Docs

Backup overview

How Tenvara backs up devices and Microsoft 365, how the Backup area is laid out, and how to read the overview page.

Tenvara backs up two things:

  • Devices, through the agent you already install: whole volumes as images, virtual machines on Hyper-V hosts and Proxmox VE nodes, and chosen folders file by file (the only kind on a Mac).
  • Microsoft 365, straight from Microsoft for each customer tenant: mailboxes, OneDrive, calendars, contacts, SharePoint sites and Teams.

Both land in the same encrypted, deduplicated storage, are scheduled and kept the same way, and are restored through one guided Restore flow.

The Backup overview with protected devices, Microsoft 365, success rate and storage
The Backup overview with protected devices, Microsoft 365, success rate and storage

How it works

Devices

When you protect a device, the agent downloads a small backup helper onto it and keeps it running and up to date. There is nothing to install by hand, and the helper only goes onto devices you protect.

  • The helper reads the data on the device and sends it to your backup storage over HTTPS. It encrypts the data before it leaves, so the backup server never sees your files in plain text during a backup.
  • Each customer has one repository for its devices. Identical data across that customer's machines is stored once, so backing up ten similar laptops costs little more than one.
  • Only changed data is sent after the first backup.
  • Restores run on the device itself, from the same repository.

Microsoft 365

Microsoft 365 backup reads each connected tenant through Microsoft Graph, using one app registration you set up once and each customer's admin consent. Each run fetches only what changed since the last one, so frequent runs stay small.

Storage and encryption

Backups are stored in one repository per customer and source, either in a folder on the backup server or in S3-compatible storage. Everything is encrypted with a master key that Tenvara creates on first start. See Setting up backup.

Warning: If the master key is lost, no backup can ever be restored. Keep a copy of it away from the backup server. The Status tab in backup settings shows how.

The Backup sidebar

Open Backup from the rail. The sidebar has:

Item What it shows
Overview The page described below
Devices Every device with the agent and whether it is backed up
Microsoft 365 Each customer's tenant and what is protected in it
Jobs Every backup, restore, download, directory sync and maintenance run
Restore The guided restore flow
Devices views Protected, Failing, Overdue and Not protected
Jobs views Running now, Failed and errors, Restores and downloads
Backup settings Storage, defaults, the Microsoft 365 app registration and status

Reading the overview

The top row sums up backup across every customer:

  • Protected devices: how many devices are protected, with how many are failing or overdue underneath.
  • Microsoft 365: how many users, sites and teams are protected.
  • Success, last 24 hours: the share of runs that succeeded, with the number of runs and failures, and the figure for the last seven days.
  • Storage used: how much space backups take, and underneath how much data they protect. The difference is what deduplication and compression save.

Below that:

  • Needs attention lists failed and overdue backups, new devices left unprotected, helpers that will not start and tenants that refuse sign-in, most serious first. Each has a button to act on it, such as See the log or Review.
  • Last 14 days gives each customer a strip of their daily backup results, so a pattern of failures stands out.
  • Recent jobs lists the newest jobs. All jobs opens the Jobs list.

Settings and Restore at the top right go straight to backup settings and the restore flow.

Where else backup shows up

Backup is built into the rest of Tenvara rather than living only in its own area:

  • Customer page: a Backup tab lists that customer's devices and tenants with protection, Back up now and Restore, their recent jobs, and their schedule and retention. The overview has a short backup summary.
  • Device page: a Backup section with the protection switch, what is backed up, the schedule, recovery points and recent jobs. See Protecting devices.
  • Devices list: a backup column and views, and Back up now on the row and in Cmd+K.
  • Alerts: failed and overdue backups raise alerts that your alert rules can turn into tickets. See Backup alerts and troubleshooting.
  • Home: a backup line with how many are protected, how many are failing, and success in the last 24 hours.

Backup and the Backup module

Backup is a module. In Modules you can switch Backup off. While it is off, no scheduled backups, directory syncs or checks run. Queued jobs wait and start once it is on again, and running jobs finish. Anyone who could see backup sees "Backup is switched off" instead of the backup pages.

Who can see and change backup is set in Roles and permissions.

In this section

Was this page helpful?

Thanks for the feedback.