Skip to main content
C1 provides identity governance for Kaseya Spanning Backup for Office 365. Integrate your Spanning tenant with C1 for unified visibility and governance over user access.

Capabilities

ResourceSyncProvision
Users
Roles

Gather Spanning credentials

The Spanning connector is read-only. You need administrator access to the Spanning Backup for Office 365 admin console to generate an API key.
1
Sign in to the Spanning Backup for Office 365 admin console for your tenant’s region.
2
Open Settings > API Token and generate an API key. The API key is region-specific.
3
Note the admin email address used to sign in — it is the Basic Auth username — and copy the generated API key, which is the Basic Auth password.
4
Note your tenant’s data region and use its API base URL: ushttps://o365-api-us.spanningbackup.com, and likewise eu, ap, ca, uk, af.

Configuration fields

FieldRequiredDescription
spanning-admin-emailYesSpanning admin email address, used as the Basic Auth username.
spanning-api-keyYesAPI key generated in the Spanning admin console, used as the Basic Auth password.
spanning-base-urlYesRegion-specific API base URL: https://o365-api-<region>.spanningbackup.com where region is us, eu, ap, ca, uk, or af.

Synced resource types

  • Users: Spanning users from the tenant, mapped as C1 users. Each user carries its principal name, email, display name, Microsoft object id, license assignment, and admin status.
  • Roles: A fixed set of seven Spanning role tiers — User, Shared Mailbox, Global Admin, Spanning Admin, Archived (read-only), No Microsoft License, and Deleted From Microsoft. Each user is granted membership in the roles corresponding to its tags.

Special notes

  • The connector authenticates with HTTP Basic Auth. The admin email is the username and the API key is the password.
  • The base URL is the region-specific host (https://o365-api-<region>.spanningbackup.com). The API key is region-scoped, so the base URL must match the account’s region.
  • Roles are synthesized from each user’s tags. Spanning has no dedicated roles endpoint, so all seven roles are always present and role membership is derived from the tags on each user record.
  • User accounts that are deleted or archived in Spanning are marked disabled in C1.

Configure the Spanning connector

Follow these instructions to use a built-in, no-code connector hosted by C1.
1
In C1, navigate to Integrations > Connectors and click Add connector.
2
Search for Spanning and click Add.
3
Choose how to set up the new Spanning connector.
4
Set the owner for this connector.
5
Click Next.
6
Find the Settings area of the page and click Edit.
7
Enter the Spanning credentials:
  • Admin email: The Spanning admin email address.
  • API key: The API key generated in the Spanning admin console.
  • API base URL: Your region host, https://o365-api-<region>.spanningbackup.com.
8
Click Save.
9
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.
Done. Your Spanning connector is now pulling access data into C1.