Loading...
Loading...
Exchange backup jobs in Veeam Backup for Microsoft 365 or Veeam Data Cloud for Microsoft 365 run far longer than expected or fail to complete. The job log contains the following warnings and errors: Warning: Failed to retrieve Exchange Online REST API cmdlet information Warning: HTTP request timed out after 00:06:00. Warning: Cannot find Exchange Online REST API cmdlets Error: Contract schema check for the Exchange Online REST API failed Error: The user "<tenant>\<service-principal-id>" isn't assigned to any management roles. Additionally, when editing the Exchange backup job, the mailbox/user selection list may appear empty without any error message.
Veeam Backup for Microsoft 365 and Veeam Data Cloud for Microsoft 365 connect to Exchange Online using an Entra application registration that holds the Exchange.ManageAsApp permission and the Global Reader Entra role. As part of every Exchange job, the service validates the Exchange Online REST API connection by calling the CmdletInfo endpoint: https://outlook.office365.com/AdminApi/beta/<TenantId>/CmdletInfo This call requires the application's service principal to hold Exchange Online RBAC permissions. With the recommended configuration, those permissions are inherited indirectly: The Entra Global Reader role places its members into the Microsoft-managed Global Readers group. The Global Readers group is automatically added to the Exchange role group View-Only Organization Management. The View-Only Organization Management role group derives its actual EXO permissions from two role assignments: View-Only Configuration and View-Only Recipients. If either or both of these role assignments are removed from View-Only Organization Management (for example, as part of a security hardening exercise), the role group is left without permissions. Every identity that inherits from it loses its EXO RBAC access, including the application principal used by Veeam Backup for Microsoft 365 or Veeam Data Cloud for Microsoft 365. When the connection check is then performed, the CmdletInfo call hangs and times out after 6 minutes. The check is repeated for each mailbox processed, which causes large Exchange backup jobs to run extremely long or to fail to complete.
Issue Confirmation Connect to Exchange Online PowerShell as a tenant administrator and run the following commands:
Manually removing the Global Readers group from View-Only Organization Management has no lasting effect. Microsoft re-adds the membership automatically. Only the role assignments within the role group are user-controllable, which is why this issue occurs when those assignments are removed. This behavior is observed in both cloud-only and hybrid Exchange organizations. If the diagnostic command returns the expected role assignments but the symptoms above persist, open a support case and include the relevant Exchange backup job log so support can review the connection telemetry.
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.