Backup & Recovery
Back up Google Workspace, Microsoft 365 and Linux servers, see which accounts are protected, and restore to the same account, another account, another organization, or from Google to Microsoft and back.
What the page is for
Backup & Recovery is a page in the Lavawall® console. Lavawall is the RMM, security, and compliance platform from ThreeShield, built and hosted in Canada.
Use it to add the Google Workspace and Microsoft 365 organizations and Linux servers you protect, to check that every account was backed up completely, and to restore or download what you need. Backups run on a schedule you choose, three times a day by default, and each run sends only what changed.
Google Workspace backups cover Gmail, Drive, Calendar, Contacts, Tasks, Google Chat (including the chat of Google Meet meetings) and shared drives. Microsoft 365 backups cover mail, OneDrive, Calendar and Contacts, shared mailboxes, SharePoint sites, Teams chats, Teams channels with their messages and files, and your Microsoft 365, Entra ID and Intune settings. See exactly what is backed up. Mail, calendars and contacts are kept in standard formats (.eml, .ics and .vcf), so they can be restored into either service or downloaded and opened in common mail and calendar apps.
When someone leaves the organization, their account's backups are kept and can still be restored, for example into a manager's mailbox. Dates are shown in your local time.
What you see
- Backup plan banner: shown only when new backups cannot run, or storage is nearly full, with what to do next and See storage and capacity. See Your backup plan and capacity.
- Security alerts: shown only when a backup looks like ransomware is at work, such as many files changed or renamed at once.
- Storage & capacity: whether backup is on (Backup enabled, Backup enabled, paused or Backup not enabled), the space your backups use against your plan's capacity, the Largest units, and Restore up to, how far back backups can be restored.
- Protection & activity: what is protected and how backups went over the Time range you choose (14, 30 or 90 days).
- Recent snapshots: each backup run with what it covered, how many files and how many changed.
- Restore & export jobs: every restore and download you queued, its status, and a download link when a download is ready.
- Search files & build a restore: find files by path, type, size or date in any backup, see a file's change history, and build a restore.
- Backup relays and Backup agents: the relay that runs your cloud backups and the agents on your servers. A super-admin approves each one.
- Backup sources: each Google Workspace organization, Microsoft 365 tenant and server you back up, with Add source, Back up now, Pause and Resume.
- Accounts: every account in the chosen Google Workspace or Microsoft 365 source, plus rows for shared drives, SharePoint sites, Teams channels and Microsoft 365 settings, with the status, Last complete backup, items, size, a note, and Restore this account (or Download for content that is kept for download only).
- Backup errors: every backup or restore problem, with the time, what was running and the details, and Resolve once it is handled.
How to use Backup & Recovery
How to add a Google Workspace or Microsoft 365 organization
- Ask your Lavawall operator to set up the backup credential for the organization. They give you its Credential name. You never type passwords or keys into this page.
- Under Backup sources, click Add source and choose the Kind: Google Workspace or Microsoft 365.
- Enter a Label and the Credential name. Leave Backup interval (minutes) at 480 for three backups a day, or choose another interval.
- For Google Workspace, enter the Primary domain and the Administrator to act as. For Microsoft 365, enter the Tenant ID.
- Under What to back up, everything is ticked for a new source, and a line above the list says what that collects, including chats and your directory and policy settings. For Google Workspace that includes Google Chat (includes Meet chat) and Also back up shared drives. For Microsoft 365 it includes Shared mailboxes, Teams chats, Teams channels and channel files, Microsoft 365, Entra ID and Intune settings and Also back up SharePoint sites. Tick Room and equipment mailboxes if you want those too, and untick anything you do not need. You can list particular SharePoint sites, or leave the box blank for every site.
- To back up only some people, list them under Only these accounts. To leave people out, list them under Skip these accounts. Otherwise every account is backed up, including new ones as they are added.
- Click Add. The first backup starts at the next scheduled time, or click Back up now.
A source you added earlier keeps the choices it was saved with. New options are never switched on for it without you.
Your backup plan and capacity
Backups run while Lavawall Backup is enabled for your company, your company is active, and the plan has storage left. Your provider sets the plan's capacity; see Subscription and Billing. The Storage & capacity card shows where you stand:
- Backup enabled: backups run as scheduled.
- Backup enabled, paused: the storage in your plan is full, so new backups are paused.
- Backup not enabled: Lavawall Backup is not turned on, so no new backups run.
Below the badge, the bar shows the space used and the capacity, for example 1.5 TB of 2 TB and 75% used. It changes colour at your plan's warning level, and shows 100% used (full) when storage is full. A plan without a limit shows unlimited capacity.
Capacity is counted by the protected size: the size of the newest complete backup of each account, site, server or computer. Older restore points are not counted against it, so keeping backups for longer does not use up your capacity. Largest units shows what takes the most space.
What pauses, and what keeps working
When storage is full, backup is not enabled, or the company is not active:
- New backups do not run, neither on schedule nor with Back up now. This covers Google Workspace, Microsoft 365, servers and Windows computers.
- Restores, downloads and searches of past backups keep working.
- Nothing is deleted because backups are paused. Restore points are still removed only as your Restore up to setting says.
- When backup is not enabled or the company is not active, you cannot add a new source. When storage is full you still can, and it backs up once there is room.
New backups run again once the cause is fixed: capacity is added or space is freed, backup is turned on, or the company is reactivated.
Notifications when storage is nearly full or full
- Backup storage nearly full: raised when the space used reaches your plan's warning level, 90% unless your plan sets another.
- Backup storage full, backups paused: raised at 100%.
Both appear in the notification bell, for your company and for its MSP, and open the Storage & capacity card. Each is raised once, and closes by itself when the space used drops back down. To have them emailed, see Notification Setup. Nothing is raised for a plan with unlimited capacity.
How to deal with storage that is nearly full
- Click See storage and capacity in the banner, or open the notification.
- Check Largest units to see which accounts, sites, servers or computers use the most space.
- Ask your provider to add capacity, or back up less, for example by leaving out accounts or folders you do not need.
What is backed up
Google Workspace
- Gmail, Drive (with Google Docs, Sheets and Slides saved as Word, Excel and PowerPoint files), Calendar, Contacts and Tasks.
- Shared drives.
- Google Chat: spaces, group chats and direct messages, with threads, reactions, edits and uploaded attachments. The chat of meetings scheduled in Google Calendar is part of Google Chat, so it is included. Chat logs saved with older meeting recordings are in the organizer's Drive and are backed up with it.
Microsoft 365
- Mail, OneDrive, Calendar and Contacts, for people and for shared mailboxes, including shared mailboxes nobody signs in to. Room and equipment mailboxes are optional.
- SharePoint sites.
- Teams chats: one-to-one, group and meeting chats, with their pictures.
- Teams channels: every team's settings, members, channels (standard, private and shared), tabs, channel messages and replies, and the files of every channel, each backed up once.
- Microsoft 365, Entra ID and Intune settings: directory details, groups, roles, app registrations, Conditional Access and other sign-in policies, and Intune device profiles, compliance and app settings, as readable files.
- Microsoft Loop components saved as files in OneDrive or in a Teams channel, like any other file.
Kept for download only. Google Chat, Teams chats, Teams channel messages and the Microsoft 365, Entra ID and Intune settings can be searched and downloaded from any backup, but they are not written back into Google or Microsoft. Neither service offers a way to put messages back as they were, and settings are safer to review and re-apply by hand. Files in Teams channels can be restored into SharePoint when SharePoint sites are also backed up; with SharePoint sites off, they can be downloaded.
Not included. Loop workspaces (shared and personal), notes kept in them, and Copilot Pages. Microsoft keeps these in separate storage that backup services cannot reach. Use Microsoft Purview or Microsoft 365 Backup to export them. Files that other organizations share with your people belong to those organizations and are backed up by them.
Teams chats and channel messages need Microsoft's approval
Microsoft only lets a backup app read Teams chat and channel messages after it approves the app for that use. Until then, everything else is still backed up, including teams, channels, members and channel files, and the account or Teams channels row shows a note that messages could not be read. Your Lavawall operator can request the approval with you.
How to set up Google Chat backup
- In the Google Admin console, add the three read-only Google Chat permissions to the Lavawall backup's domain-wide delegation:
chat.spaces.readonly,chat.messages.readonlyandchat.memberships.readonly. Your Lavawall operator gives you the full list for the backup. - In the Google Cloud project that holds the backup credential, turn on the Google Chat API.
- In the same project, configure a Chat app (Google Chat API, then Configuration): give it a name such as Lavawall Backup, an avatar and a description, and do not build it as a Google Workspace add-on. The app never joins a conversation and never posts anything; Google requires it before any chat can be read.
Until these steps are done, everything else is still backed up, and each account shows a note that Google Chat was not backed up and why.
How to check that every account is backed up
- Under Accounts, choose the Source.
- Read the summary line, for example how many accounts are up to date and how many need attention.
- Choose Needs attention under Status to list only the accounts with a problem, or type in Filter accounts to find one person. Click a column heading to sort, for example by Last complete backup to find the oldest.
Each account shows one of these statuses:
- Up to date: the last backup finished with nothing missed.
- Partly backed up: the backup finished but some items could not be copied. The note says how many. They are tried again on every backup, and the account is never shown as up to date while anything is missing.
- Nothing to back up: for example the person has no mailbox or drive, the account is on the skip list, or it is a kind of mailbox the source leaves out, such as a room mailbox (the note says "excluded by mailbox type"). The note says why, and earlier backups are kept.
- Left the organization (kept): the account is no longer in the directory. Its backups are kept and can be restored.
- Failed, Waiting or Running: the backup did not finish, has not started yet, or is in progress.
How to restore an account
- Under Accounts, click Restore this account on the person's row. The restore builder fills in that account. To restore one folder or a few files instead, search under Search files & build a restore and pick them.
- Choose the Point in time to restore from.
- Under Deliver to, choose Google Workspace or Microsoft 365. Either one works with either kind of backup.
- Enter the Target credential name your Lavawall operator gave you for restores, and the Administrator to act as (Google) or Target tenant ID (Microsoft).
- Under Restore to, choose Same account(s), Another account or Another organization. For another account, enter it under Restore everything into this account, or list several under Map accounts, one per line, such as
jane@example.com = manager@example.com. - Under What to restore, tick Mail, Files, Calendar, Contacts, Tasks, SharePoint sites or Shared drives. Chats, Teams channel messages and settings are left out of a restore; download them instead.
- Optionally enter Put restored items in a folder named. When you restore into a different account, a folder named "Restored from" the original account and the date is used automatically, so nothing mixes with that person's own mail and files.
- For files, keep Add alongside existing files (recommended), which puts them in a dated folder, or choose Restore to original locations. A file that already exists is never overwritten: the restored copy gets a new name.
- Click Queue restore. Follow it under Restore & export jobs.
How to move a mailbox or drive from Google Workspace to Microsoft 365, or the reverse
- Start a restore of the account as above.
- Under Deliver to, choose the other service, then Another organization, and enter that organization's target credential name and tenant ID or administrator.
- Enter the account in the other service under Restore everything into this account, or use Map accounts for many people at once.
- Click Queue restore. Mail keeps its folders (Gmail labels become folders), and calendars, contacts and files move with it. Google Docs, Sheets and Slides arrive as Word, Excel and PowerPoint files.
How to download mail, calendars, contacts or files
- Build the restore as above, and under Deliver to choose Download.
- Under Download as, choose ZIP file(s), or Files into a folder (agent) to have an agent save them to a folder on one of your servers.
- Under Format, choose Mail, calendar and contact files (.eml, .ics, .vcf), One mailbox file per folder (.mbox) for apps such as Thunderbird and Apple Mail, or Exactly as backed up.
- Click Queue restore, then click download under Restore & export jobs when it is ready. Large downloads are split into parts and can be resumed if the connection drops.
How to choose how far back backups can be restored
- Under Storage & capacity, choose Restore up to: 90 days, 3, 6 or 12 months, 3, 5 or 7 years back, or No limit.
- Click Save and confirm.
- Restore points older than the period are removed a few at a time. The latest backups and one restore point a day for the last month are kept, then one a week for about three months, then one a month (and one a year for the longest periods). The newest backup of each account or server is always kept, even when it is older than the period.
Only a super-admin can shorten the period. Administrators can lengthen it. The setting covers Google Workspace, Microsoft 365 and server backups; Windows computers are set in Endpoint Backup. Backups of an account or server with an open ransomware alert are never removed until the alert is handled.
How to find an older version of a file
- Under Search files & build a restore, choose the Unit and search for the file.
- Click History on the file to see every version, when it changed and its size.
- Click Restore this on the version you want.
Tips
- Restores add to what is there. Running the same restore again skips what was already restored, so you can safely restart a restore that stopped.
- A restore that is started again on another day continues in the same dated folder instead of creating a second one.
- Backups of people who leave are kept for as long as your retention allows, even after the account is deleted from Google Workspace or Microsoft 365.
- Teams chats and channel messages are backed up once Microsoft has approved the backup app for them (see Teams approval). Backed-up chats and messages are kept for reference and can be downloaded. They are not put back into Teams.
- To download a team's channels or your Microsoft 365 settings, click Download on the Teams channels or Microsoft 365, Entra ID and Intune settings row under Accounts. The settings include a readable index page.
- A file in a backup whose name starts with a dot or an underscore is shown in search with a
u_in front. It is restored and downloaded with its real name. - To choose where backups are kept, or to see the space they use, open Backup Storage.
Troubleshooting
- Backups paused: "Backups paused: storage is full"
- The space used has reached your plan's capacity. Restores and downloads still work and nothing is deleted. Ask your provider to add capacity, or back up less. New backups run again once the space used is below the capacity.
- Storage nearly full
- The space used has reached your plan's warning level. Backups keep running, and pause when storage is full. See How to deal with storage that is nearly full.
- Backups not enabled
- Lavawall Backup is not turned on for your company, so no new backups run. Backups already taken can still be restored and downloaded. Contact your provider to add Lavawall Backup to your plan.
- Company not active
- Your company is not active in Lavawall, so no new backups run. Restores and downloads still work. Contact your provider to reactivate the company.
- Plan not checked
- Lavawall could not check your backup plan just now. Refresh the page in a minute. New backups wait until the check succeeds.
- A source shows Paused: storage full, Not run: backup not enabled, Not run: company not active or Waiting: plan check
- The source was not backed up for the reason shown, which matches the banner above. It backs up again at its next scheduled time once the cause is fixed.
- "Lavawall Backup is not part of your plan"
- Your company has no Lavawall Backup and no earlier backups. Contact your provider to add it. Lavawall Backup is priced per TB of backup capacity.
- An account shows Partly backed up
- Some items could not be copied, often because the service was busy. They are tried again on every backup. If the number does not go down after a day, open Backup errors for the reason.
- An account shows Nothing to back up
- The person has no mailbox, drive or calendar, or is on the skip list. The note says which.
- The note says Google Chat was not backed up
- Google Chat is not set up for the backup yet. Follow How to set up Google Chat backup. The rest of the account is backed up and shows as up to date.
- The note says Teams messages are not readable
- Microsoft has not yet approved the backup app for Teams messages, or a permission is missing. See Teams approval. Everything else is backed up.
- The Microsoft 365, Entra ID and Intune settings row says some areas were skipped
- Each skipped area names the permission or licence it needs, for example an area that needs Intune or Entra ID P1. Everything else is saved. When there are many, the note ends with how many more there are; the full list is in the backup's summary file, which is included when you download the settings. Ask your Lavawall operator to add the permission if you want that area too.
- A mailbox shows "excluded by mailbox type"
- It is a shared, room or equipment mailbox, or an account without a licence, and the source's options leave that kind out. It has not left the organization, and its earlier backups are kept. Add a source with Shared mailboxes or Room and equipment mailboxes ticked to back it up again.
- "... can be downloaded but not restored into a service: choose Download"
- You chose only chats, Teams channel messages or settings. Under Deliver to, choose Download.
- Nobody was marked as having left, but an error says the directory listing looked wrong
- When the list of accounts suddenly shrinks by more than half, Lavawall assumes a permission or service problem rather than mass departures, and changes nothing. Check the backup credential with your Lavawall operator.
- "Only a super-admin can shorten how far back backups can be restored"
- Ask a super-admin to change Restore up to, or choose a longer period.
- "Enter the target credential name your Lavawall operator provided"
- Restores use a separate credential with permission to write. Ask your Lavawall operator for its name.
- "To restore into another account, enter the target account or map the accounts"
- Fill in Restore everything into this account, or add lines to Map accounts.
- "Line 2 of Map accounts must look like source@domain = target@domain"
- Each line needs one address, an equals sign and another address.
- A shared drive or SharePoint site was restored into a person's drive
- When you move shared drives to Microsoft 365, or SharePoint sites to Google Workspace, they go into the drive of the account you named, in a folder for each one, because the two services organize shared storage differently.
Related articles
Still need help?
Search the support centre, or contact our support team and tell us which page you were on:
- Chat now: use the chat button in the bottom-right corner of this page to reach our team right away. Where cookie consent is needed, the chat starts after you accept (cookie settings).
- Email: send our support team a message through the contact page. It goes straight to a person.
- Phone: AB: 1-403-538-5053, BC: 1-778-731-1339, ON: 1-289-724-8829, US: 1-406-988-7333, UK: +44 20 3695 9786.