If you prefer to manually register the app, log on to the Azure portal.
Register Azure Active Directory in the Azure Portal
-
In the navigation pane, click App registrations.
The App registrations page appears.
-
Click New registration.
The Register an application screen appears.
-
In the Name box, type a name for the app.
-
Under Supported account types, select Accounts in this organizational directory only (tenant_prefix - Single tenant).
-
Click Register.
-
Copy and paste the following values in a file or other document that you can access later:
-
Application (client) ID
-
Directory (tenant) ID
You will enter these values in the Metallic software when you create the Azure AD app.
-
-
From the left navigation pane, click Certificates & secrets, and then copy the client secret value shown in the page.
-
In the navigation pane, click API permissions.
-
Click Add a permission.
The Request API permissions page appears.
-
Click Microsoft Graph and complete the following steps:
-
Click Application Permissions.
-
Select the following permissions:
-
Application: Application.ReadWrite.All. This API permission is required to backup and restore the Registry and Enterprise applications.
-
AppRoleAssignment: AppRoleAssignment.ReadWrite.All. This API permission is required to backup and restore the Registry and Enterprise applications.
-
AuditLog: AuditLog.Read.All. This API permission is required to backup the Office 365 agents.
-
Directory: Directory.ReadWrite.All. This API permission is required to backup your organization's directory.
-
Domain: Domain.ReadWrite.All
-
Group: Group.ReadWrite.All. This API permission is required to backup and restore Groups.
-
Reports: Reports.Read.All. This API permission is required to backup the Office 365 agents.
-
RoleManagement: RoleManagement.ReadWrite.Directory. This API permission is required to backup and restore the Azure Active Directory objects.
-
User: User.ReadWrite.All. This API permission is required to backup and restore the user profiles.
-
-
Click Add permissions.
For more information regarding permissions, see Microsoft Permissions.
-
-
Return to the Request API permissions page.
-
On the app API permissions page, click Grant admin consent for tenant_name.