Microsoft 365 Backup Job Failure

Product version: 11.2.2 

Last modified: 1 September 2026

Problem

The Microsoft 365 backup job fails.

Possible Causes and Solutions

EWS API Retired or Blocked by Microsoft

Microsoft retires the Exchange Web Services (EWS) API for Exchange Online. From October 1, 2026, Microsoft starts to block EWS in tenants that have no EWS allow list. On April 1, 2027, Microsoft removes EWS for all tenants. (Read more on Everything You Should Know About NAKIVO and EWS API Deprecation).

If EWS is not available in your Microsoft 365 tenant, the Exchange Online objects in the backup job fail. This cause applies to all versions of NAKIVO Backup & Replication.

The alarm has one of these messages:

  • Backup of the "<mailbox name>" mailbox failed because Exchange Web Services (EWS) is disabled for this mailbox.

  • Use of Legacy EWS API detected.

To resolve the issue, do the following:

  1. Click the user menu, then click About, to find your product version.

    • If you use v11.2.3 or later, go to Settings > Expert, set system.o365.mailbox.api.mode to graphonly, and save the change. Then run the backup job again.

    • If you use a version earlier than v11.2.3, update the product to v11.2.3 or later. This is the permanent solution. The product then uses the Microsoft Graph API and needs no allow list.

  2. If you cannot update the product now, ask your Microsoft 365 administrator to add the Azure Client ID of your NAKIVO application to the EWS allow list in the tenant. Note: this solution is not available after April 1, 2027, when Microsoft fully deprecate EWS API.

Insufficient Permissions

Your Microsoft 365 account credentials may lack the necessary permissions. 

Make sure that the Microsoft 365 (Exchange Online) credentials have sufficient permissions to be used by NAKIVO Backup & Replication.

Interrupted Connectivity

Incorrect network settings may cause a Microsoft 365 backup job to fail.

Make sure the network settings are configured correctly.

Temporary Java Transporter Folder Free Space Problem

The Microsoft 365 backup job may fail if the temporary java transporter folder is out of space.

The temporary java transporter folder must have more than 5GB of free space on disk for temporary files in tmp folder. The disk that installed this path should also have at least 10GB of free space available. The default path for the tmp folder is the following:

  • Win: C:\Program Files\NAKIVO Backup & Replication\transporter\java\tmp

  • Linux: opt/nakivo/transporter/java/tmp

To change tmp java transporter folder location, take the following steps:

  1. Stop the NAKIVO Backup & Replication Transporter service.

  2. Enable Expert mode in your instance by adding “expert” (or “&expert”) to the end of the URL of the Settings page.

  3. Locate the expert setting system.transporter.modern.arguments.

  4. Add this to the end of the string:

    -DtempPath={full directory}

    For example: -DtempPath=D:\Dtmp

  5. Start the NAKIVO Backup & Replication Transporter service.

Antivirus Software Problem

Some NAKIVO Backup & Replication actions may result in antivirus software flagging the solution as a threat.

Make sure the following path is added to the exception of the antivirus software:

C:\Program Files\NAKIVO Backup & Replication\transporter\java\tmp

Lack of RAM

The lack of sufficient amount of RAM may case the Microsoft 365 job to fail.

Refer to the following article.

MS Graph Forbidden

Microsoft Graph rejected the request sent during the Microsoft 365 backup operation. This usually occurs when access to a Microsoft 365 resource is denied due to insufficient permissions, security policies, or other Microsoft service restrictions.

Check the following:

  • Make sure the Microsoft 365 account or application used for the backup job has the required Microsoft Graph permissions.

  • Verify that admin consent has been granted for the required permissions.

  • Check whether Microsoft Entra Conditional Access or other security policies are blocking the request.

  • Review the backup job logs to identify the Microsoft Graph operation that was rejected.

Backup Repository Hit Storage API Limit

The storage service used by the backup repository rejects requests due to limits or restrictions.

Check the following:

  • Ensure the storage account has not reached its quota or usage limits.

  • Verify that the repository credentials have sufficient permissions.

  • If the repository uses cloud or object storage, review the bucket or container settings in the storage provider and ensure that object lock, immutability, or default retention policies are not preventing write or cleanup operations.

  • Retry the backup job after resolving the issue.

Other Causes

In case none of the solutions solve your problem, create a support bundle, and send it to us.