To work with SharePoint locations, you must set up a valid level of permissions. When you work with individual Sites or Site Collections in the Navigator pane of Essentials, the lowest level of user to connect to a site is a Site contributor. However, this level allows a minimal list of actions (view structure, views, content etc.). With this permissions level, for example, we reconnect to use users who have direct site collection administrator permissions.
When you work in Hyper Migration Mode and do bulk migrations using SharePoint Administrator or Global administrator. An account with less privileges will only be able to perform a limited set of migrations.
The Essentials tool requests certain user roles to start and successfully finish hyper migration or hyper backup jobs. These administrative accounts are required to connect to the tenant level, to each site collection, users OneDrives, Office 365 groups, Microsoft Teams sites, etc. In order to connect to all of this you must be either a Global Administrator or a SharePoint Administrator. If you use an Exchange Administrator or Billing Administrator, or any other user role, the Migration will fail. This is because Essentials will not be able to access the target site collection in order to upload content and/or the azure job would be restricted by Office 365.
URLs that need to be Unblocked.
Purpose |
URL |
---|---|
Connection to Quest license server |
|
Migrating to SharePoint Online |
|
Migrating Nintex Forms and/or workflows to SharePoint Online |
|
Location for AutoUpdate |
The first time that OAuth Authentication is selected when connecting to SharePoint Online, the Quest SharePoint Migration Client application must be registered for the tenant.
It is recommended that an account with the Global Administrator role be used to register the application, because a Global Administrator can provide consent on behalf of the entire organization. In the event that a Global Administrator does not register the application, users with the Application Administrator role can register the application for their own account only.
IMPORTANT: For an Application Administrator, the the Quest SharePoint Migration Client application records current SharePoint permissions as part of the registration process. Therefore, a user who registers as an Application Administrator must already have the appropriate permissions to connect and perform migrations using OAuth authentication. For example, at the time of registration, a user who is going to make tenant-level connections must also be a SharePoint Administrator if they want the app to allow them to access to all site collections within the tenant and to be able to Paste as a Site Collection. Similarly, a user who will be migrating Managed Metadata must also be a Term Store Administrator at the time of registration.
The following table provides an overview of the Account Permission required to perform various operations for and with Essentials.
Operation |
SharePoint | ||||
Global |
Application Administrator
|
Farm or SharePoint Administrator |
Site Collection Administrator |
Term Store Administrator
| |
Connecting to SharePoint | |||||
Client Side Object Model Connection (Site-level) |
ü |
- |
ü |
ü |
ü |
Office 365 Tenant Connection |
ü |
- |
- |
ü |
ü |
Migration Actions | |||||
Deploying Nintex Apps to SPO |
ü |
- |
- |
- |
- |
Migrating as a Site Collection |
ü |
- |
ü |
ü |
ü |
Transferring Columns into Managed Metadata |
ü |
- |
ü |
ü |
ü |
Content Migrations to SharePoint Online |
ü |
- |
- |
ü |
ü |
OneDrive Account Migrations |
üWith Provisioning |
- |
- |
- |
- |
SharePoint Migrations |
ü |
- |
ü |
ü |
ü |
SharePoint On-Premises Migration |
- |
- |
ü |
ü |
-
|
© 2024 Quest Software Inc. ALL RIGHTS RESERVED. Termini di utilizzo Privacy Cookie Preference Center