Cohesity Alta SaaS Protection Administrator's Guide
- Introduction to Cohesity Alta SaaS Protection
- Cohesity Alta SaaS Protection Copilot (AI chatbot)
- Cohesity Alta SaaS Protection Administrator portal (Web UI)
- Supported SaaS workloads
- Workflow to protect data using Cohesity Alta SaaS Protection
- Manage users and roles
- API permissions
- What is a connector?
- What is a connector?
- About transient errors
- Overview of adding connectors
- Configure General settings
- Configure Capture scope
- Configure User filter
- Configure Group filter
- Configure Folder filter
- Configure credentials
- Configure Custom backup policy and guidelines
- Configure Delete policy for SharePoint Online and guidelines
- Configure Stubbing policy
- Guidelines to configure Stubbing policy for SharePoint Online
- Schedule a backup
- Configure email addresses to get notifications
- Review configuration and edit/save/initiate backup
- Connectors page
- Connector status
- Edit connector configuration
- Delete connectors
- Pre-requisites to setup protection for M365
- Protect Microsoft 365 Multi-Geo tenant
- Protect Exchange Online data
- Protect SharePoint sites and data
- Setting up SharePoint Online protection with Cohesity Alta SaaS Protection
- Backup and restore support for SharePoint Online
- End-user SharePoint data access in Cohesity Alta SaaS Protection
- Run the Delete and Stubbing policies to the SharePoint Online environment
- Backup limitations for SharePoint Online
- Protect Teams sites
- Protect OneDrive data
- Protect Teams chats
- Protect GoogleDrive data
- Protect Gmail data
- Protect Audit logs
- Protect Salesforce data and metada
- Protect Entra ID objects
- Protect Box data
- Protect Slack data
- Protect Email/Message data
- Configure Retention policies
- Perform backups
- View and share backed-up data
- Analytics
- About analytics
- Analytics page and refresh behavior
- Aggregation buckets
- Gain insights into storage utilization
- Gain insights into storage utilization for Entra ID and Salesforce connectors
- Gain insights into blocked activities, most active users, and more
- Gain insights into data volume (size and item count) on legal hold
- Gain insights into data volume (size and item count) saved in different Enhanced cases
- Gain insights into data volume (size and count) under different policies
- Gain insights into data volume (size and item count) under different Tags
- Gain insights into data volume (size and item count) under different Tags behaviors
- Gain insights into storage savings after deduplication and compression
- Gain insights into data ingestion trends
- Perform restores using Administration portal
- About restore
- Prerequisites for restore
- Restore Exchange Online mailboxes
- Restore SharePoint/OneDrive/Teams Sites and data
- Restore Teams chat messages and Teams channel conversations
- Restore O365 audit logs
- Restore Box data
- Restore Google Drive data
- Restore Gmail data
- About Salesforce Data, Metadata, and CRM Content restore and Sandbox seeding
- Guidelines for Schema changes in Salesforce organization to prevent restore failures
- Restore Standard and Custom objects (Structured data restore)
- Custom Object restore - post processing steps
- Restore specific Records (Structured data) using Query filters
- Restore Salesforce CRM Content (Unstructured data restore)
- Restore Salesforce files/documents in Public/Shared libraries (Unstructured data restore)
- Limitations of Salesforce Data restore
- Salesforce Objects not supported for restore
- Key considerations for Salesforce Metadata restore
- Restore Salesforce Metadata
- Limitations of Salesforce Metadata backup and restore
- About Entra ID (Azure AD) objects and records restore
- Restore Slack data
- Restore data to File server
- Set default restore point
- Configure Restore all, Restore all versions, Point-in-time, and Specific range restore options
- Configure email addresses for notifications
- Downloading an item
- Restore dashboard
- Install services and utilities
- About services and utilities
- Pre-requisites to download and install services and utilities
- Downloading services and utilities
- Where to install the services and utilities
- Installing or upgrading services and utilities
- Configuring service accounts for services and utilities
- About the Apps Consent Grant Utility
- Discovery
- Configure Tagging polices
- Configure Tiering policy
- Auditing
- Manage Stors (Storages)
Supported SaaS workloads and backup capabilities
Cohesity Alta SaaS Protection supports backup and restore for the following SaaS applications:
Microsoft 365
Exchange Online
SharePoint Online
Teams sites
Teams chats
Google
Google Drive
Gmail
Box
Salesforce
Entra ID
Note:
A Cohesity Alta SaaS Protection connector is a logical interface that links the source application to backup storage in Cohesity Alta SaaS Protection. You can create and configure connectors for each workload to meet your backup requirements.
The users data in the Exchange Online environment is protected using the Cohesity Alta SaaS Protection Exchange connector with the following features:
:
Granular backup and restore is supported for the following items in the Exchange Online environment:
Mailboxes of users, groups, and Teams mailboxes.
Public Folders
Archive mailboxes
Shared mailboxes
Contacts and calendars
Tasks and notes
Mailbox Rules
Junk Email and Deleted Items: Junk email and deleted items folders to restore accidentally deleted or wrongly categorized emails.
Note:
The emails in the EWS environment are backed as
.emlfiles. Cohesity Alta SaaS Protection receives these .eml files from Exchange, containing the original email as an encrypted attachment and a message body indicating that the email is encrypted. To view these .eml files, they must be downloaded/restored from Cohesity Alta SaaS Protection and opened in Outlook by a user with the necessary permissions.Soft deleted mailboxes (can be configured using the Connector service).
Recoverable items folder
Public folders
Archived mailboxes
An option to back up archived mailboxes, ensuring that all user data, including archived content, is backed up.
Groups created using the Role assigned and Dynamic users options.
Microsoft 365 Group and Teams mailboxes.
The following configuration options are available for customizing SharePoint backup:
Flexible backup options
Back up all user mailboxes or selectively back up specific mailboxes (granular backup) based on backup requirements.
Rolling Mailbox Scope to distribute the backup load across jobs.
: With the 2.32.1 release, this option will not be available for new connectors. For existing connectors, this option will appear as read-only.
Alphabetical Mailbox Scope to back up mailboxes based on alphabetical name ranges.
: With the 2.32.1 release, this option will not be available for new connectors. For existing connectors, this option will appear as read-only.
Domain-based mailbox backup
Back up of mailboxes belonging to specific email domains.
The users data in the SharePoint Online environment is protected using the Cohesity Alta SaaS Protection SharePoint Online connector with the following features:
:
Granular backup and restore is supported for the following items in the SharePoint Online environment:
Documents
List items
Versions
Site pages
Site collections
Sub-site settings
Site and sub-site columns
Site and sub-site content types
List settings
List columns
List content types
Permission objects such as groups
Role definitions
Role assignments
See Supported and unsupported SharePoint Settings and Types for backup and restore.
See Supported Sites and List templates for backup and restore.dd
See Supported Sites and List templates for backup and restore.
:
The following configuration options are available for customizing SharePoint backup:
Define specific data types, versions, permissions, columns, and content types to back up.
Define a Delete policy to manage storage by removing unnecessary items from the source SharePoint Online environment while retaining backups in Cohesity Alta SaaS Protection.
See Configure Delete policy for SharePoint Online and guidelines.
Define a Stubbing policy to replace original items with stubs (shortcuts) in the SharePoint Online environment, which helps reduce storage usage while maintaining access to data.
The users data in the OneDrive environment is protected using the Cohesity Alta SaaS Protection OneDrive connector with the following features:
:
The OneDrive for Business connector is used to back up the users' My Sites or OneDrive for Business data. It includes the documents and other important files in the user's OneDrive account, apart from other SharePoint data in the user's OneDrive site.
: All files and documents stored in the user's OneDrive account, including documents, spreadsheets, presentations, images, videos, and any other file types.
: Folder hierarchy and structure.
: Shared files or folders.
: Version history of files.
: Metadata associated with files, such as file names, creation dates, modification dates, and other custom properties.
: Permissions and sharing settings applied to files and folders, including user access rights, and permissions inheritance.
The users data in the is protected using the Cohesity Alta SaaS Protection Teams site collection connector.
You can protect of the following data in the Team chat environment using the Cohesity Alta SaaS Protection Teams chat connector:
:
Chat conversations: All chat conversations that occur within the Teams chat environment, including one-on-one chats and group chats.
Media files: Media files that are shared within Teams chat, such as images, videos, and audio files.
Emojis, GIFs, and Stickers: Links, emojis, GIFs, stickers, or other visual element.
Chat history: Chat history for each user.
:
The following configuration options are available for customizing backup:
An option to back up one-on-one and group chat data for all users.
An option to back up one-on-one and group chat data for specific users.
An option to back up all chats in Teams channels.
An option to limit the backup to a specific number of days.
You can protect the users data in GoogleDrive environment using the using the Cohesity Alta SaaS Protection Google Drive connector.
:
You can back up the following data in the Google Drive environment:
: All files and documents that are stored in Google Drive, including documents, spreadsheets, presentations, images, videos, and any other file types.
User drives and Shared drives: Drives dedicated to each user and common shared Drives.
: Version history of files.
: Deleted files.
: Metadata and properties, such as owner information, last modified date, and custom metadata fields associated with Google Drive.
The following configuration options are available for customizing backup:
An option to back up all or specific users' Google Drive data.
An option to include or exclude deleted items in the backup.
An option to include or exclude the permissions on the items.
An option to back up Shared drives.
You can protect the users data in the Gmail environment using the Cohesity Alta SaaS Protection Gmail connector.
:
Cohesity Alta SaaS Protection supports the backup of the following Gmail data:
: All emails in the Gmail account, including inbox messages, sent items, drafts, and archived emails.
: Attachments associated with emails.
: Labels and folders.
: Deleted emails.
:
The following configuration options are available for customizing backup:
An option to back up all or specific users' data.
An option to exclude certain users from the backup by adding their email addresses to the excluded users list.
An option to include or exclude deleted items and the items in the Spam folder.
You can protect data in the Entra ID environment using the Cohesity Alta SaaS Protection Entra ID connector.
:
It includes backing up the user-related data such as profiles, settings, permissions, and other user-specific information.
It includes backing up the structure, memberships, and settings associated with the groups.
It includes backing up the configurations, settings, and information associated with applications registered within the Entra ID environment.
It includes backing up the configurations, settings, and data associated with enterprise-level applications registered and used within the Entra ID environment.
You can protect the users data in the Box environment using the Cohesity Alta SaaS Protection Box connector.
:
All files and folders for all users, or a set of specified users, including documents, spreadsheets, presentations, images, videos, and other file types.
All folders and files shared with the user being processed. For instance, all data accessible to a user is backed up in the context of that user. If the same folder is shared with ten users, it is backed up ten times (once per user). Deduplication ensures that only one physical copy is stored.
The version history of files, including all previous revisions and versions that have been trashed.
Set the Access Control List (ACL) for backed-up content to the user whose account the content belongs to. Similar to O365 mailboxes and OneDrive for Business, existing ACLs are ignored, and a specific user's ACL is applied.
All tags applied to files.
Notes for collaborative note-taking. The raw Boxnote file is backed up and can be restored properly.
Delete file versions and files that match the deletion policy. If the last version of a file is deleted, the file is removed. An option to purge deleted content (bypassing the Box trash) is available.
Missing files can be restored with their entire version history.
Existing files will have only the latest version restored from the backup and made the current version.
This data in the Salesforce environment is protected using the Cohesity Alta SaaS Protection Salesforce connector. It supports the backup and restore of the following:
Data
File/attachments/Salesforce CRM
Metadata