SharePoint backup — insecure destination

Status
Not open for further replies.

alanjmcfL

Bronze Partner
Basic Certified
Joined
Nov 27, 2022
Messages
35
Reaction score
13
I love that SharePoint is supported for a backup destination now. (My struggles with setting up backup over SFTP are discussed here previously[1].)

However I hope that it is on the To Do list is that a different site can be selected

The root SharePoint site is by default the "Team Site"[2] and has read-write permissions for "Everyone (except external users)." Thus any user in the tenant could read the contents of the backup, and could alter it such that different permissions and settings would be created on restore! (ZIP password allowing.)

I suggest you add such a note to https://www.3cx.com/docs/manual/sharepoint/ saying something like "Note that by default the root SharePoint site has permission "Everyone (except external users)." You should adjust the permissions on the destination folder as appropriate for your environment."

Alan

----
[1] SFTP backup in 3CX apparently writes the ZIP file in random-access mode, ie rewinds to update the ZIP header on completion. Many SFTP destinations including Azure only handle writing a file in one go! There's a setting in 3CX to disable the random-access mode but that isn't available in Hosted.
[2] EDIT: Ohh its a "Communications Site" on new tenants now, but the permissions are the apparently the same.
 
Last edited:
+1000

We are an MSP first, and 3CX is a value add we provide for our managed clients. The overwhelming majority of our clients are Microsoft 365 cloud native organizations, with the bulk having been using SharePoint online for years before the 3CX backup to SharePoint functionality was available. Most organization we work with use the default Documents library in the root SharePoint site as their public share that has common data available to everyone in the organization (again, due to the default permissions on the root site and default Documents library. In addition, this library is almost always synchronized to client devices via the OneDrive client. As a result, using SharePoint for 3Cx backup & recording storage is currently not a viable option for our clients.

It's bad form to dump disparate data into a single repository. We have separate SharePoint sites in each client tenant for various restricted data, including admin/tech specific data. Ideally, any piece of the 3CX integration with M365 SharePoint should allow us to specify the SharePoint site, library, and folder (although the folder shouldn't be required). We would like to have separate document libraries in the admin SharePoint site for the different integrations - e.g. one document library for 3CX Backups, and one for 3CX Recordings. With dedicated document libraries for each 3CX storage type, we would not need to specify a folder in the path, which is why it would be nice to have the folder path not required but an option.
 
+1000

Finding the same issue with Version 20. Where can I upvote this?
Has anyone got a link to a feature request for this?
 
  • Like
Reactions: EIT-Brendan
Status
Not open for further replies.