Connecting sources
A source is where Restow backs up from. Restow supports two kinds: Microsoft 365 tenants (through Microsoft Graph) and IMAP mailboxes (through IMAP, password-authenticated today; OAuth2 for Microsoft 365 or Google mailboxes accessed over IMAP comes in a later release). A third kind, Imported mail files, holds mail you bring in from files (see below). Servers and client computers are not sources: see Servers and clients are not sources. This page is the reference for how sources work day to day; for the exact, step-by-step walkthrough of connecting your first source, including the Entra app registration and its permissions, see First steps.
Microsoft 365
Section titled “Microsoft 365”Restow talks to Microsoft 365 exclusively through the Microsoft Graph API, never Exchange Web Services (EWS) or PowerShell remoting, both legacy paths Microsoft is retiring. Connecting a tenant uses the Entra admin-consent flow:
- An administrator with the right privileges in the Microsoft 365 tenant grants Restow the permissions it asks for, scoped to what backup and restore actually need.
- Restow checks the grant and reports exactly what was and was not consented to: a partial consent is shown as such, not silently treated as complete.
- Once connected, Restow synchronizes the tenant’s directory (users, mailboxes, OneDrives) via Entra ID sync, on the protection scope you choose: all users, a specific group, everyone except an exclusion list, or only selected objects (mailboxes and OneDrives an admin picks individually, one at a time or through bulk Include, Exclude and “Follow the rules again” actions on the Protected objects page, including “select all N matching” the active filter, up to 1,000 objects at once). A newly created source starts in the “all” or “group” scope; switch it to “only selected objects” afterward under Protected objects if that’s what you want.
Connecting a source, or re-verifying one whose first sync never ran, queues that directory sync immediately, instead of waiting for the next scheduled run (up to six hours by default): a newly connected tenant’s mailboxes and OneDrives don’t sit empty in the meantime.
Backups then run incrementally using Microsoft Graph’s delta query support, so each run after the first only has to look at what changed. A newly protected object also gets its first backup queued automatically the moment it becomes active (an include, a directory sync finding it newly active, or, for IMAP, an account import) rather than waiting for the tenant’s next scheduled backup window.
For an IMAP source, you provide the server (host, port, security) and credentials. Today that means regular username/password authentication only, one password per source; OAuth2 for providers that offer it (including Microsoft 365 and Google mailboxes reached over IMAP instead of Graph) comes in a later release, not in 0.1.0. Because IMAP-only mailboxes do not have an Entra directory to sync from, you add them as a manual list or import them from a CSV file.
An IMAP source currently stores one password, shared by every account added under it. There is no per-mailbox IMAP credential in this release. If your provider requires a distinct password per mailbox, that isn’t supported yet.
Imported mail files
Section titled “Imported mail files”Imported mail files is a source that holds mail you bring in from files instead of syncing it from a server: EML files, folders or ZIP archives, MSG, MBOX (Thunderbird, Apple Mail) and MailStore exports in EML or MSG form. There is one per tenant, with no server and no credentials. Add it under Sources → Add source → Import mail files, then upload files in the browser or pick files from the tenant’s folder on the server.
Nothing is backed up from this source, because there is no mailbox to read from. Each import instead produces an imported mailbox that you browse and restore in the Restore explorer, export as files, and optionally ingest into the archive. See Mail file import and export.
Servers and clients are not sources
Section titled “Servers and clients are not sources”Servers and client computers are not sources. They are endpoints: a small agent on the machine sends file backups to your Restow instance, and you set them up in the section for endpoint backup, not under Sources. See Endpoint backup.
What connecting a source does not do
Section titled “What connecting a source does not do”Connecting a source does not immediately expose any mailbox data anywhere in the Restow UI beyond backup status: end users only ever see their own data after they sign in themselves (see For end users), and every administrator read of user data is written to the audit log.