Adding a SaaS instance as a source

To be able to protect SaaS application data, you must add the SaaS instance to which the SaaS application is related as a source to R‑Cloud.

Prerequisites

  • Only if you plan to add the SaaS instance to a protection set other than the default one. The protection set must be created. For instructions, see Creating a protection set.

  • Only if the R-Cloud module supports OAuth 2.0 and you want to use it to access the SaaS application data. The OAuth 2.0 application credentials must be available to R‑Cloud. You can use the global OAuth 2.0 application credentials that R‑Cloud generates automatically for you and adds them to R‑Cloud, or the custom OAuth 2.0 application credentials that you need to add to R‑Cloud yourself.

    You can add the custom OAuth 2.0 application credentials as part of adding a SaaS instance, or use the ones that you already added as part of adding a cloud account to R‑Cloud. For details, see Adding OAuth 2.0 application credentials.

Considerations

  • Only if you plan to select a data mover configuration to be assigned to all the entities that belong to this source. Consider the following:

    • You can create the data mover configuration that you want to be assigned to the entities by following the procedure described in Creating a data mover configuration or as part of adding the source.

    • If you later assign a different data mover configuration to an entity that belongs to the source by specifying the Data Movers configuration property, that data mover configuration will be used instead of the one that was used for the source.

  • Only if the R-Cloud module requires using a data mover configuration. The Use data mover configuration switch is automatically enabled. In this case, you must specify the preferred data mover configuration.

  • Only if the R-Cloud module supports OAuth 2.0. If renewing consent is required after you added a SaaS instance and granted access to the registered application, an event is created in R‑Cloud and an email is sent to the R‑Cloud administrator. You can renew consent by editing the application credentials of the SaaS instance in the Sources panel.

Procedure

  1. In the Sources panel, click Add Add.

  2. Select SaaS, and then click Next.

  3. From the R‑Cloud Module drop-down menu, select the appropriate R-Cloud module for the SaaS instance that you want to add to R‑Cloud.

  4. In the Display Name field, enter a display name for the SaaS instance.

  5. Only if you are adding the SaaS instance in the Subscription context. From the Protection Set drop-down menu, select the protection set to which you want to add the SaaS instance.

  6. Depending on whether the R-Cloud module supports OAuth 2.0, select the preferred authentication type, and then provide the required authentication information:

    • If the R-Cloud module supports OAuth 2.0 and you want to use it to access SaaS application data:

      1. From the Authentication Type drop-down menu, select one of the following authentication types:

        Authentication type Description
        OAuth 2.0 - authorization code

        Your application authorization code and the client credentials are exchanged for an access token that must be refreshed periodically or when the SaaS instance configuration changes.

        OAuth 2.0 - authorization code with certificate Your application authorization code and the certificate are exchanged for an access token that must be refreshed periodically or when the SaaS instance configuration changes.
        OAuth 2.0 - client credentials Your application credentials are exchanged for an access token.
        OAuth 2.0 - client credentials with certificate

        Your application certificate is used for acquiring an access token.

        OAuth 2.0 - pre-approved client credentials Your application credentials are exchanged for an access token without the need to grant consent.
        OAuth 2.0 - pre-approved client credentials with certificate

        Your application certificate is used for acquiring an access token without the need to grant consent.

      2. Specify the requested authentication information.

      3. Above the application credentials list, click New New.

      4. From the Application Credentials drop-down menu, select the OAuth 2.0 application credentials that you want to add to R‑Cloud. If such OAuth 2.0 application credentials are not already added to R‑Cloud, you can add them as follows:

        1. In the drop-down menu, click Add Add New. You are automatically redirected to the Add OAuth 2.0 Application Credentials dialog box.

        1. In the Name field, enter a name for your OAuth 2.0 application credentials.

        2. From the Protection Set drop-down menu, select the protection set to which you want to add the OAuth 2.0 application credentials. By default, the OAuth 2.0 application credentials are added to the currently selected protection set.

        3. From the Application Platform drop-down menu, select the platform that hosts your registered application.

        4. In the Client ID field, enter the client ID of the registered application.

        5. From the Authentication Method drop-down menu, select one of the following authentication methods, and then do as requested:

          Authentication method Instructions
          Client Secret Enter the client secret of the registered application.
          Certificate
          1. Browse and upload the client private key.

          2. Only if the private key is encrypted. Enter the private key passphrase.

        6. Click Save.

      5. Click Grant Consent to grant access to the registered application. You are redirected to the platform that hosts your registered application.

    • If the R-Cloud module does not support OAuth 2.0: Select your authentication type, and then specify the requested authentication information, such as the organization name, the user name, API tokens, the preferred service account, and so on.

  7. For SaaS applications in Google Cloud: Depending on the service account that you want to be used for performing all operations on the target, do one of the following:

    Service account Instructions
    HYCU Managed Service Account (HMSA)
    1. Select the Use HYCU Managed Service Account check box, and then click Grant Consent to open the HYCU Managed Service Account configuration wizard that guides you through all the required steps of enabling the HMSA for the SaaS instance.

    2. Return to the R‑Cloud web user interface.

    Service account other than the HMSA

    From the Service Account drop-down menu, select the preferred service account.

    By clicking Add Add New, you are automatically redirected to the dialog box that enables you to add the preferred cloud account to R‑Cloud, if not already added.

  8. Only if the R-Cloud module requires using a data mover configuration or if you want a specific data mover configuration to be assigned to all SaaS applications that belong to the source you are adding. Enable the Use data mover configuration switch, and then, from the Data Movers drop-down menu, select the preferred data mover configuration.

    By clicking Add Add New, you are automatically redirected to the dialog box that enables you to add a data mover configuration, if not already added. For details, see Creating a data mover configuration.

  9. Click Save.

The SaaS instance is added to the list of sources. You can later do the following:

  • Edit any of the existing SaaS instances (click Edit Edit and make the required modifications).

  • Remove the SaaS instances that you do not need anymore (click Remove Remove). Before removing a SaaS instance from R‑Cloud, make sure that the following prerequisites are met:

    • The policy must be unassigned from the SaaS application related to the SaaS instance. To unassign the policy from the SaaS application, in the SaaS panel, select the application, and then click Set Policy Set Policy. Click Unassign, and then click Yes to confirm that you want to unassign the policy from the selected SaaS application.

    • No restore points may be present for the SaaS application related to the SaaS instance. If the SaaS application still has valid restore points, you must expire them manually and wait for the next retention maintenance task to finish before removing the SaaS instance. For details on how to expire restore points, see Expiring backups manually.

    • No tasks with the Ready status or a progress bar indicating the Running status may be present for the SaaS application related to the SaaS instance.