Skip to content

SaaS-Backup

CloudRebuild backs up Microsoft 365, Google Workspace and Microsoft Intune on a dedicated engine, isolated from cloud infrastructure backup. Authentication is application-permission and certificate-based, admin-consented, so backups run unattended at 3am with nobody signed in.

Why SaaS needs its own engine

SaaS backup and infrastructure backup fail in different ways and at different rates. CloudRebuild runs the SaaS Backup Engine with separate API servers, worker pools, queue namespaces and database schemas. A stalled Graph API tenant cannot consume the capacity your infrastructure restores depend on, and neither engine can reach the other’s data.

Microsoft 365

Full workload coverage across the suite, via admin-consented Microsoft Graph permissions.

  • Exchange Online — mail across all folders with labels and metadata, calendar events including recurrences, contacts and contact groups.
  • SharePoint Online — sites and subsites, document libraries and lists, site permissions and sharing settings.
  • OneDrive for Business — personal drives, shared drives and folders, version history to a configurable depth.
  • Microsoft Teams — channel messages with thread context, channel metadata and configuration, team membership.
  • Identity & directory — read-only configuration backup, group memberships and roles, application registration snapshots.

Google Workspace

OAuth2 service account authentication with domain-wide delegation, scoped to the minimum required permissions.

  • Gmail — mailboxes and all labels, thread and message metadata, attachment handling.
  • Google Drive — personal and shared drives, file permissions and sharing, folder hierarchy preservation.
  • Google Calendar — events and recurrence rules, calendar access controls, shared calendars.
  • Google Contacts — user contact directories, contact groups, directory-level contacts at admin scope.

Microsoft Intune

Policy and configuration backup for your Intune-managed estate. Read-only and admin-consented.

  • Device configuration profiles — all platform-specific profiles, with assignments and scope tags included in the snapshot.
  • Compliance policies — per-platform device compliance rules, with non-compliance actions and notification templates captured.
  • App protection policies — MAM policies for managed applications.
  • User and group assignments — so a restored policy lands on the same population.

Common questions

Doesn’t Microsoft already back up Microsoft 365?

Microsoft operates the service and protects its own infrastructure, and provides retention and recycle-bin features. That is a different guarantee from an independent, point-in-time copy you control and can restore on your own schedule. This distinction is the reason most compliance frameworks treat SaaS backup as the customer’s responsibility.

What permissions does CloudRebuild need?

Application permissions, admin-consented, certificate-based for Microsoft 365 and Intune; an OAuth2 service account with domain-wide delegation for Google Workspace. Intune and directory backups are read-only.

Can I license SaaS backup without cloud infrastructure backup?

Yes. The SaaS Backup Engine runs independently and can be licensed on its own — see pricing.

Why certificate-based authentication rather than a user account?

Backups run on a schedule, unattended. Delegated user authentication breaks the moment that user’s session expires, their password rotates or MFA challenges them. Application-permission auth with certificates is built to run with nobody signed in.

Request a demo to see SaaS backup running against your tenant.