exchange.
- In the left navigation pane of the Exchange admin center, click permissions.
- On the admin roles page, click the + icon to create a new role group.
- In the new role group window, enter a suitable role group name in the Name field, such as Folder Sync App Impersonation.
- In the Roles section of the new role group window, click the + icon.
- In the Select a Role window, select each of the following roles from the list, and click add to add them to the role group: - ApplicationImpersonation 
- View-Only Configuration 
- View-Only Recipients 
 
- Click OK to close the Select a Role window and to return to the new role group window.
- In the Members section of the new role group window, click the + icon.
- In the Select Members window, select the new account that you are using as the Office 365 service account, and then click Add.
- Click OK to close the Select Members window and to return to the new role group window.
- Click Save to save the new role group.The new role group now appears in the list of Admin Role Groups on the admin roles page. Note: If you do not see the new role group, wait several minutes and then refresh the page. 
- Select the new role group in the admin roles list. Confirm that the three required  roles are shown as assigned roles, and that the account that is to act as the Office 365 service account is listed as a member.Note: A long propagation time may be required for an account to acquire any new or changed role settings. You can also use PowerShell commands such as get-managementroleassignment and get-rolegroupmember to confirm that the new settings have taken effect. For more information on PowerShell commands see Microsoft's support documentation.