# Introduction

Taking your first steps into the world of backup doesn't have to be a challenge. We have prepared the following list of questions to make it easier for you to decide what kind of backup would suit your company best:

1. Do you want to use the on-premise version (deployed in your infrastructure) or the SaaS (cloud) version?
2. What is your goal? What results do you want to achieve?
3. How do you imagine a perfect backup solution? What are your desired essentials for a backup software?
4. What kind of data do you want to protect? What resources do you have to secure?
5. Have you already thought about the backup schedule? Is there a specific RTO/RPO you want to achieve?
6. Are there any policies, requirements or conditions you have to meet?
7. Do the resources you want to protect have any technological limitations or access restrictions?
8. What type of storage do you want to use (i.e., on-site, cloud)?
9. Who will manage your backup service? Would you need several accounts with different levels of permissions?
10. Do you need to integrate your backup service with an external identity provider (IdP) via SAML protocol?

Having these answered, you can head to [**GitProtect** website](https://gitprotect.io/) and check all available backup options to find the one which best suits your needs, or schedule a demo with our sales team to learn more about the **GitProtect** backup system and how it works.


# Licensing overview

Overview of GitProtect licensing models, including license types, usage-based components, and key licensing principles.

**Licensing in GitProtect defines how product usage rights are assigned and managed within an organization, covering subscription scope, activated instances, and available feature sets depending on the selected plan.**

***

## General information

Licenses are required to use **GitProtect** for backup and recovery. They define how data protection is enabled across different environments and workloads and are assigned based on the type and number of protected resources. Depending on the deployment scenario, licenses cover SaaS platforms, **Microsoft 365** organizations, and repositories, ensuring that each protected element is properly accounted for within the licensing model.

{% hint style="info" %}
To get a license, please contact one of our sales partners or email us directly at <sales@xopero.com>.
{% endhint %}

{% hint style="warning" %}
Cancellation and extension of a **GitProtect** license purchased through a marketplace (e.g., **Atlassian Marketplace**) are handled and billed directly by the marketplace, without **GitProtect's** involvement. If you encounter any issues with the transaction or marketplace functionality, **please contact the respective marketplace's support team first**.
{% endhint %}

***

## Pricing

**GitProtect** pricing is available on the [official website](https://gitprotect.io/pricing.html).

{% hint style="info" %}
To get a tailored offer for your business, please use the [contact form](https://gitprotect.io/contact-us.html) on the **GitProtect** website.
{% endhint %}

***

## License types <a href="#license_types_from_a_business_point_of_view" id="license_types_from_a_business_point_of_view"></a>

Below you can find all license types available in **GitProtect**, categorized by protected resource type.

### <mark style="background-color:$tint;">Microsoft 365</mark> <a href="#microsoft_365" id="microsoft_365"></a>

1. **Microsoft 365** — licenses for protecting **Microsoft Exchange** data (including individual mailboxes, shared mailboxes, calendars, contacts) and **OneDrive**, assigned based on the number of **Microsoft 365** user accounts.
2. **Microsoft 365 PRO** — licenses for protecting **Microsoft Exchange** data (including individual mailboxes, shared mailboxes, calendars, contacts), **OneDrive**, and **SharePoint**. Assigned based on the number of **Microsoft 365** user accounts.

{% hint style="info" %}
Shared mailboxes require the same licensing as individual user mailboxes, with each shared mailbox requiring one **Microsoft** user license.
{% endhint %}

### <mark style="background-color:$tint;">Git platforms</mark> <a href="#git_platforms" id="git_platforms"></a>

Licenses for protecting **Git** repositories (**Azure DevOps**, **Bitbucket**, **GitHub**, **GitLab**), assigned based on the number of repositories:

1. **GitProtect Enterprise (on-premises)** — a license type that enables backup of all on-premises systems installed across the entire company.
2. **GitProtect Enterprise (cloud)** — a license type that enables backup of all cloud-hosted systems across the entire company.
3. **GitProtect PRO (cloud)** — a license type that enables backup of the entire organization. It is designed for individuals, startups, and small teams.

{% hint style="info" %}
There is no need to assign a license to all repositories. The license is assigned only to the repositories that are to be protected.
{% endhint %}

### <mark style="background-color:$tint;">Jira</mark>

1. **Jira** — protection for cloud-hosted **Jira** instances, assigned based on the number of users; the license must cover all users in the protected **Jira** instance.

### <mark style="background-color:$tint;">Confluence</mark>

1. **Confluence** — protection for cloud-hosted **Confluence** instances, assigned based on the number of users; the license must cover all users in the protected **Confluence** instance.

***

## Backup agents (workers) <a href="#license_types_in_xopero_one_management_console" id="license_types_in_xopero_one_management_console"></a>

In addition to standard licenses, **GitProtect** provides supplementary free backup agent (worker) licenses used to initiate specific operations and processes within the software, depending on the use case or deployment scenario.

{% hint style="info" %}
In an on-premises deployment model, these licenses must be assigned to an installed agent.
{% endhint %}

Free worker licenses allow you to manage storage, restore backups, and back up resources locally, when combined with a dedicated **Microsoft 365**, **Git**, **Jira**, or **Confluence** license:

1. **Cloud worker** — agent responsible for running backup tasks in SaaS deployments. Each **GitProtect** environment is assigned one cloud worker.
2. **Local worker** — licenses for an agent responsible for running backup tasks in on-premises deployments. It allows the agent to be run on the same host as **GitProtect Management Service** and enables copying its settings. A maximum of one license is available in the license package.
3. **Feature worker** — licenses for an agent responsible for running backup tasks for **Microsoft 365**, **Git** platforms, **Jira**, and **Confluence**. It is always included in the license package in unlimited quantities.

{% hint style="danger" %}
Backup agents are used for process management and data restoration (e.g., restoring cloud platform data). A device assigned a free worker license **cannot perform backups of its own local resources**.
{% endhint %}

***

## Useful links and items

{% content-ref url="/pages/mbJ4FiIhRkMOFhK2dgJQ" %}
[License administration](/management/license-administration)
{% endcontent-ref %}


# Software information

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/srQ5F6tnpeA8r4mpbgA8">/pages/srQ5F6tnpeA8r4mpbgA8</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/xK9JJWFmkVYCqBknYEoP">/pages/xK9JJWFmkVYCqBknYEoP</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/CO7vhDWB9wYNj0IjKlNl">/pages/CO7vhDWB9wYNj0IjKlNl</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/zitku7YWZyE4tTpIJlPD">/pages/zitku7YWZyE4tTpIJlPD</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/cKKxZNagmCm6D5HjYzpl">/pages/cKKxZNagmCm6D5HjYzpl</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Supported platforms

Below you can find all supported OS for GitProtect and GitProtect worker.

{% tabs %}
{% tab title="GitProtect Management Service" %}

#### Supported operating systems: <a href="#management_service" id="management_service"></a>

* [x] Debian: 9+
* [x] Ubuntu: 16.04+
* [x] Fedora: 29+
* [x] CentOS: 7+
* [x] RHEL: 6+
* [x] openSUSE: 15+
* [x] SUSE Enterprise Linux (SLES): 12 SP2+
* [x] Windows Client: 7 +
* [x] Windows Server: 2012 R2 +

#### Supported web browsers: <a href="#supported_web_browsers" id="supported_web_browsers"></a>

* [x] Google Chrome
* [x] Opera
* [x] Mozilla Firefox
* [x] Microsoft Edge
  {% endtab %}

{% tab title="GitProtect worker" %}

#### Supported operating systems: <a href="#supported_operating_systems_1" id="supported_operating_systems_1"></a>

* [x] Alpine: 3.10+
* [x] Debian: 9+
* [x] Ubuntu: 16.04+
* [x] Fedora: 29+
* [x] CentOS: 7+
* [x] RHEL: 6+
* [x] openSUSE: 15+
* [x] SUSE Enterprise Linux (SLES): 12 SP2+
* [x] macOS: 10.13+
* [x] Windows Client: 7 +
* [x] Windows Server: 2008 R2 +
  {% endtab %}
  {% endtabs %}

***

## Useful links and items

{% content-ref url="/pages/xK9JJWFmkVYCqBknYEoP" %}
[System requirements](/gitprotect-software/software-information/system-requirements)
{% endcontent-ref %}


# System requirements

Below you can find system requirements for GitProtect Management Service and GitProtect worker.

{% tabs fullWidth="false" %}
{% tab title="GitProtect Management Service" %}

#### Minimum requirements: <a href="#minimum_requirements" id="minimum_requirements"></a>

* [x] 4 GB of RAM
* [x] 4 core CPU
* [x] 1 GB of disk space
* [x] internet connection

#### Recommended requirements: <a href="#recommended_requirements" id="recommended_requirements"></a>

* [x] 8 GB of RAM
* [x] 4 core CPU
* [x] 10 GB of disk space
* [x] internet connection
  {% endtab %}

{% tab title="GitProtect worker" %}

#### Minimum requirements: <a href="#minimum_requirements_1" id="minimum_requirements_1"></a>

* [x] 4GB of RAM
* [x] 2 core CPU
* [x] 1 GB of disk space

#### Recommended requirements: <a href="#recommended_requirements_1" id="recommended_requirements_1"></a>

* [x] 8GB of RAM
* [x] 4 core CPU
* [x] 2 GB of disk space

#### Required software: <a href="#required_software" id="required_software"></a>

* [x] .NET Framework 4.6.1 (for Windows Server 2008R2 and 2012 only)
* [x] Microsoft Visual C++ 2015-2019 Redistributable
  {% endtab %}
  {% endtabs %}

***

## Useful links and items

{% content-ref url="/pages/srQ5F6tnpeA8r4mpbgA8" %}
[Supported platforms](/gitprotect-software/software-information/supported-platforms)
{% endcontent-ref %}


# System components & architecture

## System architecture

**GitProtect** system architecture is presented in the following diagram:

<figure><img src="/files/N2hXXcLGk6nQbG9i3Tak" alt=""><figcaption></figcaption></figure>

***

## Components

**GitProtect** product as a platform consists of three main components: management service, worker, and storage.

### <mark style="background-color:blue;">Management system</mark>

The main component required to run **GitProtect** backup system is called **GitProtect Management Service**. It allows you to comprehensively manage your backups and related resources using **Management Service** console with a user-friendly and easy to navigate UI. In on-premise deployment model it can be installed on almost any computer with **Windows** and **Linux** operating systems or **Docker** environment (even popular **NAS** devices). When it comes to SaaS deployment model, the management service runs on provider's cloud infrastructure.

**GitProtect Management Service** is divided into separate modules, each of them dedicated to a different aspect of backup management:

1. Dashboard
2. DevOps
3. Plans
4. Storages
5. Tasks
6. Logs
7. Settings

### <mark style="background-color:blue;">Worker</mark>

The second main component is called **GitProtect worker** and is an application installed on end devices with **Windows**, **Linux**, or **Mac** operating systems. **Worker** performs all operations requested by the **Management Service** including data processing (i.e., encryption, compression), connecting to data storage, sending data directly to the storage, and restoring data.

### <mark style="background-color:blue;">Storage</mark>

The last component on the list is storage—**GitProtect**, as a multi-storage system, allows you to store your backup data in the cloud (**GitProtect Cloud**, **AWS**, and any **S3** compatible public cloud), locally (NFS, SMB, iSCSI network shares, local disk resources), or in a hybrid environment.


# Third-party libraries

Full list of third-party libraries' licenses used in GitProtect.

<table data-full-width="false"><thead><tr><th width="64">#</th><th>COMPONENT NAME</th><th>LICENSE TYPE</th><th>LICENSE DETAILS</th></tr></thead><tbody><tr><td>1</td><td>Microsoft.Extensions.Logging.Configuration</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>2</td><td>Mono.Posix-4.5</td><td>MIT/BSD-3/Microsoft Patents</td><td><a href="https://github.com/mono/mono/blob/master/LICENSE">https://github.com/mono/mono/blob/master/LICENSE</a></td></tr><tr><td>3</td><td>NETStandard.Library</td><td>MIT</td><td><a href="https://github.com/dotnet/standard/blob/master/LICENSE.TXT">https://github.com/dotnet/standard/blob/master/LICENSE.TXT</a></td></tr><tr><td>4</td><td>Npgsql.EntityFrameworkCore.PostgreSQL</td><td>PostgreSQL License</td><td><a href="https://licenses.nuget.org/PostgreSQL">https://licenses.nuget.org/PostgreSQL</a></td></tr><tr><td>5</td><td>MailKit</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>6</td><td>Microsoft.VisualStudio.Web.CodeGeneration.Design</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>7</td><td>Swashbuckle.AspNetCore</td><td>MIT</td><td><a href="https://raw.githubusercontent.com/domaindrivendev/Swashbuckle.AspNetCore/master/LICENSE">https://raw.githubusercontent.com/domaindrivendev/Swashbuckle.AspNetCore/master/LICENSE</a></td></tr><tr><td>8</td><td>Microsoft.AspNetCore</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>9</td><td>Microsoft.AspNetCore.Mvc.NewtonsoftJson</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>10</td><td>Microsoft.AspNetCore.Identity.EntityFrameworkCore</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>11</td><td>Vibrant.InfluxDB.Client</td><td>MIT</td><td><a href="https://github.com/MikaelGRA/InfluxDB.Client/blob/master/LICENSE">https://github.com/MikaelGRA/InfluxDB.Client/blob/master/LICENSE</a></td></tr><tr><td>12</td><td>Microsoft.Extensions.Identity.Stores</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>13</td><td>Microsoft.EntityFrameworkCore.Sqlite</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>14</td><td>Microsoft.AspNetCore.Authentication.JwtBearer</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>15</td><td>System.Reactive</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>16</td><td>AutoMapper</td><td>MIT</td><td><a href="https://github.com/AutoMapper/AutoMapper/blob/master/LICENSE.txt">https://github.com/AutoMapper/AutoMapper/blob/master/LICENSE.txt</a></td></tr><tr><td>17</td><td>FluentScheduler</td><td>BSD (3-clause)</td><td><a href="https://opensource.org/licenses/BSD-3-Clause">https://opensource.org/licenses/BSD-3-Clause</a></td></tr><tr><td>18</td><td>Microsoft.EntityFrameworkCore.Design</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>19</td><td>Microsoft.AspNetCore.SignalR</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>20</td><td>Microsoft.AspNetCore.Hosting</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>21</td><td>System.Text.Json</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>22</td><td>Microsoft.AspNetCore.SignalR.Protocols.NewtonsoftJson</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>23</td><td>LiteDB</td><td>MIT</td><td><a href="https://raw.github.com/mbdavid/LiteDB/master/LICENSE">https://raw.github.com/mbdavid/LiteDB/master/LICENSE</a></td></tr><tr><td>24</td><td>Microsoft.Extensions.Logging.Debug</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>25</td><td>Microsoft.Extensions.Logging.Console</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>26</td><td>AgileObjects.ReadableExpressions</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>27</td><td>RestSharp</td><td>Apache 2.0</td><td><a href="https://github.com/restsharp/RestSharp/blob/master/LICENSE.txt">https://github.com/restsharp/RestSharp/blob/master/LICENSE.txt</a></td></tr><tr><td>28</td><td>Microsoft.AspNetCore.Identity</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>29</td><td>Microsoft.Extensions.Hosting.WindowsServices</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>30</td><td>Microsoft.AspNetCore.Http.Connections</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>31</td><td>Microsoft.EntityFrameworkCore.InMemory</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>32</td><td>NLog.Web.AspNetCore</td><td>BSD (3-clause)</td><td><a href="https://github.com/NLog/NLog.Web/blob/master/LICENSE">https://github.com/NLog/NLog.Web/blob/master/LICENSE</a></td></tr><tr><td>33</td><td>Microsoft.EntityFrameworkCore.Proxies</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>34</td><td>Microsoft.AspNetCore.SpaServices</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>35</td><td>Microsoft.AspNetCore.SpaServices.Extensions</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>36</td><td>Microsoft.Identity.Client</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>37</td><td>Microsoft.AspNetCore.Mvc.Core</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>38</td><td>Microsoft.EntityFrameworkCore.Sqlite</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>39</td><td>Microsoft.AspNetCore.CookiePolicy</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>40</td><td>Microsoft.AspNetCore.Razor.Design</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>41</td><td>Microsoft.AspNetCore.StaticFiles</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>42</td><td>Microsoft.AspNetCore.Identity.EntityFrameworkCore</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>43</td><td>Microsoft.AspNetCore.SignalR.Client</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>44</td><td>xunit.runner.visualstudio</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>45</td><td>Microsoft.AspNetCore.Mvc.Testing</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>46</td><td>coverlet.collector</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>47</td><td>xunit</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/xunit/xunit/master/license.txt">https://raw.githubusercontent.com/xunit/xunit/master/license.txt</a></td></tr><tr><td>48</td><td>Microsoft.CodeAnalysis.Common</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>49</td><td>Moq</td><td>BSD (3-clause)</td><td><a href="https://raw.githubusercontent.com/moq/moq4/master/License.txt">https://raw.githubusercontent.com/moq/moq4/master/License.txt</a></td></tr><tr><td>50</td><td>Microsoft.AspNet.WebApi.Client</td><td>Microsoft EULA</td><td><a href="http://www.microsoft.com/web/webpi/eula/net_library_eula_ENU.htm">http://www.microsoft.com/web/webpi/eula/net_library_eula_ENU.htm</a></td></tr><tr><td>51</td><td>Microsoft.EntityFrameworkCore.InMemory</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>52</td><td>Microsoft.AspNetCore.Identity.EntityFrameworkCore</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>53</td><td>Rnwood.SmtpServer</td><td>BSD (3-clause)</td><td><a href="https://github.com/rnwood/smtpserver/blob/master/LICENSE.md">https://github.com/rnwood/smtpserver/blob/master/LICENSE.md</a></td></tr><tr><td>54</td><td>Microsoft.Extensions.Localization.Abstractions</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>55</td><td>Newtonsoft.Json</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>56</td><td>Microsoft.NETCore.App</td><td>MIT</td><td><a href="https://github.com/dotnet/core-setup/blob/master/LICENSE.TXT">https://github.com/dotnet/core-setup/blob/master/LICENSE.TXT</a></td></tr><tr><td>57</td><td>Microsoft.AspNetCore.Server.Kestrel</td><td>Apache 2.0</td><td><a href="https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt">https://raw.githubusercontent.com/aspnet/AspNetCore/2.0.0/LICENSE.txt</a></td></tr><tr><td>58</td><td>MSTest.TestFramework</td><td>MIT</td><td><a href="https://www.nuget.org/packages/MSTest.TestFramework/2.2.0-preview-20210115-03/License">https://www.nuget.org/packages/MSTest.TestFramework/2.2.0-preview-20210115-03/License</a></td></tr><tr><td>59</td><td>MSTest.TestAdapter</td><td>MIT</td><td><a href="https://www.nuget.org/packages/MSTest.TestAdapter/2.2.0-preview-20210115-03/License">https://www.nuget.org/packages/MSTest.TestAdapter/2.2.0-preview-20210115-03/License</a></td></tr><tr><td>60</td><td>Microsoft.NET.Test.Sdk</td><td>Microsoft EULA</td><td><a href="https://www.microsoft.com/web/webpi/eula/net_library_eula_enu.htm">https://www.microsoft.com/web/webpi/eula/net_library_eula_enu.htm</a></td></tr><tr><td>61</td><td>Microsoft.VisualStudio.Azure.Containers.Tools.Targets</td><td>Microsoft EULA</td><td><a href="https://www.nuget.org/packages/Microsoft.VisualStudio.Azure.Containers.Tools.Targets/1.7.12/license">https://www.nuget.org/packages/Microsoft.VisualStudio.Azure.Containers.Tools.Targets/1.7.12/license</a></td></tr><tr><td>62</td><td>Microsoft.Win32.Registry</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>63</td><td>System.IO.FileSystem.AccessControl</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>64</td><td>System.Management</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>65</td><td>AlphaVSS</td><td>Apache 2.0</td><td><a href="https://licenses.nuget.org/Apache-2.0">https://licenses.nuget.org/Apache-2.0</a></td></tr><tr><td>66</td><td>Microsoft.CSharp</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a></td></tr><tr><td>67</td><td>MSTest.TestFramework</td><td>EULA Microsoftu</td><td><a href="http://www.microsoft.com/web/webpi/eula/net_library_eula_enu.htm">http://www.microsoft.com/web/webpi/eula/net_library_eula_enu.htm</a></td></tr><tr><td>68</td><td>Moq</td><td>BSD (3-clause)</td><td><a href="https://raw.githubusercontent.com/moq/moq4/master/License.txt">https://raw.githubusercontent.com/moq/moq4/master/License.txt</a></td></tr><tr><td>69</td><td>Microsoft.NET.Test.Sdk</td><td>Microsoft EULA</td><td><a href="http://www.microsoft.com/web/webpi/eula/net_library_eula_enu.htm">http://www.microsoft.com/web/webpi/eula/net_library_eula_enu.htm</a></td></tr><tr><td>70</td><td>NETStandard.Library</td><td>MIT</td><td><a href="https://github.com/dotnet/standard/blob/master/LICENSE.TXT">https://github.com/dotnet/standard/blob/master/LICENSE.TXT</a></td></tr><tr><td>71</td><td>SMBLibrary.Std</td><td>LGPL 3.0</td><td><a href="https://licenses.nuget.org/LGPL-3.0-or-later">https://licenses.nuget.org/LGPL-3.0-or-later</a></td></tr><tr><td>72</td><td>FirebirdSql.Data.FirebirdClient</td><td>Developer's Public License Version 1.0</td><td><a href="https://raw.githubusercontent.com/FirebirdSQL/NETProvider/master/license.txt">https://raw.githubusercontent.com/FirebirdSQL/NETProvider/master/license.txt</a></td></tr><tr><td>73</td><td>Newtonsoft.Json</td><td>MIT</td><td><a href="https://raw.github.com/JamesNK/Newtonsoft.Json/master/LICENSE.md">https://raw.github.com/JamesNK/Newtonsoft.Json/master/LICENSE.md</a></td></tr><tr><td>74</td><td>FluentFTP</td><td>MIT</td><td><a href="https://github.com/robinrodricks/FluentFTP/blob/master/LICENSE.TXT">https://github.com/robinrodricks/FluentFTP/blob/master/LICENSE.TXT</a></td></tr><tr><td>75</td><td>LightningDB</td><td>OpenLDAP Public License</td><td><a href="https://www.nuget.org/packages/LightningDB/0.13.0/License">https://www.nuget.org/packages/LightningDB/0.13.0/License</a></td></tr><tr><td>76</td><td>AWSSDK.S3</td><td>Apache 2.0</td><td><a href="http://aws.amazon.com/apache2.0/">http://aws.amazon.com/apache2.0/</a></td></tr><tr><td>77</td><td>Mono.Posix.NETStandard</td><td>MIT/BSD-3/Microsoft Patents</td><td><a href="https://go.microsoft.com/fwlink/?linkid=869050">https://go.microsoft.com/fwlink/?linkid=869050</a></td></tr><tr><td>78</td><td>SharpCifs.Std</td><td>LGPL 2.1</td><td><a href="https://github.com/ume05rw/SharpCifs.Std/blob/master/LICENSE">https://github.com/ume05rw/SharpCifs.Std/blob/master/LICENSE</a></td></tr><tr><td>79</td><td>JsonLogic.Net</td><td>MIT</td><td><a href="https://raw.githubusercontent.com/yavuztor/JsonLogic.Net/master/LICENSE">https://raw.githubusercontent.com/yavuztor/JsonLogic.Net/master/LICENSE</a></td></tr><tr><td>80</td><td>K4os.Hash.xxHash</td><td>MIT</td><td><a href="https://raw.githubusercontent.com/MiloszKrajewski/K4os.Hash.xxHash/master/LICENSE">https://raw.githubusercontent.com/MiloszKrajewski/K4os.Hash.xxHash/master/LICENSE</a></td></tr><tr><td>81</td><td>protobuf-net</td><td>Apache 2.0</td><td><a href="https://github.com/mgravell/protobuf-net/blob/master/Licence.txt">https://github.com/mgravell/protobuf-net/blob/master/Licence.txt</a></td></tr><tr><td>82</td><td>UnQLite</td><td>BSD (2-clause)</td><td><a href="https://unqlite.org/licensing.html">https://unqlite.org/licensing.html</a></td></tr><tr><td>83</td><td>LZ4</td><td>BSD (2-clause)</td><td><a href="https://github.com/bwlewis/lz4/blob/master/LICENSE">https://github.com/bwlewis/lz4/blob/master/LICENSE</a></td></tr><tr><td>84</td><td>OpenSSL.Net</td><td>BSD</td><td><a href="https://github.com/openssl-net/openssl-net/blob/master/LICENSE">https://github.com/openssl-net/openssl-net/blob/master/LICENSE</a></td></tr><tr><td>85</td><td>Zstandard</td><td>BSD (3-clause)</td><td><a href="https://github.com/facebook/zstd/blob/dev/LICENSE">https://github.com/facebook/zstd/blob/dev/LICENSE</a></td></tr><tr><td>86</td><td>VMWare SDK</td><td>Proprietary</td><td><a href="https://vdc-download.vmware.com/vmwb-repository/dcr-public/3d076a12-29a2-4d17-9269-cb8150b5a37f/8b5969e2-1a66-4425-af17-feff6d6f705d/SDK/VMware%20vSphere%20Mgmt%20SDK-License%20Agmt.docx">https://vdc-download.vmware.com/vmwb-repository/dcr-public/3d076a12-29a2-4d17-9269-cb8150b5a37f/8b5969e2-1a66-4425-af17-feff6d6f705d/SDK/VMware%20vSphere%20Mgmt%20SDK-License%20Agmt.docx</a></td></tr><tr><td>87</td><td>DiscUtils</td><td>MIT</td><td><a href="https://github.com/DiscUtils/DiscUtils/blob/develop/LICENSE.txt">https://github.com/DiscUtils/DiscUtils/blob/develop/LICENSE.txt</a></td></tr><tr><td>89</td><td>Hali4831.MixERP.Net.VCards</td><td>Apache 2.0</td><td><a href="http://www.apache.org/licenses/LICENSE-2.0">http://www.apache.org/licenses/LICENSE-2.0</a></td></tr><tr><td>90</td><td>Ical.Net</td><td>MIT</td><td><a href="https://github.com/rianjs/ical.net/blob/master/license.md">https://github.com/rianjs/ical.net/blob/master/license.md</a></td></tr><tr><td>91</td><td>iSCSIConsole</td><td>LGPL 3.0</td><td><a href="https://github.com/TalAloni/iSCSIConsole/blob/master/License.txt">https://github.com/TalAloni/iSCSIConsole/blob/master/License.txt</a></td></tr><tr><td>92</td><td>FubarDev.FtpServer</td><td>MIT</td><td><a href="https://github.com/FubarDevelopment/FtpServer/blob/master/LICENSE.md">https://github.com/FubarDevelopment/FtpServer/blob/master/LICENSE.md</a></td></tr><tr><td>93</td><td>MSTest.TestAdapter</td><td>MIT</td><td><a href="https://www.nuget.org/packages/MSTest.TestAdapter/2.1.2/License">https://www.nuget.org/packages/MSTest.TestAdapter/2.1.2/License</a></td></tr><tr><td>94</td><td>Microsoft.Graph</td><td>MIT</td><td><a href="https://www.nuget.org/packages/Microsoft.Graph/3.23.0/License">https://www.nuget.org/packages/Microsoft.Graph/3.23.0/License</a></td></tr><tr><td>95</td><td>Microsoft.NETCore.App</td><td>MIT</td><td><a href="https://github.com/dotnet/core-setup/blob/master/LICENSE.TXT">https://github.com/dotnet/core-setup/blob/master/LICENSE.TXT</a></td></tr><tr><td>96</td><td>Microsoft.Identity.Client</td><td>MIT</td><td><a href="https://licenses.nuget.org/MIT">https://licenses.nuget.org/MIT</a>T</td></tr><tr><td>97</td><td>@fortawesome/fontawesome-svg-core</td><td>Font Awesome Free License</td><td><a href="https://github.com/FortAwesome/Font-Awesome/blob/master/LICENSE.txt">https://github.com/FortAwesome/Font-Awesome/blob/master/LICENSE.txt</a></td></tr><tr><td>98</td><td>@fortawesome/free-brands-svg-icons</td><td>Font Awesome Free License</td><td><a href="https://github.com/FortAwesome/Font-Awesome/blob/master/LICENSE.txt">https://github.com/FortAwesome/Font-Awesome/blob/master/LICENSE.txt</a></td></tr><tr><td>99</td><td>@fortawesome/pro-duotone-svg-icons</td><td>Font Awesome Pro License</td><td><a href="https://fontawesome.com/license">https://fontawesome.com/license</a></td></tr><tr><td>100</td><td>@fortawesome/pro-light-svg-icons</td><td>Font Awesome Pro License</td><td><a href="https://fontawesome.com/license">https://fontawesome.com/license</a></td></tr><tr><td>101</td><td>@fortawesome/pro-regular-svg-icons</td><td>Font Awesome Pro License</td><td><a href="https://fontawesome.com/license">https://fontawesome.com/license</a></td></tr><tr><td>102</td><td>@fortawesome/pro-solid-svg-icons</td><td>Font Awesome Pro License</td><td><a href="https://fontawesome.com/license">https://fontawesome.com/license</a></td></tr><tr><td>103</td><td>@microsoft/signalr</td><td>Apache 2.0</td><td><a href="https://docs.microsoft.com/en-us/gaming/playfab/sdks/unity3d/licenses/signalr-license">https://docs.microsoft.com/en-us/gaming/playfab/sdks/unity3d/licenses/signalr-license</a></td></tr><tr><td>104</td><td>@ng-select/ng-select</td><td>MIT</td><td><a href="https://github.com/ng-select/ng-select/blob/master/LICENSE">https://github.com/ng-select/ng-select/blob/master/LICENSE</a></td></tr><tr><td>105</td><td>@ngrx/effects</td><td>MIT</td><td><a href="https://github.com/ngrx/platform/blob/master/LICENSE">https://github.com/ngrx/platform/blob/master/LICENSE</a></td></tr><tr><td>106</td><td>@ngrx/store</td><td>MIT</td><td><a href="https://github.com/ngrx/platform/blob/master/LICENSE">https://github.com/ngrx/platform/blob/master/LICENSE</a></td></tr><tr><td>107</td><td>angular-i18next</td><td>MIT</td><td><a href="https://github.com/Romanchuk/angular-i18next/blob/master/LICENSE">https://github.com/Romanchuk/angular-i18next/blob/master/LICENSE</a></td></tr><tr><td>108</td><td>chart.js</td><td>MIT</td><td><a href="https://github.com/chartjs/Chart.js/blob/master/LICENSE.md">https://github.com/chartjs/Chart.js/blob/master/LICENSE.md</a></td></tr><tr><td>109</td><td>chartjs-plugin-datalabels</td><td>MIT</td><td><a href="https://github.com/chartjs/chartjs-plugin-datalabels/blob/master/LICENSE.md">https://github.com/chartjs/chartjs-plugin-datalabels/blob/master/LICENSE.md</a></td></tr><tr><td>110</td><td>i18next</td><td>MIT</td><td><a href="https://github.com/i18next/i18next/blob/master/LICENSE">https://github.com/i18next/i18next/blob/master/LICENSE</a></td></tr><tr><td>111</td><td>i18next-browser-languagedetector</td><td>MIT</td><td><a href="https://github.com/i18next/i18next-browser-languageDetector/blob/master/LICENSE">https://github.com/i18next/i18next-browser-languageDetector/blob/master/LICENSE</a></td></tr><tr><td>112</td><td>i18next-http-backend</td><td>MIT</td><td><a href="https://github.com/i18next/i18next-http-backend/blob/master/licence">https://github.com/i18next/i18next-http-backend/blob/master/licence</a></td></tr><tr><td>113</td><td>jwt-decode</td><td>MIT</td><td><a href="https://github.com/auth0/jwt-decode/blob/master/LICENSE">https://github.com/auth0/jwt-decode/blob/master/LICENSE</a></td></tr><tr><td>114</td><td>ng-click-outside</td><td>MIT</td><td><a href="https://github.com/arkon/ng-click-outside/blob/master/LICENSE">https://github.com/arkon/ng-click-outside/blob/master/LICENSE</a></td></tr><tr><td>115</td><td>ng2-charts</td><td>ISC License</td><td><a href="https://github.com/valor-software/ng2-charts/blob/development/LICENSE">https://github.com/valor-software/ng2-charts/blob/development/LICENSE</a></td></tr><tr><td>116</td><td>ngx-toastr</td><td>MIT</td><td><a href="https://github.com/scttcper/ngx-toastr/blob/master/LICENSE">https://github.com/scttcper/ngx-toastr/blob/master/LICENSE</a></td></tr><tr><td>117</td><td>rxjs</td><td>Apache 2.0</td><td><a href="https://github.com/ReactiveX/rxjs/blob/master/LICENSE.txt">https://github.com/ReactiveX/rxjs/blob/master/LICENSE.txt</a></td></tr><tr><td>118</td><td>tslib</td><td>BSD (0-clause)</td><td><a href="https://github.com/microsoft/tslib/blob/master/LICENSE.txt">https://github.com/microsoft/tslib/blob/master/LICENSE.txt</a></td></tr><tr><td>119</td><td>tsutils</td><td>MIT</td><td><a href="https://github.com/ajafff/tsutils/blob/master/LICENSE">https://github.com/ajafff/tsutils/blob/master/LICENSE</a></td></tr><tr><td>120</td><td>uuid</td><td>MIT</td><td><a href="https://github.com/uuidjs/uuid/blob/master/LICENSE.md">https://github.com/uuidjs/uuid/blob/master/LICENSE.md</a></td></tr><tr><td>121</td><td>zone.js</td><td>MIT</td><td><a href="https://github.com/angular/angular/blob/master/LICENSE">https://github.com/angular/angular/blob/master/LICENSE</a></td></tr></tbody></table>


# Deployment models

Learn more about SaaS and on-prem models.

## Solution deployment - SaaS vs. on-premise

{% hint style="success" %}
Regardless of the deployment model **GitProtect** provides the same functionalities in one user interface.
{% endhint %}

**GitProtect** is a flexible backup solution that can be deployed in two different models: SaaS and on-premise.

The main difference between SaaS and on-premise models is where **GitProtect** service is installed and running. The first implementation type — SaaS (software as a service, a cloud-based model) — is hosted and maintained by us while the other, on-prem model, is hosted in-house (directly on your local infrastructure). Which implementation type works best for your company depends on a variety of factors including your objectives, system limitations, company's budget, security requirements, company policy, and more. Before you decide which solution deployment model to use, you need to evaluate your options and compare it with your infrastructure to figure out which implementation type would be the best fit.

{% hint style="info" %}
The location where the backup copies are stored is independent of where the management server is running - with a SaaS-based management service you can store data locally and likewise, you can store data in cloud with an on-premise service.
{% endhint %}

***

## GitProtect SaaS

Software as a service (SaaS) is a way of delivering software over the internet. Instead of installing and maintaining software on your computer, you access it online through a subscription with a cloud service provider.

To deploy **GitProtect** SaaS you don't have to allocate any additional devices that could be used as a local server - the service runs in our cloud infrastructure. You don't have to worry about its maintenance or administration, and the continuity of operation is guaranteed by us.

#### **SaaS main advantages:**

1. Service installation doesn’t require a local server.
2. Accessible from anywhere.
3. Guaranteed business continuity.
4. Cloud-to-cloud copies.
5. Automatic updates.

***

## GitProtect on-premise

On-premises software is installed and runs on local computers within your organization, rather than at a remote facility such as cloud. As it's run locally, the service maintenance and control is up to the housing unit, or to simplify—up to your IT department.

You can install **GitProtect** on-premise service on almost any computer with **Windows** or **Linux**—or even on popular **NAS** devices. This deployment model let's you avoid any issues related to network connectivity—your backup copies are made using the local network, which makes the whole process faster and more efficient.

#### **On-premise main advantages:**

1. Implementation on any infrastructure.
2. No failures related to the lack of network access.
3. No data transfer outside the company.
4. Copies made without internet access.


# GitProtect SaaS

How to sign up for a free GitProtect account in a cloud-based management service deployment.

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/xjnAzoSZa0gZePc9HJjM">/pages/xjnAzoSZa0gZePc9HJjM</a></td><td>Where <strong>GitProtect Management Service</strong> is hosted across different regions.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/lhFB9x26NB9fc9UZGvLp">/pages/lhFB9x26NB9fc9UZGvLp</a></td><td>Learn how to register for a free <strong>GitProtect</strong> account with the cloud-based <strong>GitProtect Management Service</strong>.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Service hosting location

Where GitProtect Management Service is hosted across different regions.

**GitProtect Management Service is available in two deployment models: as a SaaS offering or as an on-premises component. For SaaS customers, the Management Service is hosted in the EMEA region and the US region.**

***

## Service deployment

In SaaS model, the **GitProtect Management Service** platform is deployed in two different locations:

<table data-card-size="large" data-view="cards" data-full-width="false"><thead><tr><th align="center"></th><th align="center"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center"><strong>EMEA</strong></td><td align="center">For the EMEA region, <strong>GitProtect Management Service</strong> platform is hosted in Poland.</td><td><a href="/files/z0LNRBMoukTHEMSlu44j">/files/z0LNRBMoukTHEMSlu44j</a></td></tr><tr><td align="center"><strong>US</strong></td><td align="center">For the US region, <strong>GitProtect Management Service</strong> platform is hosted in the United States.</td><td><a href="/files/GbeoqXpLzGr8EGl0gRCq">/files/GbeoqXpLzGr8EGl0gRCq</a></td></tr></tbody></table>

***

## Useful links and items

{% content-ref url="/pages/lhFB9x26NB9fc9UZGvLp" %}
[Registration](/registration/gitprotect-saas/registration)
{% endcontent-ref %}

{% content-ref url="/pages/dW8GZsD33sfAu487mNih" %}
[Two-factor authentication (2FA)](/sign-in-and-authentication/two-factor-authentication-2fa)
{% endcontent-ref %}


# Registration

Learn how to register for a free GitProtect account with the cloud-based GitProtect Management Service.

**Registration for a GitProtect account in the SaaS deployment model is a simple, self-service process on the GitProtect website. To sign up, customers provide basic business contact details, select data residency, and create administrator credentials. After registration, access to the GitProtect Management Service is granted via a unique SaaS login URL for subsequent provisioning, adding storage or cloud agents, and configuring roles and permissions.**

***

## Creating an account

The below steps outline the registration process on the [GitProtect website](https://gitprotect.io/).

{% hint style="warning" %}
**Automatic registration is available only for the cloud version of the management console.** To register an account with the on-premises version of the software, please contact us at: <https://gitprotect.io/contact-us.html>.
{% endhint %}

{% hint style="info" %}
Signing up creates a new account with a 14-day free **GitProtect** service trial.
{% endhint %}

{% stepper %}
{% step %}
Open <https://gitprotect.io/> and click the **Try for free** button in the upper-right corner of the screen (or use [this link](https://gitprotect.io/sign-up.html)).

<figure><img src="/files/QzRXPIamWDsy4K6JhCA1" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Enter your business email address and click **Join free**.

{% hint style="success" %}
You can also use one of the **Sign up with (...)** options to register with your business account.
{% endhint %}

<figure><img src="/files/yyuTLvJn9MvFTg4GfEH3" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Enter all required information (full name, company, phone number, and data residency location) and set a strong password for your new account. Once completed, verify that the information is correct and click the **Create account** button.

<figure><img src="/files/zkX3tXgiDG9HsYglILwN" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Wait for the system to create your account.

<figure><img src="/files/thDR7bXoF6gldhJ5DQ3o" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Once the account is created, you will be redirected to the **GitProtect Management Service** landing page, where you can immediately add organizations to protect and create backup plans for them.

{% hint style="success" %}
**GitProtect** uses a simple widget to guide users through the entire onboarding process, including connecting their first resource, configuring the environment, starting and monitoring their first backup, and performing a test restoration.
{% endhint %}

<figure><img src="/files/jYx6UEUAXMeMbsnzHjbe" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
The system will generate a unique **GitProtect Management Service** instance URL for login. For subsequent logins, use this URL or go directly to <https://gitprotect.io/login.html>.

{% hint style="info" %}
Your unique **Management Service** URL will be included in the welcome email.
{% endhint %}

<figure><img src="/files/9vZnEWxPVTyjGrpKD2Ve" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Additionally, you will receive a welcome email from **GitProtect** containing all important information about your account and the **GitProtect** system (including your unique [login URL](#user-content-fn-1)[^1]).

<figure><img src="/files/KlcZehOHrsQwhN1JQA2N" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/dW8GZsD33sfAu487mNih" %}
[Two-factor authentication (2FA)](/sign-in-and-authentication/two-factor-authentication-2fa)
{% endcontent-ref %}

{% content-ref url="/pages/Mr0Wa83rD5soGvK2JqzI" %}
[Configuration](/sign-in-and-authentication/external-identity-providers-idp/configuration)
{% endcontent-ref %}

{% content-ref url="/pages/KEH5lHJdxHViN9HsbXz6" %}
[Login methods](/sign-in-and-authentication/login-methods)
{% endcontent-ref %}

[^1]: GitProtect Management Service instance URL


# Marketplace

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/FwdO4TnprN9MqfaROyyY">/pages/FwdO4TnprN9MqfaROyyY</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/UDIJ1goWoQqU31jxEa1b">/pages/UDIJ1goWoQqU31jxEa1b</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# GitProtect.io for Jira

In this article, you will learn how to sign up for a free GitProtect trial through the Atlassian Marketplace.

#### Registering for GitProtect through the Atlassian Marketplace allows you to quickly connect your Jira instance to a dedicated GitProtect service for seamless backup and management.

***

## General information

The **GitProtect.io for Jira** application was built on the **Atlassian Forge** developer platform. The application acts as a connector between **Jira** and **GitProtect** — during registration, each **GitProtect.io for Jira** app is linked to a single **GitProtect** service instance, which is created at the moment the app is installed on your **Jira** site.

{% hint style="info" %}
Registering your **Jira** site with **GitProtect** via the **Atlassian Marketplace** automatically starts a free trial — you can change your subscription model using the [Atlassian Administration](https://admin.atlassian.com/) panel.
{% endhint %}

Most backup operations are managed through the **GitProtect Management Service**, while the **Jira** interface allows basic actions like viewing the latest backup status, adjusting the backup schedule, and starting the backup process.

***

## Registration

{% hint style="warning" %}
To register a **GitProtect** account and connect it to **Jira**, you must have a personal access token (PAT).
{% endhint %}

{% stepper %}
{% step %}
Log in to your **Atlassian** account and go to the **Atlassian Marketplace** ([https://marketplace.atlassian.com](https://marketplace.atlassian.com/)).
{% endstep %}

{% step %}
Type **gitprotect** in the search box and press **Enter**.

<figure><img src="/files/bI7SF8fa5fnhEuBsrX5Q" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Find the **GitProtect.io for Jira** tile in the search results and click it.

<figure><img src="/files/tBWGEp3VBgEO1JsQfSOu" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
On the application page, click the **Try it free** button in the top-right corner.

<figure><img src="/files/bVWL37uDWAcJ6qSHCYYZ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the site where **GitProtect** will be installed and click **Review** in the bottom-right corner.

<figure><img src="/files/B4ZP2OizKi2ejAOfCQTf" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Review your configuration settings and click the **Start free trial** button.

<figure><img src="/files/7g9YW0vLzz6pJBxvSULs" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Atlassian** will add the **GitProtect** app to your selected **Jira** site.

<figure><img src="/files/ibi6ujOUzarkYgpC7m4W" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
When the **GitProtect** app is successfully added to your **Jira** site, a notification pop-up will appear. Select **Configure** to open the app view page.

<figure><img src="/files/fwbe7gnXBFYxS3F6oAm4" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Wait for the installation to complete.
{% endstep %}

{% step %}
Another pop-up will appear. Enter your personal access token (**Jira** API key) and click **Save** to proceed.

<figure><img src="/files/uhr8RLwex6S0jKFtMDCE" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After the installation is complete, you will see a confirmation message. Click **Not now** to continue to the **GitProtect** app main page, or select **Run Plan** to start your first backup using the default settings.

<figure><img src="/files/8YailaEg99tdcnjiJfWz" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Your **GitProtect** registration and deployment are now complete. Proceed to the [Post-registration actions](#post-registration-actions) section to learn about app features and how to create and manage your **Jira** backups.

<figure><img src="/files/nPRqCtmgJM6SnP43GePc" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## Post-registration actions

In the **GitProtect.io** app view in **Jira** you can change the plan execution time, manually trigger a backup job, and check your backup status.

To fully manage your **Jira** backups—including setting up backup plans, managing storage, monitoring running tasks, reviewing logs, adding additional accounts, configuring notifications, and using all **GitProtect** features—log in to the **GitProtect Management Service** using the **More features** button in the top-right corner of the app page.

Accessing the **Management Service** does not require additional credentials. You are automatically logged in through the **GitProtect** integration with **Jira**.

{% hint style="info" %}
You can learn more about using the **GitProtect.io for Jira** app in [this section](/management/marketplace/atlassian-marketplace).
{% endhint %}

***

## Useful links and items

{% content-ref url="/pages/Rzwit7dBQ9hW6wTnTB0V" %}
[Protected resources](/backup-and-recovery/jira/backup/protected-resources)
{% endcontent-ref %}

{% content-ref url="/pages/IkMp2576EOKN31ghd1Q2" %}
[Backup management](/management/marketplace/atlassian-marketplace/backup-management)
{% endcontent-ref %}

{% content-ref url="/pages/cVEfVqUyFodKZf9MVgP6" %}
[License management](/management/marketplace/atlassian-marketplace/license-management)
{% endcontent-ref %}


# GitHub

Lorem ipsum dolor sit amet, consectetur adipiscing elit.

<figure><picture><source srcset="/files/A7g5b0oRdkT7E2NcGxK0" media="(prefers-color-scheme: dark)"><img src="/files/ACdXsVVxeP5bGiYPDMta" alt=""></picture><figcaption></figcaption></figure>


# Login methods

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/5uvAKLBS4f1S7bOLSFAy">/pages/5uvAKLBS4f1S7bOLSFAy</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/ssFlv6ksHH9QCU0iMdNc">/pages/ssFlv6ksHH9QCU0iMdNc</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Login with SSO

Learn how to log in to GitProtect with SSO.

{% stepper %}
{% step %}
Connect to your **GitProtect Management Service**.

Use <kbd>\<ipAddress>:\<port></kbd> for the on-prem model or [your unique login URL](#user-content-fn-1)[^1] for SaaS model.
{% endstep %}

{% step %}
Select one of the available SSO options.

{% hint style="success" %}
To log in to **Xopero ONE** using SSO, you can choose one of the following providers: **Bitbucket**, **GitHub**, **GitLab**, **Google**, or **Microsoft**. If you want to use your private identity provider for quick login, configure your IdP using the **SAML** protocol. See more in [External Identity Providers (SAML)](/sign-in-and-authentication/external-identity-providers-idp) section.
{% endhint %}

<figure><img src="/files/xDxAQJ0NlfWjPeWHILGk" alt=""><figcaption><p><em>SSO options example for <strong>GitProtect</strong> SaaS.</em></p></figcaption></figure>
{% endstep %}

{% step %}
Go through the selected supplier's login process.
{% endstep %}

{% step %}
Once signed in, you will be automatically redirected to your **Management Service** main page.
{% endstep %}
{% endstepper %}

[^1]: You can find it in the welcome email sent by **GitProtect** — it will also be automatically generated when you log in using <https://gitprotect.io/login.html>.


# Login with username and password

Simple guide on how to log in to GitProtect with a username and password.

{% stepper %}
{% step %}
Connect to your **GitProtect Management Service**.

Use <kbd>\<ipAddress>:\<port></kbd> for the on-prem model or [your unique login URL](#user-content-fn-1)[^1] for SaaS model.
{% endstep %}

{% step %}
Enter your login and password in the appropriate fields and hit **Login**.

<figure><img src="/files/orU9U0HIInwaAJjI44zi" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

[^1]: You can find it in the welcome email sent by **GitProtect**.


# External Identity Providers (IdP)

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/Mr0Wa83rD5soGvK2JqzI">/pages/Mr0Wa83rD5soGvK2JqzI</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/G072o7uYVSqUWzndi6wA">/pages/G072o7uYVSqUWzndi6wA</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Configuration

In this article you will learn how to configure your GitProtect login with SAML.

#### SAML provides secure single sign-on by integrating an identity provider (IdP) with GitProtect, allowing users to authenticate with centralized credentials while ensuring controlled access and compliance.

***

## Overview

**GitProtect** integration works via the SAML 2.0 protocol, meaning any platform supporting this protocol can be integrated with **GitProtect**.

The configuration process is straightforward and requires only the entity ID, metadata URL, reply URL, and logout URL (the names may vary depending on the naming conventions used by specific platforms). In some cases, a certificate and a private key are also required.

***

## Configuration

{% hint style="danger" %}
Do not test the integration in the IdP panel (for example, the **Azure Portal**) as it will initiate login from the IdP panel.
{% endhint %}

Below table illustrates SAML integration configuration for selected platforms, including [Auth0](#auth0), [Entra ID](#entra-id), [CyberArk](#cyberark), [Google](#google), [JumpCloud](#jumpcloud), [Okta](#okta), and [OneLogin](#onelogin).

{% tabs %}
{% tab title="Auth0" %}

<p align="center"><a href="#configuration-in-auth0" class="button primary" data-icon="circle-1">Configuration in Auth0</a> <a href="#xop-auth" class="button primary" data-icon="circle-2">Configuration in GitProtect</a></p>

### Configuration in Auth0

1. Open your **Auth0** admin dashboard, go to **Dashboard** > **Applications** > **Applications**, and hit **Create Application button** in the top-right corner of the screen.

<figure><img src="/files/GPsJUAJRadMEKqvq94rj" alt=""><figcaption></figcaption></figure>

2. In **Create application** window enter a unique, custom application name (in this example we'll be using **XoperoAuth0**), select **Regular Web Applications** option, and click **Create**:

<figure><img src="/files/rTty4CGhqDjLq8N36uLd" alt="" width="563"><figcaption></figcaption></figure>

3. In the newly created application window go to **Settings** tab, scroll down to the very bottom, and click **Advanced Settings** collapsible to expand it.

<figure><img src="/files/xUnjIQhNhufCZYVZT3l7" alt="" width="563"><figcaption></figcaption></figure>

4. Go to the **Endpoints** tab and locate **SAML** section. Copy the **SAML Metadata URL** and save it for later— it will be needed for **GitProtect** configuration.

<figure><img src="/files/nEvvPHz22c9QnhnRvxGR" alt="" width="563"><figcaption></figcaption></figure>

5. Scroll back to top and open the **Addons** tab, then toggle the **SAML2 WEB APP** button.

<figure><img src="/files/emm85Y8p6PrYWaMPzwHJ" alt="" width="522"><figcaption></figcaption></figure>

6. In the window that opens up open the **Settings** tab and enter the **Application Callback URL** as follows:

> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/Auth/AssertionConsumerService

{% hint style="warning" %}
In the above address, change <mark style="color:red;">**GitProtectManagementServiceURL**</mark> to your unique **Management Service** URL. You can find it in your login URL— it's the first part of the address (i.e., in <mark style="color:red;">**<https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com>**</mark>**/authorization/login** the part highlighted in <mark style="color:red;">**red**</mark> is the URL you need to copy).
{% endhint %}

<figure><img src="/files/CFcAr9Prud5982H26AyN" alt=""><figcaption></figcaption></figure>

7. In the same tab, scroll down inside the code input field and uncomment 31st, 32nd and 33rd line, then edit line 32 as follows:

{% code overflow="wrap" %}

```
“callback”: "https://GitProtectManagementServiceURL/auth/SAMLLogoutResponse"
```

{% endcode %}

{% hint style="warning" %}
In the above address, change <mark style="color:red;">**GitProtectManagementServiceURL**</mark> to your unique **Management Service** URL. You can find it in your login URL— it's the first part of the address (i.e., in <mark style="color:red;">**<https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com>**</mark>**/authorization/login** the part highlighted in <mark style="color:red;">**red**</mark> is the URL you need to copy).
{% endhint %}

<figure><img src="/files/3HeasRVOwDLYGTgKHisN" alt=""><figcaption></figcaption></figure>

8. Once done, scroll down to the bottom of the addon window and click **Enable** button, then close the window to finish app configuration.

***

### Configuration in GitProtect <a href="#xop-auth" id="xop-auth"></a>

1. Login to your **Management Service** web panel, go to **Settings** (bottom-left corner in the left-hand side menu) and select **External Identity Providers**.

<figure><img src="/files/QjE46rUKDebt0AcoeafN" alt=""><figcaption></figcaption></figure>

2. Click **Add new provider** button and fill in the details:

> **Name:** your own custom name, i.e., **Auth0**
>
> **Entity ID:** should be the same name you've set as application name in **Auth0** (in this example it's **XoperoAuth0**)

3. Next, paste the previously copied **SAML Metadata URL** in the **Metadata URL** field.

<figure><img src="/files/pfBHKo1lkgX9de1MtTU5" alt=""><figcaption></figcaption></figure>

4. Add certificate and password if required.
5. Set up a default **Language** and **Role** for users with **Auth0** **SAML** authentication permissions.
6. Double-check the settings and hit **Save** at the bottom of **Add identity provider tab**.
7. Click **Save** to finish the setup. You can now log out and test your configured **SAML** login integration.
   {% endtab %}

{% tab title="Entra ID" %}

<p align="center"><a href="#configuration" class="button primary" data-icon="circle-1">Configuration in Azure</a> <a href="#xop-azure" class="button primary" data-icon="circle-2">Configuration in GitProtect</a></p>

### Configuration in Azure

1. Login to [portal.azure.com](http://portal.azure.com/), select **Azure Active Directory** and click **Manage** > **Enterprise applications**.
2. Click the **New application** button and then **Create your own application**.
3. Enter a custom name for the app and select **Integrate any other application you don’t find in the gallery (Non-gallery)**.

<figure><img src="/files/DAlM998isnBrcfiJwHJh" alt="" width="563"><figcaption></figcaption></figure>

4. Confirm the configuration and click **Create** button.
5. Open the **Single sign-on** tab and select **SAML** method.

<figure><img src="/files/QAbCIJV07ocjSBfCx1iU" alt=""><figcaption></figcaption></figure>

6. Click the **Edit** button in **Basic SAML Configuration** section to edit it.

<figure><img src="/files/oq2kJ1hRqrt2z5uVqG9z" alt=""><figcaption></figcaption></figure>

7. Set up a unique **Identifier (Entity ID)** i.e., **SAMLTestAzure**
8. Enter the following URL in **Reply URL (Assertion Consumer Service URL)** section:

> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/Auth/AssertionConsumerService

9. Change the **Logout Url (Optional)** to the following address:

> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/auth/SAMLLogoutResponse

{% hint style="warning" %}
In the above address, change <mark style="color:red;">**GitProtectManagementServiceURL**</mark> to your unique **Management Service** URL. You can find it in your login URL— it's the first part of the address (i.e., in <mark style="color:red;">**<https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com>**</mark>**/authorization/login** the part highlighted in <mark style="color:red;">**red**</mark> is the URL you need to copy).
{% endhint %}

10. Double-check if the info you have entered is correct and click the **Save** button.
11. Next, click the **Edit** button in **Attributes & Claims** section and click **+ Add a group claim** button.

<figure><img src="/files/JbFioC7J9kPPwZ1MxZ6e" alt="" width="563"><figcaption></figcaption></figure>

12. Select **All groups** and go to **Advanced options**. Check the **Filter group** box and fill in the fields as follows:

> **Attribute to match**: Display name\
> **Match with**: Prefix\
> **String**: XONE

<figure><img src="/files/W6ukaSfBFgtYKOpQdSSi" alt="" width="563"><figcaption></figcaption></figure>

13. Check the **Customize the name of the group claim** checkbox. Enter **xoperogroup** in the **Name** field and save your settings.

<figure><img src="/files/Y9cRSsut5V9VgsEJo9Er" alt="" width="563"><figcaption></figcaption></figure>

14. Go back to **SAML-based Sign-on** page and copy the **App Federation Metadata Url**.
15. Save your settings.
16. Open the **Users and groups** tab and click **+ Add user/group** button. Select users you want to be able to login to **GitProtect** and save your settings.

***

### Configuration in GitProtect <a href="#xop-azure" id="xop-azure"></a>

1. Login to your **Management Service** web panel, go to **Settings** (bottom-left corner in the left-hand side menu) and select **External Identity Providers**.

<figure><img src="/files/QjE46rUKDebt0AcoeafN" alt=""><figcaption></figcaption></figure>

2. Click **Add new provider** button and fill in the details:

> **Name:** your own custom name, i.e., **Entra ID**
>
> **Entity ID:** should be the same name you've set in **Identifier (Entity ID)** in **Azure Portal** (in this example it's **SAMLTestAzure**)

3. Next, paste the previously copied **App Federation Metadata Url** in the **Metadata URL** field.

<figure><img src="/files/FFvKZesnqS0ndjGRX3qM" alt=""><figcaption></figcaption></figure>

4. Add certificate and password if required.
5. Set up a default **Language** and **Role** for users with **Entra ID** **SAML** authentication permissions.
6. Double-check the settings and click **Save** at the bottom of **Add identity provider tab**.
7. Click **Save** to finish the setup. You can now log out and test your configured **SAML** login integration.
   {% endtab %}

{% tab title="CyberArk" %}

<p align="center"><a href="#cyberark-side" class="button primary" data-icon="circle-1">Configuration in CyberArk</a> <a href="#xop-cyber" class="button primary" data-icon="circle-2">Configuration in GitProtect</a></p>

### Configuration in CyberArk

1. Log in to your **CyberArk** account. Expand **Apps & Widgets** dropdown menu and select **Web Apps**.
2. Click **Add Web Apps** button in the top-right corner.

<figure><img src="/files/oNtFAR0d7snt3kpwVi5V" alt=""><figcaption></figcaption></figure>

3. Go to **Custom** tab, find **SAML** on the list, and click the **Add** button next to it.

<figure><img src="/files/wd8enAuE3ph5O07n1kVg" alt=""><figcaption></figcaption></figure>

4. Confirm adding **SAML** as a web app.

<figure><img src="/files/iDvFfQAFlZP5IuQNVtQS" alt=""><figcaption></figcaption></figure>

5. You’ll be redirected to **SAML** web app settings. Start with setting up a custom name for the app (i.e., **XONESAML**).

<figure><img src="/files/XMsNoKqYvtBZ9WruSDAe" alt=""><figcaption></figcaption></figure>

6. Next, set up a unique **Application ID** in **Advanced** section and **Save** your settings (in this example we will be using **XONESAMLID**).

<figure><img src="/files/MNZXdXJ9a9zd5aADct6e" alt=""><figcaption></figcaption></figure>

7. Open the **Trust** tab and copy **Metadata URL** in **Identity Provider Configuration** section (it will be needed later for **GitProtect** configuration).

<figure><img src="/files/Z71xeV1xVCzef1kpJlSh" alt=""><figcaption></figcaption></figure>

8. Next, scroll down to **Service Provider Configuration** section, set it to **Manual Configuration**, and enter the following data:

> In **SP Entity ID / Issuer / Audience** type your previously defined **Application ID** (in this example it is **XONESAMLID**)
>
> In **Assertion Consumer Service (ACS) URL** enter:
>
> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/Auth/AssertionConsumerService
>
> In **Single Logout URL** enter:
>
> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/auth/SAMLLogoutResponse

{% hint style="warning" %}
In the above address, change <mark style="color:red;">**GitProtectManagementServiceURL**</mark> to your unique **Management Service** URL. You can find it in your login URL— it's the first part of the address (i.e., in <mark style="color:red;">**<https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com>**</mark>**/authorization/login** the part highlighted in <mark style="color:red;">**red**</mark> is the URL you need to copy).
{% endhint %}

<figure><img src="/files/nvCfxvpKbSp5H9lp08BC" alt="" width="563"><figcaption><p><em>Manual configuration overview.</em></p></figcaption></figure>

9. Go to **SAML Response** tab and scroll down to **Script to set custom claims** section. Enter the following script and press the **Save** button:

{% code overflow="wrap" lineNumbers="true" %}

```xml
setFilteredAttributeArray("xoperogroup", LoginUser.RoleNames, "XONE.*");
setFilteredAttributeArray("xoperogroup", LoginUser.GroupNames, "XONE.*");
```

{% endcode %}

<figure><img src="/files/Nvv2Gsbb0aCApDnka3s3" alt=""><figcaption></figcaption></figure>

10. Head over to **Permissions** tab, click **Add** button, select all users you want to authorize to use SAML integration, and **Save** your settings.

<figure><img src="/files/xtPN88sjqopTSCLLrKnI" alt=""><figcaption></figcaption></figure>

***

### Configuration in GitProtect <a href="#xop-cyber" id="xop-cyber"></a>

1. Login to your **Management Service** web panel, go to **Settings** (bottom-left corner in the left-hand side menu) and select **External Identity Providers**.

<figure><img src="/files/QjE46rUKDebt0AcoeafN" alt=""><figcaption></figcaption></figure>

2. Click **Add new provider** button and fill in the details:

> **Name:** your own custom name, i.e., **CyberArk**
>
> **Entity ID:** should be the same name you've set in **Application ID** in **CyberArk** (in this example it's **XONESAMLID**)

3. Next, paste the previously copied **Metadata URL** in the **Metadata URL** field.

<figure><img src="/files/KdvGUwWLEoJwSxOdhUkD" alt=""><figcaption></figcaption></figure>

4. Add certificate and password if required.
5. Set up a default **Language** and **Role** for the users with **CyberArk** **SAML** authentication permissions.
6. Click **Save** to finish the setup. You can now log out and test your configured **SAML** login integration.

<figure><img src="/files/iRtIy3rrV7Zd4YinoThx" alt="" width="554"><figcaption><p><em><strong>XMS</strong> login page with <strong>CyberArk</strong> SAML integrity set up.</em></p></figcaption></figure>
{% endtab %}

{% tab title="Google" %}

<p align="center"><a href="#configuration-in-google" class="button primary" data-icon="circle-1">Configuration in Google</a> <a href="#xop-google" class="button primary" data-icon="circle-2">Configuration in GitProtect</a></p>

### Configuration in Google

1. Login to your **Google** admin console. Next, click the burger menu icon ![](/files/RkrOtA9ic7iGMBJmmVzZ) in the top-left corner of the screen and go to ![](/files/PZnCTGdwDL4N8WCESpGD)**Apps** > **Web and mobile apps**. Click **Add app** and select **Add custom SAML app** from the drop-down menu.

<figure><img src="/files/JAcgVUDgKn42rPaiNhHH" alt="" width="563"><figcaption></figcaption></figure>

2. In the app details page create a custom name for your app and type it in **App name** field, then click **Continue**.

<figure><img src="/files/qBcbXgNTA23gFqsWJdkO" alt="" width="563"><figcaption></figcaption></figure>

3. Next, click **DOWNLOAD METADATA** button under **Option 1: Download IdP metadata**. Upload the downloaded file to your web server and save its URL (it will be needed later for **GitProtect** configuration).

<figure><img src="/files/1ld7AXseNhQvIzCW3lMZ" alt="" width="563"><figcaption></figcaption></figure>

4. Click **Continue** and in the next window screen fill the **Service provider details** as follows:

> **ACS URL:**
>
> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/Auth/AssertionConsumerService
>
> **Entity ID:** custom, globally unique name (in this example we'll be using **SAMLGOOGLE**)
>
> **Start URL (optional):** your <mark style="color:red;">**GitProtectManagementServiceURL**</mark>

{% hint style="info" %}
In the above address, change <mark style="color:red;">**GitProtectManagementServiceURL**</mark> to your unique **Management Service** URL. You can find it in your login URL— it's the first part of the address (i.e., in <mark style="color:red;">**<https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com>**</mark>**/authorization/login** the part highlighted in <mark style="color:red;">**red**</mark> is the URL you need to copy).
{% endhint %}

<figure><img src="/files/uwVzhzaQzh7rXVIUFHSL" alt=""><figcaption></figcaption></figure>

5. Once done, click **Continue** and on the next page hit **Finish**.
6. Back on the admin console main page, click the burger menu in the top-left corner, go to **Apps** > **Web and mobile apps**, then select your newly created SAML app.
7. Click **User access** and select either **On for everyone** or **Off for everyone** based on your organization's needs.

<figure><img src="/files/nzqpKyWRjsmhxea9P9Z2" alt=""><figcaption></figcaption></figure>

8. Once done, hit **Save** to finish the configuration process.

***

### Configuration in GitProtect <a href="#xop-google" id="xop-google"></a>

1. Login to your XMS web panel, go to **Settings** (bottom-left corner in the left-hand side menu) and select **External Identity Providers**.

<figure><img src="/files/QjE46rUKDebt0AcoeafN" alt=""><figcaption></figcaption></figure>

2. Click **Add new provider** button and fill in the details:

> **Name:** your own custom name, i.e., **Google**
>
> **Entity ID:** should be the same name you've set in Google (in this example it's **SAMLGOOGLE**)

<figure><img src="/files/Z3m8UUyPBKLOl3ZPrulW" alt=""><figcaption></figcaption></figure>

3. Next, paste the previously copied metadata URL in the **Metadata URL** field.
4. Add certificate and password if required.
5. Set up a default **Language** and **Role** for the users with **Google** **SAML** authentication permissions.
6. Click **Save** to finish the setup. You can now log out and test your configured **SAML** login integration.
   {% endtab %}

{% tab title="JumpCloud" %}

<p align="center"><a href="#configuration-in-jumpcloud" class="button primary" data-icon="circle-1">Configuration in JumpCloud</a> <a href="#xop-jump" class="button primary" data-icon="circle-2">Configuration in GitProtect</a></p>

### Configuration in JumpCloud

1. Log in to the **JumpCloud Admin Portal**, navigate to **USER AUTHENTICATION** > **SSO Applications**, and then click **+ Add New Application**.
2. In **Create New Application Integration** window search for **Custom Application**, select it, and hit **Next**.

<figure><img src="/files/cbfAvVmwD8WeWYl48b1R" alt="" width="563"><figcaption></figcaption></figure>

3. Check **Manage Single Sign-On (SSO)** checkbox and select **Configure SSO with SAML** option., then hit **Next**.

<figure><img src="/files/zRg1cCJaCtwNedb8hzs8" alt="" width="563"><figcaption></figcaption></figure>

4. In **Enter general info** set a unique custom application name (in this example we'll be using **XONE**), type it in **Display Label** field, and click **Save Application**.

<figure><img src="/files/XJckwnC0EjWpMW2SGMTb" alt="" width="563"><figcaption></figcaption></figure>

5. In your new application settings go to **SSO** tab and fill the fields as follows:

> **IdP Entity ID:** your unique application name (in this example it's **XONE**)
>
> **SP Entity ID:** your unique application name (in this example it's **XONE**)

<figure><img src="/files/pJlNFlDYxcxZZzIIfy4c" alt="" width="563"><figcaption></figcaption></figure>

6. Click the **Copy Metadata URL** button under **JumpCloud Metadata** at the top and save it for later— it will be needed for **GitProtect** configuration in **XMS**.
7. Scroll down, set **SAMLSubject NameID** to **email**, and for **SAML Subject NameID Format** select **urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress** from the drop down menu.

{% hint style="warning" %}
The **Signature Algorithm** by default is `RSA-SHA256`— leave it as is.
{% endhint %}

<figure><img src="/files/xs2C5VIxa4f4n5SAZsCg" alt=""><figcaption></figcaption></figure>

8. In **Sign** section select **Assertion**. The IDP URL should read:

> <kbd><https://sso.jumpcloud.com/saml2/xone></kbd>

<figure><img src="/files/JbNZTiIHYl2FyeIH7E6j" alt="" width="442"><figcaption></figcaption></figure>

{% hint style="danger" %}
If you also want to login to GitProtect from the JumpCloud panel, additionally, add your **XoperoONEManagementServiceURL** in **Login URL** field.
{% endhint %}

<figure><img src="/files/IlOuhCABR4s89mHYMDaf" alt="" width="495"><figcaption><p><em>Correctly filled <strong>Login URL</strong> example.</em></p></figcaption></figure>

9. In **Attributes** section add a new logout response by filling the fields as follows:

> **Service Provider Attribute Name:**
>
> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/auth/SAMLLogoutResponse
>
> **JumpCloud Attribute Name:** select **email** from the drop-down menu

{% hint style="warning" %}
In the above address, change <mark style="color:red;">**GitProtectManagementServiceURL**</mark> to your unique **Management Service** URL. You can find it in your login URL— it's the first part of the address (i.e., in <mark style="color:red;">**<https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com>**</mark>**/authorization/login** the part highlighted in <mark style="color:red;">**red**</mark> is the URL you need to copy).
{% endhint %}

<figure><img src="/files/uX9MryqBb2G9Tn7w99OJ" alt=""><figcaption></figcaption></figure>

10. Click **Save** to update the connector and move to the **User Groups** tab. Select the groups/users you want to enable JumpCloud SAML authorization for GitProtect login to.

<figure><img src="/files/LDq9uSqXvpsmTScpTss1" alt="" width="563"><figcaption></figcaption></figure>

11. Double-check if the data you entered is correct and save your configuration.

***

### Configuration in GitProtect <a href="#xop-jump" id="xop-jump"></a>

1. Login to your **Management Service** web panel, go to **Settings** (bottom-left corner in the left-hand side menu) and select **External Identity Providers**.

   <figure><img src="/files/QjE46rUKDebt0AcoeafN" alt=""><figcaption></figcaption></figure>
2. Click **Add new provider** button and fill in the details:

> **Name:** your own custom name, i.e., **JumpCloud**
>
> **Entity ID:** should be the same name you've set in **SSO IDP Entity ID** in **JumpCloud** (in this example it's **XONE**)

<figure><img src="/files/4VaHByTJtgMqJxasVRSk" alt=""><figcaption></figcaption></figure>

3. Next, paste the previously copied **Metadata URL** in the **Metadata URL** field.
4. Add certificate and password if required.
5. Set up a default **Language** and **Role** for the users with **JumpCloud** **SAML** authentication permissions.
6. Click **Save** to finish the setup. You can now log out and test your configured **SAML** login integration.
   {% endtab %}

{% tab title="Okta" %}

<p align="center"><a href="#general-requirements-and-limitations" class="button primary" data-icon="circle-1">Requirements and limitations</a> <a href="#configuration" class="button primary" data-icon="circle-2">Configuration in Okta</a> <a href="#xop-okta" class="button primary" data-icon="circle-3">Configuration in GitProtect</a></p>

### Requirements and limitations

**PKCS #12** file with **X.509** certificate and private key (usually a .pfx file; can be password protected) <mark style="color:red;">**must be included**</mark> in IdP configuration in **GitProtect**. **X.509** certificate file (usually a .crt file) for signature verification on IdP side <mark style="color:red;">**must be included**</mark> in application configuration defined in **Okta** panel.

Both files contain the same certificate. The **PKCS #12** file also contains a private key to this certificate.

{% hint style="warning" %}
If the **PKCS #12** file is password protected, add this password to the IdP configuration in **GitProtect** web panel.
{% endhint %}

***

### Configuration in Okta

1. In **Admin** dashboard (in the right-top corner of the window) expand the **Applications** tab and select the **Applications** option.

<figure><img src="/files/P8l95Yx94EgiibU5r7dn" alt=""><figcaption></figcaption></figure>

2. Hit **Create App Integration** button and select **SAML 2.0**.

<figure><img src="/files/oK4Idb7N3iwgy5ipwHPO" alt=""><figcaption></figcaption></figure>

3. In **General Settings** enter a unique application name and move to **Configure SAML** section.

<figure><img src="/files/G85nvXFXYJlIENmChB2z" alt=""><figcaption></figcaption></figure>

4. In **Configure SAML** tab set the **Single sign-on URL** parameter as follows:

> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/Auth/AssertionConsumerService

{% hint style="warning" %}
In the above address, change <mark style="color:red;">**GitProtectManagementServiceURL**</mark> to your unique **Management Service** URL. You can find it in your login URL— it's the first part of the address (i.e., in <mark style="color:red;">**<https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com>**</mark>**/authorization/login** the part highlighted in <mark style="color:red;">**red**</mark> is the URL you need to copy).
{% endhint %}

5. In **Audience URL** type your unique application name that you've previously set in **General Settings** tab.
6. Click **Show advanced settings** and upload the certificate file to **Signature Certificate** field. Check **Allow application to initiate Single Logout** checkbox in the **Enable Single Logout** section— <mark style="color:red;">**it's necessary**</mark>.
7. You will now see two additional fields under **Enable Single Logout**— fill them as follows:

> **Single Logout URL:**
>
> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/auth/SAMLLogoutResponse
>
> **SP Issuer:** your unique application name that you've previously set in **General Settings** tab (in this example it's **MyOktaApp**)

{% hint style="warning" %}
In the above address, change <mark style="color:red;">**GitProtectManagementServiceURL**</mark> to your unique **Management Service** URL. You can find it in your login URL— it's the first part of the address (i.e., in <mark style="color:red;">**<https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com>**</mark>**/authorization/login** the part highlighted in <mark style="color:red;">**red**</mark> is the URL you need to copy).
{% endhint %}

<figure><img src="/files/NaVF2N9lwh2668EnT8Am" alt=""><figcaption></figcaption></figure>

8. Next, go to **Group Attribute Statements** section and fill it as follows:

> **Name:** xoperogroup
>
> **Starts with:** XONE

<figure><img src="/files/5IcXfrVMyPY8G7qnH515" alt=""><figcaption></figcaption></figure>

9. Double-check if the data you've entered is correct and click **Next**. In the next window select **I'm an Okta customer adding an internal app** optio&#x6E;*,* then hit **Finish**.
10. Open the created application and go to **Sign On** tab.

<figure><img src="/files/bniqhczTSlOikanXvAqC" alt=""><figcaption></figcaption></figure>

11. In **SAML Signing Certificates** section select your uploaded certificate and click **Actions** > **View IdP metadata**. Copy the URL of the opened page— it will be required later in **GitProtect** configuration.
12. Once done, go to the **Assignments** tab.

<figure><img src="/files/jo0YE7TuJWlhGg8XtpI5" alt=""><figcaption><p><em><strong>Assignments</strong> tab view.</em></p></figcaption></figure>

13. Assign the application to a selected user, or group. Hit **Done** to finish the configuration.

<figure><img src="/files/K3g7Ud95T5M3g5upnPF2" alt=""><figcaption></figcaption></figure>

***

### Configuration in GitProtect <a href="#xop-okta" id="xop-okta"></a>

1. Login to your **Management Service** web panel, go to **Settings** (bottom-left corner in the left-hand side menu) and select **External Identity Providers**.

<figure><img src="/files/QjE46rUKDebt0AcoeafN" alt=""><figcaption></figcaption></figure>

2. Click **Add new provider** button and fill in the details:

> **Name:** your own custom name, i.e., **Okta**
>
> **Entity ID:** should be the same name you've set in **General Settings** in Okta (in this example it's **MyOktaApp**)

3. Next, paste the previously copied **IdP metadata URL** in the **Metadata URL** field.

<figure><img src="/files/To8nRt4Sykdt1EJvsMT5" alt=""><figcaption></figcaption></figure>

4. Add the required **certificate** and a **password** to the **Password Manager**.

<figure><img src="/files/nAWQFp6wfnq9YEzcE9gx" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
You can read more about adding a new password to the **Password Manager** in [Adding a new password](https://github.com/axurban/kb_gitprot/blob/kb_gitprot_en/login-and-password/security-assertion-markup-language-saml/broken-reference/README.md) KB article.
{% endhint %}

5. Set up a default **Language** and **Role** for the users with **Okta SAML** authentication permissions.

{% hint style="info" %}
Learn more about roles in [Roles and permissions](/management/user-accounts/roles-and-permissions) KB article.
{% endhint %}

6. Click **Save** to finish the setup. You can now log out and test your configured **SAML** login integration.
   {% endtab %}

{% tab title="OneLogin" %}

<p align="center"><a href="#configuration-in-onelogin" class="button primary" data-icon="circle-1">Configuration in OneLogin</a> <a href="#xop-onelog" class="button primary" data-icon="circle-2">Configuration in GitProtect</a> <a href="#group-mapping" class="button primary" data-icon="circle-3">Group mapping</a></p>

### Configuration in OneLogin

1. Login to your **OneLogin** admin console and go to **Applications** > **Applications** > **Add App**.
2. Search for **SAML Custom Connector (Advanced)** and select the first result from the search results.
3. Next, enter a unique, custom name for the app in **Display Name** field and hit **Save**.
4. Open the **Configuration** settings of your custom app, fill the displayed fields as follows and hit **Save** to save the configuration:

> **Audience (EntityID):** a unique, custom name to identify the app on the IdP side (in this example we'll be using **XOPEROSAML**)
>
> **ACS (Consumer) URL Validator\*:**
>
> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/Auth/AssertionConsumerService
>
> **ACS (Consumer) URL\*:**
>
> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/Auth/AssertionConsumerService
>
> **Single Logout URL:**
>
> <mark style="color:red;">**<https://GitProtectManagementServiceURL>**</mark>/auth/SAMLLogoutResponse

{% hint style="warning" %}
In the above address, change <mark style="color:red;">**GitProtectManagementServiceURL**</mark> to your unique **Management Service** URL. You can find it in your login URL— it's the first part of the address (i.e., in <mark style="color:red;">**<https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com>**</mark>**/authorization/login** the part highlighted in <mark style="color:red;">**red**</mark> is the URL you need to copy).
{% endhint %}

<figure><img src="/files/cI8KQLbVsZrymsM9qlIQ" alt="" width="532"><figcaption></figcaption></figure>

5. Click the **SSO** menu option on the left. Change **SAML Signature Algorithm** to **SHA-256**. Copy the **Issuer URL** value and save it for later— it will be needed for **GitProtect** configuration.

{% hint style="warning" %}
To properly configure logout, the private key of the entity that receives the logout request is <mark style="color:red;">**required**</mark>. You <mark style="color:red;">**must**</mark> upload a file with the .pfx extension to **GitProtect** for **OneLogin** integration to work properly. Unfortunately, the .pfx file cannot be downloaded directly from **OneLogin**— you have to use your own certificate or generate it for implementation.
{% endhint %}

{% hint style="success" %}
**OneLogin** offers a form where you can generate a self-signed certificate: <https://developers.onelogin.com/saml/online-tools/x509-certs/obtain-self-signed-certs>
{% endhint %}

6. Save all your settings. Open **Users** settings in the left-hand side menu, select user(s) you want to have permission to use **OneLogin** for **GitProtect** authentication, then in the window that pops-up, check the **Allow user to sign in** checkbox and hit **Save**.

{% hint style="danger" %}
Manually edited login details <mark style="color:red;">**always**</mark> override those set by rules or with provisioned attributes.
{% endhint %}

7. In the **Applications** tab, use the **(+)** button to add proper permissions to your custom application.

***

### Configuration in GitProtect <a href="#xop-onelog" id="xop-onelog"></a>

1. Login to your **Management Service** web panel, go to **Settings** (bottom-left corner in the left-hand side menu) and select **External Identity Providers**.

<figure><img src="/files/QjE46rUKDebt0AcoeafN" alt=""><figcaption></figcaption></figure>

2. Click **Add new provider** button and fill in the details:

> **Name:** your own custom name, i.e., **OneLogin**
>
> **Entity ID:** should be the same name you've set in **Configuration** (**Audience (EntityID)**) in OneLogin (in this example it's **XOPEROSAML**)

3. Next, paste the previously copied **Issuer URL** in the **Metadata URL** field.

<figure><img src="/files/CATnPof9p4PJJe4zmJwD" alt=""><figcaption></figcaption></figure>

4. Upload the previously downloaded **OneLogin** .pfx certificate file and add a password to it if required.
5. Set up a default **Language** and **Role** for the users with **OneLogin** **SAML** authentication permissions.
6. Click **Save** to finish the setup. You can now log out and test your configured **SAML** login integration.

{% hint style="warning" %}
It's important to understand that with this integration method, you <mark style="color:red;">**cannot**</mark> initiate the login from the **OneLogin** application page. Instead, the login <mark style="color:red;">**must always**</mark> be triggered directly from the **GitProtect** side.
{% endhint %}

***

### Group mapping

{% hint style="success" %}
You can use group mapping if you have many users whom you want to assign different permissions to.
{% endhint %}

{% hint style="danger" %}
Each new login to **GitProtect** resets permissions to default— if you change permissions for a user it will only apply <mark style="color:red;">**during the active session**</mark>. Relogging the user will make permissions return to default.
{% endhint %}

{% hint style="warning" %}
Group mapping configuration <mark style="color:red;">**must**</mark> be done both in **OneLogin** and **GitProtect**— start by configuring the **OneLogin** side.
{% endhint %}

1. Go to **User** > **Roles** and create roles you would like to use (i.e., **XONE viewers**, **XONE admins**, etc.). Assign these roles to different users.

<figure><img src="/files/GjsSkMgruU6GsxQOC3NJ" alt="" width="563"><figcaption></figcaption></figure>

2. Next, in **Applications** tab, edit the SAML application. Go to **Parameters** and use the **(+)** icon to create a new parameter. In **Name** field enter <kbd><http://schemas.xmlsoap.org/claims/Group></kbd>. Check both **Flags** (**Include in SAML assertion** and **Multi-value parameter**) and save your settings.
3. In **Default if no value selected** section select **User Roles** and **Semicolon Delimited input (Multi-value output)** from the drop-down menu, and save the parameter.

<figure><img src="/files/KFgO89tI6o8ixov5yfek" alt="" width="539"><figcaption></figcaption></figure>

4. In your **GitProtect** console go to ⚙️ **Settings** > **External Identity Providers** and select the IdP you want to edit.
5. Click the **Group mapping** button in the bottom left. In **Claim type** field enter <kbd><http://schemas.xmlsoap.org/claims/Group></kbd>, and in **Claim value** field enter the name of the role, e.g., **XONE viewers**. Select roles and permissions you want this group to have, then save. Repeat this step for each role/permission you want to create.

<figure><img src="/files/onhrt6xXTWUWwv6e4Qs4" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

***

## Using IdP authentication method

To log in to **GitProtect** using a SAML-integrated identity provider, always start from the **GitProtect** panel. Do not log in from the IdP panel (for example, the **Okta** panel) to the application configured for **GitProtect** — the only exception is **JumpCloud**, which provides a built-in option to log in directly from its panel.

To enable an existing **GitProtect** user to log in via an identity provider (IdP), you must turn on the IdP login toggle for that account (⚙️ **Settings** > **Accounts** > **Edit**). Once an account is set to use an identity provider (IdP) for authentication, it cannot be switched back. To change the authentication method, **you must delete the account and add it again**.

{% hint style="danger" %}
Enabling IdP login for the root admin account will prevent logging into the system when an external provider is unavailable.
{% endhint %}

<figure><img src="/files/h2JG8hvpCxeCygzbKuh5" alt=""><figcaption></figcaption></figure>


# Group mapping

In this article you will learn how to configure group mapping for SAML authentication.

For IdP integration, **GitProtect** uses differentiated login levels (i.e., **Admin**, **Backup Operator**, **Viewer**, etc.). By default, single users are being authenticated with predefined permissions, based on the roles they are assigned. If you require multiple users to log in with consistent security policies, permissions, or access rights, you can implement group mapping.

The configuration process includes specifying two key parameters: **claim type** and **claim value** — for example, in **Entra ID**, the following parameters refer to:

1. **Claim type** — name of the custom claim defined for the application on the **Entra ID** side to identify the group. In this example, **claim type** value is set to <kbd>xoperogroup</kbd>.
2. **Claim value** — a unique **Entra ID** group identifier (ID) to be mapped (<mark style="color:red;">**not its name**</mark>).

<figure><img src="/files/6PI9FDjqdX3qwcCWEfnm" alt="Azure AD group mapping"><figcaption><p><em>Group mapping configuration.</em></p></figcaption></figure>

{% hint style="warning" %}
The only account not subject to group mapping permissions is the root admin — logging in using SAML with different group permissions doesn't change the root admin access level; user remains the root admin after signing in, and so do their root admin assigned permissions.
{% endhint %}


# Active Directory integration

Learn how to integrate Active Directory with GitProtect using LDAP.

**Integrating Active Directory (AD) with GitProtect enables automated user provisioning upon login, group-to-role mapping, and administrative fallback authentication.**

***

## General information

Integrating **Active Directory** (**AD**) with **GitProtect** (supporting both LDAP and LDAPS protocols) enables centralized and automated permission management within the backup system.

The automatic provisioning feature eliminates the need to create user accounts manually. Instead, each user's **GitProtect** profile is created automatically during their first login. User information and assigned roles are continuously synchronized and updated based on the **Active Directory** group structure. Administrators can further control the **GitProtect** environment by limiting authentication to selected **AD** groups and configuring the system's default language.

Additionally, administrators retain independent emergency access to the system. After each successful authentication, the system stores user's LDAP attributes and group memberships retrieved from **Active Directory** in its local database, while the user's password is securely managed by the password module. If the **Active Directory** server becomes unavailable, the system retrieves the required user and group information from the local database. If the provided password matches the securely stored record in the password module, the user is authenticated and granted access as if they had logged in through **Active Directory**.

***

## Adding Active Directory service to **GitProtect**

The following steps outline how to configure **Active Directory** (**AD**) settings in **GitProtect Management Service**.

{% stepper %}
{% step %}
Navigate to **⚙️ Settings** > **External Identity Providers**, then click **Add new provider** and select **Active Directory**.

<figure><img src="/files/407eXi2mAo11Riicmzck" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Specify the required parameters.

<figure><img src="/files/lSShQIkXg0R4nLpkBnDB" alt=""><figcaption></figcaption></figure>

* **Name:** custom IdP name.
* **Server address:** **Active Directory** server address, either IP or FQDN.
* **Server port:** 389 (LDAP) or 636 (LDAPS).
* **Start point:** the starting point in the **Active Directory** tree (e.g., `ou=local-dev,DC=ad,DC=local,DC=dev,DC=organization,DC=com`).
* **Account name:** service account name, either UPN (**username\@domain**) or DL (**domain\username**).
* **LDAP server certificate:** if required by your network infrastructure, upload the server's security certificate (PEM, DER, or CRT format) to verify the server's identity.

{% hint style="danger" %}
The connection will succeed if the certificate specified in the settings—or located in the certificates directory (matching the server name)—is valid and matches the server's certificate. Otherwise, the system falls back to default verification, meaning **self-signed certificates will be automatically rejected and the connection will fail**.
{% endhint %}

* **Directory synchronization frequency:** define how often the user database is refreshed and synchronized with **Active Directory**.
* **Add or select password from Password Manager:** service account password.
  {% endstep %}

{% step %}
Select the preferred language, default role assigned to users, and default user permissions.

<figure><img src="/files/SulfjKlBpGUerleuv7jX" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
To define roles for specific user groups, click **Group mapping**. You can [configure group mapping](#group-mapping) at any time, either during the initial integration or later.

{% hint style="warning" %}
If no group mapping is configured, all users within the specified **Active Directory** domain inherit the default role and permissions for their **GitProtect** accounts.
{% endhint %}
{% endstep %}

{% step %}
Before proceeding, you can test the connection by clicking the question mark at the bottom of the configuration panel.

<figure><img src="/files/nBUkWKMbaDlSf4NOv5qm" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Review your settings and click **Save**. After successfully integrating **Active Directory** with **GitProtect**, a **GitProtect** account is created for each user upon their first login, with permissions based on the default roles or group mapping.

{% hint style="success" %}
Users can log in to the **GitProtect Management Service** using either their UPN (**username\@domain**) or DL (**domain\username**).
{% endhint %}
{% endstep %}
{% endstepper %}

***

## Group mapping

The following steps outline how to configure group mapping settings in **GitProtect Management Service**.

{% stepper %}
{% step %}
Navigate to **⚙️ Settings** > **External Identity Providers**, then click **Add new provider** > **Active Directory** or edit an existing one. In the **Active Directory** configuration aside, scroll down and click **Group mapping**.

<figure><img src="/files/cdlFZJfH6uqjyXjuB1N9" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the next aside, click **+ Add new group mapping** (or edit an existing one) and specify the required parameters.

<figure><img src="/files/rKEDNg0NlG9yPimnXfHE" alt=""><figcaption></figcaption></figure>

* **Claim type:** context for the claim value, in this case <kbd><http://schemas.microsoft.com/ws/2008/06/identity/claims/role></kbd>
* **Claim value:** name of the **Active Directory** (**AD**) group (for example, **Domain Admins**).
* **Role:** permission level that will be assigned to all users belonging to the specified **AD** group.
* **Permissions:** supplementary privileges to grant to the specified **AD** group beyond their base role (optional).
  {% endstep %}

{% step %}
Review your configuration details and click **Save**. Once done, all users within the specified **Active Directory** group will automatically inherit the selected roles and permissions.&#x20;

{% hint style="success" %}
Access mapping applies dynamically, both during initial user provisioning and as an immediate update to existing **GitProtect** accounts.
{% endhint %}
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% embed url="<https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/technical-reference/the-role-of-claims>" %}


# Two-factor authentication (2FA)

Learn how to enable two-factor authentication in GitProtect.

#### 2FA (two-factor authentication) is a security method that requires two verification factors to confirm a user’s identity, making accounts much harder to compromise even if a password is stolen.

***

## General information

**GitProtect** supports two-factor authentication (aka **2FA**, multi-factor authentication, **MFA**) based on an authenticator application. To use **2FA** with your **GitProtect** account, you have to first enable **MFA** in your **GitProtect Management Service** admin panel, and then set it up.

## Enabling 2FA in GitProtect

{% stepper %}
{% step %}
Click your profile icon in the top-right corner of your **Management Service** panel and select **Account**.

<figure><img src="/files/KL6vnJinSavHXQbiILeD" alt=""><figcaption><p><em>Account settings in GitProtect.</em></p></figcaption></figure>
{% endstep %}

{% step %}
Toggle **Two-factor authentication** button and click **Save** in the bottom-right.

<figure><img src="/files/SaS6IPPcpp8m3hQxbyyl" alt=""><figcaption><p><em>2FA option turned on.</em></p></figcaption></figure>
{% endstep %}

{% step %}
You will see the change confirmation in the top-right corner of the screen. Once done, log out of your **Management Service**, then log back in to trigger **2FA** setup.
{% endstep %}
{% endstepper %}

***

## 2FA setup in GitProtect

{% hint style="danger" %}
With **2FA** turned on in **Management Service**, you will be prompted to complete the authenticator app setup during your next login. All subsequent logins will require a successful two-factor verification.
{% endhint %}

{% stepper %}
{% step %}
Scan the QR code or copy the secret key to your authenticator app. Enter the code from your authenticator app in the designated fields. Once done, click **Verify now** to finish the application setup.

<figure><img src="/files/PZq6UbySJmgXyH9zt9Uk" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
If the verification is successful, you will see a confirmation message.

Below the message you will find your recovery codes — save them before you go to the management console app. If you fail o save the codes right away, you can generate them later in your **Management Service** account settings.

<figure><img src="/files/JW75uyP0qhk3JQ4fDjKk" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Your **MFA** setup is now complete. Next time you login to your **Management Service** panel, you will be prompted to verify yourself with **MFA**.
{% endstep %}
{% endstepper %}

***

## Recovery codes

If you lose access to your authenticator app, you can log in to **Management Service** using one of the recovery codes generated during 2FA setup.

{% hint style="danger" %}
**Each code is valid for a single login only** — once used, it expires.
{% endhint %}

Unused codes do not expire over time; they remain active until used or until new codes are generated, either manually or by re-registering the **2FA**.

If you have used several codes or suspect they have been compromised, you can generate a new set by going to ⚙️ **Settings** > **Accounts** > **Edit account** and clicking **Generate recovery codes** button.

<figure><img src="/files/oz1HzKRG5yGunknPdskM" alt=""><figcaption></figcaption></figure>

***

## Reconfiguring the authenticator app

{% stepper %}
{% step %}
Log in to your account (use a recovery code if your authentication device is lost or otherwise unavailable).
{% endstep %}

{% step %}
Go to **⚙️ Settings** > **Accounts** > **Edit account**.
{% endstep %}

{% step %}
Toggle **Two-factor authentication** off to disable it and **save the change**. Then toggle it back on and **save the change again**.

<figure><img src="/files/dd74iYROVltLDxm3dMBr" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Your 2FA configuration is now reset. During your next sign-in, you will be prompted to complete the authenticator app setup.
{% endstep %}
{% endstepper %}


# Password reset

Find how to reset the root password in GitProtect for on-premise & SaaS deployment models.

## If you have access to your GitProtect Management Service <a href="#on-premise" id="on-premise"></a>

{% stepper %}
{% step %}
Login to **Management Service**, open **Settings** (gear ⚙️ icon in the bottom-left corner) and select **Accounts**.

<figure><img src="/files/MoaRaXRp6INbSnZrnqPK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Find your root account and click the **edit** (✏️) icon.

<figure><img src="/files/oFBI1ugqY1j3kkXXSTps" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Enter your old password and your new password in the correct fields, then click **Change**.

{% hint style="warning" %}
Keep in mind that when you're creating a new root account password you <mark style="color:red;">**have to meet the password complexity requirements**</mark>.
{% endhint %}

{% hint style="danger" %}
By default, the system remembers **three most recently used passwords**, which **cannot be used again when creating a new password —** the number of previously used passwords that must remain unique can be adjusted in the **Unique new passwords** section under ⚙️**Settings** > **Advanced**.
{% endhint %}

<figure><img src="/files/KAEmto7KAn4CWkg4x7wJ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Hit the **Save** button to finish. Your password should now be successfully changed.
{% endstep %}
{% endstepper %}

***

## If you don't have access to your GitProtect Management Service

{% stepper %}
{% step %}
Open your **Management Service** login page and click **Forgot password?** link under credentials fields.

<figure><img src="/files/DsFXjKw2SrCtc5L8nBbE" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Enter the email address associated with your root account and hit **Send me a recovery link** button.

<figure><img src="/files/WLkE6kY7t5DK0WwxeYFQ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
You will see a message confirming the password reset has been initiated. Follow the next steps based on your deployment model (SaaS or on-premise):

**a. For SaaS model:**

1. If the password reset was initiated correctly you will see the following message:

<figure><img src="/files/EjgSLCrdr6qeqQnotS85" alt=""><figcaption></figcaption></figure>

2. Open your inbox, find the email from **GitProtect & GitProtect.io** and click the **Password reset** button.
3. Set a new password for your root account and press **Save**.

{% hint style="warning" %}
Keep in mind when you're creating a new root account password you <mark style="color:red;">**have to meet the password complexity requirements**</mark>.
{% endhint %}

{% hint style="danger" %}
By default, the system remembers **three most recently used passwords**, which **cannot be used again when creating a new password —** the number of previously used passwords that must remain unique can be adjusted in the **Unique new passwords** section under ⚙️**Settings** > **Advanced**.
{% endhint %}

4. You will receive a confirmation once the password is changed successfully.

<figure><img src="/files/cxQXu7eGwqeWHleG5Wg4" alt=""><figcaption></figcaption></figure>

**b. For on-premise model:**

{% hint style="warning" %}
The following steps apply to the on-prem model <mark style="color:red;">**without a configured SMTP server**</mark>. When the SMTP server is configured, the on-prem version processes the password reset via email, similarly to the SaaS model.
{% endhint %}

1. Once you see the following message, your root account password is already changed.

<figure><img src="/files/MzYV1EKB4TOMRaw2JrBb" alt=""><figcaption></figcaption></figure>

2. You can find it in a .txt file in the following path:

> <sub><kbd>C:\ProgramData\GitProtect\GitProtect Backup\&Recovery Service\pwdreset<kbd></sub>\ <sub><kbd><email@domain.com.txt><kbd></sub>
> {% endstep %}
> {% endstepper %}


# GitProtect Management Service

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/aSXxFD7oby8Y0Gl10dAa">/pages/aSXxFD7oby8Y0Gl10dAa</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/Qgurz8HKbI3g3aceZOoP">/pages/Qgurz8HKbI3g3aceZOoP</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/z1IDz5F71jPtch3nfLOD">/pages/z1IDz5F71jPtch3nfLOD</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/vE6HIsISBA1qYpXmzFhu">/pages/vE6HIsISBA1qYpXmzFhu</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Installation on Windows & Linux

This article describes the process of GitProtect Management Service installation on Windows, Linux, and as a Docker container for on-premise deployment model.

{% hint style="warning" %}
Before you begin the installation process, check the following articles: [System requirements](/gitprotect-software/software-information/system-requirements), [Supported platforms](/gitprotect-software/software-information/supported-platforms).
{% endhint %}

{% hint style="success" %}
To register for a free trial and download the installer visit the [**GitProtect** website](https://gitprotect.io/). If you're already a registered user, download the installer [here](https://gitprotect.io/latest-update.html#installers).
{% endhint %}

{% tabs fullWidth="false" %}
{% tab title="Windows" %}

### Installation process for Windows

1. Download and run **GitProtect** installer.

<figure><img src="/files/6Xblr9CVvfBP1ph4t5Hz" alt=""><figcaption></figcaption></figure>

2. Click **Next** to start the installation setup.

<figure><img src="/files/4rrW335nAszwjZjm2CLc" alt=""><figcaption></figcaption></figure>

3. Accept the **End-User License Agreement** and hit **Next** to continue.

<figure><img src="/files/D8XUbgFsYFfs9IG8YTBi" alt=""><figcaption></figcaption></figure>

4. Select the installation folder and click **Next**.

<figure><img src="/files/WIVaGNFjmFnp7P7DIWWX" alt=""><figcaption></figcaption></figure>

5. Define the HTTP port for **GitProtect Management Service**. Depending on your needs you can either use a custom HTTP port, or stay with the default **Management Service** HTTP port (28555).

<figure><img src="/files/QKBDyeEvayZA4pCmRsrX" alt=""><figcaption></figcaption></figure>

6. Click **Install** to start the installation process.

<figure><img src="/files/raYOY6mQm0b3gNTQhJh5" alt=""><figcaption></figcaption></figure>

7. Once the installation is completed successfully, click **Finish** to close the installation wizard.
   {% endtab %}

{% tab title="Linux" %}

### Installation process for Linux

1. Download and run **GitProtect** installer (`xoperoserver.sh`).

<figure><img src="/files/wuhgR2ZJGKDOt9o8aAX1" alt="Downloading xoperoserver.sh"><figcaption></figcaption></figure>

2. Add `execute` permission to the downloaded file using the following command:

```bash
chmod +x xoperoserver.sh
```

<figure><img src="/files/oxnBTK1MagadKDD9JHY8" alt="Adding execute permission"><figcaption></figcaption></figure>

3. Run `xoperoserver.sh`. Accept the **End-User License Agreement** to continue.

<figure><img src="/files/kVXOzOyiPd8UzTa1eywO" alt="End-user license agreement"><figcaption></figcaption></figure>

4. Once the installation is completed, you can close the software installation window.

{% hint style="warning" %}
Please note that, by default, the **GitProtect Management Service** installed on **Linux** uses port 28555.
{% endhint %}

<figure><img src="/files/xKrIYxSznYo1LuYyrdFZ" alt="Finished installation window"><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}


# Installation within a Docker container

This article describes the process of GitProtect Management Service installation within Docker container for on-premise deployment model.

{% tabs %}
{% tab title="Docker Desktop (manual)" %}

### Deployment <a href="#installation_process" id="installation_process"></a>

1. Download the **GitProtect Management Service** [**Docker** image](https://xopero.com/download/xopero_one/latest/management-image.tar) to your device. Open **cmd** console and pull **Management Service** **Docker** image using the following command:

```docker
docker load -i <docker_name>.tar
```

{% hint style="danger" %}
Replace `<docker_name>.tar` with the name of your **Management Service Docker** image file.
{% endhint %}

2. Once the **Docker** image is imported, use the following command to create a container:

```docker
docker run -d \
  --name <container_name> \
  -p <xms_port>:80 \
  -v <database_location_outside_container>:/app/Xopero \
  xopero/xopero-one-service
```

{% hint style="warning" %}
In the above command, replace **drive\_location\_database** with the location to mount the database on (from the container to the local directory) — <mark style="color:red;">**this is important for upgrading the container later**</mark>. In place of **container\_name**, enter the name of your container and in place of **service\_port**, enter the service port which will be used by **GitProtect** (by default, **Management Service** port is set to 28555).
{% endhint %}

{% code title="Example:" overflow="wrap" %}

```docker
docker run -d \
  --name xone \
  -p 28555:80 \
  -v C:\database_docker\xone:/app/Xopero \
  xopero/xopero-one-service
```

{% endcode %}

<figure><img src="/files/4j1nQBUp9ugcpzUSNx05" alt=""><figcaption></figcaption></figure>

3. Next, use the following command to view the list of containers (or view the list in **Docker Desktop**):

```docker
docker ps -a
```

<figure><img src="/files/eOB8XOF1k3iq0KJQ1r7Q" alt="viewing the container list"><figcaption></figcaption></figure>

<figure><img src="/files/JjNVvp3dFe3VFifT1d1U" alt="Docker GUI"><figcaption></figcaption></figure>

4. If you see no errors, that means the **Management Service** implementation was done correctly. You can open the **GitProtect Management Service** web panel using the following address:

```http
http://<DockerHostAddress>:28555
```

5. Before you start using **Management Service** you must create an administrator account and assign a license to your unit.
   {% endtab %}

{% tab title="QNAP NAS (Container Station > 3.0)" %}

<p align="center"><a href="#pre-qnap" class="button primary" data-icon="circle-1">Prerequisites</a> <a href="#env-qnap" class="button primary" data-icon="circle-2">Environment setup</a> <a href="#dep-qnap" class="button primary" data-icon="circle-3">Deployment</a></p>

### Prerequisites <a href="#pre-qnap" id="pre-qnap"></a>

**QNAP** with:

* x86 or x64 CPU (ARM is <mark style="color:red;">**not supported**</mark>)
* minimum 2GB of RAM
* **Container Station** app from the **App Center**

***

### Environment setup <a href="#env-qnap" id="env-qnap"></a>

1. Login to your **QNAP** web panel and open the **App Center** application. Go to **QNAP Store** > **All Apps** and search for **Container Station**.

<figure><img src="/files/WaTotFlthlbB1sOJR2ag" alt="Selecting Container Station"><figcaption></figcaption></figure>

2. Download the **Container Station** application. Once downloaded, open the app and select the path you'll be using as your **Docker** container data directory.
3. Click **Start Now** to proceed.

***

### Deployment <a href="#dep-qnap" id="dep-qnap"></a>

1. In the **Container Station** application, open the **Containers** menu option, and click the **Create** button.

<figure><img src="/files/KOId23INx4xf3VTomflK" alt=""><figcaption></figcaption></figure>

2. In **Image Configuration**, choose **Advanced mode**. For **Image type** select **Docker image**, and in the **Image** field, paste the following:

```docker
xopero/gitprotect-service:latest
```

3. Ensure **Try pulling the image from the registry before creating the container.** checkbox is checked, then hit **Next**.

<figure><img src="/files/AqobSJ4U0Mg50SvtlTPC" alt="" width="563"><figcaption></figcaption></figure>

4. In the **Configure Container** tab, configure the **GitProtect Docker** container and hit **Next** to continue.

> **Name** — set a custom name for the container
>
> **Auto start** — defines if the container should startup automatically (i.e., in case of **QNAP** restart)
>
> **Publish network ports** — enter a port number in the **Host** field— this will be the port used to connect to **GitProtect** service on the container on port 80 (the recommended host port number is 28555)

<figure><img src="/files/FXi6P32dxLDnuvL8uTVv" alt=""><figcaption></figcaption></figure>

5. Double-check your configuration settings and hit **Finish**.
6. **Container Station** will download the latest **GitProtect** image and create the container based on it.

<figure><img src="/files/ptQDElCOJPLG7WL0KZ4c" alt="" width="375"><figcaption></figcaption></figure>

7. Once the container creation process is completed, your new container will be available in the **Container Station** application (under **Containers** menu option).

<figure><img src="/files/FKdI1DGpfuDepv33wwly" alt=""><figcaption></figcaption></figure>

8. Connect to **GitProtect** using your web URL address in the following format (you can find it under **Container Details** > **General** > **Web URL**):

> `http://<QNAPaddress>:<port>`

9. To finish the **XMS** setup, create a new administrative account, provide the license code, and select data to protect.
   {% endtab %}

{% tab title="QNAP NAS (Container Station < 3.0)" %}

<p align="center"><a href="#pre-qnap2" class="button primary" data-icon="circle-1">Prerequisites</a> <a href="#env-qnap2" class="button primary" data-icon="circle-2">Environment setup</a> <a href="#dep-qnap2" class="button primary" data-icon="circle-3">Deployment</a></p>

### Prerequisites <a href="#pre-qnap2" id="pre-qnap2"></a>

**QNAP** with:

* [x] x86 or x64 CPU (ARM is <mark style="color:red;">**not supported**</mark>)
* [x] minimum 2GB of RAM
* [x] **Container Station** app from the **App Center**

***

### Environment setup <a href="#env-qnap2" id="env-qnap2"></a>

1. Login to your **QNAP** web panel and open the **App Center** application. Go to **QNAP Store** > **All Apps** and search for **Container Station**.

<figure><img src="/files/WaTotFlthlbB1sOJR2ag" alt="Selecting Container Station"><figcaption></figcaption></figure>

2. Download the **Container Station** application. Once downloaded, open the app and select the path you'll be using as your **Docker** container data directory.
3. Click **Start Now** to proceed.

***

### Deployment <a href="#dep-qnap2" id="dep-qnap2"></a>

1. Open the **Container Station** application and click ➕ **Create** in the left-hand side menu.
2. Copy and paste `xopero/gitprotect-service` in the search field and hit **Enter** to search for the **Management Service Docker** image (it should be the first search result in **Docker Hub** tab).
3. Click the **Install** button next to the **Docker** image to start the container creation process.
4. Select the latest image version and click **Next** to continue.

<figure><img src="/files/niSfC6RO68DGeowAU3es" alt="Selecting GitProtect version"><figcaption></figcaption></figure>

5. In the **Create Container** window, configure the **GitProtect Docker** container.

> **Name** — set a custom name for the container
>
> **Auto start** — defines if the container should startup automatically (i.e., in case of **QNAP** restart)
>
> **CPU Limit** — allows you to set the CPU percentage usage available for the container
>
> **Memory Limit** — RAM memory allocated to the container

6. Scroll down a little and click the ⚙️ **Advanced Settings>>**
7. In the ⚙️ **Advanced Settings>>** go to **Network** and click the **Add** button on the right. Enter a port number in the **Host** field under the **Port Forwarding** section— this will be the port used to connect to **GitProtect** service (the recommended, default port number is **28555**).

<figure><img src="/files/KZs7rTCtGxfsyEkf9lsE" alt="Creating contener - network tab"><figcaption></figcaption></figure>

8. Click the **Create** button— this will display the setup summary. Double-check your configuration and click **OK** to create the container.
9. Once the container creation process is completed, your new container will be available in the **Container Station** application (under **Container** menu option).

<figure><img src="/files/fBS6rNQeFysIXcXeRekQ" alt="View on running container with GitProtect"><figcaption></figcaption></figure>

10. Connect to **GitProtect Management Service** by launching it via **Container Station**, or using your web URL address in the following format:

> `http://<QNAPaddress>:<port>`

11. To finish the **Management Service** setup, create a new administrative account, provide the license code, and select data to protect.
    {% endtab %}

{% tab title="Synology NAS (Docker Hub)" %}

<p align="center"><a href="#pre-syno" class="button primary" data-icon="circle-1">Prerequisites</a> <a href="#dep-syno" class="button primary" data-icon="circle-2">Deployment</a></p>

### Prerequisites <a href="#pre-syno" id="pre-syno"></a>

**Synology** must meet the following requirements:

* [x] x86 or x64 CPU (ARM is <mark style="color:red;">**not supported**</mark>)
* [x] minimum 2 GB of RAM
* [x] **Docker** app from the **Package Center**

***

### Deployment <a href="#dep-syno" id="dep-syno"></a>

1. Open the **Docker Hub**, navigate to the **Container** menu, and click **Create** button.
2. Expand the **Image** section and select **Add image**. Then, search for `xopero/gitprotect-service`. Once located, select the image, click **Download**, and choose the version tagged as <mark style="color:red;">**latest**</mark>. Confirm the selection to proceed.

<figure><img src="/files/6sd3fYvRDt8QVEjjyivN" alt="" width="482"><figcaption></figcaption></figure>

3. Once you download the image, select it from the **Image** drop-down menu in **General Settings**. Next, define a name for the container and enter it in the **Container Name** field. Configure container resource limits if necessary.
4. Check the **Enable auto-restart** checkbox to ensure the container automatically restarts when the device reboots, and proceed to the next step.

<figure><img src="/files/nuOg3v7NxVDmIHJlknZG" alt="" width="549"><figcaption></figcaption></figure>

5. In **Volume Settings**, click ➕ **Add Folder** button. To ensure data persistence during container updates or maintenance operations, mount the management databases to an external directory. The databases are stored in **/app/Xopero** and should be mapped to a designated location outside the container to prevent data loss or inconsistencies.

<figure><img src="/files/fdZrsZxGuEU3EdXqTKId" alt=""><figcaption></figcaption></figure>

6. In the **Environment** section, define the required variables:

> **ASPNETCORE\_URLS** — **Management Service** ports for http and https protocol (i.e., **http\://+:**<mark style="color:red;">**PORT\_NUMBER**</mark>**;https\://+:**<mark style="color:red;">**PORT\_NUMBER**</mark>)

{% hint style="warning" %}
The management console is available on port **28555** for the encrypted protocol (**https**), and on port **28556** for the unencrypted (**http**) protocol.
{% endhint %}

<figure><img src="/files/5nw7ogzkKJnJqAPgBqo0" alt=""><figcaption></figcaption></figure>

7. Select **host** from the **Network** drop-down menu to enable the container to share the same network namespace as the container's host.

<figure><img src="/files/tUXHemuiOSAUebZvT914" alt=""><figcaption></figcaption></figure>

8. Confirm the configuration and click **Next**. In **Summary**, double-check the settings and hit **Done** to finish the container creation process.

<figure><img src="/files/18E2OAx9wveWDMNeGVqk" alt="" width="551"><figcaption></figcaption></figure>

9. Once you've created the container, you can connect to your **XMS** using one of the following addresses:

> https\://<mark style="color:red;">**yourSynologyAddress**</mark>:28555 (i.e., https\://<mark style="color:red;">**192.168.0.100**</mark>:28555)
>
> http\://<mark style="color:red;">**yourSynologyAddress**</mark>:28556 (i.e., http\://<mark style="color:red;">**192.168.0.100**</mark>:28556)
> {% endtab %}
> {% endtabs %}


# Installation with an SSL certificate

Learn how to connect to GitProtect Management Service admin panel via encrypted HTTPS protocol.

## Kestrel configuration <a href="#using_your_own_ssl_certificate" id="using_your_own_ssl_certificate"></a>

{% hint style="danger" %}
Remember that once you modify the **Management Service** settings you **must** switch the agent's communication protocol to HTTPS for the **GitProtect** service to work correctly.
{% endhint %}

{% hint style="info" %}
You can find more information about **Kestrel** configuration [here](https://learn.microsoft.com/en-us/aspnet/core/fundamentals/servers/kestrel/endpoints?view=aspnetcore-5.0).
{% endhint %}

{% stepper %}
{% step %}
Open `appsettings.json` file located in **GitProtect Management Service** installation directory.
{% endstep %}

{% step %}
Find `commented_out_Kestrel` line.

{% code title="Default commented\_out\_Kestrel line:" overflow="wrap" %}

```json
"commented_out_Kestrel": {
"Endpoints": {
"Http": {
"Url": "http://*:5000"
}
}
```

{% endcode %}
{% endstep %}

{% step %}
Modify the following code lines — erase `commented_out_` prefix and add the HTTPS configuration as follows:

{% code title="Modified commented\_out\_Kestrel section:" overflow="wrap" %}

```json
"Kestrel": {
"Endpoints": {
"Http": {
"Url": "http://*:5000"
},
"Https": {
"Url": "https://*:5001",
"Certificate":{
"Path": "<.pfx file path>",
"Password": "<certificate password>"
}}}}}
```

{% endcode %}

> **Path:** path to the .pfx fil&#x65;**\***
>
> **Password:** certificate password
>
> **\***<mark style="color:red;">**IMPORTANT!**</mark> Remember to use double slash— if you're keeping the certificate in **C:**<mark style="color:red;">**\\**</mark>**cert.pfx** directory, the path should be entered as **C:**<mark style="color:red;">**\\\\**</mark>**cert.pfx** instead.
> {% endstep %}
> {% endstepper %}

***

## Worker configuration

{% hint style="warning" %}
Modifying the IP address or the protocol (http, https) of the **Management Service** will change the active worker's status to **offline**. It will reconnect once you switch the worker's protocol to HTTPS.
{% endhint %}

{% stepper %}
{% step %}
Go to your **GitProtect worker** installation directory and open `config.json` file.

Default location of the `config.json` file is:

1. <img src="/files/C8MqFxrD1OFNMYSwuuWO" alt="" data-size="line"> **For Windows:** `C:\Program Files\Xopero ONE Backup&Recovery Agent`
2. <img src="/files/uaotmuyBCveCZzAIspW2" alt="" data-size="line"> **For Linux:** `/opt/XoperoONEBackupAgent/`
   {% endstep %}

{% step %}
Change the `ServiceUrl` value from **HTTP** to **HTTPS**.

{% hint style="success" %}
You can edit `config.json` with a simple text editor (i.e., **Notepad**, **Notepad++**).
{% endhint %}

<figure><img src="/files/PVca03N8J1oQNBmCVS0k" alt=""><figcaption><p><em>Example of <code>config.json</code> file opened in <strong>Notepad++</strong>.</em></p></figcaption></figure>
{% endstep %}

{% step %}
Once the value is changed, the worker will come back online.
{% endstep %}
{% endstepper %}


# Post-installation actions

This article contains information about how to proceed after installing the GitProtect Management Service component.

## Accessing the Management Service in on-prem deployment model

To access the on-premise **GitProtect Management Service**, connect to the device which **Management Service** console is installed on, using the following address:

```
ipAddress:port
```

> **`ipAddress`** — the IP address of the device with **Management Service** installed on
>
> **`port`** — port defined during installation process — by default, **GitProtect** uses **28555**

If your **Management Service** opened successfully, you can proceed with the below steps (creating your root account, adding the license code, logging in, running your first setup).

***

## GitProtect first configuration

{% stepper %}
{% step %}
When you launch the **Management Service** for the first time, you will be prompted to create an administrator account. To register a valid admin account you have to provide your **login** (it has to be a **valid email address**) and create a **password** compliant with the **GitProtect** password policy. Once you complete the form click **Register** to proceed to the next step.

<figure><img src="/files/e1OmNmRIYG3DThnhXiHk" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Having the administrator account registered, you will then be asked to provide a license key (which you should've received via email upon registering for **GitProtect**) — this is the last step before the **GitProtect** system becomes operational and ready to use. Once done, click **Proceed** to go to the system setup.

<figure><img src="/files/xOAv4cf6b3LFDiYwyCj0" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the initial setup you should add your first device which you want to use to set up the storage. Then, you have to install the backup **worker** and activate it in **GitProtect** system.

{% hint style="info" %}
Browse [**GitProtect worker** category](/deployment-and-configuration/gitprotect-worker) to find more information about **worker** installation.
{% endhint %}
{% endstep %}

{% step %}
Next, add the storage where you want to store your data. As **GitProtect** is a multi-storage system, you can add different storages from different sources and use both local storage (i.e., **SMB**, **NFS**) and cloud solutions (i.e., **Wasabi**, **Amazon**, etc.).

{% hint style="info" %}
Learn more about storages in [STORAGE (BACKUP DESTINATION) OVERVIEW & SETUP](/storage/overview) section.
{% endhint %}
{% endstep %}

{% step %}
With all system components initialized, you can start protecting your data and create backup plans.

<figure><img src="/files/7mkhw9Dxn4MIO0KqcvMU" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# GitProtect worker

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/iILOzIXrHMsxK9E7vvtD">/pages/iILOzIXrHMsxK9E7vvtD</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/SFPEgLTAI0LZwmZFHZyN">/pages/SFPEgLTAI0LZwmZFHZyN</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Cloud worker

{% hint style="warning" %}
Cloud worker is available <mark style="color:red;">**only**</mark> for the **GitProtect** SaaS deployment model.
{% endhint %}

The cloud **worker** is a **GitProtect worker** installed in the cloud. It connects to cloud-based environments like or cloud storage services to perform backup tasks.

You don't have to assign any licenses to cloud workers — the correct license is assigned automatically by **GitProtect** system.

Cloud worker's installation location depends on the **GitProtect Management Service** installation directory.


# Local worker

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/IPWx8wCuz6zls9PtdRX8">/pages/IPWx8wCuz6zls9PtdRX8</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/vcdp55NwIGN0qTptEqrF">/pages/vcdp55NwIGN0qTptEqrF</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/y5SqpyWypeeNVAFsfDJu">/pages/y5SqpyWypeeNVAFsfDJu</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/WAdiso4rCm6r9L36NL0S">/pages/WAdiso4rCm6r9L36NL0S</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Installation on Windows servers and workstations

{% tabs fullWidth="false" %}
{% tab title="WS 2008R2 & WS 2012" %}

<p align="center"><a href="#installer_download" class="button primary" data-icon="circle-1">Installer download</a> <a href="#installation_process" class="button primary" data-icon="circle-2">Installation process</a></p>

#### Installer download <a href="#installer_download" id="installer_download"></a>

1. Login to **GitProtect Management Service** using a web browser, then go to **Settings** > **Advanced** > **Workers** and click **Download agent** button.
2. The **Download agent** window will open — click the appropriate **worker** version to download it.

<figure><img src="/files/JjmVDL6hPObAOexj33Ln" alt=""><figcaption></figcaption></figure>

3. The download will start automatically; additionally, an **Installation** tab with a step-by-step installation instruction will pop-up in the **Management Service**.

<figure><img src="/files/9eau8z9zdg7232uzQxIp" alt="Downloading a installator"><figcaption></figcaption></figure>

4. Under the **Install** section you will see the address combined a port — save it for later as you will have to use it during **worker** installation.

<figure><img src="/files/6X7IXFLin7rfDnqbDi5t" alt="Service&#x27;s IP address and port"><figcaption></figcaption></figure>

5. Once the installation wizard is downloaded, you can move to the installation process.

***

#### Installation process <a href="#installation_process" id="installation_process"></a>

1. Open and run the downloaded setup wizard. Click **Next** to begin the installation process.

<figure><img src="/files/Q5J9X2WAHOKYUlk51HPx" alt="Installation wizard window"><figcaption></figcaption></figure>

2. Read and accept the **End-User License Agreement**, then move to the next step.

<figure><img src="/files/5KXfIfySJes1xjF40EgQ" alt="End-user agreement"><figcaption></figcaption></figure>

3. Choose the installation directory for the **GitProtect** client.

<figure><img src="/files/Z1E6zLW9El52FM8oOrOW" alt="Choosing installation path"><figcaption></figcaption></figure>

4. Paste the previously copied address to the **Address** field and hit **Next** to continue.

<figure><img src="/files/Q4oSbn3cYOXHXgzX3YIV" alt="Setting Management Service URL"><figcaption></figcaption></figure>

5. Click **Install** to start the installation.

<figure><img src="/files/MHqUszCqouoiKuN8kkaR" alt="Installation of GitProtect"><figcaption></figcaption></figure>

6. Once the wizard finishes installation, click the **Finish** button to close it.

<figure><img src="/files/7btVcnnBkCD4f3DcLUgI" alt="Finished installation"><figcaption></figcaption></figure>

7. You can now activate your device in **GitProtect Management Service**.
   {% endtab %}

{% tab title="Windows workstations & WS 2012 R2+" %}

<p align="center"><a href="#installer-download-serv" class="button primary" data-icon="circle-1">Installer download</a> <a href="#installation_process_serv" class="button primary" data-icon="circle-2">Installation process</a></p>

#### Installer download <a href="#installer-download-serv" id="installer-download-serv"></a>

1. Login to **GitProtect Management Service** using a web browser, then go to **Settings** > **Advanced** > **Workers** and click **Download agent** button.
2. The **Download agent** window will open — click the appropriate **worker** version to download it.

<figure><img src="/files/JjmVDL6hPObAOexj33Ln" alt="Choosing server version"><figcaption></figcaption></figure>

3. The download will start automatically; additionally, an **Installation** tab with a step-by-step installation instruction will pop-up in the **Management Service**.

<figure><img src="/files/SPMrzrfcBQmYYQ7Mrvqi" alt="Download link"><figcaption></figcaption></figure>

5. Under the **Install** section you will see the address combined a port— save it for later as you will have to use it during **worker** installation.

<figure><img src="/files/McwjLwLp6JGoZbZcybHq" alt="Service&#x27;s IP address and port"><figcaption></figcaption></figure>

***

#### Installation process <a href="#installation_process_serv" id="installation_process_serv"></a>

1. Open and run the downloaded setup wizard. Click **Next** to begin the installation process.

<figure><img src="/files/Q5J9X2WAHOKYUlk51HPx" alt="Installation wizard window"><figcaption></figcaption></figure>

2. Read and accept the **End-User License Agreement**, then move to the next step.

<figure><img src="/files/5KXfIfySJes1xjF40EgQ" alt="End-user agreement"><figcaption></figcaption></figure>

3. Choose the installation directory for the **GitProtect** client.

<figure><img src="/files/Z1E6zLW9El52FM8oOrOW" alt="Choosing installation path"><figcaption></figcaption></figure>

4. Paste the previously copied address to the **Address** field and hit **Next** to continue.

<figure><img src="/files/Q4oSbn3cYOXHXgzX3YIV" alt="Setting Management Service URL"><figcaption></figcaption></figure>

5. Click **Install** to start the installation.

<figure><img src="/files/MHqUszCqouoiKuN8kkaR" alt="Installation of GitProtect"><figcaption></figcaption></figure>

6. Once the wizard finishes installation, click the **Finish** button to close it.

<figure><img src="/files/7btVcnnBkCD4f3DcLUgI" alt="Finished installation"><figcaption></figcaption></figure>

7. You can now activate your device in **GitProtect Management Service**.
   {% endtab %}
   {% endtabs %}


# Installation on Linux & MacOS

{% tabs %}
{% tab title="Linux" %}

<p align="center"><a href="#prerequisites" class="button primary" data-icon="circle-1">Prerequisites</a> <a href="#agent_setup" class="button primary" data-icon="circle-2">Installation</a></p>

#### Prerequisites

Prior to **worker** installation, check if your system is meets all the requirements.

{% content-ref url="/pages/xK9JJWFmkVYCqBknYEoP" %}
[System requirements](/gitprotect-software/software-information/system-requirements)
{% endcontent-ref %}

{% content-ref url="/pages/srQ5F6tnpeA8r4mpbgA8" %}
[Supported platforms](/gitprotect-software/software-information/supported-platforms)
{% endcontent-ref %}

***

#### Installation <a href="#agent_setup" id="agent_setup"></a>

1. Download the **worker** installer (bash script) to your **Linux** system and grant execute permission to the file owner (user or group) using the following `chmod` command:

{% hint style="info" %}
To download the worker installer, login to **GitProtect Management Service** using a web browser, then go to **Settings** > **Advanced** > **Workers** and click **Download agent** button. The **Download agent** window will open — click the appropriate worker version to download it.
{% endhint %}

```bash
chmod +x xoperoclient.sh
```

<figure><img src="/files/S4bWOUDLFrYgU2ucgrlW" alt="Granting permission for installer"><figcaption></figcaption></figure>

2. Next, run the script using the following command:

```bash
./xoperoclient.sh or bash xoperoclient.sh
```

<figure><img src="/files/Iulz1nYSMcfoWsemvXcE" alt="Running the installer"><figcaption><p><em>Running the script along with <strong><code>sudo</code></strong> command</em></p></figcaption></figure>

{% hint style="warning" %}
The above script should be initiated using an account with administrative privileges— because of that it might be required to use the **`sudo`** command simultaneously (as in the above example).
{% endhint %}

3. Accept the **END-USER LICENSE AGREEMENT** to proceed.

<figure><img src="/files/OeSPrfRBKiauZPSfJR0N" alt="End-user agreement"><figcaption></figcaption></figure>

4. Next, enter the IP address in the **Address** field (including the protocol and port) and click **OK** to finish the installation. Your address can be found in **GitProtect Management Service** — the system will display it once you start downloading the **worker** installer.

<figure><img src="/files/CZWspR4Zzv22IyZ9dgeo" alt=""><figcaption></figcaption></figure>

5. Now that **GitProtect** **worker** is installed, you can activate it in the **GitProtect Management Service** web panel and start protecting your data.
   {% endtab %}

{% tab title="MacOS" %}

#### Installation <a href="#installation-mac" id="installation-mac"></a>

1. Download **GitProtect** **worker** installation wizard and run it.

{% hint style="info" %}
To download the worker installer, login to **GitProtect Management Service** using a web browser, then go to **Settings** > **Advanced** > **Workers** and click **Download agent** button. The **Download agent** window will open — click the appropriate worker version to download it.
{% endhint %}

2. Click **Continue** to proceed.

<figure><img src="/files/t7BEhOmRu1rLlNDsPBLl" alt=""><figcaption></figcaption></figure>

3. Select **Continue** in the **Read Me** section.

<figure><img src="/files/t9klc7kjJjXI5RP3l6Qs" alt=""><figcaption></figcaption></figure>

4. Read the **END-USER LICENSE AGREEMENT** and hit **Continue** to accept it.

<figure><img src="/files/D5U253mN2NKsWg2SmKWL" alt=""><figcaption></figcaption></figure>

5. Hit **Agree** to accept the terms of the software license agreement.

<figure><img src="/files/an3egmRNJoJ0fgIYgRrG" alt=""><figcaption></figcaption></figure>

6. Change the installation directory if needed and click **Install** to begin the installation.

<figure><img src="/files/YwAUJxSg106zwKsAmyUh" alt=""><figcaption></figcaption></figure>

7. During the installation process, the creator will ask you for the address of your **Management Service** — define it in this step. Your address can be found in **GitProtect Management Service**; the system will display it once you start downloading the **worker** installer.

<figure><img src="/files/qrwbQyWpe121sNvLcM0X" alt=""><figcaption></figcaption></figure>

8. Click **OK** to confirm your configuration.
9. The **GitProtect** worker has been successfully installed — you can close the installation wizard.

<figure><img src="/files/obUwv0vl5naFo4y2e5a4" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}


# Installation within a Docker container

{% tabs %}
{% tab title="Docker" %}

#### Deployment <a href="#deployment" id="deployment"></a>

1. To install the **GitProtect** **worker** within a **Docker** container, use the images available on **Docker Hub** (or download the image from the [**Xopero** website](https://xopero.com/download/xopero_one/latest/client-image.tar)):

```docker
docker pull xopero/gitprotect-agent:latest
```

2. Create a host directory for the **GitProtect Management Service** container databases (which are located at `/app/Xopero` inside the container) to store databases outside the container:

```docker
mkdir -p /opt/gitprotect-agent/data
```

3. Run the container with the correct volume mounting and environment variables using the following command:

```docker
docker run -v /host/path:/container/path -e ENV_VAR=value image_name
```

```docker
docker run -d \
  --name <container_name> \
  -e ManagementServiceUrl="<your_gitprotect_service_URL>" \
  -e XoperoOverriddenHostName="<device_name>" \
  -v /opt/gitprotect-agent/data:/app/Xopero \
  --restart unless-stopped \
  xopero/gitprotect-agent:latest
```

{% code title="Example" overflow="wrap" %}

```docker
docker run -d \
  --name xopero-worker\
  -e ManagementServiceUrl="https://192.168.1.10:28555" \
  -e XoperoOverriddenHostName="Docker_agent" \
  -v /opt/gitprotect-agent/data:/app/Xopero \
  --restart unless-stopped \
  xopero/gitprotect-agent:latest
```

{% endcode %}

4. Check if the container works correctly by using the following command:

```docker
docker ps
```

5. Once all the above steps are completed, the **worker** will report to the **Management Service** panel for activation.
   {% endtab %}

{% tab title="QNAP NAS (CS > 3.0)" %}

<p align="center"><a href="#prerequisites" class="button primary" data-icon="circle-1">Prerequisites</a> <a href="#environment_setup" class="button primary" data-icon="circle-2">Environment setup</a> <a href="#deployment-1" class="button primary" data-icon="circle-3">Deployment</a></p>

#### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

**QNAP** with:

* x86 or x64 CPU (<mark style="color:red;">**ARM is not supported**</mark>)
* minimum 2GB RAM
* **Container Station** app from **AppCenter**

***

#### Environment setup <a href="#environment_setup" id="environment_setup"></a>

1. Download the **Container Station** app from the **AppCenter**.
2. Login to your **QNAP** web panel and open the **AppCenter** application. In **QNAP Store**, select **All Apps** and search for the **Container Station**.

<figure><img src="/files/duC8cvYlmtTm0yU447EJ" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/3eGgrVyEVXRIu17X5ULQ" alt=""><figcaption></figcaption></figure>

3. Download and open the application. Select the path that will be used as a directory for your **Docker** container data, and click **Start Now** to proceed.

***

#### Deployment <a href="#deployment" id="deployment"></a>

1. Open the **Container Station** application, select the **Containers** tab, and click the **Create** button.

<figure><img src="/files/KOId23INx4xf3VTomflK" alt=""><figcaption></figcaption></figure>

2. In **Image Configuration** choose the **Advanced mode** option. In the image type, select **Docker image**, and in the **Image** field, paste the following command:

```docker
xopero/gitprotect-agent:latest
```

3. Ensure the **Try pulling image from the registry before creating the container** option is checked, and hit **Next**.

<figure><img src="/files/iopbJVzkRsGxXqj8prDb" alt=""><figcaption></figcaption></figure>

4. Within the **Configure Container** tab, the form contains several fields, with the most crucial being:

> **Name** — here you can set a custom name for the container
>
> **Restart policy** — defines if the container will star automatically in case of, for example, **QNAP** restart

<figure><img src="/files/hTDpsHGM9fhauroUJezC" alt=""><figcaption></figcaption></figure>

5. In the **Configure Container** tab, navigate to ⚙️**Advanced Settings**.
6. Go to the **Environments** section and click **Add New Variable** to add new environment variables with the following values:

{% code title="ASPNETCORE\_URLS" overflow="wrap" %}

```docker
http://+:80
```

{% endcode %}

{% code title="DOTNET\_RUNNING\_IN\_CONTAINER" overflow="wrap" %}

```docker
true
```

{% endcode %}

{% code title="ManagementServiceUrl" overflow="wrap" %}

```docker
GitProtect Management Service address
```

{% endcode %}

{% code title="XoperoOverriddenHostName" %}

```docker
your custom QNAP container name
```

{% endcode %}

{% hint style="warning" %}
Replace `GitProtect Management Service address` with your **GitProtect Management Service** addres&#x73;**\***.
{% endhint %}

**‼️\*ManagementServiceUrl** – your **GitProtect Management Service** (address in one of the following formats (depending on the deployment model):

> a. `http://ipaddress:port`, i.e., `http://192.168.0.1:28555`
>
> b. `https://XMSID.ads.xopero.com`, i.e., `https://a00b0dc0-0116-0000-0000-d0000028960e.ads.xopero.com`

<figure><img src="/files/wrJNedD5SPlXxxP2BWnt" alt=""><figcaption><p><em>Example of correctly filled environments variables.</em></p></figcaption></figure>

7. Click **Apply** to save your changes.
8. Navigate to **Storage** tab — here you can mount your **QNAP** volumes to the **GitProtect** **worker Docker** container.

{% hint style="success" %}
You can mount multiple directories to the container using **Add Volume** button and repeating the operation.
{% endhint %}

{% hint style="info" %}
To back up data from your **QNAP** device, choose **Bind Mount Host Path** under **Add Volume** drop-down menu — it lets you specify which data the **GitProtect** container can access. Select a directory from the host and enter the path visible inside the container in the **Container** field.
{% endhint %}

<figure><img src="/files/VpZni2iXRx8S5TfGmV0m" alt="" width="563"><figcaption></figcaption></figure>

<figure><img src="/files/Yq5f9MFYI3DdgpwQey7M" alt="" width="563"><figcaption></figcaption></figure>

9. Next, double-check and confirm your settings, then click **Finish** to create the container.

<figure><img src="/files/q3RaboADF5RmCeqfpjoL" alt="" width="563"><figcaption></figcaption></figure>

10. **Container Station** will download the latest **GitProtect** image and create the container based on that image.

<figure><img src="/files/NYFAfYQhks32D8iPPRz0" alt=""><figcaption></figcaption></figure>

11. Once the container creation process is completed, your new container will be visible under **Container** tab in **Container Station**.

<figure><img src="/files/4qIj38Lx0pA1BOwaSfUn" alt=""><figcaption></figcaption></figure>

12. You can now connect to your **GitProtect Management Service** admin panel to activate the **worker**.
    {% endtab %}

{% tab title="QNAP NAS (CS < 3.0)" %}

<p align="center"><a href="#prerequisites-sec" class="button primary" data-icon="circle-1">Prerequisites</a> <a href="#environment_setup-sec" class="button primary" data-icon="circle-2">Environment setup</a> <a href="#deployment-sec" class="button primary" data-icon="circle-3">Deployment</a></p>

#### Prerequisites <a href="#prerequisites-sec" id="prerequisites-sec"></a>

**QNAP** with:

* x86 or x64 CPU (<mark style="color:red;">**ARM is not supported**</mark>)
* minimum 2GB RAM
* **Container Station** app from **AppCenter**

***

#### Environment setup <a href="#environment_setup-sec" id="environment_setup-sec"></a>

1. Download the **Container Station** app from the **AppCenter**.
2. Login to your **QNAP** web panel and open the **AppCenter** application. In **QNAP Store**, select **All Apps** and search for the **Container Station**.

<figure><img src="/files/duC8cvYlmtTm0yU447EJ" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/3eGgrVyEVXRIu17X5ULQ" alt=""><figcaption></figcaption></figure>

3. Download and open the application. Select the path that will be used as a directory for your **Docker** container data, and click **Start Now** to proceed.
4. Once done, download the **GitProtect** **worker Docker** image, which is available [on our official server](https://xopero.com/download/xopero_one/latest/client-image.tar).

***

#### Deployment <a href="#deployment-sec" id="deployment-sec"></a>

1. Open the **Container Station** application and navigate the **Import** tab.
2. Click the ➕**Import** button to upload the previously downloaded **Docker** image file.

<figure><img src="/files/mznJ39ByFpph570yG2Vu" alt="Importing the docker file"><figcaption></figcaption></figure>

3. In **Create Import Task** window, select the source type and file path of the **GitProtect** worker**Docker** image and hit **Next** to continue.

{% hint style="info" %}
Selecting a file from a local source enables you to choose files stored on your device. Alternatively, you can use the **NAS** option to access files directly from **QNAP**.
{% endhint %}

<figure><img src="/files/spS07xWrd4CD29v9Rvxn" alt="Creating import task" width="375"><figcaption></figcaption></figure>

4. Within the **Create Container** tab, the form contains several fields, with the most crucial being:

> **Name** — here you can set a custom name for the container
>
> **Auto start** — defines if the container will star automatically in case of, for example, **QNAP** restart
>
> **CPU Limit** — allows you to specify the percentage of CPU usage allocated for the container
>
> **Memory Limit** — RAM limit for the container

<figure><img src="/files/di4j0xuoUDxQOCxaglI0" alt="Creating container"><figcaption></figcaption></figure>

5. Click the ⚙️**Advanced Settings >>** button and navigate to the **Environment** section.

<figure><img src="/files/15gZLJX1yIB7ZjyIqsfH" alt=""><figcaption></figcaption></figure>

6. To add a new environment variable, click the **Add** button, name it **ManagementServiceUrl**, and set its value to your **GitProtect Management Service** addres&#x73;**\***.

**‼️\*ManagementServiceUrl** – your **GitProtect Management Service** address in one of the following formats (depending on the deployment model):

> a. `http://ipaddress:port`, i.e., `http://192.168.0.1:28555`
>
> b. `https://XMSID.ads.xopero.com`, i.e., `https://a00b0dc0-0116-0000-0000-d0000028960e.ads.xopero.com`

<figure><img src="/files/W4IXwP8y980NRCMGOQn2" alt="create container"><figcaption></figcaption></figure>

7. Go to the **Shared Folders** section — here you can mount your **QNAP** volumes to the **GitProtect** **worker** **Docker** container.

{% hint style="success" %}
You can mount multiple directories to the container using **Add** button in **Volume from host** section and repeating the operation.
{% endhint %}

<figure><img src="/files/3DOQccJG89G4J8w8M3wq" alt="Setting shared folders"><figcaption></figcaption></figure>

8. To back up data from your **QNAP** device, choose **Add** under **Volume from host** section — it lets you specify which data the **GitProtect** container can access. Select a directory from the host in **Volume from host** field and enter the path visible inside the container in the **Mount Point** field.

{% hint style="info" %}
For instance, if you need to back up a directory named **Backup** inside a public shared folder, set the **Volume from the host** field to `/Public/Backup`. The **Mount Point** can be different, i.e., `/Backup`.
{% endhint %}

9. Once you're done with the above steps, click **Create** to continue.
10. In the **Summary** window double-check your settings, then click **OK** to finish the configuration.

<figure><img src="/files/kPssaRN5eYeeaBJeNFum" alt="Summary window"><figcaption></figcaption></figure>

10. You can now connect to your **GitProtect Management Service** admin panel to activate the agent.
    {% endtab %}

{% tab title="Synology NAS" %}

#### Deployment

{% hint style="warning" %}
To deploy the **GitProtect** **worker** on a **Synology** device using **Docker**, use the **Container Manager** application. If it's not installed, download it from the **Package Center**.
{% endhint %}

1. Navigate to the **Container** tab and click the **Create** button. Expand the **Image** section and click **Add image**, then search for `xopero/gitprotect-agent` image.

<figure><img src="/files/YMoZEYHWrLSQbaPLbn4v" alt="" width="563"><figcaption></figcaption></figure>

2. Select the image, click **Download**, and choose the version tagged as latest. Click **Select** to confirm.
3. Once the image is downloaded, select it from the **Image** field drop-down menu.
4. Next, define a custom name for the container. Additionally, configure container resource limits if needed.
5. Check the **Enable auto-restart** option to ensure the container automatically restarts when the device reboots, then click **Next** to proceed.

<figure><img src="/files/cNnmo5tg8tjTltGvcMYL" alt="" width="563"><figcaption></figcaption></figure>

6. In the **Volume Settings** section, click the ➕**Add Folder** button, and select directories that require protection. The container needs to have external directories mounted to access them while performing backups.

{% hint style="info" %}
To protect data stored in the **Public** directory, select this folder and specify the same path to ensure consistency between the host and the container's file systems.
{% endhint %}

{% hint style="success" %}
You can mount multiple directories to the container by clicking ➕ **Add Folder** and repeating the operation.
{% endhint %}

7. Additionally, to ensure data persistence during container updates or maintenance operations, mount **worker** databases to an external directory. These databases are located in `/app/Xopero` and should be mapped to a designated location outside the container to avoid data loss or inconsistency.

<figure><img src="/files/V3w9U6FGEGT5erIPEHxe" alt=""><figcaption></figcaption></figure>

8. Next, in the **Environment** section, define the required variables:

> **ManagementServiceUrl** — your **GitProtect Management Service** address in one of the following formats (depending on the deployment model):
>
> a. `http://ipaddress:port`, i.e., `http://192.168.0.1:28555`
>
> b. `https://XMSID.ads.xopero.com`, i.e., `https://a00b0dc0-0116-0000-0000-d0000028960e.ads.xopero.com`
>
> **XoperoOverriddenHostName** — specify worker's name to facilitate identification

<figure><img src="/files/IfNDJD0w5hkzYqli0t5o" alt=""><figcaption></figcaption></figure>

9. Click **Next** to confirm the configuration. In **Summary** window, double-check your settings and if they're all correct, hit **Done** to finalize the process.

<figure><img src="/files/H9UargZa34xbitTJjtpd" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}


# Worker configuration

## Activation (license assignment)

{% stepper %}
{% step %}
Login to your **GitProtect Management Service** console.
{% endstep %}

{% step %}
Click the **Activate agent** icon in the top menu.
{% endstep %}

{% step %}
A sidebar will appear, showing a list of available agents — you can view basic details like device type, name, IP address, and operating system.

<figure><img src="/files/mKnKVphror2IvzRpDquO" alt="workeractivation"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the device you want to activate (you can select multiple devices if you assign them the same license type) and press the **Activate** button to proceed.
{% endstep %}

{% step %}
Next, select the license type you want to assign to the chosen device(s) and click **Assign license** to confirm your selection.
{% endstep %}

{% step %}
Once the license is correctly assigned, your device(s) will be visible in the **Devices** tab.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
In the **GitProtect** system, the local worker, cloud worker, and feature worker licenses are free. These licenses allow specific operations, except for backing up the device itself — thus, devices with these licenses appear under **Settings** > **Advanced** > **Workers** tab.
{% endhint %}

***

## Configuration

{% hint style="danger" %}
To modify the `config.json` file, **you must stop** the **GitProtect worker** service. After making your changes, restart the service (you might also need to refresh the changes in the **Management Service** panel).
{% endhint %}

The `config.json` file, by default, is located in the following locations:

1. For **Windows**: `C:\Program Files\Xopero ONE Backup&Recovery Agent`
2. For **Linux**: `/opt/XoperoONEBackupAgent/`

💡You can edit `config.json` with a simple text editor (i.e., **Notepad++**).

### <mark style="background-color:blue;">Management Service address</mark> <a href="#management_service_address" id="management_service_address"></a>

The **GitProtect** **Management Service** address to which your **worker** connects is crucial during both installation and configuration. If the IP address or protocol (http/https) of the **Management Service** changes, the agent's status will switch to offline. To re-establish the connection, update the `ServiceUrl` value in the configuration file with the updated address.

<figure><img src="/files/MSWfdmvzGA0cn5buvbcR" alt="notepad  json configuration1"><figcaption></figcaption></figure>

***

### <mark style="background-color:blue;">Log level</mark> <a href="#log_level" id="log_level"></a>

By default, the `LogLevel` value is set to `Information`. You can change it to:

1. `Trace`
2. `Debug`
3. `Information`
4. `Warning`
5. `Error`
6. `Critical`
7. `None`

<figure><img src="/files/HH2ZY8JHC2cQHzClETds" alt="notepad  json configuration2"><figcaption></figcaption></figure>

***

### <mark style="background-color:blue;">Default log path</mark> <a href="#default_log_path" id="default_log_path"></a>

By default, application logs are stored in the following directory: `C:\ProgramData\Xopero ONE\Xopero ONE Backup&Recovery Agent\Logs`. To change the location, modify the `AppDataFolder` parameter.

{% hint style="warning" %}
Please note that the correct `AppDataFolder` value format includes **double slash** after the drive letter (i.e., `D:\\`).
{% endhint %}

<figure><img src="/files/NzM3Wiy9psAjeR9tfK2j" alt="notepad  json configuration3"><figcaption></figcaption></figure>

***

### <mark style="background-color:blue;">Device name</mark> <a href="#device_name" id="device_name"></a>

The device name defaults to the system's name. To customize it, modify the `OverriddenHostName` parameter.

{% hint style="warning" %}
Please note that the custom name must be in entered with quotation marks (i.e., `"TESTNAME"`).
{% endhint %}

<figure><img src="/files/f1kHYYPMD2efNMgfvDxM" alt="notepad  json configuration4"><figcaption></figcaption></figure>

***

### <mark style="background-color:blue;">Number of retries</mark>

If database backup task ends with error **DV0249 - "Unable to read backup data"**, first address any connection stability issues on your end. If the problem persists, you can increase the retry attempts in the **GitProtect** application—to do this, simply edit the `MaxRetriesCount` parameter, changing its default value from **2** to a higher value, i.e., **20**.

<figure><img src="/files/XXVrdIt3wftyhn3MPDp4" alt="MaxRetriesCount config json"><figcaption></figcaption></figure>


# Microsoft 365

Information about backup and recovery for Microsoft 365 tenants.

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/VIHZRQgdcN0dRudWSWkU">/pages/VIHZRQgdcN0dRudWSWkU</a></td><td>Learn about integrating a <strong>Microsoft 365</strong> tenant with <strong>GitProtect</strong> to protect its resources.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/rrmp1Sqt9clYLRSLeytW">/pages/rrmp1Sqt9clYLRSLeytW</a></td><td>Learn how to back up your <strong>Microsoft 365</strong> resources with <strong>GitProtect</strong>.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/3ZNSNNH1UzS1rQFGyHzB">/pages/3ZNSNNH1UzS1rQFGyHzB</a></td><td>How to restore <strong>Microsoft Exchange</strong>, <strong>OneDrive</strong>, and <strong>SharePoint</strong> data from backup.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Integration

Learn about integrating a Microsoft 365 tenant with GitProtect to protect its resources.

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/uv6Gm8udM6Sv8Ki6VzrB">/pages/uv6Gm8udM6Sv8Ki6VzrB</a></td><td>Permissions required for integrating <strong>Microsoft 365</strong> with <strong>GitProtect</strong>.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/htBWjAiGXBuaKq8W1LTX">/pages/htBWjAiGXBuaKq8W1LTX</a></td><td>How to integrate a <strong>Microsoft 365</strong> organization with <strong>GitProtect</strong>.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/JP5h53YHCHjm3WowUvtm">/pages/JP5h53YHCHjm3WowUvtm</a></td><td>How to integrate a <strong>Microsoft 365</strong> organization with <strong>GitProtect</strong> and include <strong>SharePoint</strong> protection.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Required permissions

Permissions required for integrating Microsoft 365 with GitProtect.

**The required Microsoft 365 permissions define the access levels GitProtect needs to securely back up and restore your data.**

***

## General requirements

To integrate a **Microsoft 365** organization with **GitProtect**, ensure it uses a **Microsoft 365** business license.

To back up a single **Microsoft 365** account, the account must have a **Microsoft 365** license assigned. This also applies to shared mailboxes. License assignments can be managed in the **Microsoft 365** admin center.

Each **Microsoft 365** account and shared mailbox requires one **GitProtect** license to back up its data.

The backup process requires a backup agent (worker), which communicates with the **Microsoft 365** API, downloads the requested data, and performs the backup. You can use either a cloud or local worker. Any device with the **Xopero ONE Backup\&Recovery Agent** installed can act as a worker.

{% hint style="success" %}
You do not need to assign any licenses to cloud workers — the appropriate license is assigned automatically by the **GitProtect** system.
{% endhint %}

***

## Account permissions

To add your **Microsoft 365** organization to **GitProtect**, you must use a global administrator account. Only a global administrator has the necessary permissions to back up data from all user accounts in the organization.

{% hint style="info" %}
Learn more about **Microsoft 365** administrator roles in [the official Microsoft documentation](https://learn.microsoft.com/en-us/microsoft-365/admin/add-users/about-admin-roles?view=o365-worldwide).
{% endhint %}

***

## Application permissions <a href="#xopero-one-registrator" id="xopero-one-registrator"></a>

The following tables list **Xopero** apps and their permissions, which are automatically installed in the end user's **Entra ID** when integrating **Microsoft 365** with **GitProtect**.

### <mark style="background-color:$tint;">Xopero ONE Registrator</mark> <a href="#xopero-one-registrator" id="xopero-one-registrator"></a>

This application is used at the beginning of the integration to install and grant the necessary permissions for the **Xopero ONE MS365 PRO** app.

#### Microsoft Graph <a href="#microsoft-graph" id="microsoft-graph"></a>

| API name        | Claim value                | Permission                                          | Type      |
| --------------- | -------------------------- | --------------------------------------------------- | --------- |
| Microsoft Graph | Directory.AccessAsUser.All | Access directory as the signed-in user.             | delegated |
| Microsoft Graph | offline\_access            | Maintain access to data you have granted access to. | delegated |
| Microsoft Graph | profile                    | View user's basic profile.                          | delegated |
| Microsoft Graph | openid                     | Sign users in.                                      | delegated |

### <mark style="background-color:$tint;">Xopero ONE MS365 PRO</mark> <a href="#xopero-one-ms365-pro" id="xopero-one-ms365-pro"></a>

This application is required to back up and recover data from **Microsoft 365** tenants and is installed automatically in **Entra ID** by **Xopero ONE Registrator**.

#### Microsoft Graph <a href="#microsoft-graph.1" id="microsoft-graph.1"></a>

<table data-search="false"><thead><tr><th>API name</th><th>Claim value</th><th>Permission</th><th>Type</th></tr></thead><tbody><tr><td>Microsoft Graph</td><td>Mail.ReadWrite</td><td>Read and write mail in all mailboxes.</td><td>application</td></tr><tr><td>Microsoft Graph</td><td>User.ReadWrite.All</td><td>Read and write all users' full profile information.</td><td>application</td></tr><tr><td>Microsoft Graph</td><td>Application.ReadWrite.All</td><td>Read and write all applications.</td><td>application</td></tr><tr><td>Microsoft Graph</td><td>Group.Read.All</td><td>Read all groups.</td><td>application</td></tr><tr><td>Microsoft Graph</td><td>Contacts.ReadWrite</td><td>Read and write contacts in all mailboxes.</td><td>application</td></tr><tr><td>Microsoft Graph</td><td>Group.Create</td><td>Create groups.</td><td>application</td></tr><tr><td>Microsoft Graph</td><td>Files.ReadWrite.All</td><td>Read and write files in all site collections.</td><td>application</td></tr><tr><td>Microsoft Graph</td><td>Calendars.ReadWrite</td><td>Read and write calendars in all mailboxes.</td><td>application</td></tr><tr><td>Microsoft Graph</td><td>Tasks.ReadWrite</td><td>Create, read, update, and delete user's tasks and task lists.</td><td>delegated</td></tr><tr><td>Microsoft Graph</td><td>Directory.ReadWrite.All</td><td>Read and write directory data.</td><td>delegated</td></tr><tr><td>Microsoft Graph</td><td>Group.ReadWrite.All</td><td>Read and write all groups.</td><td>delegated</td></tr><tr><td>Microsoft Graph</td><td>offline_access</td><td>Maintain access to data you have granted access to.</td><td>delegated</td></tr></tbody></table>

#### Exchange Online <a href="#exchange-online" id="exchange-online"></a>

| API name                   | Claim value             | Permission                                                                 | Type        |
| -------------------------- | ----------------------- | -------------------------------------------------------------------------- | ----------- |
| Office 365 Exchange Online | full\_access\_as\_app   | Use **Exchange Web Services** (**EWS**) with full access to all mailboxes. | application |
| Office 365 Exchange Online | Mail.ReadWrite          | Read and write mail in all mailboxes.                                      | application |
| Office 365 Exchange Online | Calendars.ReadWrite.All | Read and write calendars in all mailboxes.                                 | application |
| Office 365 Exchange Online |                         |                                                                            | delegated   |

#### Office 365 SharePoint Online <a href="#office-365-sharepoint-online" id="office-365-sharepoint-online"></a>

| API name                   | Claim value             | Permission                                                                 | Type        |
| -------------------------- | ----------------------- | -------------------------------------------------------------------------- | ----------- |
| Office 365 Exchange Online | full\_access\_as\_app   | Use **Exchange Web Services** (**EWS**) with full access to all mailboxes. | application |
| Office 365 Exchange Online | Mail.ReadWrite          | Read and write mail in all mailboxes.                                      | application |
| Office 365 Exchange Online | Calendars.ReadWrite.All | Read and write calendars in all mailboxes.                                 | application |
| Office 365 Exchange Online |                         |                                                                            | delegated   |

***

## Useful links and items

{% embed url="<https://learn.microsoft.com/en-us/microsoft-365/admin/add-users/about-admin-roles?view=o365-worldwide>" %}


# Adding Microsoft 365 tenant to GitProtect

How to integrate a Microsoft 365 organization with GitProtect.

**Adding a Microsoft 365 tenant to GitProtect connects your organization's environment and enables data protection for supported services. The integration requires proper authorization and tenant-level permissions to establish a secure connection between Microsoft 365 and GitProtect, allowing you to configure backup settings, manage protection policies, and perform recovery operations.**

***

## Important notice

The following documentation applies only to **Microsoft 365** organizations with **GitProtect** licenses that include backup for **Microsoft Exchange** data (including individual mailboxes, calendars, and contacts) and **OneDrive**.

For instructions on enabling protection for **SharePoint** sites in new and existing **Microsoft 365** organizations, refer to the [Enabling SharePoint protection in GitProtect](/backup-and-recovery/microsoft-365/integration/enabling-sharepoint-protection-in-gitprotect) article.

***

## Integration process

The below steps demonstrate how to integrate a **Microsoft 365** organization with **GitProtect** using **GitProtect Management Service**.

{% stepper %}
{% step %}
Select **Microsoft 365** from the left pane.

<figure><img src="/files/a5kc5K3UBKKOzIAJqpMc" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Connect** under **Microsoft 365**.

{% hint style="info" %}
If you already have a **Microsoft 365** organization added, click the **+ Add new** button in the top-left corner first.
{% endhint %}

<figure><img src="/files/BEfP0XdZ941NhDuSqdSf" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Copy the authentication code, then click **Log in to Microsoft 365**.

<figure><img src="/files/dUDj22SrDIPO3IgobG5K" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Microsoft** authentication tab, paste the copied code and click **Next**.

<figure><img src="/files/7DGVc702cwdhQwlYNaCL" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select your account and sign in if prompted. Next, click **Continue** to confirm your sign-in to **Xopero Registrator**.

<figure><img src="/files/8qaos2rL0p2pDghMpcNu" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
If the registration is completed successfully, the following message will appear. Close the tab and return to **GitProtect Management Service**.

<figure><img src="/files/sfDaRKEadnTJ22UYCM8D" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
The **Microsoft 365** organization has been successfully added to **GitProtect**. Click **Custom policy** to modify your backup policy settings, or click **Run backup** to start a backup using the current policy configuration.

<figure><img src="/files/r3eELSU266wvCT9H1vfe" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## Additional permissions for shared mailboxes

After adding the organization, you may see the following message. Click **Repair** to configure permissions for shared mailbox protection.

<figure><img src="/files/nJOU3Gu5hBacO0lUDy35" alt=""><figcaption></figcaption></figure>

To start the permission update process, click **Continue** at the bottom of the configuration pane. If prompted, sign in to your **Microsoft 365** account and grant **GitProtect** the required permissions.

<figure><img src="/files/d7ovtWFl3jVAqv7wCPEL" alt=""><figcaption></figcaption></figure>

After the required permissions have been granted, you can configure a **Microsoft 365** backup plan and start protecting your resources.

***

## Useful links and items

{% content-ref url="/pages/ezmIfnTo5tG6rORWzKlF" %}
[Licensing overview](/gitprotect-software/licensing-overview)
{% endcontent-ref %}

{% content-ref url="/pages/uv6Gm8udM6Sv8Ki6VzrB" %}
[Required permissions](/backup-and-recovery/microsoft-365/integration/required-permissions)
{% endcontent-ref %}

{% content-ref url="/pages/JP5h53YHCHjm3WowUvtm" %}
[Enabling SharePoint protection in GitProtect](/backup-and-recovery/microsoft-365/integration/enabling-sharepoint-protection-in-gitprotect)
{% endcontent-ref %}


# Enabling SharePoint protection in GitProtect

How to integrate a Microsoft 365 organization with GitProtect and include SharePoint protection.

**Enabling SharePoint protection in GitProtect allows SharePoint sites to be included in the Microsoft 365 backup scope. The setup follows the same tenant-based flow used for other Microsoft 365 resources and requires that the necessary prerequisites and permissions are in place before backup configuration is started.**

***

## Important notice

The following documentation applies only to **Microsoft 365** organizations with **GitProtect** licenses (**Microsoft 365 PRO**) that include backup for **Microsoft Exchange** data (including individual mailboxes, shared mailboxes, calendars, and contacts), **SharePoint**, and **OneDrive**.

For instructions on adding **Microsoft 365** tenants with only **Microsoft Exchange** and **OneDrive** protection to **GitProtect**, see [this article](/backup-and-recovery/microsoft-365/integration/adding-microsoft-365-tenant-to-gitprotect).

***

## Adding new Microsoft 365 organization with SharePoint protection

The below steps demonstrate how to integrate a **Microsoft 365** organization with **GitProtect** using **GitProtect Management Service**.

{% stepper %}
{% step %}
Select **Microsoft 365** from the left pane.

<figure><img src="/files/e5t98nCz9GDbk6TUPRt2" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Connect** under **Microsoft 365 Pro**.

{% hint style="info" %}
If you already have a **Microsoft 365** organization added, click the **+ Add new** button in the top-left corner first.
{% endhint %}

<figure><img src="/files/zaX6enx2OSImUou2AuD4" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Add new organization** pane, click **Advanced configuration** at the bottom of the pane.

<figure><img src="/files/0jKRD11MO3y6sFWJBpge" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In **Advanced configuration**, enable the **Enable SharePoint protection** switch, and specify whether **GitProtect** should automatically assign licenses to users.

<figure><img src="/files/tkIHUXRHmtezMK3vMjW6" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Next, click the **Add new or select certificate from (…)** tile. In the **Add certificate** pane, select the certificate option that aligns with your deployment model: automatically generate a certificate, upload a custom certificate, or select an existing certificate from the list. Once done, click **Save**.

<figure><img src="/files/59rh5SIN3f4MaJEL8FA4" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Set the synchronization interval (if needed), review your settings, and click **Save** to proceed.

<figure><img src="/files/OjthYbb5LEwARQbCXNwm" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Back in the **Add new organization** pane, copy the authentication code, and then click **Log in to Microsoft 365**.

<figure><img src="/files/VGhvo0nLdFibWUYpA7s3" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Microsoft** authentication tab, paste the copied code and click **Next**.

<figure><img src="/files/RQCP0pZ3nfmsXmBa1zUV" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select your account and sign in if prompted. Next, click **Continue** to confirm your sign-in to **Xopero Registrator**.

<figure><img src="/files/xl6vLGl9ix4vt9vKFHDb" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
If the registration is completed successfully, the following message will appear. Close the tab and return to **GitProtect Management Service**.

<figure><img src="/files/Zc0omGGQtWXtkODtwLWU" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
The **Microsoft 365** organization has been successfully added to **GitProtect**. Click **Custom policy** to modify your backup policy settings, or click **Run backup** to start a backup using the current policy configuration.

<figure><img src="/files/wOauBtfSS4ZnlChlv8KL" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## Enabling SharePoint protection for existing organizations

The following steps demonstrate how to enable **SharePoint** protection for existing **Microsoft 365** organizations using **GitProtect Management Service**.

{% hint style="warning" %}
To enable **SharePoint** protection for an existing **Microsoft 365** organization, you must have the **Microsoft 365 PRO** license.
{% endhint %}

{% stepper %}
{% step %}
Select **Microsoft 365** from the left pane.

<figure><img src="/files/yZSymY1xGhAS0IajQ9lB" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Edit** in the lower-left corner of the organization tile.

<figure><img src="/files/4uOrsSXAk2RKtOs5kunC" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In **Settings** section, turn on the **Enable SharePoint protection** switch, and then click the **Add new or select certificate from (…)** tile.

<figure><img src="/files/y0rcTCtumg0Yn3D0OGeV" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Add certificate** pane, select the certificate option that aligns with your deployment model: automatically generate a certificate, upload a custom certificate, or select an existing certificate from the list. Once done, click **Save**.

<figure><img src="/files/HUcLfiwW0S8ehp4trDMt" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
The system will automatically prompt you to create or run a default backup plan. You can skip this step and configure the **SharePoint** backup plan later.

<figure><img src="/files/BIKN6qonH2xzEvrw3syH" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Back in the **Microsoft 365** organization dashboard, click **Repair** to configure permissions for **SharePoint** protection.

<figure><img src="/files/yz6R17FpQxXbaSg6C9Om" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
To start the permission update process, click **Continue** at the bottom of the **Edit organization** pane. If prompted, sign in to your **Microsoft 365** account and grant **GitProtect** the required permissions.

<figure><img src="/files/kVEDSVULGeRhBrp3Y3XJ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After the required permissions have been granted, you can configure a **SharePoint** backup plan and start protecting your resources.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/ezmIfnTo5tG6rORWzKlF" %}
[Licensing overview](/gitprotect-software/licensing-overview)
{% endcontent-ref %}

{% content-ref url="/pages/uv6Gm8udM6Sv8Ki6VzrB" %}
[Required permissions](/backup-and-recovery/microsoft-365/integration/required-permissions)
{% endcontent-ref %}

{% content-ref url="/pages/htBWjAiGXBuaKq8W1LTX" %}
[Adding Microsoft 365 tenant to GitProtect](/backup-and-recovery/microsoft-365/integration/adding-microsoft-365-tenant-to-gitprotect)
{% endcontent-ref %}


# Backup

Learn how to back up your Microsoft 365 resources with GitProtect.

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/H6v3oNcSAoSMMgd8vnoR">/pages/H6v3oNcSAoSMMgd8vnoR</a></td><td>An overview of <strong>Microsoft 365</strong> backup plans in <strong>GitProtect</strong>.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/GwaGUHxFDpceqfi0qbkH">/pages/GwaGUHxFDpceqfi0qbkH</a></td><td>Overview of <strong>Microsoft 365</strong> resources protected by backup, including applications such as <strong>Microsoft Exchange</strong>, <strong>OneDrive</strong>, and <strong>SharePoint</strong>.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/OAH3DbSVQoiBGMquh9J6">/pages/OAH3DbSVQoiBGMquh9J6</a></td><td>Learn how to create a <strong>Microsoft 365</strong> backup plan in <strong>GitProtect</strong> to configure protection for <strong>Microsoft Exchange</strong>, <strong>OneDrive</strong>, and <strong>SharePoint</strong>.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Process overview

An overview of Microsoft 365 backup plans in GitProtect.

**In GitProtect, creating a backup plan allows you to define what data should be protected, where backups are stored, and how often they are performed.**

***

## General information

A **Microsoft 365** backup plan in **GitProtect** defines which data is protected, how frequently backups are performed, and how long recovery points are retained. A dedicated **Microsoft 365** backup plan enables protection of mailboxes, **OneDrive** resources, and **SharePoint** sites while applying automated schedules and granular retention policies that align with organizational data protection and compliance requirements.

To optimize backup tasks, **GitProtect Management Service** provides several advanced features that enable flexible configuration based on specific infrastructure requirements. When creating a backup plan, you can customize settings such as backup windows, task balancing, storage locations, bandwidth limits, and more.

***

## Selective backup configuration

**GitProtect** provides granular control over **Microsoft 365** backups. Instead of backing up an entire environment, you can selectively target specific data types—such as messages, calendars, or contacts—to optimize storage capacity and focus exclusively on critical assets.

<figure><img src="/files/zCfVzYb1OHlt4qgAltzE" alt=""><figcaption></figcaption></figure>

***

## Microsoft 365 groups

**GitProtect** supports **Microsoft 365** groups — they appear in the users list (for example, when creating a backup plan) and can be used to filter it.

{% hint style="warning" %}
If you cannot see the **Groups** field and the **Search by group** option is unavailable in **GitProtect Management Service**, re-register your **Microsoft 365** organization to enable these options.
{% endhint %}

<figure><img src="/files/TBjmd0CxAzpSN264Hqeg" alt=""><figcaption></figcaption></figure>


# Protected resources

Overview of Microsoft 365 resources protected by backup, including applications such as Microsoft Exchange, OneDrive, and SharePoint.

**Microsoft 365 protected resources define which parts of the environment GitProtect can access, backup, and restore.**

***

## Backup coverage

The following list includes all **Microsoft 365** resources covered by backup.

{% hint style="info" %}
The list is presented in alphabetical order.
{% endhint %}

<details>

<summary>Microsoft Exchange</summary>

* [x] Calendar&#x73;**\***
* [x] Contact&#x73;**\***
* [x] Message&#x73;**\***

<sub>**\***</sub><sub>Protection includes both individual and shared mailboxes. Shared mailboxes require the same licensing as individual user mailboxes, with each shared mailbox requiring one</sub> <sub></sub><sub>**Microsoft**</sub> <sub></sub><sub>user license.</sub>

</details>

<details>

<summary>OneDrive</summary>

* [x] Catalog&#x73;**\***
* [x] File&#x73;**\***

<sub>**\***</sub><sub>Includes information about permission settings.</sub>

</details>

<details>

<summary>SharePoint</summary>

* [x] Board Vie&#x77;**\***
* [x] ClientSideWebPart (JSON properties)**\*\***
* [x] Column (SiteColumn and list-scoped)
* [x] ContentType (including fields and workflow associations)
* [x] Document
* [x] DriveItem (including versions and metadata)**\*\***
* [x] Event
* [x] Folder
* [x] Gallery Vie&#x77;**\***
* [x] Gantt Vie&#x77;**\***
* [x] Grid Vie&#x77;**\***
* [x] Library (including columns, ContentTypes, versioning, and DraftVisibility)
* [x] Link
* [x] List (including columns, ContentTypes, versioning, and DraftVisibility)
* [x] Modern Calendar View (including begin and end date fields)**\***
* [x] Site Collection
* [x] SiteColumn (global columns inherited across lists)
* [x] SiteContentType (global)
* [x] SitePage (including layout, sections, and web parts)**\*\***
* [x] Theme (color themes)
* [x] Timeline Vie&#x77;**\***
* [x] Web (including title, description, SiteLogoUrl, and WebTemplate)
* [x] WebPartGallery

<sub>**\***</sub><sub>These elements can be backed up, but they cannot be fully restored to their original state.</sub>

<sub>**\*\***</sub><sub>The size limit for restored files is 2 MB.</sub>

</details>


# Creating a backup plan

Learn how to create a Microsoft 365 backup plan in GitProtect to configure protection for Microsoft Exchange, OneDrive, and SharePoint.

**A reliable backup plan is essential for protecting your Microsoft 365 organization's resources and ensuring business continuity when unexpected events occur.**

***

## Backup plan setup (Microsoft Exchange & OneDrive) <a href="#backup_plan_creation" id="backup_plan_creation"></a>

The following steps demonstrate how to create a **Microsoft Exchange** and **OneDrive** backup plan using **GitProtect Management Service**.

{% stepper %}
{% step %}
Open the **Backup** tab (**Plans** > **Backup**) and click the **+ Add plan** button in the top bar.
{% endstep %}

{% step %}
Select **Microsoft 365** from the list.

<figure><img src="/files/PPB6lUI01IdWwnb5IhhL" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the **Microsoft 365 Exchange** option.

<figure><img src="/files/W1hDct0xW4WPdPWkKO4c" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Select**, then specify whether you want to protect the entire organization or only specific user accounts or shared mailboxes.

{% hint style="success" %}
**GitProtect** supports **Microsoft 365** groups — they appear in the users list and can be used to filter it. If the **Search by group** option is unavailable, re-register your **Microsoft 365** organization to enable it.
{% endhint %}

<figure><img src="/files/dvsm4xmOFnqpo8M5aR05" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Set up a name for your backup plan.

<figure><img src="/files/1PXOcCZzhBxWply4m9Ul" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In **Data to protect** section, select the resources that you want to back up. You can also change the default backup agent (worker), which is directly responsible for backing up your **Microsoft 365** data.

{% hint style="success" %}
You can deploy multiple agents and assign different agents to each backup plan.
{% endhint %}

<figure><img src="/files/EW9pDwUjuMDRzokjSqzn" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select one of the data stores assigned to your **GitProtect** instance to use as the backup storage.

<figure><img src="/files/nPdEJSv4GBrdZezw4NKg" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Customize the scheduler and specify the retention period for your data.

<figure><img src="/files/KF8R8x8N9JauVJ2Y9nM0" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Adjust the advanced settings, such as encryption, error handling, or bandwidth limit, to meet your organization's requirements.

<figure><img src="/files/58Np3KVlfpJwuRzJhqM8" alt=""><figcaption></figcaption></figure>

1. **Encryption**: lets you secure your backup copy with encryption.
2. **Compression**: lets you compress and reduce copy size.
3. **Deduplication:** allows you to reduce the backup size.
4. **Error handling**: allows you to specify how to handle potential backup operation errors.
5. **Bandwidth limit:** allows you to reduce network usage and limit network speed during backup.
6. **Backup scripts:** enables configuring pre/post scripts executed during backup.
7. **Microsoft 365 diagnostics:** lets you enable pre-backup diagnostics, such as the mail message download test.
8. **Task balancing:** balances backup speed and CPU load.
9. **Prevent system sleep:** prevents your system from suspending while a backup is in progress.
10. **Email notifications:** lets you set up email notifications and its recipients.
11. **S3 Buffer Settings:** allows you to specify the buffer size allocated for large resources.
    {% endstep %}

{% step %}
Review your configuration and click **Save** to create the backup plan, or **Save\&Run** to start the first backup run immediately.
{% endstep %}
{% endstepper %}

***

## Backup plan setup (SharePoint) <a href="#backup_plan_creation" id="backup_plan_creation"></a>

The following steps demonstrate how to create a **SharePoint** backup plan using **GitProtect Management Service**.

{% stepper %}
{% step %}
Open the **Backup** tab (**Plans** > **Backup**) and click the **+ Add plan** button in the top bar.
{% endstep %}

{% step %}
Select **Microsoft 365** from the list.

<figure><img src="/files/KHq0cSIXt6JBTzrpWyAb" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the **SharePoint sites** option.

<figure><img src="/files/QWqCZNPu96daNn6oINpe" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Select**, then specify whether you want to protect the entire environment or only specific **SharePoint** sites.

<figure><img src="/files/ssDDDBJMrZlOBD8ZW28e" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Set up a name for your backup plan.

<figure><img src="/files/QfpEMv6EsncAjMpZ6GH8" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In **Data to protect** section, you can change the default backup agent (worker), which is directly responsible for backing up your **SharePoint** data.

<figure><img src="/files/VLmSquzOTPl1CWfBF4wA" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select one of the data stores assigned to your **GitProtect** instance to use as the backup storage.

<figure><img src="/files/0PRGnC3aM2JGvJil9KTf" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Customize the scheduler and specify the retention period for your data.

<figure><img src="/files/Nef75tWpY7XoCrK5p9jc" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Adjust the advanced settings, such as encryption, error handling, or bandwidth limit, to meet your organization's requirements.

<figure><img src="/files/y6wdgNIcjGngfdzjlSX9" alt=""><figcaption></figcaption></figure>

1. **Encryption**: lets you secure your backup copy with encryption.
2. **Compression**: lets you compress and reduce copy size.
3. **Deduplication:** allows you to reduce the backup size.
4. **Error handling**: allows you to specify how to handle potential backup operation errors.
5. **Bandwidth limit:** allows you to reduce network usage and limit network speed during backup.
6. **Backup scripts:** enables configuring pre/post scripts executed during backup.
7. **Task balancing:** balances backup speed and CPU load.
8. **Prevent system sleep:** prevents your system from suspending while a backup is in progress.
9. **Email notifications:** lets you set up email notifications and its recipients.
   {% endstep %}

{% step %}
Review your configuration and click **Save** to create the backup plan, or **Save\&Run** to start the first backup run immediately.
{% endstep %}
{% endstepper %}


# Recovery

How to restore Microsoft Exchange, OneDrive, and SharePoint data from backup.

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/zrDYf0U88VPEJgzLgVVu">/pages/zrDYf0U88VPEJgzLgVVu</a></td><td>Restore emails, calendars, contacts, and selected <strong>OneDrive</strong> folders and files from a backup.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/4Geo56BvQC3dfIgHdYRo">/pages/4Geo56BvQC3dfIgHdYRo</a></td><td>Learn how to restore <strong>SharePoint</strong> sites from a backup.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Restoring Microsoft Exchange and OneDrive data

Restore emails, calendars, contacts, and selected OneDrive folders and files from a backup.

**Microsoft Exchange and OneDrive data can be restored with granular control over the recovery scope and destination. Emails, calendars, contacts, files, and folders can be restored directly to a Microsoft 365 user account or locally to a device, supporting recovery after accidental deletion, migration, and other data-loss scenarios.**

***

## Recovery process

The below steps demonstrate how to restore **Microsoft Exchange** data and **OneDrive** folders and files using **GitProtect Management Service**.

{% stepper %}
{% step %}
Open the **Microsoft 365** tab, then click the **Explore** button next to the organization whose backup you want to restore.

<figure><img src="/files/tr0UOln7tgQJkQESU7SH" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Microsoft 365 Users** tab, search for the user whose data you want to restore, and then click the restore button in the action menu for that user.

<figure><img src="/files/8njKe8R4CP6KU89A89ix" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Next, select the backup plan from which you want to restore data. Click **View available plans**, and then select a plan from the list.

<figure><img src="/files/8MLYZ4CwfCXtivdYqNhp" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Choose the backup version from all the backups that have already been performed — select the desired date and click the **Restore** button.

<figure><img src="/files/i6sVXBKjK2v3O6fqnv3z" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the restore destination and click **Next**.

<figure><img src="/files/07yBnWNc3fJLa23wKaAF" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the next pane, browse the tabs, select the data you want to restore, and click **Restore selected**. Alternatively, click **Restore all** to restore all available data.

<figure><img src="/files/agFPdMXGcuIV0PYHAbhL" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Next, depending on the selected restore destination, configure the **Restore to** and **Restore directory** settings.

#### Restore to the original account

1. In the **Restore directory** section, choose one of the following options:
   1. **New directory** — creates a new directory to restore the data to.
   2. **Original directory** — restores the data to its original location. You can also choose to overwrite existing **OneDrive** files and email messages.

{% hint style="warning" %}
The option to create a copy of overwritten **OneDrive** files is currently unavailable.
{% endhint %}

<figure><img src="/files/D0GLY1bx9C4MsUgvBgWr" alt=""><figcaption></figcaption></figure>

#### Restore to a new account

1. In the **Restore to** pane, select the user to whom you want to restore the data, and click **Save**.

<figure><img src="/files/PiKe2viWQBEUyJzP5IEJ" alt=""><figcaption></figcaption></figure>

2. In the **Restore directory** section, choose one of the following options:
   1. **New directory** — creates a new directory to restore the data to.
   2. **Original directory** — restores the data to its original location. You can also choose to overwrite existing **OneDrive** files and email messages.

{% hint style="warning" %}
The option to create a copy of overwritten **OneDrive** files is currently unavailable.
{% endhint %}

#### Restore to a device

1. In the **Restore to** pane, select the device to use as the restore destination, and click **Save**.
2. In the **Restore directory** section, select the directory where the data will be restored, and then click **Apply**.

<figure><img src="/files/hvp8YETv8uVDoDPoP5hZ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In **Restore settings**, you can limit bandwidth usage and select the default backup agent (worker) that will be used to restore the data (where applicable).

<figure><img src="/files/4mAinyQM5gYppgrD7I6t" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After defining all parameters, click the **Restore** button to start the recovery process. You can monitor the process in the **Tasks** tab.
{% endstep %}
{% endstepper %}


# Restoring SharePoint sites

Learn how to restore SharePoint sites from a backup.

**GitProtect allows you to recover SharePoint data from available backup points and restore it to the original location or another selected destination. The recovery process helps restore entire sites after accidental deletion, unwanted changes, or other data-loss scenarios while preserving their structure, documents, lists, and associated data.**

***

## Recovery process

The below steps demonstrate how to restore **SharePoint** sites and their metadata using **GitProtect Management Service**.

{% stepper %}
{% step %}
Open the **Microsoft 365** tab, then click the **Explore** button next to the organization whose backup you want to restore.

<figure><img src="/files/4d574fIy1npLYsRY4Pdz" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **SharePoint Sites** tab, search for the site whose data you want to restore, and then click the restore button in the action menu for that site.

<figure><img src="/files/pgO3EKJP1ufvXqfK154b" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Next, select the backup plan from which you want to restore data. Click **View available plans**, and then select a plan from the list.

<figure><img src="/files/VOB3fAInd4qmIy9B8P0Q" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Choose the backup version from all the backups that have already been performed — select the desired date and click the **Restore** button.

<figure><img src="/files/UbQcahZdSNQPvxJbI1tW" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the restore destination and click **Next**.

<figure><img src="/files/TeHiQcqGQ3bkEwnuc0Bh" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the next pane, select the data you want to restore, and then click **Restore selected**. Alternatively, click **Restore all** to restore all available data.

<figure><img src="/files/FotXTEp8oVky6VMrqlqu" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Next, depending on the selected restore destination, configure the **Restore to** and **Restore directory** settings.

#### Restore to the original site

1. In the **Overwrite data** section, choose one of the following options:
   1. Don't overwrite site and its data.
   2. Overwrite only if existing resources are older than restored.
   3. Always overwrite.
2. In the **Site permissions** section, specify whether **GitProtect** should restore site permissions along with other site data.

<figure><img src="/files/6qCYJeWKHjbOgwZnT101" alt=""><figcaption></figcaption></figure>

#### Restore to an existing site

1. In the **Restore to** pane, select the site where you want to restore the data, and click **Save**.

<figure><img src="/files/2PkVWaNvbGjy6f0pt1fE" alt=""><figcaption></figcaption></figure>

2. In the **Overwrite data** section, choose one of the following options:
   1. Don't overwrite site and its data.
   2. Overwrite only if existing resources are older than restored.
   3. Always overwrite.
3. In the **Site permissions** section, specify whether **GitProtect** should restore site permissions along with other site data.

#### Restore to a new site

1. In the **Restore to** pane, select the **Microsoft 365** organization where you want to restore the data, and click **Save**.

<figure><img src="/files/MZkoTmL7m79Y98eZABSP" alt=""><figcaption></figcaption></figure>

2. Next, enter a custom name for the new site.

{% hint style="info" %}
If the site URL is already in use, **SharePoint** will modify the new URL by adding a few characters to make it unique (typically, a number at the end).
{% endhint %}

<figure><img src="/files/mXNzK3erXjGzziZS7AhQ" alt=""><figcaption></figcaption></figure>

3. In the **Site permissions** section, specify whether **GitProtect** should restore site permissions along with other site data.

#### Restore to a device

1. In the **Restore to** pane, select the device to use as the restore destination, and click **Save**.
2. In the **Restore directory** section, select the directory where the data will be restored, and then click **Apply**.

<figure><img src="/files/jzQa3brDG9jdDMuHJJJk" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In **Restore settings**, you can limit bandwidth usage and select the default backup agent (worker) that will be used to restore the data (where applicable).

<figure><img src="/files/Gb1idDg9rPbRoZLcu68N" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After defining all parameters, click the **Restore** button to start the recovery process. You can monitor the process in the **Tasks** tab.
{% endstep %}
{% endstepper %}


# DevOps

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/aPmXq8RC5fGyWE57AOOX">/pages/aPmXq8RC5fGyWE57AOOX</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/8kglQ8cznZx338d23P2L">/pages/8kglQ8cznZx338d23P2L</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/edzoCWlHJiG2pGkKndT3">/pages/edzoCWlHJiG2pGkKndT3</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/vousaZcLJCE77EMe4CGl">/pages/vousaZcLJCE77EMe4CGl</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/eyxvo1ckhi4ScnvoIuE8">/pages/eyxvo1ckhi4ScnvoIuE8</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/dFOZ9gHNeEmG7RSXPTkR">/pages/dFOZ9gHNeEmG7RSXPTkR</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/6NwFUnTlbWpzQhbBwsBq">/pages/6NwFUnTlbWpzQhbBwsBq</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# General

Useful tools and tips for backup and recovery across all supported DevOps platforms.

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/7ED8t5MyNmUSDOdigxkU">/pages/7ED8t5MyNmUSDOdigxkU</a></td><td>Learn about repository and project selection methods in <strong>GitProtect</strong>, including manual selection and rule-based configuration.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/yYGYOxC0G7AfT7DK18tV">/pages/yYGYOxC0G7AfT7DK18tV</a></td><td>Configure selection rules to automatically include or exclude specific <strong>Git</strong> repositories and projects from backup jobs.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/NqYA6IzA1GmHxLsZwtrZ">/pages/NqYA6IzA1GmHxLsZwtrZ</a></td><td>How <strong>GitProtect</strong> restores repositories and metadata across <strong>Git</strong> providers for rapid disaster recovery and <strong>DevOps</strong> migrations.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/IiVUjDfL7V7Z9YEIHaQs">/pages/IiVUjDfL7V7Z9YEIHaQs</a></td><td>Learn how <strong>GitProtect</strong> restores <strong>Git</strong> LFS objects alongside repositories to ensure complete data recovery for <strong>DevOps</strong> organizations.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/KUrX1uY5hrsK7Rn9NVmn">/pages/KUrX1uY5hrsK7Rn9NVmn</a></td><td>How to restore a <strong>DevOps</strong> organization wiki and its metadata separately.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Repository selection methods

Learn about repository and project selection methods in GitProtect, including manual selection and rule-based configuration.

**GitProtect supports multiple repository selection methods that allow administrators to define the scope of backup and recovery operations according to organizational requirements. Repositories can be selected manually, automatically, or included and excluded based on configurable rules and filters.**

***

## Selecting data to protect

When creating a backup plan, one of the steps is to specify which repositories you want to protect. **GitProtect** offers several methods for selecting repositories:

1. **Protect all**: this option ensures that all existing repositories and projects, as well as any newly created ones, are automatically included in the backup plan without requiring manual updates.
2. **Select projects**: using checkboxes, you can choose specific projects to protect.
3. **Select repositories**: using checkboxes, you can choose specific repositories to protect.

{% hint style="danger" %}
Repositories and projects created after applying method 2 or method 3 **will not be automatically included in the backup plan and must be added manually**.
{% endhint %}

3. **Exclude repositories**: using checkboxes, you can exclude specific repositories, allowing the plan to cover all other repositories by default.
4. **Set rules**: this option lets you define criteria to include repositories and projects based on attributes such as their names or associated topics, ensuring that repositories meeting these conditions are automatically protected.

{% hint style="info" %}
Learn more about selection rules and rule patterns in [this article](/backup-and-recovery/devops/general/repository-selection-rules).
{% endhint %}


# Repository selection rules

Configure selection rules to automatically include or exclude specific Git repositories and projects from backup jobs.

**GitProtect provides selection rules, allowing administrators to determine which repositories and projects are included or excluded from backup and recovery tasks. Rules can be based on names, owners, creation dates, branches, or specific patterns, offering granular control over the backup scope and ensuring that only relevant repositories and projects are processed.**

***

## Selection rules and rule patterns

Below are the selection rules and rule patterns you can use in **GitProtect** to select repositories and projects for inclusion in backup jobs within your **DevOps** organization.

### <mark style="background-color:blue;">Azure DevOps & Bitbucket</mark>

1. **Repository name** — you can use the full or partial name of a repository. Wildcard characters can be used at the end of the rule to match repository names:
   1. `*` matches zero or more characters
   2. `?` matches exactly one character
2. **Project name**: protects all repositories within the specified project.

### <mark style="background-color:blue;">GitHub</mark>

1. **Repository name** — you can use the full or partial name of a repository. Wildcard characters can be used at the end of the rule to match repository names:
   1. `*` matches zero or more characters
   2. `?` matches exactly one character
2. **Topic name** — specify the exact name of a topic. For example, if you enter the topic `html`, all repositories assigned to the `html` topic will be backed up.

### <mark style="background-color:blue;">GitLab</mark>

1. **Repository name** — you can use the full or partial name of a repository. Wildcard characters can be used at the end of the rule to match repository names:
   1. `*` matches zero or more characters
   2. `?` matches exactly one character
2. **Topic name** — specify the exact name of a topic. For example, if you enter the topic `html`, all repositories assigned to the `html` topic will be backed up.
3. **Group path**: protects all repositories within the specified group or subgroup path.

***

## Selection rule examples

The following are examples of rule patterns, along with brief explanations:

* **Pattern:** `yourorganization/*`
  * This will match all repositories in the organization named `yourorganization`.
* **Pattern:** `yourorganization/n??`
  * Matches repositories where `n` is followed by exactly **two characters**.

***

## Regular expression patterns (regex)

All selection rules can use **regular expression patterns** (**regex**).

Regular expressions let you create flexible and adaptable rules that align with your organization's naming conventions. This approach allows precise targeting and automation based on consistent patterns in repository or project names.

The following are illustrative examples of how these rules can be applied, although the available configurations extend well beyond these cases:

* **Pattern:** `yourorganization/repo[0-9]+`
  * This will match repositories such as `repo1`, `repo12`, `repo123`, and so on.
* **Pattern:** `yourorganization/.*data.*`&#x20;
  * Matches any repository name containing the word `data`.
* **Pattern:** `yourorganization/(?!.*data.*)`
  * Excludes any repository name that contains the word `data`.


# Cross-recovery for DevOps organizations

How GitProtect restores repositories and metadata across Git providers for rapid disaster recovery and DevOps migrations.

**GitProtect enables cross-recovery across DevOps ecosystems by letting organizations restore repositories and associated metadata between different hosting providers such as GitHub, GitLab, Bitbucket and Azure DevOps. Recovered content covers repositories and many forms of metadata, including pull requests, wikis, issues and other repository artifacts where supported by the source and target platforms.**

***

## Available resources

The following tables outline which resources and metadata can be cross-restored between platforms.

{% hint style="info" %}
For a complete list of protected resources and metadata, refer to the **Protected resources** article for the relevant **DevOps** platform.
{% endhint %}

{% hint style="warning" %}
Different vendors provide various types of metadata, which may not be common to all providers. As a result, during the restore process, **some metadata might not be available for restoration**.
{% endhint %}

{% hint style="info" %}
In the tables below, the term **GitLab** refers collectively to both **GitLab** self-managed and **GitLab** SaaS environments.
{% endhint %}

{% hint style="info" %}
The list is presented in alphabetical order.
{% endhint %}

<p align="center"><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#additional-data" class="button secondary">ADDITIONAL DATA</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#branches" class="button secondary">BRANCHES</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#commit-comments" class="button secondary">COMMIT COMMENTS</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#commits" class="button secondary">COMMITS</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#deployment-keys" class="button secondary">DEPLOYMENT KEYS</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#github-projects-classic" class="button secondary">GITHUB PROJECTS (CLASSIC)</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#issue-comments" class="button secondary">ISSUE COMMENTS</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#issues-closed" class="button secondary">ISSUES (CLOSED)</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#issues-open" class="button secondary">ISSUES (OPEN)</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#labels" class="button secondary">LABELS</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#lfs" class="button secondary">LFS</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#milestones" class="button secondary">MILESTONES</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#pull-request-comments" class="button secondary">PULL REQUEST COMMENTS</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#pull-requests-closed" class="button secondary">PULL REQUESTS (CLOSED)</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#pull-requests-open" class="button secondary">PULL REQUESTS (OPEN)</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#release-assets" class="button secondary">RELEASE ASSETS</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#releases" class="button secondary">RELEASES</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#repository" class="button secondary">REPOSITORY</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#tag" class="button secondary">TAG</a><a href="/pages/NqYA6IzA1GmHxLsZwtrZ#wiki" class="button secondary">WIKI</a></p>

<details>

<summary>ADDITIONAL DATA</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">GitHub</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>BRANCHES</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Azure DevOps</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket DC</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>COMMIT COMMENTS</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">GitHub</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td></tr></tbody></table>

</details>

<details>

<summary>COMMITS</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Azure DevOps</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket DC</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>DEPLOYMENT KEYS</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Bitbucket</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>GITHUB PROJECTS (CLASSIC)</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">GitHub</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td></tr></tbody></table>

</details>

<details>

<summary>ISSUE COMMENTS</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Bitbucket</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>ISSUES (CLOSED)</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Bitbucket</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>ISSUES (OPEN)</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Bitbucket</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">❌</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>LABELS</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Azure DevOps</td><td align="center">✅</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">✅</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">✅</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>LFS</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Azure DevOps</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket DC</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>MILESTONES</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">GitHub</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>PULL REQUEST COMMENTS</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Azure DevOps</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>PULL REQUESTS (CLOSED)</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Azure DevOps</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>PULL REQUESTS (OPEN)</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Azure DevOps</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket DC</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>RELEASE ASSETS</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">GitHub</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td></tr></tbody></table>

</details>

<details>

<summary>RELEASES</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">GitHub</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td></tr><tr><td align="center">GitLab</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>REPOSITORY</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Azure DevOps</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket DC</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>TAG</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Azure DevOps</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket DC</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

<details>

<summary>WIKI</summary>

<table data-header-hidden data-header-sticky data-first-column-sticky><thead><tr><th width="102" align="center"></th><th width="85" align="center"></th><th width="96" align="center"></th><th width="96" align="center"></th><th width="77" align="center"></th><th width="102" align="center"></th><th width="75" align="center"></th></tr></thead><tbody><tr><td align="center"><p><strong>TO →</strong></p><p><strong>↓ FROM</strong></p></td><td align="center">Azure DevOps</td><td align="center">Bitbucket</td><td align="center">Bitbucket DC</td><td align="center">GitHub</td><td align="center">GitHub Enterprise</td><td align="center">GitLab</td></tr><tr><td align="center">Azure DevOps</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">Bitbucket</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitHub Enterprise</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td align="center">GitLab</td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr></tbody></table>

</details>

***

## Useful links and items

{% content-ref url="/pages/IiVUjDfL7V7Z9YEIHaQs" %}
[LFS recovery for DevOps organizations](/backup-and-recovery/devops/general/lfs-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/KUrX1uY5hrsK7Rn9NVmn" %}
[Wiki recovery for DevOps organizations](/backup-and-recovery/devops/general/wiki-recovery-for-devops-organizations)
{% endcontent-ref %}


# LFS recovery for DevOps organizations

Learn how GitProtect restores Git LFS objects alongside repositories to ensure complete data recovery for DevOps organizations.

**GitProtect supports backup and recovery of Git Large File Storage (LFS) content for DevOps organizations, ensuring that repositories configured with Git LFS are protected together with their associated large binary objects. During restore operations, both standard Git data and LFS objects are recovered to preserve repository integrity and maintain consistency across supported DevOps platforms.**

***

## Restoring LFS metadata

**GitProtect** supports the backup and recovery of LFS objects across all supported **DevOps** platforms.

While you can choose whether to include LFS metadata during the recovery process, please note that **LFS must be restored alongside its parent repository**; it cannot be recovered as a standalone item.

{% hint style="danger" %}
If LFS objects are included in your repository’s source code archives, downloading those archives will count toward the repository’s bandwidth usage.
{% endhint %}

<figure><img src="/files/93U1kV9ezuo5GtzJGAyt" alt=""><figcaption><p><em>Example of LFS metadata included in <strong>Azure DevOps</strong> project recovery process.</em></p></figcaption></figure>

***

## Useful links and items

{% embed url="<https://learn.microsoft.com/en-us/azure/devops/repos/git/manage-large-files?view=azure-devops>" %}

{% embed url="<https://support.atlassian.com/bitbucket-cloud/docs/storage-policy-for-git-lfs-with-bitbucket/>" %}

{% embed url="<https://support.atlassian.com/bitbucket-cloud/docs/manage-large-files-with-git-large-file-storage-lfs/>" %}

{% embed url="<https://docs.github.com/en/billing/concepts/product-billing/git-lfs>" %}


# Wiki recovery for DevOps organizations

How to restore a DevOps organization wiki and its metadata separately.

**Recovering an organization wiki restores lost or overwritten documentation, enabling projects to quickly regain access to their knowledge base without affecting other repository or project metadata.**

***

## Recovery process for Bitbucket, GitHub, and GitLab

The following steps demonstrate how to quickly recover your wiki using **GitProtect Management Service**.

{% stepper %}
{% step %}
Get into the restore view using the following method:

1. Open the appropriate **DevOps** tab, then click the **Explore** button next to the organization whose backup you want to restore (explore icon ![](/files/H9cvqYuZg8gsyMXFKU9l) in list view).
2. Search for the repository containing the wiki you want to restore, then click the restore icon ![](/files/IyFlgWJXXcdC6zuDZNs2) in the action menu of that repository.

<figure><img src="/files/h5x1oJkxqbl3DXQT9rqp" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Backup plans** section, select the appropriate backup plan, then go to the **Backup copies** section to choose the point in time from which you want to restore your wiki.

<figure><img src="/files/J463QmC8i5lLxljE97fN" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the **Restore now** button in the **Restore wiki** section to configure the restoration settings.

<figure><img src="/files/O3iwdnOulmdm6vSHVZRh" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the destination for the recovery and click **Next**.

{% hint style="info" %}
You can choose any organization registered in **GitProtect** (you can find more information about cross-recovery in **Useful links and items section**).
{% endhint %}

{% hint style="danger" %}
If your destination is **GitHub**, make sure that your repository has **at least one wiki page created**.
{% endhint %}

<figure><img src="/files/gcPDz5SEXszcJ9FLDHpB" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Restore to** section, select the repository where you want to restore the wiki. If you are restoring the wiki to an **Azure DevOps** or **Azure DevOps Server** organization, also select the target project.

<figure><img src="/files/44N9R1YfO3C89bFMA0yk" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Restore settings** section, you can limit the bandwidth if required by your network infrastructure and change the device that will perform the restoration.

<figure><img src="/files/QJKGmUBsBaraYDBR2d8N" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Once all parameters are defined, click **Restore** to start the recovery process. You can monitor the progress in the **Tasks** tab; once finished, the wiki will be available in the defined organization account.
{% endstep %}
{% endstepper %}

***

## Recovery process for Azure DevOps & DevOps Server

The following steps demonstrate how to quickly recover your **Azure DevOps** project wiki using **GitProtect Management Service**.

{% stepper %}
{% step %}
Get into the restore view using the following method:

1. Open the appropriate **DevOps** tab, then click the **Explore** button next to the organization whose backup you want to restore (explore <img src="/files/H9cvqYuZg8gsyMXFKU9l" alt="" data-size="original"> icon in list view).
2. In the **Projects & repositories** tab, search for the project containing the wiki you want to restore, then click the restore <img src="/files/IyFlgWJXXcdC6zuDZNs2" alt="" data-size="original"> icon in the action menu of that project.

<figure><img src="/files/LfdLs0TUFr5VgmALB81z" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Backup plans** section, select the appropriate backup plan, then go to the **Backup copies** section to choose the point in time from which you want to restore your wiki.

<figure><img src="/files/FXL8xqMK7ndY272AiJIQ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the destination for the recovery and click **Next**.

{% hint style="info" %}
You can choose any organization registered in **GitProtect** (you can find more information about cross-recovery in **Useful links and items section**).
{% endhint %}

{% hint style="danger" %}
If your destination is **GitHub**, make sure that your repository has **at least one wiki page created**.
{% endhint %}

<figure><img src="/files/liaBhv3R45FMkh5K5L9n" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the **Restore now** button in the **Restore wiki** section to configure the restoration settings.

<figure><img src="/files/rWCmqdSBSWNhkIptdQ34" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Restore to** section, select the repository where you want to restore the wiki. If you are restoring the wiki to an **Azure DevOps** or **Azure DevOps Server** organization, also select the target project.

<figure><img src="/files/Rny9cLkm2qP2qVLamRhM" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Restore settings** section, you can limit the bandwidth if required by your network infrastructure and change the device that will perform the restoration.

<figure><img src="/files/T8nnfjuCEN1ZmLhhzmMb" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Once all parameters are defined, click **Restore** to start the recovery process. You can monitor the progress in the **Tasks** tab; once finished, the wiki will be available in the defined organization account.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/NqYA6IzA1GmHxLsZwtrZ" %}
[Cross-recovery for DevOps organizations](/backup-and-recovery/devops/general/cross-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/IiVUjDfL7V7Z9YEIHaQs" %}
[LFS recovery for DevOps organizations](/backup-and-recovery/devops/general/lfs-recovery-for-devops-organizations)
{% endcontent-ref %}


# Azure DevOps & DevOps Server

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/7EAiKarYh5q58oGREIYy">/pages/7EAiKarYh5q58oGREIYy</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/RHpCXoig4zD8p7PPN4Ce">/pages/RHpCXoig4zD8p7PPN4Ce</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/Dz8TxluCNBsgjxFYwlg7">/pages/Dz8TxluCNBsgjxFYwlg7</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Integration

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/HaSuykFA78aXGqJnUqhL">/pages/HaSuykFA78aXGqJnUqhL</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/eQEWZtyHnZAfVZ6hF8xf">/pages/eQEWZtyHnZAfVZ6hF8xf</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/oK81N77aMKHx7rOtbjV3">/pages/oK81N77aMKHx7rOtbjV3</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/XPXS2RvLd5qQcOehih4Q">/pages/XPXS2RvLd5qQcOehih4Q</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Required permissions

Full list of permissions required for integrating Azure DevOps and Azure DevOps Server with GitProtect.

#### Required permissions for Azure DevOps and Azure DevOps Server specify the access levels GitProtect needs to securely back up and restore your data.

***

## Permissions for Azure DevOps

### <mark style="background-color:blue;">User access levels</mark>

The account used for integration must have an appropriate access level assigned within **Azure DevOps**:

* **Basic**.
* **Visual Studio Subscriber** — professional or enterprise tier.
* **GitHub Enterprise** — similar to basic.
* **Stakeholder** (not recommended) — this level has limited access and cannot properly protect repositories.

{% hint style="warning" %}
**GitProtect** can only protect projects that the integrated user account has explicit access to.
{% endhint %}

### <mark style="background-color:blue;">OAuth integration</mark>

{% hint style="danger" %}
**GitProtect** supports only organizational accounts (**Microsoft Entra ID**) — **personal accounts are not supported**. For private accounts, use PAT instead.
{% endhint %}

To integrate **Azure DevOps** with **GitProtect** using **OAuth**, make sure the account has an administrator role. Otherwise, you may encounter permission errors or find that the approval button is inactive.

When integrating **Azure DevOps** via **OAuth**, the following scopes are required:

* [x] Build: <mark style="color:$success;">**read and execute**</mark> (vso.build\_execute)
* [x] Code: <mark style="color:$success;">**read, write and manage**</mark> (vso.code\_manage)
* [x] Environment: <mark style="color:$success;">**read and manage**</mark> (vso.environment\_manage)
* [x] Projects and Teams: <mark style="color:$success;">**read, write and manage**</mark> (vso.project\_manage)
* [x] Variable Groups: <mark style="color:$success;">**read and create**</mark> (vso.variablegroups\_write)
* [x] Wiki: <mark style="color:$success;">**read and write**</mark> (vso.wiki\_write)
* [x] Work Items: <mark style="color:$success;">**read and write**</mark> (vso.work\_write)
* [x] Packaging: <mark style="color:$success;">**read, write and manage**</mark> (vso.packaging\_manage)
* [x] Artifacts: user\_impersonation
* [x] Login and read the profile

### <mark style="background-color:blue;">Installation permissions for OAuth</mark>

The ability to authorize the **GitProtect** **OAuth** application depends on your organization's **User consent settings** within **Azure DevOps**. The following options are available:

<table><thead><tr><th width="242">Consent policy</th><th width="500">Authorization requirement</th></tr></thead><tbody><tr><td>Allow user consent for apps from verified publishers, for selected permissions</td><td>Any user can authorize the app, provided that all requested permissions are classified as low impact by your administrator.</td></tr><tr><td>Do not allow user consent</td><td>Only users with the <strong>Application Administrator</strong> or <strong>Global Administrator</strong> role can authorize the integration.</td></tr><tr><td>Let Microsoft manage your consent settings (Recommended)</td><td>Authorization is subject to <strong>Microsoft's</strong> current security guidelines. While this currently allows for <strong>GitProtect</strong> integration, availability may change based on <strong>Microsoft's</strong> evolving policies.</td></tr></tbody></table>

<figure><img src="/files/d5nKrQ7PoGlE8hFg1vZz" alt=""><figcaption></figcaption></figure>

### <mark style="background-color:blue;">Personal Access Token (PAT) integration</mark>

#### Prerequisites:

* [x] **Organization** — when generating PAT, you **must enable** the **All accessible organizations** value in the **Organization** field.

#### Required scopes:&#x20;

* [x] Build: <mark style="color:$success;">**read and execute**</mark>&#x20;
* [x] Code: <mark style="color:$success;">**read, write and manage**</mark>
* [x] Environment: <mark style="color:$success;">**read and manage**</mark>
* [x] Extensions: <mark style="color:$success;">**read**</mark>
* [x] Project and Team: <mark style="color:$success;">**read, write and manage**</mark>
* [x] Test Management: <mark style="color:$success;">**read and write**</mark>
* [x] Variable Groups: <mark style="color:$success;">**read and create**</mark>
* [x] Wiki: <mark style="color:$success;">**read and write**</mark>
* [x] Work Items: <mark style="color:$success;">**read and write**</mark>
* [x] Packaging: <mark style="color:$success;">**read, write and manage**</mark>

{% hint style="danger" %}
When performing a backup with minimal permissions, some metadata might be excluded. To ensure complete protection, select the permissions based on your data protection needs. Note that with read-only permissions, backups can be made, **but restoring requires a new token or password with write access**.
{% endhint %}

### <mark style="background-color:blue;">Granular permission settings</mark>

To ensure both backup and restore operations succeed, the following permissions are required:

1. **Organization level:**
   1. **General:**
      1. Create new projects (restore)
   2. **Boards:**
      1. Create process (restore)
      2. Edit process (restore)
2. **Project level:**
   1. **General:**
      1. View project-level information (backup)
3. **Repositories level:**
   1. Create branch (restore)
   2. Create repository (restore)
   3. Read (backup)

***

## Permissions for Azure DevOps Server

### <mark style="background-color:blue;">Personal Access Token (PAT) integration</mark>

For on-premise installations, use the personal access token (PAT) method.

#### Prerequisites:

* [x] **Organization** — when generating PAT, you **must enable** the **All accessible organizations** value in the **Organization** field.

#### Required scopes:&#x20;

* [x] Build: <mark style="color:$success;">**read and execute**</mark>&#x20;
* [x] Code: <mark style="color:$success;">**read, write and manage**</mark>
* [x] Environment: <mark style="color:$success;">**read and manage**</mark>
* [x] Extensions: <mark style="color:$success;">**read**</mark>
* [x] Project and Team: <mark style="color:$success;">**read, write and manage**</mark>
* [x] Test Management: <mark style="color:$success;">**read and write**</mark>
* [x] Variable Groups: <mark style="color:$success;">**read and create**</mark>
* [x] Wiki: <mark style="color:$success;">**read and write**</mark>
* [x] Work Items: <mark style="color:$success;">**read and write**</mark>
* [x] Packaging: <mark style="color:$success;">**read, write and manage**</mark>

{% hint style="danger" %}
When performing a backup with minimal permissions, some metadata might be excluded. To ensure complete protection, select the permissions based on your data protection needs. Note that with read-only permissions, backups can be made, but **restoring requires a new token or password with write access**.
{% endhint %}


# API limits

#### API limits for Azure DevOps and Azure DevOps Server outline the restrictions on requests that can affect how Xopero ONE interacts with your data.

***

## Azure DevOps

Rate limits enhance security by preventing an overwhelming number of requests that could disrupt, block, or destabilize the application's functionality—the system enforces these limits for stability. For more information, visit [the official **Microsoft Learn** website](https://learn.microsoft.com/en-us/azure/devops/integrate/concepts/rate-limits?view=azure-devops).

{% hint style="danger" %}
Unfortunately, unlike other **DevOps**, **Microsoft** does not provide information about the exact number of queries that can be sent in a given time period.
{% endhint %}

***

## Azure DevOps Server

In **Azure DevOps Server** (on-premises), **API** limits are flexible and depend on server resources and configuration. Unlike the cloud version, there are no fixed, global request limits—administrators set performance parameters and limits tailored to the organization's specific needs.


# Adding Azure DevOps organization to GitProtect

This article explains how to add an Azure DevOps organization to GitProtect.

#### Adding an Azure DevOps organization to GitProtect connects your environment to the platform, enabling secure backup of projects, repositories, and related data.

***

## Using OAuth

{% stepper %}
{% step %}
Log in to **GitProtect Management Service**, open the **DevOps** tab on the left side of the window, and select **Azure DevOps** from the list.

<figure><img src="/files/l5iPOGNP6lC4xcGCSGBG" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click the **Connect** button under **Azure DevOps**.

<figure><img src="/files/NznT9t5Ab2uiDoO4Vrk9" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
[In the window that pops-up](#additional-browser-permissions), log in with a user account which has the required permissions for the repositories or projects to protect. If your **Azure** login session is active in a different tab, the login will complete automatically.

<figure><img src="/files/zJJSXtcoplPq3qWhYBTv" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Check the **Consent on behalf of your organization** checkbox and click **Accept** to proceed.

<figure><img src="/files/c8DqrudYQp0hsPdRZvmM" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Your **Azure DevOps** organization has now been successfully added to **GitProtect**. Click **Custom policy** to adjust your backup policy settings, or click **Run backup** to execute the backup immediately using the current policy configuration.

<figure><img src="/files/1pPrym9aXoazwsquXyaz" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## Using a Personal Access Token (PAT)

{% stepper %}
{% step %}
Log in to **GitProtect Management Service**, open the **DevOps** tab on the left side of the window, and select **Azure DevOps** from the list.

<figure><img src="/files/4yLJWbJvfF8o8YHnE9kT" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click the **advanced mode** link under **Azure DevOps** and **Azure DevOps Server** tiles.

<figure><img src="/files/qIsYDDYDPUCuhHbxBcEO" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Set your authentication method.

1. In **Authentication**, select **Azure DevOps**.
2. For **Connect using**, choose **Username and Personal Access Token**.
3. Add or select **PAT** from the **Password Manager**.
4. Choose whether **GitProtect** should automatically add new repositories to your backup.

<figure><img src="/files/YjgFTeqFXXpk8kHIEQss" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure your repository sync and default worker. Specify hours for synchronization, or set a time interval for automatic updates.

{% hint style="warning" %}
Cloud workers cannot access local network storage. Choose a device with the necessary access if backing up locally.
{% endhint %}

<figure><img src="/files/PlCRf5BMIOIIPNjxBO9D" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Proceed** to complete adding your **Azure DevOps** organization and grant **GitProtect** access to the specified resources.
{% endstep %}

{% step %}
Your **Azure DevOps** organization has now been successfully added to **GitProtect**. Click **Custom policy** to adjust your backup policy settings, or click **Run backup** to execute the backup immediately using the current policy configuration.

<figure><img src="/files/msfWKga5Ru5q1Mod1BtP" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## Additional browser permissions

When adding an organization, you may be prompted to grant additional permissions to the **GitProtect** application — make sure your browser allows **GitProtect** to open pop-up windows.

<figure><img src="/files/wlEd4lRBglPnofKhy6QP" alt=""><figcaption></figcaption></figure>

Depending on your browser, you can either adjust the settings to allow pop-ups or permit the authorization window to open once.


# Adding Azure DevOps Server to GitProtect

This article explains how to add an Azure DevOps Server organization to GitProtect.

#### Adding an Azure DevOps Server to GitProtect connects your projects and repositories to the platform, enabling seamless backup management and secure data protection.

***

## Using a Personal Access Token (PAT)

{% hint style="warning" %}
**Azure DevOps Server** (self-managed, on-premise) does not support **OAuth** and requires a **personal access token**.
{% endhint %}

{% stepper %}
{% step %}
Log in to **GitProtect Management Service**, open the **DevOps** tab on the left side of the window, and select **Azure DevOps** from the list.

<figure><img src="/files/4yLJWbJvfF8o8YHnE9kT" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click the **Connect** button under **Azure DevOps Server**.
{% endstep %}

{% step %}
Set your authentication method.

1. In **Authentication**, select **Azure DevOps Server**.
2. Enter the **service address** of your **Azure DevOps Server** (IP or DNS name, including the protocol).
3. Add or select **PAT** from the **Password Manager**.
4. Choose whether **GitProtect** should automatically add new repositories to your backup.

<figure><img src="/files/XO5oUbScxbr4OrJNSJIU" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure your repository sync and default worker. Specify hours for synchronization, or set a time interval for automatic updates.

{% hint style="warning" %}
Cloud workers cannot access local network storage. Choose a device with the necessary access if backing up locally.
{% endhint %}

<figure><img src="/files/PlCRf5BMIOIIPNjxBO9D" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Proceed** to complete adding your **Azure DevOps Server** organization and grant **GitProtect** access to the specified resources.
{% endstep %}

{% step %}
Your **Azure DevOps Server** organization has now been successfully added to **GitProtect**. Click **Custom policy** to adjust your backup policy settings, or click **Run backup** to execute the backup immediately using the current policy configuration.

<figure><img src="/files/IRObymYgvv7QPNcWQeBB" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Backup

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/BXPuLCQBgeABgbIlWjmc">/pages/BXPuLCQBgeABgbIlWjmc</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/DYEWstzW0IOqZAnR1UW9">/pages/DYEWstzW0IOqZAnR1UW9</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/U3l8mfGEVrm5UTshCJIS">/pages/U3l8mfGEVrm5UTshCJIS</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Process overview

Learn more about the backup process for Azure DevOps.

## General information

**GitProtect** is designed to protect **DevOps** ecosystems, including **Azure DevOps**.

To ensure your entire **Azure DevOps** environment is reliably backed up, make sure to include all repositories along with their related metadata — the best practice is to create a backup plan for critical repositories and metadata that change daily (or even more frequently), for example, using the recommended **Grandfather-Father-Son** (**GFS**) rotation scheme.&#x20;

Additionally, create a separate backup plan for unused repositories that you need to keep for future reference. This type of backup primarily serves **Azure DevOps** archival purposes, and with unlimited retention, you can store your copies for as long as needed — even indefinitely.

You can also delete repositories from your **Azure DevOps** account while keeping a copy in storage, which helps bypass **Azure DevOps** limits.

***

## Backup type

**Incremental** and **differential backups** help save storage space. In **GitProtect** you can define different retention and performance settings for each type of backup (**full**, **incremental**, and **differential**). For example, our software allows you to include only the blocks of **Azure DevOps** data that have changed since the last backup, reducing storage usage, speeding up the process, and limiting bandwidth.

***

## Adding multiple storage instances

Use different types of storage to replicate backups, minimize the risk of outages or disasters, and comply with the **3-2-1 backup rule** (which means having at least **three copies** of your data on **two different storage types**, with at least **one copy** stored in the cloud).

**GitProtect** is a multi-storage system that allows you to store your data:

* [x] In the cloud (**Xopero Cloud Storage**, **AWS S3**, **Wasabi Cloud**, **Backblaze B2**, **Google Cloud Storage**, **Azure Blob Storage**, or any **S3**-compatible public cloud).
* [x] Locally (**NFS**, **CIFS**, **SMB** network shares, or local disk resources).
* [x] In a hybrid or multi-cloud environment.


# Protected resources

Overview of protected Azure DevOps and Azure DevOps Server resources, including repositories, wikis, and metadata secured by backup.

**Azure DevOps protected resources define which parts of the environment GitProtect can access, backup, and restore.**

***

## Backup coverage <a href="#bitbucket" id="bitbucket"></a>

The following tables list all **Azure DevOps** and **Azure DevOps Server** resources covered by backup.

{% hint style="info" %}
The list is presented in alphabetical order.
{% endhint %}

| ARTIFACTS                                                                                                                                                                                                                                                                                                                                                                | BOARDS                                                                                                                                                                                                                                                                                                               | BOARD PROCESSES                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <ul class="contains-task-list"><li><input type="checkbox" checked>Artifact Settings</li><li><input type="checkbox" checked>Deleted Package Options</li><li><input type="checkbox" checked>Feed</li><li><input type="checkbox" checked>Feed Name</li><li><input type="checkbox" checked>Packages</li><li><input type="checkbox" checked>Package Sharing Options</li></ul> | <ul class="contains-task-list"><li><input type="checkbox" checked>Work Item Attachments</li><li><input type="checkbox" checked>Work Item Comments<strong>\*</strong></li><li><input type="checkbox" checked>Work Items<strong>\*\*</strong></li><li><input type="checkbox" checked>Work Items Related Work</li></ul> | <ul class="contains-task-list"><li><input type="checkbox" checked>Work Item Types<strong>\*\*\*</strong></li><li><input type="checkbox" checked><p>Work Item Types - Layout</p><ul class="contains-task-list"><li><input type="checkbox" checked>Fields</li><li><input type="checkbox" checked>Groups</li><li><input type="checkbox" checked>Pages</li><li><input type="checkbox" checked>Picklists</li></ul></li><li><input type="checkbox" checked>Work Item Types - States</li></ul> |

<sub>**\***</sub><sub>The restored comment is attributed to the account performing the restore; content includes the original comment author information and the original creation date.</sub>

<sub>**\*\***</sub><sub>Assignee and identity-type fields are not restored directly; instead, a comment is added identifying the original assignee and related values.</sub>

<sub>**\*\*\***</sub><sub>A work item type consists of a name, description, color, icon, enabled/disabled status, and its internal configuration (layout and states).</sub>

| PIPELINES                                                                                                                                                                                                                                | PROJECT                                                                                  |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- |
| <ul class="contains-task-list"><li><input type="checkbox" checked>Environments</li><li><input type="checkbox" checked>Pipelines<strong>\*</strong></li><li><input type="checkbox" checked>Variable Groups<strong>\*\*</strong></li></ul> | <ul class="contains-task-list"><li><input type="checkbox" checked>Project Wiki</li></ul> |

<sub>**\***</sub><sub>Configuration and definitions are restored; logs, run history, and artifacts are not. Only YAML pipelines that use</sub> <sub></sub><sub>**Azure Repos**</sub> <sub></sub><sub>are supported.</sub>

<sub>**\*\***</sub><sub>Secret variables are not backed up due to an API limitation.</sub>

| PULL REQUESTS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | REPOSITORY                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | TEST PLANS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <ul class="contains-task-list"><li><input type="checkbox" checked>Closed Pull Requests<strong>*</strong></li><li><input type="checkbox" checked>Comments</li><li><input type="checkbox" checked>Creation Date</li><li><input type="checkbox" checked>Creator</li><li><input type="checkbox" checked>Description</li><li><input type="checkbox" checked>Merged Pull Requests<strong>*</strong></li><li><input type="checkbox" checked>Open Pull Requests</li><li><input type="checkbox" checked>Reviewers</li><li><input type="checkbox" checked>Tags</li></ul> | <ul class="contains-task-list"><li><input type="checkbox" checked>Branches</li><li><input type="checkbox" checked>Commits</li><li><input type="checkbox" checked>Commit Creators</li><li><input type="checkbox" checked>Commit History</li><li><input type="checkbox" checked>Commit Messages </li><li><input type="checkbox" checked>Default Branch</li><li><input type="checkbox" checked>Git Objects</li><li><input type="checkbox" checked>LFS</li><li><input type="checkbox" checked>Tags</li></ul> | <ul class="contains-task-list"><li><input type="checkbox" checked>Configurations</li><li><input type="checkbox" checked>Configuration Variables</li><li><input type="checkbox" checked>Test Cases (assignment to Test Suites)</li><li><input type="checkbox" checked>Test Plans</li><li><input type="checkbox" checked>Test Points (state & outcome)</li><li><input type="checkbox" checked>Test Results</li><li><input type="checkbox" checked>Test Run<strong>**</strong></li><li><input type="checkbox" checked>Test Suites<strong>**\*</strong></li></ul> |

<sub>**\***</sub><sub>Included in backup, but can be restored only to</sub> <sub></sub><sub>**GitHub**</sub> <sub></sub><sub>and</sub> <sub></sub><sub>**GitLab**</sub><sub>.</sub>

<sub>**\*\***</sub><sub>Test run history is backed up and restored. The run state (for example, in progress or needs investigation) is restored in a separate step after the run is created.</sub>

<sub>**\*\*\***</sub><sub>Automated test settings (associated pipelines) are not restored due to current pipeline restore limitations.</sub>


# Creating a backup plan

This article contains information on how to set up Azure DevOps & DevOps Server backup plan.

#### Creating an Azure DevOps (or DevOps Server) backup plan ensures your projects and data are securely protected and easily restorable.

***

## Backup plan setup <a href="#backup_plan_creation" id="backup_plan_creation"></a>

{% stepper %}
{% step %}
Login to **GitProtect Management Service**, open the **Plans** > **Backup** tab and click the <img src="/files/cP3ARjuLWqJ9T4N5H2Cb" alt="" data-size="original"> **Add plan** button in the top bar.
{% endstep %}

{% step %}
Select **Azure DevOps** from the list.
{% endstep %}

{% step %}
Select (or add) the **Azure DevOps** or **DevOps Server** environment you want to include in the backup process, and choose the repositories to back up.

{% hint style="success" %}
**GitProtect** allows you to protect the entire **Azure DevOps** environment.
{% endhint %}

<figure><img src="/files/z36IlOZAHEH62hLMvoPI" alt=""><figcaption></figcaption></figure>

1. **Protect all** — protects an entire **Azure DevOps** organization.
2. **Select projects** — allows you to protect selected **Azure DevOps** projects (including its metadata).
3. **Select repositories** — protects only **selected repositories**.
4. **Set rules** — lets you set rules for **GitProtect** to automatically select resources to protect.
   {% endstep %}

{% step %}
Specify a name for the backup plan.
{% endstep %}

{% step %}
Select the appropriate metadata that you want to back up. Here, you can also change the **default worker**, which is the device directly responsible for the backup process of your repositories.

{% hint style="success" %}
You can have multiple workers and assign different workers to each backup plan.
{% endhint %}

<figure><img src="/files/UrVzLQ9wFEco6mkDoPGG" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/0JVILm01PqTxOUnyElrM" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select one of the locations assigned to your **GitProtect** instance as storage.

<figure><img src="/files/nPdEJSv4GBrdZezw4NKg" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Customize the scheduler and specify how long your data should be retained. If needed, adjust the advanced settings to suit your needs.

<figure><img src="/files/KF8R8x8N9JauVJ2Y9nM0" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
If necessary, adjust the advanced settings such as encryption, error handling, or bandwidth limits to fit your requirements.

<figure><img src="/files/oRpojLSXGWuUUdyPE1XN" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Double-check your data and click **Save** to create the backup plan.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/D9j2y4b4l51BnBsEIyA5" %}
[Cloud storage](/storage/cloud-storage)
{% endcontent-ref %}

{% content-ref url="/pages/AWu8w4uJUkVdjFTGajr0" %}
[GitProtect worker](/deployment-and-configuration/gitprotect-worker)
{% endcontent-ref %}

{% content-ref url="/pages/9AZUD1hXe2mvU7ncAHPz" %}
[Scheduler & retention](/management/scheduler-and-retention)
{% endcontent-ref %}


# Recovery

Overview of Azure DevOps and DevOps Server backup recovery in GitProtect, including restoration of repositories, wikis, and related metadata.

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/NqYA6IzA1GmHxLsZwtrZ">/pages/NqYA6IzA1GmHxLsZwtrZ</a></td><td>How <strong>GitProtect</strong> restores repositories and metadata across <strong>Git</strong> providers for rapid disaster recovery and <strong>DevOps</strong> migrations.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/PeA9pPhjDhamSFPKIvBT">/pages/PeA9pPhjDhamSFPKIvBT</a></td><td>Recover a single <strong>Azure DevOps</strong> and <strong>DevOps Server</strong> project backup copy, including its repositories and other metadata.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/ojkXax0VjOFVZ6L0LXIi">/pages/ojkXax0VjOFVZ6L0LXIi</a></td><td>Learn how to restore a single <strong>Azure DevOps</strong> and <strong>DevOps Server</strong> repository backup.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/y34pOsEMJhyeQRMV3Jch">/pages/y34pOsEMJhyeQRMV3Jch</a></td><td>Restore multiple <strong>Azure DevOps</strong> and <strong>DevOps Server</strong> project backup copies at once.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/g0jjQWW7xWOEt1wBZOTe">/pages/g0jjQWW7xWOEt1wBZOTe</a></td><td>How to restore multiple <strong>Azure DevOps</strong> and <strong>DevOps Server</strong> repository backup copies at once.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/KUrX1uY5hrsK7Rn9NVmn">/pages/KUrX1uY5hrsK7Rn9NVmn</a></td><td>How to restore a <strong>DevOps</strong> organization wiki and its metadata separately.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Single project recovery

Recover a single Azure DevOps and DevOps Server project backup copy, including its repositories and other metadata.

**GitProtect enables single project recovery for Azure DevOps, allowing organizations to restore individual projects along with their selected metadata, ensuring data integrity and consistency while minimizing disruption to other projects and repositories.**

***

## Recovery process

The below steps demonstrate how to quickly restore a single **Azure DevOps** project using **GitProtect Management Service**.

{% hint style="danger" %}
**Deleted artifacts cannot be restored&#x20;**<mark style="color:red;">**while they remain in the recycle bin**</mark>**&#x20;— they can be restored, but you must remove them from the recycle bin first.**
{% endhint %}

{% hint style="danger" %}
**Azure does not allow restoring deleted packages to the same feed.** Once a package is deleted, it must remain deleted. Restoring to a new feed does not have this limitation, so all packages should be restored there.
{% endhint %}

{% stepper %}
{% step %}
Get into the restore view using the following method:

1. Open the **Azure DevOps** tab (**DevOps** > **Azure DevOps**), then click the **Explore** button next to the organization whose backup you want to restore (explore <img src="/files/H9cvqYuZg8gsyMXFKU9l" alt="" data-size="original"> icon in list view).
2. In the **Projects & repositories** tab, search for the project you want to restore, then click the restore <img src="/files/IyFlgWJXXcdC6zuDZNs2" alt="" data-size="original"> icon in the action menu of that project.

<figure><img src="/files/gnVIoowdE0ircnXWIaOC" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the backup plan from which you want to restore data. Click the drop-down under **Backup plans** section and choose one of the plans from the list.

<figure><img src="/files/mL7AzL505ggAJGPjGi4w" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Choose the backup version from all the backups that have already been performed — select the desired date and click the **Restore** button.

<figure><img src="/files/BTvjdbusdgJhF61qmYHX" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the destination for the recovery and click **Next**.

{% hint style="info" %}
You can choose any device or organization registered in **GitProtect** (you can find more information about cross-recovery in **Useful links and items section**).
{% endhint %}

<figure><img src="/files/vDyOXISkyS2PZkyiXaQx" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the available metadata to restore and click **Restore selected** or **Restore all** to proceed.

{% hint style="success" %}
**GitProtect** allows you to select specific metadata to restore — **each element can be included or excluded by toggling the switch next to it**.
{% endhint %}

{% hint style="info" %}
The available data to restore depends on the restoration destination.
{% endhint %}

<figure><img src="/files/7AuB9SFSZ2QYtahHaAAR" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Data to restore** section at the top, you can select which of the previously chosen available data you want to restore, if needed.

<figure><img src="/files/ITUXHfHlLabrCXTOm1wu" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Restore to** section, you can change the previously selected recovery destination if needed.
{% endstep %}

{% step %}
In the **Throttling prevention** section, you can add additional **DevOps** accounts to avoid throttling.

{% hint style="warning" %}
To use additional organization accounts, you must first add them in the organization settings (organization view > **Edit**).
{% endhint %}

<figure><img src="/files/LeY8P1V1qDcPeKBixsly" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure the recovery destination settings, depending on where the backup will be restored.

#### Restore to a Git organization

1. Select the target organization (where applicable).
2. If you are restoring your project to **Azure DevOps** or **DevOps Server** organization:
   1. Set a unique, custom name for the project in **Restore settings** (or use the custom name automatically generated by **GitProtect**).
   2. Choose whether to restore repositories from the project's copy:
      1. When the **Restore repositories from this project's copy** switch is turned off during the restore process, all of project's protected repositories are restored, **regardless of whether the repositories were protected by the same plan or by different plans**. The latest available backups are used.
      2. When the switch is turned on, a different restore mechanism is applied. In this case, **only repositories backed up by the same plan as the project are restored**.

{% hint style="danger" %}
Due to required changes, the latter mechanism is not available for backups created with **GitProtect** versions earlier than 2.0.5 or for workers running versions lower than 2.0.5.
{% endhint %}

<figure><img src="/files/P1sr2wHJBM97EJDET1BB" alt=""><figcaption></figcaption></figure>

3. If you are restoring your project to a different **Git** organization than the original (for example, **GitHub**), you can set custom names for all repositories in the project or add a suffix to the original repository names. You can also choose whether to add a label to the restored elements (where applicable).

{% hint style="danger" %}
If the custom name or the original repository name already exists in the selected **Git** organization, **the restore will fail**. To complete the restoration successfully, you must choose unique repository names or select the **Add suffix to repo name** option so the restored repositories keep their original names with an automatically generated suffix.
{% endhint %}

4. Adjust the bandwidth settings.
5. Check which worker is set as the default for recovery and change it if necessary.

#### Restore to a device

{% hint style="warning" %}
To restore a repository to a local device, you must have a **Git** client and the **GitProtect** worker installed on that device (you can find more information about workers in **Useful links and items** section).
{% endhint %}

{% hint style="danger" %}
You can restore **only the repository** (without metadata) when restoring data to local resources.
{% endhint %}

1. Select the destination device (a registered device).
2. Make sure the device where you want to restore data has the **Git** client added to the PATH environment variable. The PATH variable is usually configured automatically after **Git** installation (a system restart may be required) — if it isn’t, you will have to configure it manually.

{% hint style="info" %}
To configure the PATH variable in **Windows**, open the environment variables, select the PATH variable, and click the **Edit** button. Copy the path to the git.exe file and add it to the PATH variable.
{% endhint %}

3. Specify the restoration directory and configure other options (for example, whether to overwrite existing data or reduce bandwidth). If needed, you can create a new restoration folder on the selected drive from the **Management Service** level.

<figure><img src="/files/jz23dJy74294dFQStdN9" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After defining all parameters, click the **Restore** button to begin the recovery process. When the process is complete, a new project/repository/folder will be created in your organization/on your device. You can monitor the restoration process in the **Tasks** tab.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/AWu8w4uJUkVdjFTGajr0" %}
[GitProtect worker](/deployment-and-configuration/gitprotect-worker)
{% endcontent-ref %}

{% content-ref url="/pages/NqYA6IzA1GmHxLsZwtrZ" %}
[Cross-recovery for DevOps organizations](/backup-and-recovery/devops/general/cross-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/IiVUjDfL7V7Z9YEIHaQs" %}
[LFS recovery for DevOps organizations](/backup-and-recovery/devops/general/lfs-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/KUrX1uY5hrsK7Rn9NVmn" %}
[Wiki recovery for DevOps organizations](/backup-and-recovery/devops/general/wiki-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/ajngMEBoS6fhnIrEkYfE" %}
[Throttling prevention](/compliance-and-risk-management/throttling-prevention)
{% endcontent-ref %}


# Single repository recovery

Learn how to restore a single Azure DevOps and DevOps Server repository backup.

**GitProtect allows organizations to restore individual Azure DevOps repositories along with their associated metadata. The process ensures repository integrity and consistency while minimizing impact on other projects, supporting efficient disaster recovery, migration, and point-in-time restore operations.**

***

## Recovery process

The following steps demonstrate how to quickly restore a single **Azure DevOps** repository using **GitProtect Management Service**.

{% stepper %}
{% step %}
Get into the restore view using the following method:

1. Open the **Azure DevOps** tab (**DevOps** > **Azure DevOps**), then click the **Explore** button next to the organization whose backup you want to restore (explore <img src="/files/H9cvqYuZg8gsyMXFKU9l" alt="" data-size="original"> icon in list view).
2. Go to the **Repositories** tab and search for the repository you want to restore, then click the restore ![](/files/IyFlgWJXXcdC6zuDZNs2) icon in the action menu of that repository.

<figure><img src="/files/oOrXpIJD5JiZVeSLijBp" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the backup plan from which you want to restore data. Click the drop-down under **Backup plans** section and choose one of the plans from the list.

<figure><img src="/files/ADmMndLMntdmwTKVc4gD" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Choose the backup version from all the backups that have already been performed — select the desired date and click the **Restore** button.

<figure><img src="/files/xyujGpVFPELla5zpDFix" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the data available to restore and click **Restore selected** or **Restore all** to proceed.

<figure><img src="/files/R0ZtdojrYb7UXVfmfrgr" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the destination for the recovery and click **Next**.&#x20;

{% hint style="info" %}
You can choose any device or organization registered in **GitProtect** (you can find more information about cross-recovery in **Useful links and items section**).
{% endhint %}

<figure><img src="/files/8xY9AYh6EHvvSuzlA6td" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Data to restore** section at the top, you can select which of the previously chosen available data you want to restore.

<figure><img src="/files/grDPjlwetOnJKiWEjfJA" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Restore to** section, you can change the previously selected recovery destination if needed.

<figure><img src="/files/Ziku0P5FthigBp85bM4V" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Throttling prevention** section, you can add additional **DevOps** accounts to avoid throttling.

{% hint style="warning" %}
To use additional organization accounts, you must first add them in the organization settings (organization view > **Edit**).
{% endhint %}

<figure><img src="/files/LPyVxIEO7ZNaW4h184E9" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure the recovery destination settings, depending on where the backup will be restored.

#### Restore to a Git organization

1. In **Map organizations** section, select the target organization to which the repository will be restored.

{% hint style="info" %}
If the recovery destination is **Azure DevOps**, the **Map organizations** section will be replaced by **Target organization** and **Target project** settings.
{% endhint %}

<figure><img src="/files/5IdWk1msghdON4NTKSoU" alt=""><figcaption></figcaption></figure>

2. In **Restore settings**, you can set a unique, custom name for the repository (or use the custom name automatically generated by **GitProtect**).

{% hint style="success" %}
Restoring never overwrites existing repositories in the organization — if you do not set a new name for the restored repository, it keeps its original name with an automatically generated suffix.
{% endhint %}

{% hint style="danger" %}
When you set a custom name for the repository, and a repository with that name already exists in the specified organization, **the recovery will fail**.
{% endhint %}

3. If you are restoring your repository to a different **Git** organization than the original (for example, **GitHub**), in addition to setting a custom name, you can choose whether to add a label to the restored elements (where applicable).
4. Check which worker is set as the default for recovery and change it if necessary.
5. If needed, you can also adjust the bandwidth.

<figure><img src="/files/mQBg21s4t7FasjYEKvI0" alt=""><figcaption></figcaption></figure>

#### Restore to a device

{% hint style="warning" %}
To restore a repository to a local device, you must have a **Git** client and the **GitProtect** worker installed on that device (you can find more information about workers in **Useful links and items** section).
{% endhint %}

{% hint style="danger" %}
You can restore **only the repository** (without metadata) when restoring data to local resources.
{% endhint %}

1. Select the destination device (a registered device).
2. Make sure the device where you want to restore data has the **Git** client added to the PATH environment variable. The PATH variable is usually configured automatically after **Git** installation (a system restart may be required) — if it isn’t, you will have to configure it manually.

{% hint style="info" %}
To configure the PATH variable in **Windows**, open the environment variables, select the PATH variable, and click the **Edit** button. Copy the path to the git.exe file and add it to the PATH variable.
{% endhint %}

3. Specify the restoration directory and configure other options (for example, whether to overwrite existing data or reduce bandwidth). If needed, you can create a new restoration folder on the selected drive from the **Management Service** level.

<figure><img src="/files/aV8wmd2ytIw8naQuTNdA" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After defining all parameters, click the **Restore** button to begin the recovery process. When the process is complete, a new repository/folder will be created in your organization/on your device. You can monitor the restoration process in the **Tasks** tab.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/AWu8w4uJUkVdjFTGajr0" %}
[GitProtect worker](/deployment-and-configuration/gitprotect-worker)
{% endcontent-ref %}

{% content-ref url="/pages/NqYA6IzA1GmHxLsZwtrZ" %}
[Cross-recovery for DevOps organizations](/backup-and-recovery/devops/general/cross-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/IiVUjDfL7V7Z9YEIHaQs" %}
[LFS recovery for DevOps organizations](/backup-and-recovery/devops/general/lfs-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/KUrX1uY5hrsK7Rn9NVmn" %}
[Wiki recovery for DevOps organizations](/backup-and-recovery/devops/general/wiki-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/ajngMEBoS6fhnIrEkYfE" %}
[Throttling prevention](/compliance-and-risk-management/throttling-prevention)
{% endcontent-ref %}


# Recovering multiple projects

Restore multiple Azure DevOps and DevOps Server project backup copies at once.

**Restoring multiple Azure DevOps projects enables organizations to quickly recover projects, repositories, and source code at scale, ensuring consistent and reliable restoration across the development environment.**

***

## Recovery process

The below steps demonstrate how to restore multiple **Azure DevOps** projects at once using **GitProtect Management Service**.

{% hint style="danger" %}
**Deleted artifacts cannot be restored&#x20;**<mark style="color:red;">**while they remain in the recycle bin**</mark>**&#x20;— they can be restored, but you must remove them from the recycle bin first.**
{% endhint %}

{% hint style="danger" %}
**Azure does not allow restoring deleted packages to the same feed.** Once a package is deleted, it must remain deleted. Restoring to a new feed does not have this limitation, so all packages should be restored there.
{% endhint %}

{% stepper %}
{% step %}
Get into the restore view using the following method:

1. Open the **Azure DevOps** tab (**DevOps** > **Azure DevOps**), then click the **Explore** button next to the organization whose backup you want to restore (explore <img src="/files/H9cvqYuZg8gsyMXFKU9l" alt="" data-size="original"> icon in list view).
2. In the **Projects & repositories** tab, select all projects you want to restore, and then click **Restore** in the top menu.

<figure><img src="/files/Z2vlSDxFcAdTePf6qoud" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click every chosen project to select the backup plan and copy from which you want to restore data, then click **Next**.

{% hint style="info" %}
By default, the latest backup is always selected, regardless of the plan.
{% endhint %}
{% endstep %}

{% step %}
Select the destination for the recovery and click **Next**.

{% hint style="info" %}
You can choose any device or organization registered in **GitProtect** (you can find more information about cross-recovery in **Useful links and items section**).
{% endhint %}

<figure><img src="/files/7i15PVZNN1Q7S9bANtYx" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In **Data to restore section** at the top, click **Edit** and select data you want to restore.

{% hint style="success" %}
By default, all items are selected for restoration. However, **GitProtect** allows you to choose which metadata to restore. You can include or exclude each element by toggling the switch next to it.
{% endhint %}

<figure><img src="/files/0H2ypZXMwmm3K6GQ4uw8" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Throttling prevention** section, you can add additional **DevOps** accounts to avoid throttling.

{% hint style="warning" %}
To use additional organization accounts, you must first add them in the organization settings (organization view > **Edit**).
{% endhint %}

<figure><img src="/files/zehEFUe65JySrQW3DEUm" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure the recovery destination settings, depending on where the backup will be restored.

#### Restore to a Git organization

1. Select the target organization (where applicable).
2. In **Restore settings**, you can set custom names for all projects and repositories in the project, or add a suffix to their original names.

{% hint style="danger" %}
If the custom name—or the original project and repository names—already exists within the selected **Git** organization, **the restoration will fail**. To ensure successful recovery, choose unique names or select the **Add suffix to repo/project name** option, so the restored items to retain their original names with an automatically generated suffix.
{% endhint %}

3. If you are restoring your project to the **Azure DevOps** or **DevOps Server** organization:
   1. Choose whether to restore repositories from the project's copy:
      1. When the **Restore repositories from this project's copy** switch is turned off during the restore process, along with the project, all of its protected repositories are restored, **regardless of whether the repositories were protected by the same plan or by different plans**. The latest available backups are used.
      2. When the switch is turned on, a different restore mechanism is applied. In this case, **only repositories backed up by the same plan as the project are restored**.

{% hint style="danger" %}
Due to required changes, the latter mechanism is not available for backups created with **GitProtect** versions earlier than 2.0.5 or for workers running versions lower than 2.0.5.
{% endhint %}

<figure><img src="/files/e438uNx6dnoaP0L7KHEJ" alt=""><figcaption></figcaption></figure>

4. Adjust the bandwidth and other available settings, depending on the recovery destination.
5. Check which worker is set as the default for recovery and change it if necessary.

<figure><img src="/files/g1ruAifxDceYiXn1hmjW" alt=""><figcaption></figcaption></figure>

#### Restore to a device

{% hint style="warning" %}
To restore a repository to a local device, you must have a **Git** client and the **GitProtect** worker installed on that device (you can find more information about workers in **Useful links and items** section).
{% endhint %}

{% hint style="danger" %}
You can restore **only the repository** (without metadata) when restoring data to local resources.
{% endhint %}

1. Select the destination device (a registered device).
2. Make sure the device where you want to restore data has the **Git** client added to the PATH environment variable. The PATH variable is usually configured automatically after **Git** installation (a system restart may be required) — if it isn’t, you will have to configure it manually.

{% hint style="info" %}
To configure the PATH variable in **Windows**, open the environment variables, select the PATH variable, and click the **Edit** button. Copy the path to the git.exe file and add it to the PATH variable.
{% endhint %}

3. Specify the restoration directory and configure other options (for example, whether to overwrite existing data or reduce bandwidth). If needed, you can create a new restoration folder on the selected drive from the **Management Service** level.

<figure><img src="/files/9F8EBPZbL37PSRMvmXaV" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After defining all parameters, click the **Restore** button to begin the recovery process. When the process is complete, a new project/repository/folder will be created in your organization/on your device. You can monitor the restoration process in the **Tasks** tab.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/AWu8w4uJUkVdjFTGajr0" %}
[GitProtect worker](/deployment-and-configuration/gitprotect-worker)
{% endcontent-ref %}

{% content-ref url="/pages/NqYA6IzA1GmHxLsZwtrZ" %}
[Cross-recovery for DevOps organizations](/backup-and-recovery/devops/general/cross-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/IiVUjDfL7V7Z9YEIHaQs" %}
[LFS recovery for DevOps organizations](/backup-and-recovery/devops/general/lfs-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/KUrX1uY5hrsK7Rn9NVmn" %}
[Wiki recovery for DevOps organizations](/backup-and-recovery/devops/general/wiki-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/ajngMEBoS6fhnIrEkYfE" %}
[Throttling prevention](/compliance-and-risk-management/throttling-prevention)
{% endcontent-ref %}


# Recovering multiple repositories

How to restore multiple Azure DevOps and DevOps Server repository backup copies at once.

**Recovering multiple Azure DevOps repositories simultaneously enables organizations to quickly restore only the selected repositories, ensuring consistent and reliable recovery across the development environment.**

***

## Recovery process

The following steps demonstrate how to restore multiple **Azure DevOps** repositories at once using **GitProtect Management Service**.

{% stepper %}
{% step %}
Get into the restore view using the following method:

1. Open the **Azure DevOps** tab (**DevOps** > **Azure DevOps**), then click the **Explore** button next to the organization whose backup you want to restore (explore <img src="/files/H9cvqYuZg8gsyMXFKU9l" alt="" data-size="original"> icon in list view).
2. Go to the **Repositories** tab, select all repositories you want to restore, and then click **Restore** in the top menu.

<figure><img src="/files/p96G2BHeXrbggBrIz9Cg" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click every chosen repository to select the backup plan and copy from which you want to restore data, then click **Next**.

{% hint style="info" %}
By default, the latest backup is always selected, regardless of the plan.
{% endhint %}
{% endstep %}

{% step %}
Select the destination for the recovery and click **Next**.

{% hint style="info" %}
You can choose any device or organization registered in **GitProtect** (you can find more information about cross-recovery in **Useful links and items section**).
{% endhint %}

<figure><img src="/files/iAtQDMGlI9nQepbhTIzg" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In **Data to restore section** at the top, click **Edit** and select data you want to restore.

{% hint style="success" %}
By default, all items are selected for restoration. However, **GitProtect** allows you to choose which metadata to restore. You can include or exclude each element by toggling the switch next to it.
{% endhint %}

<figure><img src="/files/b8BzRK2Vseogj80zARVC" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Throttling prevention** section, you can add additional **Azure DevOps** accounts to avoid throttling.

{% hint style="warning" %}
To use additional organization accounts, you must first add them in the organization settings (organization view > **Edit**).
{% endhint %}

<figure><img src="/files/Oy4bA1MUcB0RA9vsB8VR" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure the recovery destination settings, depending on where the backup will be restored.

#### Restore to a Git organization

1. In **Map organizations** section, select the target organizations where the repositories will be restored.

{% hint style="info" %}
If the recovery destination is **Azure DevOps**, the **Map organizations** section will be replaced by **Target organization** and **Target project** settings.
{% endhint %}

<figure><img src="/files/fN1iTgeyptYYTf5anKYV" alt=""><figcaption></figcaption></figure>

2. In **Restore settings**, you can set custom names for all repositories or add a suffix to the original repository names.

{% hint style="danger" %}
Restoration will never overwrite existing repositories. If you enter a custom name—or leave the name as default—and a repository with that name already exists in your organization, **the recovery will fail**. To ensure successful recovery, either provide a unique name or select **Add suffix to repo name** to automatically append a unique identifier to the original repository name.
{% endhint %}

3. Adjust the bandwidth and other available settings, depending on the recovery destination.
4. Check which worker is set as the default for recovery and change it if necessary.

<figure><img src="/files/0eO1FqNYabdYOIbPi4bp" alt=""><figcaption></figcaption></figure>

#### Restore to a device

{% hint style="warning" %}
To restore a repository to a local device, you must have a **Git** client and the **GitProtect** worker installed on that device (you can find more information about workers in **Useful links and items** section).
{% endhint %}

{% hint style="danger" %}
You can restore **only the repository** (without metadata) when restoring data to local resources.
{% endhint %}

1. Select the destination device (a registered device).
2. Make sure the device where you want to restore data has the **Git** client added to the PATH environment variable. The PATH variable is usually configured automatically after **Git** installation (a system restart may be required) — if it isn’t, you will have to configure it manually.

{% hint style="info" %}
To configure the PATH variable in **Windows**, open the environment variables, select the PATH variable, and click the **Edit** button. Copy the path to the git.exe file and add it to the PATH variable.
{% endhint %}

3. Specify the restoration directory and configure other options (for example, whether to overwrite existing data or reduce bandwidth). If needed, you can create a new restoration folder on the selected drive from the **Management Service** level.

<figure><img src="/files/QsHefV01yTd9yGLi3LYx" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After defining all parameters, click the **Restore** button to begin the recovery process. When the process is complete, a new project/repository/folder will be created in your organization/on your device. You can monitor the restoration process in the **Tasks** tab.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/AWu8w4uJUkVdjFTGajr0" %}
[GitProtect worker](/deployment-and-configuration/gitprotect-worker)
{% endcontent-ref %}

{% content-ref url="/pages/NqYA6IzA1GmHxLsZwtrZ" %}
[Cross-recovery for DevOps organizations](/backup-and-recovery/devops/general/cross-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/IiVUjDfL7V7Z9YEIHaQs" %}
[LFS recovery for DevOps organizations](/backup-and-recovery/devops/general/lfs-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/KUrX1uY5hrsK7Rn9NVmn" %}
[Wiki recovery for DevOps organizations](/backup-and-recovery/devops/general/wiki-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/ajngMEBoS6fhnIrEkYfE" %}
[Throttling prevention](/compliance-and-risk-management/throttling-prevention)
{% endcontent-ref %}


# Bitbucket

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/RD0ei1FeqZ51hocCMCPe">/pages/RD0ei1FeqZ51hocCMCPe</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/NIliMvM0XQqDy0ln4Xqh">/pages/NIliMvM0XQqDy0ln4Xqh</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/ZlCL7aiQt2SeGk310UtS">/pages/ZlCL7aiQt2SeGk310UtS</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Integration

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/ppfP9sIWv7y8pIfrnEdD">/pages/ppfP9sIWv7y8pIfrnEdD</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/qXPleUJWAYZpAkirzdhh">/pages/qXPleUJWAYZpAkirzdhh</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/zarNqSk7n7xoNnEIL0sv">/pages/zarNqSk7n7xoNnEIL0sv</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Required permissions

Permissions required to integrate Bitbucket with GitProtect to protect its resources.

**To protect a Bitbucket environment with GitProtect, the account or token used to authorize the connection must have sufficient permissions to access the workspaces, repositories, and related resources designated for backup. The specific permission scopes vary depending on the chosen authorization method.**

***

## OAuth permissions <a href="#account" id="account"></a>

When integrating **Bitbucket** using the OAuth authentication method, **GitProtect** requires the following permissions to securely access and protect your repository data:

* [x] Account
  * [x] Read and modify account information.

* [x] Issues
  * [x] Read and modify repositories' issues.

* [x] Pipelines
  * [x] Access repositories' build pipelines and configure their variables.

* [x] Project settings&#x20;
  * [x] Read and modify workspace's project settings.
  * [x] Read and transfer repositories within workspace's projects.

* [x] Repositories & pull requests&#x20;
  * [x] Administer repositories.
  * [x] Delete repositories.
  * [x] Read and modify repositories and their pull requests.

* [x] Manage runners
  * [x] Access and edit workspaces and repositories' runners.

* [x] Snippets
  * [x] Read and modify code snippets.

* [x] Team membership
  * [x] Read and modify team membership details.

* [x] Workspaces
  * [x] Access your workspaces for authentication.
  * [x] Access and edit your workspaces and repositories' test.

* [x] Webhooks
  * [x] Read and modify repositories' webhooks.

* [x] Wikis
  * [x] Read and modify repositories' wikis.

***

## Bitbucket API token scopes

{% hint style="warning" %}
**GitProtect** does not support unscoped API tokens for **Bitbucket** integrations.
{% endhint %}

Every API token created for **Bitbucket** integration with **GitProtect** requires specific permission scopes to restrict data access and define the exact operations the token can execute.

To ensure successful backup and recovery tasks, API token must be provisioned with the below required permissions.

{% hint style="danger" %}
Applying minimal privileges may cause certain metadata (such as issues) to be omitted from the backup. Furthermore, while read-only permissions are sufficient for running backups, restoring data requires write access, which will necessitate generating a new token with elevated privileges during a recovery operation. **To prevent backup omissions and ensure seamless, immediate data recovery, it is strongly recommended to select all required permissions when creating an API token for Bitbucket.**
{% endhint %}

#### Backup permission scopes

* [x] read:webhook:bitbucket (hooks)
* [x] read:user:bitbucket (required to link the organization)
* [x] read:repository:bitbucket (repositories, downloads, synchronization)
* [x] read:pullrequest:bitbucket (pull requests)
* [x] read:pipeline:bitbucket (variables, schedules, known hosts)
* [x] read:issue:bitbucket (issues)
* [x] read:wiki:bitbucket (wiki)
* [x] admin:repository:bitbucket (branch restriction rules, deployment keys, branching models)

#### Restore permission scopes

* [x] read:pipeline:bitbucket (schedules)
* [x] read:pullrequest:bitbucket (pull requests)
* [x] read:webhook:bitbucket (hooks)
* [x] read:issue:bitbucket (issues)
* [x] read:workspace:bitbucket (repositories)
* [x] read:wiki:bitbucket (wiki)
* [x] write:wiki:bitbucket (wiki)
* [x] write:webhook:bitbucket (hooks)
* [x] write:ssh-key:bitbucket (deployment keys)
* [x] write:repository:bitbucket (repositories, downloads)
* [x] write:pullrequest:bitbucket (pull requests)
* [x] write:pipeline:bitbucket (schedules)
* [x] write:issue:bitbucket (issues)
* [x] admin:pipeline:bitbucket (known hosts, variables)
* [x] admin:repository:bitbucket (repositories, schedules, deployment keys, advanced details, branching models, branch restrictions)
* [x] admin:project:bitbucket (project — in some cases, creation is required to restore the repository)
* [x] read:repository:bitbucket (required for synchronization, repositories)
* [x] read:user:bitbucket (required to link the organization, repositories)

***

## Useful links and items

{% embed url="<https://support.atlassian.com/bitbucket-cloud/docs/api-tokens>" %}


# API limits

Rate limits are enforced for security and stability— excessive requests may block access or disrupt the application’s operation. For detailed information, refer to the [official **Bitbucket** documentation](https://support.atlassian.com/bitbucket-cloud/docs/api-request-limits/).


# Adding Bitbucket organization to GitProtect

This article provides instructions for adding a Bitbucket organization to GitProtect.

## Using OAuth

{% stepper %}
{% step %}
Log in to **GitProtect Management Service**, open the **DevOps** tab on the left side of the window, and select **Bitbucket** from the list.

<figure><img src="/files/zI0M2Yqy2O5Kqt6rQfdx" alt="" width="227"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click the **Connect** button under **Bitbucket**.

<figure><img src="/files/vlwv6XygRLUp6OYSfCIH" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
A pop-up with **Bitbucket** login page will appear. Log in using your admin credentials and grant **GitProtect** access to the specified resources (when prompted).
{% endstep %}

{% step %}
Your **Bitbucket** organization has now been successfully added to **GitProtect**. Click **Custom policy** to adjust your backup policy settings, or click **Run backup** to execute the backup immediately using the current policy configuration.

<figure><img src="/files/IFpysbkr2NYhOcEivwGT" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## Using OAuth (Advanced Mode)

{% stepper %}
{% step %}
Log in to **GitProtect Management Service**, open the **DevOps** tab on the left side of the window, and select **Bitbucket** from the list.

<figure><img src="/files/zI0M2Yqy2O5Kqt6rQfdx" alt="" width="227"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click the **advanced mode** link under **Bitbucket** and **Bitbucket DC** tiles.

<figure><img src="/files/hIf07A9ZrYnw5tMwvsK6" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Set your authentication method.

1. In **Authentication**, select **Bitbucket**.
2. For **Connect using**, choose **OAuth App**.
3. In the **Settings** section, choose whether to enable **read-only mode** and whether **GitProtect** should automatically add new repositories to your backup.

{% hint style="warning" %}
If the **Read-Only Access** switch is enabled, the recovery options will be disabled.
{% endhint %}

<figure><img src="/files/z5uijUPmFCXkZQXgpnat" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure your repository sync and default worker. Specify hours for synchronization, or set a time interval for automatic updates.

<figure><img src="/files/0OoTxAoM9uOoQsjtY3vI" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Proceed** to complete adding your **Bitbucket** organization and grant **GitProtect** access to the specified resources (when prompted).

<figure><img src="/files/GCV0vcxVnCfhx2eRe9X7" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## Using an API token

{% stepper %}
{% step %}
Log in to **GitProtect Management Service**, open the **DevOps** tab on the left side of the window, and select **Bitbucket** from the list.

<figure><img src="/files/zI0M2Yqy2O5Kqt6rQfdx" alt="" width="227"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click the **advanced mode** link under **Bitbucket** and **Bitbucket DC** tiles.

<figure><img src="/files/hIf07A9ZrYnw5tMwvsK6" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Set your authentication method.

1. In **Authentication**, select **Bitbucket**.
2. For **Connect using**, choose **Username and App password**.
3. Enter your **Bitbucket** email address.
4. Add or select **App Password** that contains your API token from the **Password Manager**.
5. Choose whether **GitProtect** should automatically add new repositories to your backup.

<figure><img src="/files/CcXtJlpwBgCXuMCc9oE5" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure your repository sync and default worker. Specify hours for synchronization, or set a time interval for automatic updates.

<figure><img src="/files/XIuxrN7gEzCgmviJycxw" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Proceed** to complete adding your **Bitbucket** organization and grant **GitProtect** access to the specified resources.
{% endstep %}
{% endstepper %}

***

## Additional browser permissions

When adding an organization, you may be prompted to grant additional permissions to the **GitProtect** application—make sure your browser allows **GitProtect** to open pop-up windows.

<figure><img src="/files/ijoEjZ0DVf07VgKDRfuq" alt=""><figcaption></figcaption></figure>

Depending on your browser, you can either adjust the settings to allow pop-ups or permit the authorization window to open once.

<figure><img src="/files/B6FLPvwKpGiF4hnKl3nm" alt="Mozilla pop-up allowance"><figcaption></figcaption></figure>

***

## Useful links and items

{% embed url="<https://support.atlassian.com/bitbucket-cloud/docs/create-an-api-token>" %}


# Backup

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/5kC8WofdA6siusAK3I97">/pages/5kC8WofdA6siusAK3I97</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/7ZeUj603NxzjmB0S7ZOt">/pages/7ZeUj603NxzjmB0S7ZOt</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Protected resources

Overview of protected Bitbucket resources, including repositories, wikis, and metadata secured by backup.

**Bitbucket protected resources define which parts of your environment GitProtect can access, secure, and restore.**

***

## Backup coverage <a href="#bitbucket" id="bitbucket"></a>

The following list includes all **Bitbucket** resources covered by backup.

{% hint style="info" %}
The list is presented in alphabetical order.
{% endhint %}

<details>

<summary>ACCESS KEYS</summary>

* [x] Label
* [x] Key

</details>

<details>

<summary>BRANCHING MODEL</summary>

* [x] Bugfix branch prefix
* [x] Development branch
* [x] Enable inherited settings
* [x] Feature branch prefix
* [x] Hotfix branch prefix
* [x] Production branch
* [x] Release branch prefix

</details>

<details>

<summary>BRANCH RESTRICTIONS</summary>

* [x] Branch name
* [x] Branch pattern
* [x] Branch type
* [x] Merge access via pull request
  * [x] Chosen people or groups for merge access
  * [x] Everyone with access to the repository has merge access
* [x] Merge settings
  * [x] Allow automatic merge when builds pass
  * [x] Keep approvals if there is no change to the diff in the pull request
  * [x] Maximum number of commits behind destination branch
  * [x] Minimum number of approvals
  * [x] Minimum number of approvals from default reviewers
  * [x] Minimum number of successful builds for the last commit with no failed builds and no in progress builds
  * [x] No changes are requested
  * [x] No unresolved pull request tasks
  * [x] Prevent a merge with unresolved merge checks
  * [x] Reset approvals when the source branch is modified
  * [x] Reset requested changes when source branch is modified
* [x] Write access
  * [x] Allow deleting this branch
  * [x] Allow rewriting branch history
  * [x] Chosen people or groups for write access
  * [x] Everyone with access to the repository has write access

</details>

<details>

<summary>DOWNLOADS</summary>

* [x] File content
* [x] File name

</details>

<details>

<summary>ISSUES</summary>

* [x] Assignee
* [x] Attachments
* [x] Closed
* [x] Comments
* [x] Description
* [x] Kind
* [x] Open
* [x] Priority
* [x] Status
* [x] Title

</details>

<details>

<summary>PIPELINES</summary>

* [x] Enable pipelines
* [x] Known hosts
* [x] Pipeline configuration file
* [x] Repository variables
* [x] Schedules
  * [x] Schedule
  * [x] Selected branch
  * [x] Selected pipeline

</details>

<details>

<summary>PULL REQUESTS</summary>

* [x] Comments
* [x] Commits
* [x] Creation date
* [x] Creator
* [x] Description
* [x] Open pull requests
* [x] Reviewers
* [x] Title

</details>

<details>

<summary>REPOSITORY</summary>

* [x] Branches
* [x] Commit creator
* [x] Commit text
* [x] Commits
* [x] Details
  * [x] Description
  * [x] Forking
  * [x] Language
  * [x] Name
  * [x] Project
  * [x] Website
* [x] LFS
* [x] Logs
* [x] Objects
* [x] Refs
* [x] Tags
* [x] Wiki

</details>

<details>

<summary>WEBHOOKS</summary>

* [x] Issue trigger – comment created
* [x] Issue trigger – created
* [x] Issue trigger – updated
* [x] Pull request trigger – approval removed
* [x] Pull request trigger – approved
* [x] Pull request trigger – changes request created
* [x] Pull request trigger – changes request removed
* [x] Pull request trigger – comment created
* [x] Pull request trigger – comment deleted
* [x] Pull request trigger – comment reopened
* [x] Pull request trigger – comment resolved
* [x] Pull request trigger – comment updated
* [x] Pull request trigger – created
* [x] Pull request trigger – declined
* [x] Pull request trigger – merged
* [x] Pull request trigger – updated
* [x] Repository trigger – build status created
* [x] Repository trigger – build status updated
* [x] Repository trigger – commit comment created
* [x] Repository trigger – fork
* [x] Repository trigger – push
* [x] Repository trigger – updated
* [x] Status
* [x] Title
* [x] URL

</details>


# Creating a backup plan

This article provides instructions on how to set up a Bitbucket backup plan.

## Backup plan setup <a href="#backup_plan_creation" id="backup_plan_creation"></a>

{% stepper %}
{% step %}
Login to **GitProtect Management Service**, open the **Plans** > **Backup** tab and click the <img src="/files/qBMQVDXoC7Lxera5vtkq" alt="" data-size="original"> **Add plan** button in the top bar.
{% endstep %}

{% step %}
Select **Bitbucket** from the list.

<figure><img src="/files/zi4hsVOLfVP7mxVerJNP" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select (or add) the **Bitbucket** environment you want to include in the backup process, and choose the repositories to back up.

{% hint style="success" %}
Optionally, **GitProtect** allows you to protect the entire **Bitbucket** environment.
{% endhint %}
{% endstep %}

{% step %}
Specify a name for the backup plan.
{% endstep %}

{% step %}
Select the appropriate metadata that you want to back up. Here, you can also change the **default worker**, which is the device directly responsible for the backup process of your repositories.

{% hint style="success" %}
You can have multiple workers and assign different workers to each backup plan.
{% endhint %}

{% hint style="info" %}
It is worth noting that the **cloud worker** (a cloud-installed **GitProtect** worker) allows you to perform cloud-to-cloud backups if you want to store your backups in the cloud.
{% endhint %}
{% endstep %}

{% step %}
Select one of the locations assigned to your **GitProtect** instance as storage.

<figure><img src="/files/jak9or18kyGWfHGISGiu" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Customize the scheduler and specify how long your data should be retained. If needed, adjust the advanced settings to suit your needs.

<figure><img src="/files/jKcTXFJhl5ZoIlkAJhxv" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
If necessary, adjust the advanced settings such as encryption, error handling, or bandwidth limits to fit your requirements.

<figure><img src="/files/g5fQzgljLBuFiU3WAxMK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Double-check your data and click **Save** to create the backup plan.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/D9j2y4b4l51BnBsEIyA5" %}
[Cloud storage](/storage/cloud-storage)
{% endcontent-ref %}

{% content-ref url="/pages/9AZUD1hXe2mvU7ncAHPz" %}
[Scheduler & retention](/management/scheduler-and-retention)
{% endcontent-ref %}


# Recovery

Overview of Bitbucket data recovery in GitProtect, including restoration of repositories, wikis, and related metadata.

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/NqYA6IzA1GmHxLsZwtrZ">/pages/NqYA6IzA1GmHxLsZwtrZ</a></td><td>How <strong>GitProtect</strong> restores repositories and metadata across <strong>Git</strong> providers for rapid disaster recovery and <strong>DevOps</strong> migrations.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/plAqNOFu3IfBW1MS3jP4">/pages/plAqNOFu3IfBW1MS3jP4</a></td><td>How to restore a single <strong>Bitbucket</strong> repository backup copy to a <strong>Git</strong> service or to localhost.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/tnBI2hYndVnbMJpdY3s9">/pages/tnBI2hYndVnbMJpdY3s9</a></td><td>Restore multiple <strong>Bitbucket</strong> repository backup copies at once to a local device or to any <strong>Git</strong> service integrated with <strong>GitProtect</strong>.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/KUrX1uY5hrsK7Rn9NVmn">/pages/KUrX1uY5hrsK7Rn9NVmn</a></td><td>How to restore a <strong>DevOps</strong> organization wiki and its metadata separately.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Single repository recovery

How to restore a single Bitbucket repository backup copy to a Git service or to localhost.

**Single repository recovery for Bitbucket enables restoration of an individual repository together with its complete Git history, branches, tags, and associated metadata, without impacting other projects or repositories within the workspace.**

***

## Recovery process

The below steps demonstrate how to quickly restore a single **Bitbucket** repository using **GitProtect Management Service**.

{% stepper %}
{% step %}
Get into the restore view using the following method:

1. Open the **Bitbucket** tab (**DevOps** > **Bitbucket**), then click the **Explore** button next to the organization whose backup you want to restore (explore <img src="/files/H9cvqYuZg8gsyMXFKU9l" alt="" data-size="original"> icon in list view).
2. Search for the repository you want to restore, then click the restore ![](/files/IyFlgWJXXcdC6zuDZNs2) icon in the action menu of that repository.

<figure><img src="/files/TE7mUmRyHVMFUipcLS5A" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the backup plan from which you want to restore data. Click the drop-down under **Backup plans** section and choose one of the plans from the list.

<figure><img src="/files/dVjStFLt3bdxlvn2ZUbb" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Choose the backup version from all the backups that have already been performed — select the desired date and click the **Restore** button.

<figure><img src="/files/o3Rf8r1woZlco4dhZ56G" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the data available to restore and click **Restore selected** or **Restore all** to proceed.

<figure><img src="/files/m0YNiTnLdx8IaSBAjKG7" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the destination for the recovery and click **Next**.

{% hint style="info" %}
You can choose any device or organization registered in **GitProtect** (you can find more information about cross-recovery in **Useful links and items section**).
{% endhint %}

<figure><img src="/files/EjZheVhyo8Q2iW1ocjBK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Data to restore** section at the top, you can select which of the previously chosen available data you want to restore.

{% hint style="success" %}
**GitProtect** allows you to select specific metadata to restore — **each element can be included or excluded by toggling the switch next to it**.
{% endhint %}

{% hint style="warning" %}
If an item cannot be restored to the selected **Git** platform, it will be marked with an orange dot.
{% endhint %}

<figure><img src="/files/3Q5ywPxV291lmz4hAHW8" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Restore to** section, you can change the previously selected recovery destination if needed.

<figure><img src="/files/CSjQXjMfKSmFHkmQqtrQ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Throttling prevention** section, you can add additional **DevOps** organization accounts to avoid throttling.

{% hint style="warning" %}
To use additional organization accounts, you must first add them in the organization settings (organization view > **Edit**).
{% endhint %}

<figure><img src="/files/KjexeJZJGNyyfrXQoAiN" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure the recovery destination settings, depending on where the backup will be restored.

#### Restore to a Git organization

1. In **Map organizations** section, select the target organization to which the repository will be restored.

{% hint style="info" %}
If the recovery destination is **Azure DevOps**, the **Map organizations** section will be replaced by **Target organization** and **Target project** settings.
{% endhint %}

<figure><img src="/files/9NTWrUof6h1dzis3r5ly" alt=""><figcaption></figcaption></figure>

2. In **Restore settings**, you can set a unique, custom name for the repository (or use the custom name automatically generated by **GitProtect**).

{% hint style="success" %}
Restoring never overwrites existing repositories in the organization — if you do not set a new name for the restored repository, it keeps its original name with an automatically generated suffix.
{% endhint %}

{% hint style="danger" %}
When you set a custom name for the repository, and a repository with that name already exists in the specified organization, **the recovery will fail**.
{% endhint %}

3. If you are restoring your repository to a different **Git** organization than the original (for example, **GitHub**), in addition to setting a custom name, you can choose whether to add a label to the restored elements and whether to enable pipelines (where applicable).
4. Check which agent is set as the default for recovery and change it if necessary.
5. If needed, you can also adjust the bandwidth.

<figure><img src="/files/MFybnExwQdmsvTjTyO0z" alt=""><figcaption></figcaption></figure>

#### Restore to a device

{% hint style="warning" %}
To restore a repository to a local device, you must have a **Git** client and the **GitProtect** worker installed on that device (you can find more information about workers in **Useful links and items** section).
{% endhint %}

{% hint style="danger" %}
You can restore **only the repository** (without metadata) when restoring data to local resources.
{% endhint %}

1. Select the destination device (a registered device).
2. Make sure the device where you want to restore data has the **Git** client added to the PATH environment variable. The PATH variable is usually configured automatically after **Git** installation (a system restart may be required) — if it isn’t, you will have to configure it manually.

{% hint style="info" %}
To configure the PATH variable in **Windows**, open the environment variables, select the PATH variable, and click the **Edit** button. Copy the path to the git.exe file and add it to the PATH variable.
{% endhint %}

3. Specify the restoration directory and configure other options (for example, whether to overwrite existing data or reduce bandwidth). If needed, you can create a new restoration folder on the selected drive from the **Management Service** level.

<figure><img src="/files/kZKSw2gbVFUyp9nPskgE" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After defining all parameters, click the **Restore** button to begin the recovery process. When the process is complete, a new repository/folder will be created in your organization/on your device. You can monitor the restoration process in the **Tasks** tab.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/AWu8w4uJUkVdjFTGajr0" %}
[GitProtect worker](/deployment-and-configuration/gitprotect-worker)
{% endcontent-ref %}

{% content-ref url="/pages/NqYA6IzA1GmHxLsZwtrZ" %}
[Cross-recovery for DevOps organizations](/backup-and-recovery/devops/general/cross-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/IiVUjDfL7V7Z9YEIHaQs" %}
[LFS recovery for DevOps organizations](/backup-and-recovery/devops/general/lfs-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/KUrX1uY5hrsK7Rn9NVmn" %}
[Wiki recovery for DevOps organizations](/backup-and-recovery/devops/general/wiki-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/ajngMEBoS6fhnIrEkYfE" %}
[Throttling prevention](/compliance-and-risk-management/throttling-prevention)
{% endcontent-ref %}


# Recovering multiple repositories

Restore multiple Bitbucket repository backup copies at once to a local device or to any Git service integrated with GitProtect.

**GitProtect enables multiple Bitbucket repositories recovery, allowing administrators to restore several repositories simultaneously within a selected organization or project scope. The process preserves Git history, branches, tags, and supported metadata, ensuring data integrity and consistency across the restored resources.**

***

## Recovery process

The below steps demonstrate how to restore multiple **Bitbucket** repositories at once using **GitProtect Management Service**.

{% stepper %}
{% step %}
Get into the restore view using the following method:

1. Open the **Bitbucket** tab (**DevOps** > **Bitbucket**), then click the **Explore** button next to the organization whose backup you want to restore (explore ![](/files/H9cvqYuZg8gsyMXFKU9l) icon in list view).
2. Select all repositories you want to restore and click **Restore** in the top menu.

<figure><img src="/files/EgT2E0ptHI0f4ksGabkS" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click every chosen repository to select the backup plan and copy from which you want to restore data, then click **Next**.

{% hint style="info" %}
By default, the latest backup is always selected, regardless of the plan.
{% endhint %}
{% endstep %}

{% step %}
Select the destination for the recovery and click **Next**.

{% hint style="info" %}
You can choose any device or organization registered in **GitProtect** (you can find more information about cross-recovery in **Useful links and items section**).
{% endhint %}

<figure><img src="/files/6rbYtopVtnmIeZfTj0FJ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In **Data to restore** section at the top, click **Edit** and select data you want to restore.

{% hint style="success" %}
By default, all items are selected for restoration. However, **GitProtect** allows you to choose which metadata to restore. You can include or exclude each element by toggling the switch next to it.
{% endhint %}

{% hint style="warning" %}
If an item cannot be restored to the selected **Git** platform, it will be marked with an orange dot.
{% endhint %}

<figure><img src="/files/YCaBETS3MO8Ssx0AIFCl" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Throttling prevention** section, you can add additional **DevOps** organization accounts to avoid throttling.

{% hint style="warning" %}
To use additional organization accounts, you must first add them in the organization settings (organization view > **Edit**).
{% endhint %}

<figure><img src="/files/TroBQ3XkIEgrHSRAxsWm" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure the recovery destination settings, depending on where the backup will be restored.

#### Restore to a Git organization

1. In **Map organizations** section, select the target organizations where the repositories will be restored.

{% hint style="info" %}
If the recovery destination is **Azure DevOps**, the **Map organizations** section will be replaced by **Target organization** and **Target project** settings.
{% endhint %}

<figure><img src="/files/xHILaftXi07jfEwJH0MV" alt=""><figcaption></figcaption></figure>

2. In **Restore settings**, you can set custom names for all repositories or add a suffix to the original repository names.

{% hint style="danger" %}
Restoration will never overwrite existing repositories. If you enter a custom name—or leave the name as default—and a repository with that name already exists in your organization, **the recovery will fail**. To ensure successful recovery, either provide a unique name or select **Add suffix to repo name** to automatically append a unique identifier to the original repository name.
{% endhint %}

3. Adjust the bandwidth and other available settings, depending on the recovery destination.
4. Check which worker is set as the default for recovery and change it if necessary.

<figure><img src="/files/dSZKbgofLrRCVjq7Od2N" alt=""><figcaption></figcaption></figure>

#### Restore to a device

{% hint style="warning" %}
To restore a repository to a local device, you must have a **Git** client and the **GitProtect** worker installed on that device (you can find more information about workers in **Useful links and items** section).
{% endhint %}

{% hint style="danger" %}
You can restore **only the repository** (without metadata) when restoring data to local resources.
{% endhint %}

1. Select the destination device (a registered device).
2. Make sure the device where you want to restore data has the **Git** client added to the PATH environment variable. The PATH variable is usually configured automatically after **Git** installation (a system restart may be required) — if it isn’t, you will have to configure it manually.

{% hint style="info" %}
To configure the PATH variable in **Windows**, open the environment variables, select the PATH variable, and click the **Edit** button. Copy the path to the git.exe file and add it to the PATH variable.
{% endhint %}

3. Specify the restoration directory and configure other options (for example, whether to overwrite existing data or reduce bandwidth). If needed, you can create a new restoration folder on the selected drive from the **Management Service** level.

<figure><img src="/files/XdHbQqo4gpluVw6bSa3v" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After defining all parameters, click the **Restore** button to begin the recovery process. When the process is complete, a new project/repository/folder will be created in your organization/on your device. You can monitor the restoration process in the **Tasks** tab.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/AWu8w4uJUkVdjFTGajr0" %}
[GitProtect worker](/deployment-and-configuration/gitprotect-worker)
{% endcontent-ref %}

{% content-ref url="/pages/NqYA6IzA1GmHxLsZwtrZ" %}
[Cross-recovery for DevOps organizations](/backup-and-recovery/devops/general/cross-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/IiVUjDfL7V7Z9YEIHaQs" %}
[LFS recovery for DevOps organizations](/backup-and-recovery/devops/general/lfs-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/KUrX1uY5hrsK7Rn9NVmn" %}
[Wiki recovery for DevOps organizations](/backup-and-recovery/devops/general/wiki-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/ajngMEBoS6fhnIrEkYfE" %}
[Throttling prevention](/compliance-and-risk-management/throttling-prevention)
{% endcontent-ref %}


# Bitbucket Data Center

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/VhB7EGzw31HmRy9r9iEv">/pages/VhB7EGzw31HmRy9r9iEv</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/rt7UPq2Y7PLXAfWoEfVO">/pages/rt7UPq2Y7PLXAfWoEfVO</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/mjgmUEkOUm3b5UrX9Tor">/pages/mjgmUEkOUm3b5UrX9Tor</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Integration

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/YamcHFYDQoIwS6xRApwF">/pages/YamcHFYDQoIwS6xRApwF</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/ZaCYzd9XYvCLNU43oYd3">/pages/ZaCYzd9XYvCLNU43oYd3</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/1QQlQVyEGIjXsTSnMhyY">/pages/1QQlQVyEGIjXsTSnMhyY</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Required permissions

Permissions required to integrate Bitbucket Data Center with GitProtect to protect its resources.

**To protect a Bitbucket Data Center (DC) environment with GitProtect, the account used to authorize the connection must have sufficient permissions to access the workspaces, repositories, and related resources designated for backup.**

***

## Supported platform versions

**GitProtect** supports **Bitbucket Data Center** (**DC**) version 3.0.4 and higher, enabling comprehensive repository and metadata protection regardless of the underlying host operating system.

***

## Account permissions

{% hint style="info" %}
For **Bitbucket DC** integrations, an HTTP access token can be used in place of a password. Since these tokens inherit your user account's existing privileges, ensure you restrict the token's permissions to the access levels required for **GitProtect** operations before connecting.
{% endhint %}

In **Bitbucket Data Center**, account permissions can be managed in three distinct ways, all of which are fully supported for use with **GitProtect**:

1. **Global permissions** — the user account connecting **Bitbucket DC** with **GitProtect** must have at least administrator privileges. Using global permissions grants the application access to protect all repositories across the entire **Bitbucket DC** instance.
2. **Project permissions** — alternatively, you can assign write permissions at the project level to the connecting user account. This method restricts **GitProtect** synchronization and backup scope strictly to the repositories within those specific projects.
3. **Repository permissions** — permissions can also be configured individually for each specific repository, offering granular control via two operational tiers:
   1. Read (sufficient to perform data backups, but cannot be used to execute repository restorations).
   2. Write (full authorization to perform both backup and restoration operations).

***

## Useful links and items

{% embed url="<https://confluence.atlassian.com/bitbucketserver/users-and-groups-776640439.html>" %}


# Adding a Bitbucket DC instance to GitProtect

This article explains how to add a Bitbucket DC organization to GitProtect.

## Using username and password

{% stepper %}
{% step %}
Log in to **GitProtect Management Service**, open the **DevOps** tab on the left side of the window, and select **Bitbucket** from the list.

<figure><img src="/files/zI0M2Yqy2O5Kqt6rQfdx" alt="" width="227"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click the **Connect** button under **Bitbucket Data Center**.

<figure><img src="/files/nx1OJXLGDNxdyO22yOVK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Set your authentication method.

1. In **Authentication**, select **Bitbucket DC**.
2. Enter the **Bitbucket DC** server IP address and your **username**.
3. Add or select **password** from the **Password Manager** (same as your **Bitbucket DC** credentials).

{% hint style="success" %}
For **Bitbucket DC**, you can also use an HTTP access token instead of a password.
{% endhint %}

4. Choose whether **GitProtect** should automatically add new repositories to your backup.

<figure><img src="/files/xLUjBRyeCcs0wTZkPitK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure your repository sync and default worker. Specify hours for synchronization, or set a time interval for automatic updates.

<figure><img src="/files/XIuxrN7gEzCgmviJycxw" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Proceed** to complete adding your **Bitbucket DC** organization and grant **GitProtect** access to the specified resources.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% embed url="<https://confluence.atlassian.com/bitbucketserver/users-and-groups-776640439.html>" %}

{% embed url="<https://confluence.atlassian.com/bitbucketserver/http-access-tokens-939515499.html>" %}


# Backup

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/YqtlPQPRPAMDYKg7x9st">/pages/YqtlPQPRPAMDYKg7x9st</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/lU5BDYEMKdnTAWtJdI12">/pages/lU5BDYEMKdnTAWtJdI12</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Protected resources

Overview of protected Bitbucket Data Center resources, including repositories, wikis, and metadata secured by backup.

**Bitbucket Data Center protected resources define which parts of your environment GitProtect can access, secure, and restore.**

***

## Backup coverage <a href="#bitbucket" id="bitbucket"></a>

The following list includes all **Bitbucket Data Center** resources covered by backup.

{% hint style="info" %}
The list is presented in alphabetical order.
{% endhint %}

* [x] Branches
* [x] Commits
* [x] LFS
* [x] Pull requests
* [x] Repository
* [x] Tags
* [x] Webhooks


# Creating a backup plan

## Backup plan setup <a href="#backup_plan_creation" id="backup_plan_creation"></a>

{% stepper %}
{% step %}
Login to **GitProtect Management Service**, open the **Plans** > **Backup** tab and click the <img src="/files/qBMQVDXoC7Lxera5vtkq" alt="" data-size="original"> **Add plan** button in the top bar.
{% endstep %}

{% step %}
Select **Bitbucket** from the list.

<figure><img src="/files/zi4hsVOLfVP7mxVerJNP" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select (or add) the **Bitbucket DC** environment you want to include in the backup process, and choose the repositories to back up.

{% hint style="success" %}
Optionally, **GitProtect** allows you to protect the entire **Bitbucket DC** environment.
{% endhint %}
{% endstep %}

{% step %}
Specify a name for the backup plan.
{% endstep %}

{% step %}
Select the appropriate metadata that you want to back up. Here, you can also change the **default worker**, which is the device directly responsible for the backup process of your repositories.

{% hint style="success" %}
You can have multiple workers and assign different workers to each backup plan.
{% endhint %}

{% hint style="info" %}
It is worth noting that the **cloud worker** (a cloud-installed **GitProtect** **worker**) allows you to perform cloud-to-cloud backups if you want to store your backups in the cloud.
{% endhint %}
{% endstep %}

{% step %}
Select one of the locations assigned to your **GitProtect** instance as storage.

<figure><img src="/files/jak9or18kyGWfHGISGiu" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Customize the scheduler and specify how long your data should be retained. If needed, adjust the advanced settings to suit your needs.

<figure><img src="/files/jKcTXFJhl5ZoIlkAJhxv" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
If necessary, adjust the advanced settings such as encryption, error handling, or bandwidth limits to fit your requirements.

<figure><img src="/files/g5fQzgljLBuFiU3WAxMK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Double-check your data and click **Save** to create the backup plan.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/D9j2y4b4l51BnBsEIyA5" %}
[Cloud storage](/storage/cloud-storage)
{% endcontent-ref %}

{% content-ref url="/pages/9AZUD1hXe2mvU7ncAHPz" %}
[Scheduler & retention](/management/scheduler-and-retention)
{% endcontent-ref %}


# Recovery

Overview of Bitbucket Data Center data recovery in GitProtect, including restoration of repositories and related metadata.

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/NqYA6IzA1GmHxLsZwtrZ">/pages/NqYA6IzA1GmHxLsZwtrZ</a></td><td>How <strong>GitProtect</strong> restores repositories and metadata across <strong>Git</strong> providers for rapid disaster recovery and <strong>DevOps</strong> migrations.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/JrzVQpybnwaxfFovbIVD">/pages/JrzVQpybnwaxfFovbIVD</a></td><td>Restore a single <strong>Bitbucket DC</strong> repository backup copy to a <strong>Git</strong> service or to localhost.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/eKCag6fDMLrD1fogj9gE">/pages/eKCag6fDMLrD1fogj9gE</a></td><td>Restore multiple <strong>Bitbucket DC</strong> repository backup copies at once to any local device or <strong>Git</strong> service assigned to the <strong>GitProtect</strong> platform.</td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Single repository recovery

Restore a single Bitbucket DC repository backup copy to a Git service or to localhost.

**GitProtect enables single repository recovery for Bitbucket DC, allowing restoration of an individual repository together with its complete Git history, branches, tags, and supported metadata. The recovery process maintains repository integrity while ensuring that other projects and repositories within the Bitbucket DC instance remain unaffected.**

***

## Recovery process

The following steps demonstrate how to quickly restore a single **Bitbucket DC** repository using **GitProtect Management Service**.

{% stepper %}
{% step %}
Get into the restore view using the following method:

1. Open the **Bitbucket** tab (**DevOps** > **Bitbucket**), then click the **Explore** button next to the organization whose backup you want to restore (explore <img src="/files/H9cvqYuZg8gsyMXFKU9l" alt="" data-size="original"> icon in list view).
2. Search for the repository you want to restore, then click the restore ![](/files/IyFlgWJXXcdC6zuDZNs2) icon in the action menu of that repository.

<figure><img src="/files/lyOBiqMcVstExZqC2RfM" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the backup plan from which you want to restore data. Click the drop-down under **Backup plans** section and choose one of the plans from the list.

<figure><img src="/files/9fCspLmylKOlCfm9Oy6y" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Choose the backup version from all the backups that have already been performed — select the desired date and click the **Restore** button.

<figure><img src="/files/8U8gp7PJxZgSZNdg7gK9" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the data available to restore and click **Restore selected** or **Restore all** to proceed.

<figure><img src="/files/IinyihYGo4V7RyXpj4VU" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select the destination for the recovery and click **Next**.

{% hint style="info" %}
You can choose any device or organization registered in **GitProtect** (you can find more information about cross-recovery in **Useful links and items section**).
{% endhint %}

<figure><img src="/files/FtmArfdwiT5i6TzZqUNi" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Data to restore** section at the top, you can select which of the previously chosen available data you want to restore.

{% hint style="success" %}
**GitProtect** allows you to select specific metadata to restore — **each element can be included or excluded by toggling the switch next to it**.
{% endhint %}

{% hint style="warning" %}
If an item cannot be restored to the selected **Git** platform, it will be marked with an orange dot.
{% endhint %}

<figure><img src="/files/DWUPJgzp0uji8vBP2dX1" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Restore to** section, you can change the previously selected recovery destination if needed.

<figure><img src="/files/LqETRwjRiqAPhm0lzWzZ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Throttling prevention** section, you can add additional **DevOps** organization accounts to avoid throttling.

{% hint style="warning" %}
To use additional organization accounts, you must first add them in the organization settings (organization view > **Edit**).
{% endhint %}

<figure><img src="/files/vwA3vkTT5p5xjnLCPzJf" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure the recovery destination settings, depending on where the backup will be restored.

#### Restore to a Git organization

1. In **Map organizations** section, select the target organization to which the repository will be restored.

{% hint style="info" %}
If the recovery destination is **Azure DevOps**, the **Map organizations** section will be replaced by **Target organization** and **Target project** settings.
{% endhint %}

<figure><img src="/files/DKDKnd0tcZXR0SEmVX7W" alt=""><figcaption></figcaption></figure>

2. In **Restore settings**, you can set a unique, custom name for the repository (or use the custom name automatically generated by **GitProtect**).

{% hint style="success" %}
Restoring never overwrites existing repositories in the organization — if you do not set a new name for the restored repository, it keeps its original name with an automatically generated suffix.
{% endhint %}

{% hint style="danger" %}
When you set a custom name for the repository, and a repository with that name already exists in the specified organization, **the recovery will fail**.
{% endhint %}

3. If you are restoring your repository to a different **Git** organization than the original (for example, **GitHub**), in addition to setting a custom name, you can choose whether to add a label to the restored elements and whether to enable pipelines (where applicable).
4. Check which agent is set as the default for recovery and change it if necessary.
5. If needed, you can also adjust the bandwidth.

<figure><img src="/files/n5OF8IoO8K38UyZnTOip" alt=""><figcaption></figcaption></figure>

#### Restore to a device

{% hint style="warning" %}
To restore a repository to a local device, you must have a **Git** client and the **GitProtect** worker installed on that device (you can find more information about workers in **Useful links and items** section).
{% endhint %}

{% hint style="danger" %}
You can restore **only the repository** (without metadata) when restoring data to local resources.
{% endhint %}

1. Select the destination device (a registered device).
2. Make sure the device where you want to restore data has the **Git** client added to the PATH environment variable. The PATH variable is usually configured automatically after **Git** installation (a system restart may be required) — if it isn’t, you will have to configure it manually.

{% hint style="info" %}
To configure the PATH variable in **Windows**, open the environment variables, select the PATH variable, and click the **Edit** button. Copy the path to the git.exe file and add it to the PATH variable.
{% endhint %}

3. Specify the restoration directory and configure other options (for example, whether to overwrite existing data or reduce bandwidth). If needed, you can create a new restoration folder on the selected drive from the **Management Service** level.

<figure><img src="/files/zjOC8aIifk1zzqXWdEFv" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After defining all parameters, click the **Restore** button to begin the recovery process. When the process is complete, a new repository/folder will be created in your organization/on your device. You can monitor the restoration process in the **Tasks** tab.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/AWu8w4uJUkVdjFTGajr0" %}
[GitProtect worker](/deployment-and-configuration/gitprotect-worker)
{% endcontent-ref %}

{% content-ref url="/pages/NqYA6IzA1GmHxLsZwtrZ" %}
[Cross-recovery for DevOps organizations](/backup-and-recovery/devops/general/cross-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/IiVUjDfL7V7Z9YEIHaQs" %}
[LFS recovery for DevOps organizations](/backup-and-recovery/devops/general/lfs-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/KUrX1uY5hrsK7Rn9NVmn" %}
[Wiki recovery for DevOps organizations](/backup-and-recovery/devops/general/wiki-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/ajngMEBoS6fhnIrEkYfE" %}
[Throttling prevention](/compliance-and-risk-management/throttling-prevention)
{% endcontent-ref %}


# Recovering multiple repositories

Restore multiple Bitbucket DC repository backup copies at once to any local device or Git service assigned to the GitProtect platform.

**GitProtect enables multiple repositories recovery for Bitbucket DC, allowing administrators to restore several repositories simultaneously within a selected project or instance scope. The process preserves complete Git history, branches, tags, and supported metadata, ensuring consistency and data integrity across restored repositories.**

***

## Recovery process

The below steps demonstrate how to restore multiple **Bitbucket DC** repositories at once using **GitProtect Management Service**.

{% stepper %}
{% step %}
Get into the restore view using the following method:

1. Open the **Bitbucket** tab (**DevOps** > **Bitbucket**), then click the **Explore** button next to the organization whose backup you want to restore (explore ![](/files/H9cvqYuZg8gsyMXFKU9l) icon in list view).
2. Select all repositories you want to restore and click **Restore** in the top menu.

<figure><img src="/files/6cgYB71sB99OSWcsu3Ly" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click every chosen repository to select the backup plan and copy from which you want to restore data, then click **Next**.

{% hint style="info" %}
By default, the latest backup is always selected, regardless of the plan.
{% endhint %}
{% endstep %}

{% step %}
Select the destination for the recovery and click **Next**.

{% hint style="info" %}
You can choose any device or organization registered in **GitProtect** (you can find more information about cross-recovery in **Useful links and items section**).
{% endhint %}

<figure><img src="/files/IGSP9crQeudVWTjuuWH1" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In **Data to restore** section at the top, click **Edit** and select data you want to restore.

{% hint style="success" %}
By default, all items are selected for restoration. However, **GitProtect** allows you to choose which metadata to restore. You can include or exclude each element by toggling the switch next to it.
{% endhint %}

{% hint style="warning" %}
If an item cannot be restored to the selected **Git** platform, it will be marked with an orange dot.
{% endhint %}

<figure><img src="/files/jSHpjS0NkoaYjGRfGIqF" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
In the **Throttling prevention** section, you can add additional **DevOps** organization accounts to avoid throttling.

{% hint style="warning" %}
To use additional organization accounts, you must first add them in the organization settings (organization view > **Edit**).
{% endhint %}

<figure><img src="/files/tlQMuXc20ggiNkkUdEtp" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure the recovery destination settings, depending on where the backup will be restored.

#### Restore to a Git organization

1. In **Map organizations** section, select the target organizations where the repositories will be restored.

{% hint style="info" %}
If the recovery destination is **Azure DevOps**, the **Map organizations** section will be replaced by **Target organization** and **Target project** settings.
{% endhint %}

<figure><img src="/files/79Z1EkolmLsyGCiRJDBN" alt=""><figcaption></figcaption></figure>

2. In **Restore settings**, you can set custom names for all repositories or add a suffix to the original repository names.

{% hint style="danger" %}
Restoration will never overwrite existing repositories. If you enter a custom name—or leave the name as default—and a repository with that name already exists in your organization, **the recovery will fail**. To ensure successful recovery, either provide a unique name or select **Add suffix to repo name** to automatically append a unique identifier to the original repository name.
{% endhint %}

3. Adjust the bandwidth and other available settings, depending on the recovery destination.
4. Check which worker is set as the default for recovery and change it if necessary.

<figure><img src="/files/2c0xjzH6rvhlfqxmF2TD" alt=""><figcaption></figcaption></figure>

#### Restore to a device

{% hint style="warning" %}
To restore a repository to a local device, you must have a **Git** client and the **GitProtect** worker installed on that device (you can find more information about workers in **Useful links and items** section).
{% endhint %}

{% hint style="danger" %}
You can restore **only the repository** (without metadata) when restoring data to local resources.
{% endhint %}

1. Select the destination device (a registered device).
2. Make sure the device where you want to restore data has the **Git** client added to the PATH environment variable. The PATH variable is usually configured automatically after **Git** installation (a system restart may be required) — if it isn’t, you will have to configure it manually.

{% hint style="info" %}
To configure the PATH variable in **Windows**, open the environment variables, select the PATH variable, and click the **Edit** button. Copy the path to the git.exe file and add it to the PATH variable.
{% endhint %}

3. Specify the restoration directory and configure other options (for example, whether to overwrite existing data or reduce bandwidth). If needed, you can create a new restoration folder on the selected drive from the **Management Service** level.

<figure><img src="/files/2byeDhQ52ARSAtmMiukk" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
After defining all parameters, click the **Restore** button to begin the recovery process. When the process is complete, a new project/repository/folder will be created in your organization/on your device. You can monitor the restoration process in the **Tasks** tab.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/AWu8w4uJUkVdjFTGajr0" %}
[GitProtect worker](/deployment-and-configuration/gitprotect-worker)
{% endcontent-ref %}

{% content-ref url="/pages/NqYA6IzA1GmHxLsZwtrZ" %}
[Cross-recovery for DevOps organizations](/backup-and-recovery/devops/general/cross-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/IiVUjDfL7V7Z9YEIHaQs" %}
[LFS recovery for DevOps organizations](/backup-and-recovery/devops/general/lfs-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/KUrX1uY5hrsK7Rn9NVmn" %}
[Wiki recovery for DevOps organizations](/backup-and-recovery/devops/general/wiki-recovery-for-devops-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/ajngMEBoS6fhnIrEkYfE" %}
[Throttling prevention](/compliance-and-risk-management/throttling-prevention)
{% endcontent-ref %}


# GitHub

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/YZlGkuE8xUCCJA3lCFfL">/pages/YZlGkuE8xUCCJA3lCFfL</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/DB0Um6T6h3HzQed7cdiu">/pages/DB0Um6T6h3HzQed7cdiu</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/6SgHvc373wAcVNciaz3m">/pages/6SgHvc373wAcVNciaz3m</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Integration

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/qPJCEsUiBsCK55k4wVHI">/pages/qPJCEsUiBsCK55k4wVHI</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/lST8L8pz1L1HA4GgCepm">/pages/lST8L8pz1L1HA4GgCepm</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/n38SGzhJczgM5YB5vAlz">/pages/n38SGzhJczgM5YB5vAlz</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/MhAQx5yLeSM2p0nApC9V">/pages/MhAQx5yLeSM2p0nApC9V</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Required permissions

## Account

To install the **GitProtect** application, you must use an account with sufficient privileges, typically an **administrator account**. Additionally, the application requires the following permissions to function correctly:

* [x] Full control of projects
* [x] Read team discussions
* [x] Read organization and team membership, read organization projects
* [x] Read all user profile data
* [x] Full control of private repositories
* [x] Access user email addresses (read-only)
* [x] Update **GitHub Action** workflows

These permissions ensure seamless integration and proper functionality of the application within the intended environment.

💡 Below you can find examples of different types of permissions along with their explanations.

<details>

<summary>PERMISSIONS</summary>

| TYPE                                            | LEVEL    |                                                                     |
| ----------------------------------------------- | -------- | ------------------------------------------------------------------- |
| **Owner**                                       | default  | Full backup and restore.                                            |
|                                                 | admin    | Full backup and restore.                                            |
|                                                 | write    | Full backup and restore.                                            |
|                                                 | read     | Full backup. Restore only to your own account.                      |
| **Member**                                      | admin    | Full backup. Restore only to your own account.                      |
|                                                 | maintain | Full backup. Restore only to your own account.                      |
|                                                 | write    | Full backup. Restore only to your own account.                      |
|                                                 | triage   | Backup (excluding collaborators). Restore only to your own account. |
| **Collaborator** (external in the organization) | read     | Backup (excluding collaborators). Restore only to your own account. |
| **Collaborator** (outside the organization)     | default  | Backup (excluding collaborators). Restore only to your own account. |

</details>

***

## Personal Access Token (PAT)

The minimum authorization permissions required for the token to register the **GitProtect** application and perform repository backup and restore are: **repo** and **workflow**.

<figure><img src="/files/2EULsPRpdxuFcqd8GpcQ" alt=""><figcaption></figcaption></figure>

{% hint style="danger" %}
**With minimal privileges, certain metadata may not be included in the backup process.** Select the necessary permissions based on the specific data you need to protect.
{% endhint %}

You can generate a **personal access token** in the **Developer settings** > **Personal access tokens** section of your **GitHub** account. When creating a **PAT**, you can assign different types of permissions— the list below outlines the permissions required to back up specific repository metadata within your organization:

1. **admin:org** — allows you to read the organization's projects.
2. **project** — allows you to read the projects from which the repository comes.
3. **read:discussion** — allows you to read team discussions.
4. **read:public\_key** — grants access to keys.
5. **read:repo\_hook** — grants access to webhooks.
6. **repo** — grants access to repositories.

{% hint style="info" %}
Learn more about user access tokens in [the official **GitHub** documentation](https://docs.github.com/en/apps/creating-github-apps/authenticating-with-a-github-app/generating-a-user-access-token-for-a-github-app).
{% endhint %}

{% hint style="warning" %}
If you grant only **read** permissions, you will be able to perform a backup, but restoring data will require generating a new token with **write** permissions.
{% endhint %}


# API limits

Learn about GitHub API rate limits.

Rate limits are enforced for security reasons—a large number of requests could block or destabilize the application’s operation, which is why certain limitations apply. For detailed information, refer to [the official **GitHub** documentation](https://docs.github.com/en/rest?apiVersion=2022-11-28).


# GitHub App

Learn more about GitHub Apps and their features.

**GitHub can be integrated with GitProtect using several authorization methods, including a GitHub App, which provides a secure and scalable way to connect GitHub organizations for backup and recovery operations. With granular permissions, repository-level access, and short-lived authentication tokens, GitHub Apps help protect repositories and related metadata while supporting automated backup workflows, repository synchronization, and streamlined management across the GitProtect environment.**

***

## General information

A **GitHub App** is a type of integration you can build to interact with and extend **GitHub’s** functionality. **GitHub Apps** can provide flexibility and reduce friction in your processes without requiring users to sign in or create a service account.

Like OAuth apps, **GitHub Apps** use OAuth 2.0 and can act on a user’s behalf. Unlike OAuth apps, **GitHub Apps** can also act independently of a user.

***

## Advantages

The key advantages of using the **GitHub App** for integration with **GitProtect** include enhanced security, better rate limit handling, and more reliable repository management.

### <mark style="background-color:blue;">Security</mark>

**GitHub Apps** provide enhanced control and security compared to OAuth apps. Instead of broad scopes, **GitHub Apps** use fine-grained permissions, giving administrators better control over what the app can access and perform:

* **Granular permissions** — **GitHub Apps** request only the permissions they need, unlike OAuth apps, which rely on broader permission scopes.
* **Repository-specific access** — users or organization owners can choose which repositories an app can access, whereas OAuth apps can access all repositories available to the authorizing user.
* **Short-lived tokens** — **GitHub Apps** use tokens that expire quickly, reducing the risk of misuse. In contrast, OAuth app tokens remain valid until explicitly revoked.

These features make **GitHub Apps** more suitable for organizations with strict security requirements, offering stronger protection against potential security risks.

### <mark style="background-color:blue;">Rate limit</mark>

**GitHub Apps** that use installation access tokens are initially allowed **5,000 requests per hour**. This limit can increase under specific conditions:

* **GitHub Enterprise Cloud organizations** — installations associated with a **GitHub Enterprise Cloud** organization have a rate limit of 15,000 requests per hour.
* **Scaling by repositories and users** — for installations that are not part of a **GitHub Enterprise Cloud** organization:
  * Organizations with more than 20 repositories receive an additional **50 requests per hour per repository**.
  * Organizations with more than 20 users receive an additional **50 requests per hour for each user beyond 20**.
  * The total rate limit is capped at 12,500 requests per hour.

The above rules are designed to ensure fair usage while maintaining system stability and security.

{% hint style="info" %}
Learn more about rate limits in [the official GitHub documentation](https://docs.github.com/en/rest/using-the-rest-api/rate-limits-for-the-rest-api?apiVersion=2022-11-28#primary-rate-limit-for-github-app-installations).
{% endhint %}

***

## Access control and approval flow

**GitHub Apps** can be installed by users on their personal accounts and by organization owners within organizations they own. Additionally, repository admins within an organization can install **GitHub Apps**, provided the app is limited to repositories they administer and does not request permissions that affect the organization or involve repository administration.

However, organization owners have the capability to restrict these installations by outside collaborators who are repository admins. If organization members who are neither owners nor admins choose an organization during the app installation process, instead of directly installing the app, **GitHub** will notify the organization owner to request installation approval.

***

## App authorization

After installing a **GitHub App**, you may also need to authorize it. Installation lets you specify which repositories the app can access and grants it permission to use certain organizational resources.

During installation, the app displays the requested permissions for review and approval. Once authorized, the app can also operate on your behalf.

{% hint style="info" %}
You can install a **GitHub App** without authorizing it, and you can also authorize an app without installing it.
{% endhint %}

***

## Throttling prevention

Throttling limits the number of API calls or operations within a given time window to prevent resource overuse and ensure server stability. If throttling limits are exceeded, further client requests may be temporarily restricted, which can extend backup times.

**GitProtect** can use up to 10 additional apps to increase request limit and reduce throttling impact.

{% hint style="info" %}
You can find more information about throttling and throttling mitigation methods in [Useful links and items](#useful-links-and-items) section.
{% endhint %}

***

## Updating GitHub App permissions

With the upcoming release of **GitProtect** (scheduled for May 2026), we are introducing support for **GitHub** issue types.

To enable this new feature, **GitHub** requires a manual update to your **GitHub App** permissions. While your existing backup plans will continue to run without interruption, this manual approval is required to unlock the new capabilities and ensure future compatibility.

{% hint style="warning" %}
You will receive an email notification from **GitHub** for each of your installations and will need to manually review and approve the new issue types permission request within your **GitHub** account.
{% endhint %}

Below is a step-by-step walkthrough of the approval process.

{% stepper %}
{% step %}
You will get an email from **GitHub** containing information about the application and the organization or account requesting elevated access. To grant **GitProtect** the required permissions, click the **Review permission request to accept or reject this change** link.

<figure><img src="/files/aiLuhOxputSUzCixpAnF" alt=""><figcaption></figcaption></figure>

{% endstep %}

{% step %}
After clicking the link, you will be redirected to **GitHub**, where you can review the requested permissions and approve them.

<figure><img src="/files/FFUL9dEAKpkQ0s7ZWPFZ" alt=""><figcaption></figcaption></figure>

{% endstep %}

{% step %}
Once the requested permissions are accepted, your environment will be ready for full backup coverage of issue type data when the next **GitProtect** release goes live.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/ajngMEBoS6fhnIrEkYfE" %}
[Throttling prevention](/compliance-and-risk-management/throttling-prevention)
{% endcontent-ref %}

{% content-ref url="/pages/5dxUZol0miX2fdqC11pf" %}
[Avoiding API rate limits impact](/compliance-and-risk-management/avoiding-api-rate-limits-impact)
{% endcontent-ref %}

{% embed url="<https://docs.github.com/en/rest/using-the-rest-api/rate-limits-for-the-rest-api?apiVersion=2026-03-10>" %}

{% embed url="<https://docs.github.com/en/apps/creating-github-apps/about-creating-github-apps/about-creating-github-apps>" %}

{% embed url="<https://docs.github.com/en/apps/creating-github-apps/about-creating-github-apps/deciding-when-to-build-a-github-app>" %}


# Adding GitHub organization to GitProtect

This article explains how to add a GitHub organization to GitProtect.

## Using OAuth

{% stepper %}
{% step %}
Log in to **GitProtect Management Service**, open the **DevOps** tab on the left side of the window, and select **GitHub** from the list.

<figure><img src="/files/y06PMUy1hC3ddukgjRx6" alt="" width="227"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click the **Connect** button under **GitHub**.

<figure><img src="/files/lgsCwOmixzfs3ImVnu1w" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
[In the window that pops-up](#additional-browser-permissions), log in with a user account which has the required permissions for the repositories or projects to protect. If your **GitHub** login session is active in a different tab, the login will complete automatically.
{% endstep %}

{% step %}
Grant **GitProtect** access to the specified resources (when prompted).
{% endstep %}

{% step %}
Your **GitHub** organization has now been successfully added to **GitProtect**. Click **Custom policy** to adjust your backup policy settings, or click **Run backup** to execute the backup immediately using the current policy configuration.

<figure><img src="/files/7AU6IhrNPal5n7uBIZXJ" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## Using GitHub App

{% stepper %}
{% step %}
Log in to **GitProtect Management Service**, open the **DevOps** tab on the left side of the window, and select **GitHub** from the list.

<figure><img src="/files/y06PMUy1hC3ddukgjRx6" alt="" width="227"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click the **advanced mode** link under **GitHub** and **GitHub Enterprise Server** tiles.

<figure><img src="/files/E9RzhlWtaKIJ3hS8gDLs" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Set your authentication method.

1. In **Authentication**, select **GitHub**.
2. For **Connect using**, choose **GitHub App**.
3. Choose whether **GitProtect** should automatically add new repositories to your backup.
   {% endstep %}

{% step %}
Configure your repository sync and default worker. Specify hours for synchronization, or set a time interval for automatic updates.

<figure><img src="/files/XIuxrN7gEzCgmviJycxw" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Proceed** to complete adding your **GitHub** organization and grant **GitProtect** access to the specified resources. [In the window that pops-up](#additional-browser-permissions), log in with a user account which has the required permissions for the repositories or projects to protect. If your **GitHub** login session is active in a different tab, the login will complete automatically.
{% endstep %}

{% step %}
Select repositories you want to protect and click **Install & Authorize** to proceed.

<figure><img src="/files/MvYSR5MlBSxpuM8QY9zg" alt="" width="400"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Your **GitHub** organization has now been successfully added to **GitProtect**. Click **Custom policy** to adjust your backup policy settings, or click **Run backup** to execute the backup immediately using the current policy configuration.

<figure><img src="/files/JoZkUqNkHHbBhGXmmPni" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## Using Personal Access Token (PAT)

{% stepper %}
{% step %}
Log in to **GitProtect Management Service**, open the **DevOps** tab on the left side of the window, and select **GitHub** from the list.

<figure><img src="/files/y06PMUy1hC3ddukgjRx6" alt="" width="227"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click the **advanced mode** link under **GitHub** and **GitHub Enterprise Server** tiles.

<figure><img src="/files/yIFHoPewhPLufm9Ty7hQ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Set your authentication method.

1. In **Authentication**, select **GitHub**.
2. For **Connect using**, choose **Login and Personal Access Token**.
3. Enter your **username**.
4. Add or select **PAT** from the **Password Manager**.
5. Choose whether **GitProtect** should automatically add new repositories to your backup.

{% hint style="warning" %}
If the **PAT** does not exist, you need to add it. The **PAT** should be pasted into the password field.
{% endhint %}

<figure><img src="/files/qJ6dY7pv1DMN4poNyVPd" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Configure your repository sync and default worker. Specify hours for synchronization, or set a time interval for automatic updates.

<figure><img src="/files/XIuxrN7gEzCgmviJycxw" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click **Proceed** to complete adding your **GitHub** organization and grant **GitProtect** access to the specified resources.
{% endstep %}
{% endstepper %}

***

## Additional browser permissions

When adding an organization, you may be prompted to grant additional permissions to the **GitProtect** application—make sure your browser allows **GitProtect** to open pop-up windows.

<figure><img src="/files/ijoEjZ0DVf07VgKDRfuq" alt=""><figcaption></figcaption></figure>

Depending on your browser, you can either adjust the settings to allow pop-ups or permit the authorization window to open once.

<figure><img src="/files/B6FLPvwKpGiF4hnKl3nm" alt="Mozilla pop-up allowance"><figcaption></figcaption></figure>


# Backup

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/yVBx7QWURgdFe0dREWqt">/pages/yVBx7QWURgdFe0dREWqt</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/ScLrUcRuzmDkscGDjKog">/pages/ScLrUcRuzmDkscGDjKog</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr><tr><td><a href="/pages/YaZ9ZQjTlSeoGTXxQuGj">/pages/YaZ9ZQjTlSeoGTXxQuGj</a></td><td><a href="/files/4PosnkEx0nGlWRj0bnPT">/files/4PosnkEx0nGlWRj0bnPT</a></td></tr></tbody></table>


# Process overview

Learn more about the backup process for GitHub.

## General information

**GitProtect** is designed to protect **DevOps** ecosystems, including **GitHub**.

To ensure your entire **GitHub** environment is reliably backed up, make sure to include all repositories along with their related metadata — the best practice is to create a backup plan for critical repositories and metadata that change daily (or even more frequently), for example, using the recommended **Grandfather-Father-Son** (**GFS**) rotation scheme.

Additionally, create a separate backup plan for unused repositories that you need to keep for future reference. This type of backup primarily serves **GitHub** archival purposes, and with unlimited retention, you can store your copies for as long as needed — even indefinitely.

You can also delete repositories from your **GitHub** account while keeping a copy in storage, which helps bypass **GitHub** limits.

***

## Backup type

**Incremental** and **differential backups** help save storage space. In **GitProtect** you can define different retention and performance settings for each type of backup (**full**, **incremental**, and **differential**). For example, our software allows you to include only the parts of **GitHub** data that have changed since the last backup, reducing storage usage, speeding up the process, and limiting bandwidth.

***

## Adding multiple storage instances

Use different types of storage to replicate backups, minimize the risk of outages or disasters, and comply with the **3-2-1 backup rule** (which means having at least **three copies** of your data on **two different storage types**, with at least **one copy** stored in the cloud).

**GitProtect** is a multi-storage system that allows you to store your data:

* [x] In the cloud (**Xopero Cloud Storage**, **AWS S3**, **Wasabi Cloud**, **Backblaze B2**, **Google Cloud Storage**, **Azure Blob Storage**, or any **S3**-compatible public cloud).
* [x] Locally (**NFS**, **CIFS**, **SMB** network shares, or local disk resources).
* [x] In a hybrid or multi-cloud environment.


# Protected resources

Overview of protected GitHub resources, including repositories, wikis, and metadata secured by backup.

**GitHub protected resources define which repositories and data GitProtect can access, secure, and restore.**

***

## Backup coverage

The following list includes all **GitHub** resources covered by backup.

{% hint style="danger" %}
**Support for backing up projects (classic) has been removed.** It is now available only for restoring previously backed-up projects (classic). When restored, projects (classic) are automatically converted to projects v2. Protected metadata for projects (classic) includes cards, issues assigned to cards, pull requests assigned to cards, columns, and notes.
{% endhint %}

{% hint style="info" %}
The list is presented in alphabetical order.
{% endhint %}

<details>

<summary>ACTIONS AND PIPELINES</summary>

* [x] Workflows

</details>

<details>

<summary>BRANCH PROTECTION RULES</summary>

* [x] Allow deletions
* [x] Allow force pushes
* [x] Branch name pattern
* [x] Lock branch
* [x] Require a pull request before merging
* [x] Require conversation resolution before merging
* [x] Require linear history
* [x] Require signed commits
* [x] Require status checks to pass before merging

</details>

<details>

<summary>COLLABORATORS</summary>

* [x] Direct collaborators
* [x] Outside collaborators
* [x] Roles

</details>

<details>

<summary>DEPENDABOT</summary>

* [x] Dependabot alerts
* [x] Dependency graph
* [x] Dependabot security updates

</details>

<details>

<summary>ISSUES</summary>

* [x] Assignees
* [x] Closed issues
* [x] Creation date
* [x] Creator
* [x] Issue assets
* [x] Issue comments
* [x] Issue description
* [x] Issue types
* [x] Labels assigned
* [x] Milestones assigned
* [x] Open issues
* [x] Projects assigned
* [x] Sub-issues

</details>

<details>

<summary>LABELS</summary>

* [x] Assigned issues
* [x] Assigned pull requests
* [x] Color
* [x] Description
* [x] Name

</details>

<details>

<summary>MILESTONES</summary>

* [x] Assigned issues
* [x] Assigned pull requests
* [x] Closed milestones
* [x] Description
* [x] Due date
* [x] Open milestones
* [x] Title

</details>

<details>

<summary>PROJECTS (V2)</summary>

* [x] Custom date column
* [x] Custom iteration column
* [x] Custom number column
* [x] Custom single select column
* [x] Custom text column
* [x] Description
* [x] Draft issues in project
* [x] Issues in project&#x20;
* [x] Labels column
* [x] Linked pull requests column
* [x] Milestone column
* [x] Pull requests in project
* [x] Readme
* [x] Repository column
* [x] Reviewers column
* [x] State
* [x] Status column
* [x] Status updates

</details>

<details>

<summary>PULL REQUESTS</summary>

* [x] Assignees
* [x] Closed pull requests
* [x] Comments
* [x] Commits
* [x] Creation date
* [x] Creator
* [x] Description
* [x] Labels
* [x] Merged pull requests
* [x] Milestones
* [x] Open pull requests

</details>

<details>

<summary>REPOSITORY</summary>

* [x] Branches
* [x] Commits
  * [x] Commit comments
  * [x] Commit creator
  * [x] Commit message
  * [x] Commit text
* [x] General settings
  * [x] Allow merge commits
  * [x] Allow rebase merging
  * [x] Allow squash merging
  * [x] Automatically delete head branches
  * [x] Default branch&#x20;
  * [x] Default merge commits message&#x20;
  * [x] Default squash merging message
  * [x] Template repository
* [x] Homepage
* [x] LFS
* [x] Logs
* [x] Objects
* [x] Refs
* [x] Repository
* [x] Repository description
* [x] Repository name
* [x] Settings
  * [x] Deploy keys
* [x] Tags
* [x] Webhooks
* [x] Wiki

</details>

<details>

<summary>TEAMS</summary>

* [x] Description
* [x] Members
* [x] Member roles
* [x] Name
* [x] Parent team
* [x] Permissions to repository
* [x] Team notifications
* [x] Visibility

</details>

<details>

<summary>RELEASES</summary>

* [x] Assets
* [x] Description
* [x] Releases
* [x] Set as a pre-release
* [x] Set as the latest release
* [x] Tags

</details>


# Creating a backup plan

This article contains information on how to set up a GitHub backup plan.

## Backup plan setup <a href="#backup_plan_creation" id="backup_plan_creation"></a>

{% stepper %}
{% step %}
Login to **GitProtect Management Service**, open the **Plans** > **Backup** tab and click the <img src="/files/qBMQVDXoC7Lxera5vtkq" alt="" data-size="original"> **Add plan** button in the top bar.
{% endstep %}

{% step %}
Select **GitHub** from the list.
{% endstep %}

{% step %}
Select (or add) the **GitHub** environment you want to include in the backup process, and choose the repositories to back up.

{% hint style="warning" %}
In **GitProtect**, you can select repositories based on custom properties, but these properties **must be configured at the organization level in GitHub**. During synchronization, **GitProtect** retrieves the property definitions from the organization and the assigned values from the repositories. After synchronization, the panel displays a list of all properties fetched from every organization on the **GitHub** side that was added to **Management Service**. For the feature to work correctly, **the token used for authorization must also include the read:org permission**.
{% endhint %}

<figure><img src="/files/nKpoMiLbqQam8Wf3Kzxh" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
Optionally, **GitProtect** allows you to protect the entire **GitHub** environment.
{% endhint %}
{% endstep %}

{% step %}
Specify a name for the backup plan.
{% endstep %}

{% step %}
Select the appropriate metadata that you want to back up. Here, you can also change the **default worker**, which is the device directly responsible for the backup process of your repositories.

{% hint style="success" %}
You can have multiple workers and assign different workers to each backup plan.
{% endhint %}

{% hint style="info" %}
It is worth noting that the **cloud worker** (a cloud-installed **GitProtect worker**) allows you to perform cloud-to-cloud backups if you want to store your backups in the cloud.
{% endhint %}

<figure><img src="/files/CC7oZdGqj66XT9kNfXFy" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Select one of the locations assigned to your **GitProtect** instance as storage.

<figure><img src="/files/jak9or18kyGWfHGISGiu" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Customize the scheduler and specify how long your data should be retained. If needed, adjust the advanced settings to suit your needs.

<figure><img src="/files/jKcTXFJhl5ZoIlkAJhxv" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
If necessary, adjust the advanced settings such as encryption, error handling, or bandwidth limits to fit your requirements.

<figure><img src="/files/g5fQzgljLBuFiU3WAxMK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Double-check your data and click **Save** to create the backup plan.
{% endstep %}
{% endstepper %}

***

## Useful links and items

{% content-ref url="/pages/D9j2y4b4l51BnBsEIyA5" %}
[Cloud storage](/storage/cloud-storage)
{% endcontent-ref %}

{% content-ref url="/pages/9AZUD1hXe2mvU7ncAHPz" %}
[Scheduler & retention](/management/scheduler-and-retention)
{% endcontent-ref %}




---

[Next Page](/llms-full.txt/1)

