Before configuring CloudM Backup, ensure you have the following components in place.
General prerequisites
| Requirement | Detail |
|---|---|
| Google Workspace tenant | An active Google Workspace tenant. |
| CloudM subscription | CloudM Backup is available on Essential, Pro, and Enterprise tiers. Refer to What's included in your CloudM Automate tier for details. |
| CloudM platform | The CloudM Google Workspace Marketplace app must be installed. |
| Domain-wide delegation | A GCP Service Account with Domain-Wide Delegation is required. Follow the steps in Provide a Google Cloud service account with domain-wide delegation. |
| Storage provider | Access to either Google Cloud Platform (GCP) or Amazon Web Services (AWS) to create your backup storage buckets. |
Storage provider prerequisites
Google Cloud Storage (GCS)
| Requirement | Detail |
|---|---|
| GCP access | Access to GCP via the Google Cloud Console. |
| Billing account | A valid Google Cloud Billing Account. |
| GCP project | A new, customer-owned Google Cloud Project with the Billing Account assigned to it. |
| Service account | A Google Cloud Service Account created within your project, configured with domain-wide delegation. See Provide a Google Cloud service account with domain-wide delegation. |
| Storage bucket region | Your storage bucket must be in the same region as your Google Workspace tenant for optimal performance. Refer to Storage Configuration FAQs for supported regions. |
| Cloud KMS API (optional) | To add an additional layer of encryption, enable the Cloud Key Management Service (KMS) API in GCP. Search for KMS in the GCP search bar or navigate to Security > Key Management and select Enable if prompted. |
Amazon S3
| Requirement | Detail |
|---|---|
| AWS access | Access to AWS via the AWS Management Console. |
| Billing account | A valid AWS Billing Account. |
| IAM user | An IAM User with access credentials configured. |
| IAM policy | An IAM Policy to limit the user's access to the backup buckets. |
| Custom KMS key (optional) | AWS S3 encrypts data at rest by default. You can use a custom KMS key for a higher level of security if needed. |
Need help? Contact CloudM Support