Backup & Recovery
Back up Google Workspace, Microsoft 365 and Linux servers, see which accounts are protected, and restore to the same account, another account, another organization, or from Google to Microsoft and back.
What the page is for
Backup & Recovery is a page in the Lavawall® console. Lavawall is the RMM, security, and compliance platform from ThreeShield, built and hosted in Canada.
Use it to add the Google Workspace and Microsoft 365 organizations and Linux servers you protect, to check that every account was backed up completely, and to restore or download what you need. Backups run on a schedule you choose, three times a day by default, and each run sends only what changed.
Google Workspace backups cover Gmail, Drive, Calendar, Contacts and Tasks, and optionally shared drives. Microsoft 365 backups cover mail, OneDrive, Calendar and Contacts, and optionally shared mailboxes, SharePoint sites and Teams chats. Mail, calendars and contacts are kept in standard formats (.eml, .ics and .vcf), so they can be restored into either service or downloaded and opened in common mail and calendar apps.
When someone leaves the organization, their account's backups are kept and can still be restored, for example into a manager's mailbox. Dates are shown in your local time.
What you see
- Security alerts: shown only when a backup looks like ransomware is at work, such as many files changed or renamed at once.
- Storage & capacity: the space your backups use against your plan's storage.
- Protection & activity: what is protected and how backups went over the Time range you choose (14, 30 or 90 days).
- Recent snapshots: each backup run with what it covered, how many files and how many changed.
- Restore & export jobs: every restore and download you queued, its status, and a download link when a download is ready.
- Search files & build a restore: find files by path, type, size or date in any backup, see a file's change history, and build a restore.
- Backup relays and Backup agents: the relay that runs your cloud backups and the agents on your servers. A super-admin approves each one.
- Backup sources: each Google Workspace organization, Microsoft 365 tenant and server you back up, with Add source, Back up now, Pause and Resume.
- Accounts: every account in the chosen Google Workspace or Microsoft 365 source, with its status, Last complete backup, items, size, a note, and Restore this account.
- Backup errors: every backup or restore problem, with the time, what was running and the details, and Resolve once it is handled.
How to use Backup & Recovery
How to add a Google Workspace or Microsoft 365 organization
- Ask your Lavawall operator to set up the backup credential for the organization. They give you its Credential name. You never type passwords or keys into this page.
- Under Backup sources, click Add source and choose the Kind: Google Workspace or Microsoft 365.
- Enter a Label and the Credential name. Leave Backup interval (minutes) at 480 for three backups a day, or choose another interval.
- For Google Workspace, enter the Primary domain and the Administrator to act as. For Microsoft 365, enter the Tenant ID.
- Under What to back up, tick what you need. Tick Also back up shared drives (Google) or Include shared mailboxes and Also back up SharePoint sites (Microsoft) if you want those too. You can list particular SharePoint sites, or leave the box blank for every site.
- To back up only some people, list them under Only these accounts. To leave people out, list them under Skip these accounts. Otherwise every account is backed up, including new ones as they are added.
- Click Add. The first backup starts at the next scheduled time, or click Back up now.
How to check that every account is backed up
- Under Accounts, choose the Source.
- Read the summary line, for example how many accounts are up to date and how many need attention.
- Choose Needs attention under Status to list only the accounts with a problem, or type in Filter accounts to find one person. Click a column heading to sort, for example by Last complete backup to find the oldest.
Each account shows one of these statuses:
- Up to date: the last backup finished with nothing missed.
- Partly backed up: the backup finished but some items could not be copied. The note says how many. They are tried again on every backup, and the account is never shown as up to date while anything is missing.
- Nothing to back up: for example the person has no mailbox or drive, or the account is on the skip list. The note says why.
- Left the organization (kept): the account is no longer in the directory. Its backups are kept and can be restored.
- Failed, Waiting or Running: the backup did not finish, has not started yet, or is in progress.
How to restore an account
- Under Accounts, click Restore this account on the person's row. The restore builder fills in that account. To restore one folder or a few files instead, search under Search files & build a restore and pick them.
- Choose the Point in time to restore from.
- Under Deliver to, choose Google Workspace or Microsoft 365. Either one works with either kind of backup.
- Enter the Target credential name your Lavawall operator gave you for restores, and the Administrator to act as (Google) or Target tenant ID (Microsoft).
- Under Restore to, choose Same account(s), Another account or Another organization. For another account, enter it under Restore everything into this account, or list several under Map accounts, one per line, such as
jane@example.com = manager@example.com. - Under What to restore, tick Mail, Files, Calendar, Contacts, Tasks, SharePoint sites or Shared drives.
- Optionally enter Put restored items in a folder named. When you restore into a different account, a folder named "Restored from" the original account and the date is used automatically, so nothing mixes with that person's own mail and files.
- For files, keep Add alongside existing files (recommended), which puts them in a dated folder, or choose Restore to original locations. A file that already exists is never overwritten: the restored copy gets a new name.
- Click Queue restore. Follow it under Restore & export jobs.
How to move a mailbox or drive from Google Workspace to Microsoft 365, or the reverse
- Start a restore of the account as above.
- Under Deliver to, choose the other service, then Another organization, and enter that organization's target credential name and tenant ID or administrator.
- Enter the account in the other service under Restore everything into this account, or use Map accounts for many people at once.
- Click Queue restore. Mail keeps its folders (Gmail labels become folders), and calendars, contacts and files move with it. Google Docs, Sheets and Slides arrive as Word, Excel and PowerPoint files.
How to download mail, calendars, contacts or files
- Build the restore as above, and under Deliver to choose Download.
- Under Download as, choose ZIP file(s), or Files into a folder (agent) to have an agent save them to a folder on one of your servers.
- Under Format, choose Mail, calendar and contact files (.eml, .ics, .vcf), One mailbox file per folder (.mbox) for apps such as Thunderbird and Apple Mail, or Exactly as backed up.
- Click Queue restore, then click download under Restore & export jobs when it is ready. Large downloads are split into parts and can be resumed if the connection drops.
How to find an older version of a file
- Under Search files & build a restore, choose the Unit and search for the file.
- Click History on the file to see every version, when it changed and its size.
- Click Restore this on the version you want.
Tips
- Restores add to what is there. Running the same restore again skips what was already restored, so you can safely restart a restore that stopped.
- A restore that is started again on another day continues in the same dated folder instead of creating a second one.
- Backups of people who leave are kept for as long as your retention allows, even after the account is deleted from Google Workspace or Microsoft 365.
- Teams chats can be backed up once Microsoft has approved your tenant's use of the Teams export feature. Backed-up chats are kept for reference and can be downloaded. They are not put back into Teams.
- A file in a backup whose name starts with a dot or an underscore is shown in search with a
u_in front. It is restored and downloaded with its real name. - To choose where backups are kept, or to see the space they use, open Backup Storage.
Troubleshooting
- An account shows Partly backed up
- Some items could not be copied, often because the service was busy. They are tried again on every backup. If the number does not go down after a day, open Backup errors for the reason.
- An account shows Nothing to back up
- The person has no mailbox, drive or calendar, or is on the skip list. The note says which.
- Nobody was marked as having left, but an error says the directory listing looked wrong
- When the list of accounts suddenly shrinks by more than half, Lavawall assumes a permission or service problem rather than mass departures, and changes nothing. Check the backup credential with your Lavawall operator.
- "Enter the target credential name your Lavawall operator provided"
- Restores use a separate credential with permission to write. Ask your Lavawall operator for its name.
- "To restore into another account, enter the target account or map the accounts"
- Fill in Restore everything into this account, or add lines to Map accounts.
- "Line 2 of Map accounts must look like source@domain = target@domain"
- Each line needs one address, an equals sign and another address.
- A shared drive or SharePoint site was restored into a person's drive
- When you move shared drives to Microsoft 365, or SharePoint sites to Google Workspace, they go into the drive of the account you named, in a folder for each one, because the two services organize shared storage differently.
Related articles
Still need help?
Search the support centre, or contact our support team and tell us which page you were on:
- Chat now: use the chat button in the bottom-right corner of this page to reach our team right away. Where cookie consent is needed, the chat starts after you accept (cookie settings).
- Email: send our support team a message through the contact page. It goes straight to a person.
- Phone: AB: 1-403-538-5053, BC: 1-778-731-1339, ON: 1-289-724-8829, US: 1-406-988-7333, UK: +44 20 3695 9786.