Microsoft 365 and IMAP backup
Restow backs up Exchange Online mailboxes (mail, calendar and contacts) and OneDrive, incrementally through the Microsoft Graph API, and any IMAP mailbox over IMAP, password-authenticated today (OAuth2 sign-in for Microsoft 365- or Google-hosted IMAP sources comes in a later release). Every restore drawn from that backup is written to the hash-chained audit log in every edition: who ran it, when, for whom, and from where. The audit log viewer (search, details, chain verification) is part of Business and Service Provider and still in development.
How the Microsoft 365 side works
Backup runs incrementally via Microsoft Graph's delta-query
mechanism, so a normal run only fetches what changed since the last
one instead of re-scanning a whole mailbox or OneDrive. Users,
mailboxes and OneDrives come in automatically through Entra ID
directory sync (Graph users/delta), with the protected
scope controlled per tenant: everyone, a specific group, or an
exclusion list. Microsoft throttles the Graph API, especially for a
large tenant's first backup. Restow shows that wait instead of
hiding it, the same honesty rule that applies to every other
progress or limit in the product.
How the IMAP side works
Any IMAP mailbox is a valid backup source, authenticated today with a password. OAuth2 sign-in for IMAP sources hosted on Microsoft 365 or Google comes in a later release, not in 0.1.0. IMAP-only tenants (ones without an Entra ID directory to sync from) are added by a manual mailbox list or CSV import instead.
Servers, clients and mail files
Microsoft 365 and IMAP are not the only sources. In every edition, an agent for Linux and macOS backs up servers and clients to your own Restow, over outbound HTTPS only and append-only: the machine can add backups but never delete them. See server and client backup. Mailboxes that only exist as files (EML, MSG, MBOX, a MailStore export) can be imported as a legacy mailbox and exported again, see mail import and export.
When a backup fails
Every failed job, item, sync and verification says what happened, why and what to do, instead of showing a bare error string. Failures are classified under 88 stable cause codes: a missing Microsoft 365 permission, named; admin consent missing; a mailbox that is not licensed; throttling, with the wait Microsoft asked for; an IMAP login that failed; storage that is full or refuses access; a hash mismatch. Each one comes with next steps that link to the right settings page, and the technical details (HTTP status, Graph error code, request IDs, with secrets removed) stay available for a support case. See the failure explanations in the documentation.
Stated limits, not hidden ones
- Microsoft Teams messages are not part of the current scope.
- An IMAP source currently uses one login for all mailboxes under it (a master account or shared credentials); separate per-mailbox credentials, and OAuth2 sign-in as an alternative to a password, come in a later release.
- Google Workspace backup (Gmail, Google Drive) is in development. SharePoint and Exchange Public Folders are deliberately out of scope for now. PST and OST import is planned: today such files are recognised and refused with an explanation, and mail files come in as EML, MSG, MBOX or ZIP. See the roadmap for what's planned after.
- Server and client backup has no Windows agent yet, no disk images or bare-metal restore (it is file-based), and no LVM, ZFS or btrfs snapshots and no mTLS yet. Details on the server and client backup page.
Frequently asked
How does Restow back up Microsoft 365?
Incrementally, through the Microsoft Graph API: Exchange Online mail, calendar and contacts, and OneDrive, tracked with Graph's own delta-query mechanism so a run only fetches what changed since the last one, not a full re-scan every time.
Does Restow back up Microsoft Teams?
No. Teams messages are explicitly out of scope for the current version, stated on the roadmap, not silently left out.
How does IMAP backup work?
Password authentication today, one password per IMAP source. OAuth2 sign-in for Microsoft 365- or Google-hosted IMAP sources is planned for a later release. IMAP tenants without directory sync (i.e. not Microsoft 365) are added by a manual list or CSV import.
Can Restow also back up servers and laptops?
Yes, since 0.1.0 and in every edition: an agent for Linux and macOS backs up files to your own Restow over outbound HTTPS, append-only, so the machine can add backups but never delete them. Windows, filesystem snapshots (LVM, ZFS, btrfs) and mTLS are planned, and it is file-based, with no disk images or bare-metal restore.
What does Restow tell me when a backup fails?
What happened, why, and what to do. Every failed job, item, sync and verification is classified under one of 88 stable cause codes, for example a missing Microsoft 365 permission, admin consent missing, a mailbox that is not licensed, throttling with the wait Microsoft asked for, a failed IMAP login, storage that is full or refuses access, or a hash mismatch. The technical details (HTTP status, Graph error code, request IDs, with secrets removed) stay available for a support case.