Skip to content

Knowledge Base

Nexus1.1.1AdminGuide

Nexus 1.1.1 Version

Panzura TechPub Copyright © Panzura, LLC. 2026 | panzura.com

Table of Contents

  1. Home ..... 4
  2. 1.1.1 ..... 5 2.1 Panzura Nexus Overview ..... 5 2.2 Compatibility and Support in Panzura Nexus ..... 8 2.2.1 Scanning and Scaling Panzura Nexus ..... 9 2.3 Features in Panzura Nexus ..... 10 2.3.1 What's New? ..... 10 2.3.2 Key Features ..... 10 2.4 Panzura Nexus Checklist ..... 14 2.4.1 Detailed Prerequisites Overview ..... 15 2.4.2 Upload Nexus VHDs to Azure Private Marketplace ..... 16 2.4.3 Share an AWS AMI image ..... 21 2.4.4 Enabling CloudFS for Nexus ..... 23 2.5 Panzura Nexus Installation ..... 24 2.5.1 Installing Panzura Nexus on Microsoft Azure ..... 24 2.5.2 Installing Panzura Nexus on Microsoft Hyper-V ..... 24 2.5.3 Installing Panzura Nexus on AWS ..... 25 2.5.4 Installing Panzura Nexus on VMware ..... 25 2.5.5 Installing Panzura Nexus on KVM ..... 26 2.5.6 Accessing Panzura Nexus setup wizard ..... 26 2.5.7 Panzura Nexus Web UI Walkthrough ..... 27 2.6 Panzura Nexus Dashboard ..... 30 2.6.1 System Overview ..... 30 2.6.2 Data Insights ..... 34 2.7 Getting Started with Panzura Nexus Configuration ..... 37 2.8 Panzura Nexus Plugin Configuration ..... 38 2.8.1 Configure Storage Systems ..... 38 2.8.2 Configure AI Systems ..... 38 2.8.3 Configure Identity Management ..... 39 2.8.4 Configure Rules ..... 39 2.8.5 Configure Policies ..... 40 2.9 Panzura Nexus Statistics ..... 44 2.9.1 Jobs ..... 44 2.9.2 Reports ..... 45

2.10 Panzura Nexus Configuration ..... 48 2.10.1 Settings ..... 48 2.10.2 Register the application in Microsoft Entra ID ..... 52 2.10.3 Agents ..... 53 2.10.4 Support for Comprehensive Indexing and Search for Large Files ..... 72 2.11 System Operations ..... 73 2.11.1 Download Logs ..... 73 2.11.2 Backup & Restore ..... 75 2.12 System Management Audits ..... 81 2.13 User Profiles in Panzura Nexus ..... 82 2.13.1 User Profile ..... 82 2.14 Alerts in Panzura Nexus ..... 83 2.14.1 Alerts ..... 83 2.15 Glossary ..... 85

1. Home

Welcome to Panzura Nexus Documentation! We're excited to have you with us! This guide has been prepared to help you navigate the product with ease, offering clear instructions and practical insights. Your engagement is highly valued, and we look forward to supporting your journey with us.

Let's get started!

2.1 Panzura Nexus Overview

Organizations using CloudFS manage massive volumes of unstructured file data, making it difficult to search, analyze, and derive insights, as AI tools like Microsoft Copilot cannot securely access this information. Panzura Nexus eliminates this gap by seamlessly integrating CloudFS with Microsoft Copilot to deliver secure, AI-powered search and data insights.

Nexus selectively ingests file content, metadata, and change events from CloudFS into Copilot's AI ecosystem while maintaining all existing enterprise access controls and permissions. This ensures that data remains both searchable and secure. With this integration, CloudFS content becomes fully AI-searchable, enabling users to ask meaningful questions, uncover insights, and accelerate everyday tasks through a natural, conversational interface powered by Microsoft Copilot.

Key Capabilities:

Key Features Description
Native CloudFS Integration Seamlessly integrates with CloudFS to ingest data, metadata,
and security attributes for AI-powered insights.
Selective Data Ingestion Connects to Microsoft Copilot via Microsoft Graph
Connector, ingests file content and metadata. Handles file
updates, ACL changes, renames, and directory structure
changes
Access Control & Security Policies enforce strict Access Control over the data ingested
into the AI system. This ensures that users, even during AI
conversations, are prohibited from accessing CloudFS files
for which they do not have the required permissions.
Dashboard & Reporting Copilot Upload Metrics: Timeline, Volume, and
Categorizations (Policy, Extension, User, Time)
Licensing Based on storage source file system capacity.

A technical architecture diagram illustrating the Panzura Nexus components and their integration with Azure Blob Storage and Copilot. This could be useful for illustrating cloud storage workflows, data management systems, or hybrid cloud infrastructure.

The Panzura Nexus architecture is centered around three primary components that work together to deliver secure, permissionaware, AI-powered insights from CloudFS data: CloudFS as the storage source, Microsoft Copilot as the AI system, and on-premises Active Directory for identity and access mapping. In addition, Data Insights policies and rules serve as supporting elements that define what data is ingested, how it is processed, and how insights are generated.

CloudFS (Storage Source) CloudFS serves as the primary data source for Panzura Nexus. It contains the enterprise's unstructured file datasets-including file content (data), metadata, directory structures, and ACLs. Panzura Nexus integrates with CloudFS through a dedicated plugin that connects directly to one of the CloudFS nodes. This node must be within the same LAN segment as the Panzura Nexus host to ensure:

  • SMB access for reading file content and metadata
  • Accurate and timely updates to maintain the freshness of data indexed in Microsoft Copilot
  • Secure connectivity without exposure over external networks.

This architecture ensures that Panzura Nexus can continuously ingest both full-scan and real-time change events from CloudFS, maintaining an up-to-date representation of the file system.

Microsoft Copilot (AI System)

Microsoft Copilot acts as the AI engine that processes and interprets the content ingested from CloudFS. Panzura Nexus connects to Copilot through a Microsoft Graph Connector, enabling:

  • Ingestion of selected file content and metadata based on configured policies.
  • AI-powered search and conversational interactions.
  • Secure access enforcement using existing enterprise permissions
  • Configuring Copilot within Panzura Nexus is required to establish a connector that transfers CloudFS data into the Microsoft 365 ecosystem.

On-Premises Active Directory + Entra ID Connector (Identity Mapping & Access Control) Panzura Nexus supports onpremises Active Directory (AD) for user identity mapping, ensuring that security controls remain consistent across CloudFS and Microsoft Copilot. The Entra ID Connector links on-prem AD identities with Microsoft Entra ID, enabling:

  • Accurate permission mapping for every CloudFS user
  • Enforcement of ACLs during AI-based search and conversations
  • Prevention of unauthorized data exposure in Copilot responses

Data Governance Policies

Panzura Nexus uses Data Governance policies to determine what data gets ingested into Microsoft Copilot. A policy includes:

  • Rules: Filters based on file paths, extensions, metadata, timestamps, or custom conditions.
  • Scan Scope: Defines whether the policy runs on full scans, event-based updates, or both.
  • Configuration Settings: Specifies ingestion behavior, priority, and operational limits.

These policies ensure controlled, selective data ingestion aligned with security and business requirements.

Copilot Agent (Conversational Interface)

Using the Microsoft Agent Builder Portal, a Copilot Agent can be configured that:

  • Provides conversational access to the data ingested from CloudFS
  • Enables users to ask questions, explore insights, and perform tasks using natural language
  • Applies access-control mappings to ensure secure and compliant responses

2.2 Compatibility and Support in Panzura Nexus

The following table summarizes the support metrics for Panzura Nexus, including supported operating systems, network port requirements, and recommended hardware specifications.

Category Supported / Required Details Notes
Supported Platforms - Microsoft Azure
  • Microsoft Hyper-V | - | | Hardware Requirements | - CPU: Minimum 16 cores
  • Memory: Minimum 64 GB RAM
  • Storage: 4 TB SSD for data
  • Network:
  • LAN: 10 Gbps (required)
  • WAN: 1 Gbps (optional) | Panzura Nexus native image must be deployed within the same LAN segment as that of CloudFS node. | | Ports | - 443 (TCP - Inbound): Admin access to Panzura Nexus web UI
  • 5671 & 5672 (TCP - Inbound): RabbitMQ message bus for CloudFS file change events
  • 22 (TCP - Inbound): SSH connectivity from CloudFS node to Nexus
  • 389 (TCP - Outbound): From Nexus to LDAP and LDAP with TLS
  • 636 (TCP - Outbound): LDAPS | Ensure firewall rules permit the above traffic between Panzura Nexus and relevant systems. | | Directory Services | - Microsoft Active Directory (Onprem)
  • Entra ID Connector (Hybrid AD Sync) | Required for identity mapping & permission-aware queries. | | CloudFS Versions | - 8.7.0
  • 8.6.x
  • 8.5.x | A functional CloudFS ring is required for Panzura Nexus to ingest audit & snapshot data. | | Browsers | - Google Chrome - 142.0.7444.176 (Official Build) (64-bit)
  • Microsoft Edge
  • Firefox ESR
  • Apple Safari 18.3 | Recommended for Panzura Nexus web UI. | | Deployment Models | - On-prem VM (Hyper-V)
  • Cloud VM (Azure) | |

2.2.1 Scanning and Scaling Panzura Nexus

This brief introduction highlights the key considerations for performing Nexus scans on Panzura CloudFS environments. For IT teams and administrators, the main guide provides actionable recommendations on node selection, operational best practices, and performance benchmarks to ensure efficient scanning with minimal impact on production workloads. For in-depth instructions and detailed metrics, refer to the Panzura Nexus Scanning & Scaling Guide.

2.3 Features in Panzura Nexus

This section provides a comprehensive overview of the key features and capabilities available within Panzura Nexus, including the latest updates, enhancements, and newly introduced features.

2.3.1 What's New?

This section outlines the latest updates, enhancements, and recent developments introduced in Panzura Nexus. Nexus version 1.1.1 is a maintenance release that delivers quality and security improvements across the platform. The release primarily focuses on resolving reported defects, strengthening product stability, and addressing identified security vulnerabilities.

2.3.2 Key Features

Backup and Restore

The Backup & Restore feature ensures data protection and system recovery by creating backups and restoring the system to a previously saved state. For more details, refer to Backup & Restore

Support for Comprehensive Indexing and Search for Large Files

Panzura Nexus indexes the entire text content of large files. When a file's extracted text exceeds the indexing limit, Nexus automatically splits it into smaller segments for indexing. This ensures that every part of the document, including the beginning, middle, and the end, becomes searchable through Microsoft Copilot. For more details, refer to Support for Comprehensive Indexing and Search for Large Files

New platform support for AWS, VMware, and Kernel-based Virtual Machine (KVM)

Support for additional platforms has been introduced, enabling deployment of Panzura Nexus on:

  • AWS
  • VMware
  • Kernel-based Virtual Machine (KVM) environments

This enhancement broadens infrastructure compatibility and provides streamlined installation guidance to support a consistent and efficient deployment experience across supported environments. For more details, refer to Panzura Nexus Installation

Panzura Nexus Dashboard - System Overview

The Nexus Dashboard now features a streamlined interface with four dedicated tabs: Overview, CPU & Memory, Disk, and Network & System. This update consolidates all critical monitoring and analytics functions, making it easier to navigate and access key metrics.

  • The Overview tab provides a high-level summary of system configuration and data ingestion.
  • The CPU & Memory tab delivers real-time insights into processor and memory performance.
  • The Disk tab tracks storage utilization and I/O activity, while the Network & System tab monitors network traffic, uptime, and overall system health. These enhancements empower administrators with unified, actionable visibility across the entire infrastructure.

For more details, refer to Panzura Nexus Dashboard

Support for Pause and Resume in Jobs

Panzura Nexus now gives administrators in-session control of active jobs with new Pause and Resume actions in the web UI. Instead of cancelling and restarting the jobs when priorities shift or resources are constrained, administrators can temporarily halt processing and continue from the exact same point. This helps reduce rework, improve operational flexibility, and manage resource-intensive workloads more efficiently. For more details, refer to Actions on Jobs

Additional Parameters in Settings

Panzura Nexus provides centralized Preferences controls for log level, session timeout, and local/cloud backup retention, improving system management and security. It also adds editable NTP settings so administrators can configure time servers and timezone for accurate, consistent timestamps across logs, schedules, and security events. For more details, refer to Settings > Preferences and Settings > NTP Configuration

Microsoft Copilot Integration

Panzura Nexus ingests selected CloudFS filesystem subset into Microsoft Copilot, enabling insights into the metadata and data.

AI conversation on the data and metadata

Panzura Nexus supports ingestion of over 1,000 file formats, making it easier to work with diverse data sources:

  • Document formats:** PDF, DOCX, DOC, XLSX
  • Image formats: JPEG, JPG, BMP
  • AEC files: AutoCAD and more

With built-in Optical Character Recognition (OCR), Nexus can also extract text from images including those embedded within documents, ensuring no valuable information is missing.

CloudFS 8.7.0, 8.6.x or 8.5.x Support

Panzura Nexus integrates with CloudFS storage, supporting both real-time file system event processing and scheduled crawling. For more details, refer to Enabling CloudFS for Nexus

Active Directory Support

Panzura Nexus enforces on-premises Active Directory permissions via Entra ID connector, with synchronization to Microsoft Azure Entra.

Panzura Nexus Deployment

Microservices architecture supporting cloud instances (viz. Microsoft Azure) and hypervisors (viz. Hyper-V).

Access Control Compliance under SMB

Ensures all Copilot interactions comply with CloudFS SMB file-system permissions, with the ability to provide conversational support to additional users or groups.

Governance

Rules and Policies provide a governance framework that defines how data is ingested, processed, and interacted with. This framework can be applied based on content within specific directories, file path patterns, file extensions, file size, file timestamps, file ownership, and file modification attributes. For more details on Policies, refer to Configure Policies

For more details on Rules, refer to Configure Rules

Dashboard view

Displays live processing and historical statistics of System Overview and Data Insights policy. The System Overview provides statistics about plugins, rules, and policies. The Data Insights policy displays live and historical statistics, including charts for processed file counts, upload counts, failed processing events, and total uploaded file size across users and groups. It also delivers insights into ingested data such as total file count, overall file size, ingestion trends, file-type distribution, and userbased distribution. For more details, refer to Panzura Nexus Dashboard

Reports

Displays a list of ingested files for the selected policy with the ability to search and filter. For more details, refer to Reports

Catalog & Audit Capabilities

Panzura Nexus audits every operation, enabling administrators to query and filter activities with ease. It delivers a comprehensive data catalog and audit framework that:

  • Tracks all ingested objects
  • Produces file-type distribution reports
  • Provides detailed user-level access and activity statistics
  • Ensures transparent visibility into the data Copilot can access

For more details, refer to System Management Audits

Alerts

Notifies about system events that may require administrative action and intervention. For more details, refer to Alerts

Jobs Lists filesystem scan (full and incremental) jobs that are completed or currently running. For more details, refer to Jobs

Optimized Ingestion

Ingestion is optimized using incremental scans. Where applicable, only metadata is updated when data remains unchanged.

Scan support

The Scan Support feature in Panzura Nexus enables both manual and scheduled scans of your storage environment, ensuring comprehensive data visibility and up-to-date indexing. Administrators can initiate a full storage scan when activating a policy, allowing the system to analyze all existing data for compliance and reporting. The feature provides flexible scheduling options, including minute, hour, day, month, and weekday parameters, so scans can be tailored to organizational needs. When enabled, administrators can choose to run a full scan on policy activation or set up a recurring schedule using intuitive checkboxes. By default, new policies are created in an "Inactive" state, giving you full control over when scans are initiated and how often they occur.

Native VM Support

Panzura Nexus supports additional native VM formats, specifically VHDX for Hyper-V and ZMI for Microsoft Azure. For more details on Microsoft Azure, refer to Installing Panzura Nexus on Microsoft Azure

For more details on Hyper-V, refer to Installing Panzura Nexus on Microsoft Hyper-V

Enhanced Alerting

Added support for email notifications that are triggered by changes in Policy and Rule Status to provide real-time compliance visibility. For more details, refer to Email Notifications

Scoped Retrieval (Data Partitioning)

New policy-based controls allow users to limit Microsoft Copilot searches to specific datasets for more secure and relevant results.

Data Source Management

Rename or remap scanned roots and remove previously scanned folders (cleanup without a full rescan).

Ingestion Management

Improved performance and large-file handling.

License Management

License management in Nexus is the process of validating and enforcing the licenses required for the system to operate. It ensures that Nexus runs with a valid license tied to the storage system's capacity (such as CloudFS Managed Capacity). Licenses are managed through token strings registered in the Nexus System Management web UI, and if a license is missing or invalid, Nexus raises critical alerts. For more details, refer to License Management

Setup wizard / Edit Network Configuration

The Setup Wizard guides you through the essential steps required to configure your system for first-time use. Each stage ensures that critical parameters such as licensing, storage, networking, and time synchronization are properly defined for smooth and reliable operation. By following the wizard, administrators can quickly establish a secure, well-connected, and fully functional environment before moving on to daily tasks. For more details, refer to Edit Network Configuration

Download Logs

The Maintenance page provides administrators with essential system diagnostic tools to support troubleshooting and performance monitoring. It simplifies log collection by automatically aggregating system, container, and database logs into a single bundle, making it easier to analyze issues. For more details, refer to Download Logs

2.4 Panzura Nexus Checklist

The checklist outlines all required prerequisites along with the high-level steps involved in setting up Nexus.

Prerequisites Details Notes
Supported Platform - Microsoft Azure
- Hyper-V
- AWS
- KVM
- VMware
- An active subscription with Contributor or Owner permissions.
- Ensure that the images of Azure (.VHD) and Hyper-V (.VHDX) are downloaded and kept handy.
- For AWS, ensure an active AWS account with the required EC2 permissions and the shared Nexus AMI available in the target region.
- For KVM, ensure the Nexus QCOW2 image is available and the host has KVM/libvirt tools (virsh/virt-install) configured.
- For VMware, ensure the Nexus VMware image package (OVA/ OVF and VMDK) is available and deployment permissions are granted in vCenter/ESXi.
Nexus Host Resource
Requirement
- CPU and Memory: Minimum 16 core / RAM 64 GB
- Storage:
- Additional SSD: Min 4TB
- Networking:
- LAN interface (Minimum 10Gbps throughput) with static IP address (wherever applicable)
- WAN interface (Minimum 1 Gbps throughput) connectivity (optional if LAN interface has internet connectivity)
A deployment environment for the Panzura Nexus platform, which can be an on-premises virtual machine or a cloud instance.
Note: The Panzura Nexus native image for Azure and Hyper-V must reside within the same LAN segment as one of the CloudFS nodes. This is required for Panzura Nexus to have fast read access to the CloudFS filesystem data. Refer to detailed prerequisites.
Ports - 443 (TCP - Inbound): Admin access to Nexus web UI
- 5671 & 5672 (TCP Inbound): RabbitMQ message bus for CloudFS file change events
- 22 (TCP - Inbound): SSH connectivity from CloudFS node to Nexus
- 389 (TCP - Outbound): From Nexus to LDAP and LDAP with TLS
Ensure firewall rules permit the above traffic between Nexus and relevant systems.

| Prerequisites | Details

  • 636 (TCP - Outbound): LDAPS | Notes | | --- | --- | --- | | Storage Configuration (CloudFS) | - A functional CloudFS ring (8.7.0, 8.6.x, and 8.5.x)
  • CloudFS master node connection details and administrator credentials
  • One of the CloudFS nodes within the deployment (recommended to set up a dedicated CloudFS node or use an existing less-loaded node)
  • A SMB user with CloudFS global file-system read-only access at least | Note: As mentioned, the Panzura Nexus native image must reside within the same LAN segment as one of the CloudFS nodes for fast read access to CloudFS file-system data using SMB protocol. For enabling audit settings on CloudFS version 8.7.0, 8.6.x and 8.5.x, refer to Enabling CloudFS for Nexus. | | AI System Requirement | - Create a Microsoft Entra ID application using the customer Azure Tenant ID
  • Client ID
  • Client Secret | Refer to Register the application in Microsoft Entra ID to create an Entra ID application. | | Microsoft Entra ID Connector Setup | To keep your on-prem Active Directory Identity database in sync with Microsoft Entra ID, follow the Microsoft documentation steps. | A Microsoft Entra ID Connector is required to synchronize organization end-user accounts and enable access to CloudFS data insights through Copilot. Refer to the Introduction to Microsoft Entra Connect V2. | | On-prem Active Directory Information | - Hostname of the Active Directory
  • Domain name
  • AD Bind user (with user and group search capabilities)
  • Connection information (LDAP / LDAPS / LDAP with TLS) | On-prem AD details and bind user accounts are needed to map CloudFS users to corresponding Entra ID accounts for consistent access control. Check with your AD administrator for details. Refer to detailed prerequisites in the section. |

2.4.1 Detailed Prerequisites Overview

The section describes the details of each prerequisite mentioned in the checklist:

Set up the Nexus Host

Prepare the host environment for Nexus deployment by ensuring the following:

  • Panzura Nexus installer ZMI image / VHDXs.
  • Allocate 16 CPUs and 64 GB RAM.
  • Provide 4 TB RAW SSDs for Nexus usage.
  • Configure network with 10 Gbps LAN and a static IP (wherever applicable) (1 Gbps WAN optional).
  • Set up NTP, DNS, and Gateway.

Note: This Nexus host and the CloudFS node must be deployed in the same LAN.

Configure CloudFS

To enable Nexus to ingest audit, snapshot, and metadata from CloudFS:

  • Ensure that a functional CloudFS ring is running 8.7.0, 8.6.x or 8.5.x.
  • Keep CloudFS master node connection details and administrator credentials ready.
  • Provide access to at least one CloudFS node.
  • For best performance, use a dedicated node or a low-load node.
  • Create or provide an SMB user account with global read-only access to CloudFS.
  • Deploy the Nexus host in the same LAN segment as a CloudFS node for reliable SMB-based access.

Integrate Nexus with Microsoft Copilot

To enable Copilot-based data and metadata ingestion:

  • Ensure a Microsoft 365 tenant with Copilot-enabled end-user licenses is available.
  • Keep handy the following values by registering the application in Microsoft Entra ID:
  • Tenant ID
  • Client ID
  • Client Secret

Refer to the Register the application in Microsoft Entra ID for more detailed steps.

Set up On-prem Active Directory

The following parameters are required:

  • Hostname of the Active Directory: Allows Nexus to locate and communicate with the AD server.
  • Domain name: Identifies the AD domain for authentication and user lookup.
  • AD Bind user: Service account used to search and retrieve user and group information.
  • Connection information (LDAP / LDAPS / LDAP with TLS): Defines how Nexus connects securely to AD.
  • On-prem AD details: Required for mapping CloudFS users to Entra ID accounts for consistent access control.

2.4.2 Upload Nexus VHDs to Azure Private Marketplace

This procedure will guide you in uploading the Nexus VHD to Marketplace.

  1. Login to Azure portal with Owner or contributor role.
  2. Search for the text "Storage Accounts" and you are redirected to Home Storage Center Blob Storage .
  3. Under Resources tab, search for the Storage Account, for example: eastus.
  4. There are two ways to upload the .vhd files: a. Add a new container and push the vhd to the new container. b. Upload the vhd to an existing container by selecting the vhd from the container and click Upload.
  5. After uploading the VHD, create Azure image from the blob. Search for Compute infrastructure.
  6. Under Disks + images, click Custom images Images tab and click + Create.
  7. Provide the following details on the Azure image:
  • Resource Group Name: Select from the dropdown. For example: QA
  • Name: Provide the name to the image and note it for later use.
  • Region: Select from the dropdown. For example: East US
  • OS Type: Linux
  • VM Generation: Gen1
  • Storage Blob: Blob URL of the uploaded vhd to the container.
  • Account Type: Premium SSD
  1. Click Review + Create and keep the remaining configuration parameters as is. After all the parameters are provided, a new image will be created which can be used to deploy as virtual machine in Azure.
  2. After the virtual machine is created, spawn it by navigating to Custom image (Compute infrastructure > Custom image).
  1. Select the image created in step 6. Click + Create VM. Enter the required configuration. Refer to the screenshot for inputs.
Basics Disks Networking Management Monitoring Advanced Tags Review + create
Create a virtual machine that runs Linux or Windows. Select an image from Azure marketplace or use your own customized image. Complete the Basics tab then Review + create to provision a virtual machine with default parameters or review each tab for full customization. Learn more ☐
Project details
Select the subscription to manage deployed resources and costs. Use resource groups like folders to organize and manage all your resources.
Subscription * ☐ Subscription-Panzura
Resource group * ☐ QA
Create new
Instance details
Virtual machine name * ☐ nexus-nk-1
Region ☐ G2G East US
Display to an Azure Extended Zone
Availability options ☐ Availability zone
Zone options ☐ ☑ Self-selected zone
Choose up to 3 availability zones, one VM per zone
Azure-selected zone (Preview)
Let Azure assign the best zone for your needs
Using an Azure-selected zone is not supported in region 'East US'.
Availability zone * ☐ Zone 1
Security type ☐ Standard
Image * ☐
VM architecture ☐
Arm64
☑ x64
Arm64 is not supported with the selected image.
Run with Azure Spot discount ☐
Size * ☐ Standard_816s_v2 - 16 vcpus, 64 GB memory ($486.18)
See all sizes

Run with Azure Spot discount ☐ ☐

Size * ☐ Standard $16s, >2 - 16 vcpus, 64 GB memory ($486.18) See all sizes

Enable Hibernation ☐ ☐ Choose an image that is compatible with Hibernate to enable this feature. Learn more ☐

Administrator account

Authentication type ☐ SSH public key ☑ Password

Username * ☐ panzura

Password * *************

Confirm password * ***********

Inbound port rules

Select which virtual machine network ports are accessible from the public internet. You can specify more limited or granular network access on the Networking tab.

Public inbound ports * ☐ None ☑ Allow selected ports

Select inbound ports * HTTP (80), HTTPS (443), SSH (22) ☐ HTTP (80) ☑ HTTPS (443) ☐ SSH (22)

Licensing

License type * Other

If you are using a RedHat or SLES image, you may be eligible for the Azure Hybrid Benefit and can save money on the license costs. Learn more about Azure Hybrid Benefit and how to enable it using Azure CLI for custom images from snapshots and Azure compute gallery.

Previous Next : Disks > Restore > Create
  • 19/85 - Copyright © Panzura, LLC. 2020 | panzura.com

Basics

Disks Networking Management Monitoring Advanced Tags Review + create

Azure VMs have one operating system disk and a temporary disk for short-term storage. You can attach additional data disks. The size of the VM determines the type of storage you can use and the number of data disks allowed. Learn more

There is a charge for the underlying storage resources consumed by your virtual machine. Learn more

VM disk encryption

Azure disk storage encryption automatically encrypts your data stored on Azure managed disks (OS and data disks) at rest by default when persisting it to the cloud.

Encryption at host

Encryption at host is not registered for the selected subscription. Learn more

OS disk

OS disk size Image default (60 GB) ☑
OS disk type * Premium SSD (locally-redundant storage) ☑
Delete with VM
Key management Platform-managed key ☑
Enable Ultra Disk compatibility

Data disks for nexus-nk-1

You can add and configure additional data disks for your virtual machine or attach existing disks. This VM also comes with a temporary disk.

LUN Name Size (GB) Disk type Host caching Delete with VM

Create and attach a new disk. Attach an existing disk.

Advanced

Basics Disks Networking Management Monitoring Advanced Tags Review + create

Define network connectivity for your virtual machine by configuring network interface card (NIC) settings. You can control ports, inbound and outbound connectivity with security group rules, or place behind an existing load balancing solution. Learn more

Network interface

When creating a virtual machine, a network interface will be created for you.

Virtual network (1) QA-Virtual-Network (QA)
Edit virtual network
Subnet * (1) qa-private-app
Edit subnet 10.208.5.0 - 10.208.5.255 (256 addresses)
Public IP (1) None
Create new
NIC network security group (1) (1) None
(1) Basic
(1) Advanced
(1) The selected subnet 'qa-private-app (10.208.5.0/24)' is already associated to a network security group 'aadds-nsg'. We recommend managing connectivity to this virtual machine via the existing network security group instead of creating a new one here.
Delete NIC when VM is deleted (1)
Enable accelerated networking (1)

The selected image does not support accelerated networking.

Load balancing

You can place this virtual machine in the backend pool of an existing Azure load balancing solution. Learn more Place this virtual machine behind an existing load balancing solution? 11. Use the default settings for Management, Monitoring, Advanced, and Tags unless your deployment requires changes. 12. Click on Review + Create. It will validate the configuration and then, click on Create to spawn the new virtual machine in Azure.

2.4.3 Share an AWS AMI image

Prerequisites

  • Ensure you have an active AWS account with sufficient permissions (EC2 full access or at least ec2:ModifyImageAttribute).
  • Confirm that the required AMI (Panzura_Nexus_1.1.0-xxxxx) is available in the us-west-2 (Oregon) region.
  • Obtain the 12-digit AWS Account ID (e.g., 123456789012).

Note: You can only share an AMI within the AWS region where it was created. To find and use the shared AMI, make sure you are viewing the same region (for example, us-west-2) in your AWS Console. If you want to use the AMI in a different region, you need to copy it to that region first and then share it again.

To share an AWS AMI with other accounts, follow these steps in the same AWS region where the AMI was created.

Step 1: Log in to the AWS Management Console

  1. Open the browser and navigate to https://console.aws.amazon.com.
  2. Sign in using your AWS credentials (IAM user or SSO) that have EC2 permissions on the source account (909559806924 [Panzura-engineering]).
  3. Ensure the region selector (top-right corner of the console) is set to US West (Oregon) / us-west-2.

Step 2: Navigate to the AMI

  1. In the AWS Console search bar at the top, type EC2 and click on EC2 under Services.
  2. In the left-hand navigation panel, under the Images section, click AMIs.
  3. In the AMI list, ensure the filter is set to Owned by me (use the dropdown above the list).
  4. Locate the AMI named Panzura_Nexus_1.1.0-xxxxx (AMI ID will appear in the same row).
  5. Click the checkbox next to the AMI to select it.

Step 3: Open AMI Permissions (Sharing Settings)

  1. With the AMI selected, click the Actions dropdown button at the top-right of the list.
  2. From the dropdown, select Edit AMI permissions. Alternatively, you can click on the AMI name to open its detail page, then go to the Permissions tab and click Edit. You will see the AMI Permissions dialog or page. By default, the AMI is set to Private (only your account can use it).

Step 4: Add the other AWS Account ID

  1. Under the Shared accounts section, click Add account ID.
  2. In the input field that appears, enter the 12-digit AWS Account ID (e.g., 123456789012 ).
  3. If sharing with multiple accounts, click Add account ID again for each additional account and enter their respective IDs.
  4. Tip: You do not need to repeat this process per account, all account IDs are managed in one permission list on the same AMI.
  5. (Optional) If you also want to copy the AMI to another account (not just launch from it), check the option Allow shared accounts to copy the AMI. Leave this unchecked if you want to restrict usage to launches only from your shared AMI.
  6. Click Save changes.

Step 5: Verify the Sharing

  1. Navigate back to the AMI list (EC2 Images AMIs).
  2. Click on the Panzura_Nexus_1.1.0-xxxxx AMI name to open the detail view.
  3. Go to the Permissions tab.
  4. Confirm the other account ID appears under Shared with.

Step 6: Access the Shared AMI

  1. Login to the AWS Console with the account shared the AMI images by navigating to EC2 Images AMIs.
  2. In the filter dropdown, change the view from Owned by me to Private images or select Shared with me.
  3. Search for Panzura_Nexus_1.1.0-xxxxx or the AMI ID shared earlier.
  4. Select the AMI and click Launch instance to deploy it as an EC2 virtual machine.

Important: The recipient must be in the us-west-2 (Oregon) region in their console to see and launch the shared AMI.

Adding or Removing accounts

  • To add a new account: Repeat Steps 3-4 and add the new account ID.
  • To remove an account: Go to EC2 AMIs Edit AMI permissions, find the account ID under Shared accounts, and click Remove next to it. Changes take effect immediately - no procurement workflow needed.

2.4.4 Enabling CloudFS for Nexus

Before proceeding with the Nexus configuration, complete the following settings on the CloudFS master and subordinate nodes. CloudFS serves as the storage source for Nexus, and these configurations are required to enable this integration.

Note: To enable Data Insights, third-party audit settings must be enabled on every CloudFS node. For CloudFS 8.6.x and 8.7.0, configure these settings in the UI; for CloudFS 8.5.x, run the Third-Party Audit Enablement CLI commands on all nodes.

For version 8.6.x and 8.7.0

  1. Login to the CloudFS master node and navigate to Configuration > Monitoring > Audit Settings.
  2. Select the following settings:
Settings (master node) Actions
Third Party Vendor Support Generate Third Party Log - Enable the toggle
Push to Subordinate(s) - Enable the toggle
User Actions - Create File, Delete, Delete Permissions,
Move, Remove, File Lock, Change Permissions, Write
Vendor Name - Nexus
Master Audit Settings Generate Third Party Log - Enable the toggle
User Actions - Create File, Delete, Delete Permissions,
Move, Remove, File Lock, Change Permissions, Write
Vendor Name - Nexus
  1. Login to the CloudFS subordinate node and navigate to Configuration > Monitoring > Audit Settings.
Local Audit Settings (subordinate node) Actions
Third Party Vendor Support Generate Third Party Log - Enable the toggle
User Actions - Create File, Delete, Delete Permissions,
Move, Remove, File Lock, Change Permissions, Write
Vendor Name - Nexus
  1. Logout from the CloudFS web UI after the settings are done.

For version 8.5.x

SSH to the CLI of the CloudFS master node using administrator credentials.

Run the following commands:

pf_startup_ofy cmd audit-master-thirdparty "nexus" on "create,delete,deleattr,move,remove,riclain,seteattr,write" "*" "."
pf_startup_ofy cmd audit-local-thirdparty "nexus" on "create,delete,deleattr,move,remove,riclain,seteattr,write" "*" "."
pf_startup_ofy cmd audit-thirdparty enable
pf_startup_ofy write

Repeat the commands on each subordinate node:

pf_startup_ofy cmd audit-local-thirdparty "nexus" on "create,delete,deleattr,move,remove,riclain,seteattr,write" "*" "."
pf_startup_ofy cmd audit-thirdparty enable
pf_startup_ofy write

2.5 Panzura Nexus Installation

This topic provides comprehensive guidelines for installing the Panzura Nexus in the supported environment. It outlines the step-by-step installation procedures to ensure a smooth and reliable deployment. Before starting with the installation, ensure that all the prerequisites are met.

2.5.1 Installing Panzura Nexus on Microsoft Azure

Before starting with the installation, ensure that the Panzura Nexus VHD is uploaded on the marketplace. Refer to the prerequisites section.

  1. Login to Azure Portal. Ensure you have an active subscription with Contributor or Owner permissions.
  2. From the left navigation pane, navigate to Home Infrastructure Virtual machines.
  3. Click Create and select Virtual machine.
  4. Configure the VM details including VM name, region, availability options, and availability zone as applicable.
  5. Select the Panzura Nexus image from the dropdown.
  6. Choose as the virtual machine architecture.
  7. Configure the administrator account by selecting SSH key or password authentication and provide the required credentials.
  8. Allow inbound ports: - SSH (22) - HTTP (80) - HTTPS (443)
  9. Add data disks of 4 TB .
  10. Configure networking including VNet, subnet, public IP, network security group (NSG), and enable accelerated networking as applicable.
  11. Configure management settings such as diagnostics, monitoring, auto-shutdown, and backup options.
  12. Review the configuration and click Create** to provision the virtual machine.
  13. Note the IP_address of the Panzura Nexus virtual machine deployed.
  14. Access the Panzura Nexus web UI using the link - https://vm_ip.
  15. Follow the steps from the Accessing Panzura Nexus setup wizard topic to complete the setup wizard.

2.5.2 Installing Panzura Nexus on Microsoft Hyper-V

Prerequisites on the Hyper-V Host

  • Ensure Hyper-V is configured.
  • The user has sufficient permissions to create new virtual machine.
  • An external virtual switch should be available.

Create a New Virtual Machine on Hyper-V

  1. Right click on the .tar.gz bundle to extract it. You may need to perform the extract action twice to get the .vhdx image.
  2. Copy the .vhdx image to the destination virtual machine folder or directory.
  3. Navigate to Hyper-V Manager and select New > Virtual Machine.
  4. Enter a name for the virtual machine.
  5. Choose Generation 1.
  6. Assign at least 64 GB of memory.
  7. Select network in Configure Networking and click Next.
  8. On Connect Virtual Hard Disk, select the "Use an existing virtual hard disk" and **Browse the vhdx image copied in step 2.
  9. Click Finish on the wizard and verify if the virtual machine is created.
  10. Right click on the virtual machine deployed and open the Settings.
  11. Update the BIOS settings, and select IDE as the first boot device.
  12. Update the Processor count at least by 16 .
  13. In SCSI Controller, add new disk of 4TB.

Note: You can configure the VLAN settings as per the network configuration or requirements. 14. Right-click on the virtual machine and click Start. The virtual machine state changes to "Running" and the IP address is generated. Note it. 15. Access the Panzura Nexus web UI using the link - https://vm_ip. 16. Follow the steps from the Accessing Panzura Nexus setup wizard topic to complete the setup wizard.

2.5.3 Installing Panzura Nexus on AWS

  1. Login to AWS portal.
  2. From the Console Home, search for keywords "AMIs".
  3. On the Amazon Machine Images (AMIs), search for the nexus image to be deployed.
  4. Select the image and click "Launch Instance from AMI".
  5. On Launch an instance page, provide the following details:
  6. Name and tags: Provide appropriate name to the image.
  7. Instance type: Select instance type as per the requirements (Select min 16 CPUs and 64 GB Memory).
  8. Key pair: Create new key file and add it.
  9. Network settings: Configure the network settings as required.
  10. Firewall: Select as per the requirement.
  11. Common security groups: Select as per the requirement.
  12. Configure storage: Click "Advanced > Storage (volumes) > Add new volume > size min 100 GB. Select any one of the option ("Yes" or "No") for Delete on termination parameter.
  13. Click on "Launch instance". This process takes some time.
  14. From the instance summary page, copy the ip address.
  15. Access the Panzura Nexus web UI using the link - https://vm_ip.
  16. Follow the steps from the Accessing Panzura Nexus setup wizard topic to complete the setup wizard.

2.5.4 Installing Panzura Nexus on VMware

  1. Login to VMware vSphere Client.
  2. Navigate to Home > Content Libraries. Select the Content Library from the list and click on the Templates tab.
  3. Locate the .ova file from the list. Click Actions > New VM from this template and provide the following details:
  4. Virtual machine name
  5. Select a location for the virtual machine and click Next.
  6. On Select a compute resource, select the resource and click Next.
  7. On Review the details and click Next.
  8. On Select storage, choose the appropriate disk from the list and click Next.
  9. On Select networks, choose the required Destination Network from the dropdown and click Next.
  10. On Ready to complete, review the configuration details and click Finish.
  11. Again navigate to Actions > Edit Settings > Add New Device.
  12. On the New Hard disk parameter, add min 100 GB , select any one option from the dropdown and click OK.
  13. On the Datastore Recommendations, click Apply.
  14. Power On the virtual machine and note the IP address.
  15. Access the Panzura Nexus web UI using the link - https://vm_ip.
  16. Follow the steps from the Accessing Panzura Nexus setup wizard topic to complete the setup wizard.

2.5.5 Installing Panzura Nexus on KVM

  1. Verify the source QCOW2 image exists:
ls -lh /.qcow2
  1. Clean up any existing VM with the same name (skip if fresh):
virsh --connect qemu:///system destroy 2>/dev/null; virsh --connect qemu:///system underline --erram 2>/dev/null; rm -rf
  1. Create VM directory and copy boot disk:
mkdir -p & cp /.qcow2 /.qcow2
  1. Create the VM with virt-install:
virt-install \ --connect qemu:///system \ --noautoconsule \ --virt-type km \ --sa-variant \ --name \ --memory \ --vcpus \ --channel
unis.target.type=virtio.target.name=org.qemu.part_agent.0 \ --network network;.model.type=virtio,virtualport.type=,source.portgroup=.mtu.size= \ --
disk /.qcow2,format=qcow2,bus=virtio,serial= \ --import \ --disk path=/.qcow2,size=,bus=virtio,format=qcow2,serial= \ --disk path=/.qcow2,size=,bus=virti
s,format=qcow2,serial=
  1. Verify VM is running:
virsh --connect qemu:///system list --all
  1. Check VM details:
virsh --connect qemu:///system dominfo
  1. Wait minutes for boot, to get the VM IP:
virsh --connect qemu:///system domifaddr --source agent
  1. Access the Panzura Nexus web UI at:
https://cvm_ip>
  1. Follow the steps from the Accessing Panzura Nexus setup wizard topic to complete the setup wizard.

2.5.6 Accessing Panzura Nexus setup wizard

The following steps are common after you login into the web UI. The setup wizard consists of following steps:

1. License Agreement:

Read the EULA. Navigate back to Nexus web UI, select the checkbox for "I accept the terms and conditions of the End User License Agreement".

2. Storage Configuration:

This screen shows the Storage Configuration step, where you choose which disks will be used for data storage. The table lists available devices along with their capacities.

3. Network Configuration:

The Network Configuration step consists of the following parameters:

1. System Configuration:

Used to define essential system details required for proper operation. It allows administrators to configure core parameters such as the System name (e.g. <systemname>) and Fully Qualified Domain Name (FQDN) (e.g. <systemname.domainname.com>), ensuring correct system identification and network communication.

2. LAN Configuration:

This screen shows the LAN Configuration settings used to configure network connectivity for the system. Provide the following parameters:

  • Select a LAN Interface
  • IP Assignment method
  • DHCP (Automatic)
  • Static (Manual)
  • IP Address
  • Netmask
  • Gateway
  • MTU
  • Primary DNS
  • Secondary DNS

You can select the LAN interface (in this case, eth0) and choose the IP assignment method, either DHCP (Automatic) or Static (Manual). When using a static configuration, fields are provided to enter the IP address, netmask, gateway, and other network parameters such as MTU and DNS servers. This setup ensures the system is correctly connected to the local network.

3. WAN Configuration:

WAN configuration involves setting up the connection between your local network (LAN) and the broader internet or another remote network.

4. View Available Interface:

This parameter displays the available network interface details.

4. Time Configuration:

NTP (Network Time Protocol) configuration involves setting up devices like servers, routers, and switches to synchronize their internal clocks with a reliable time source. Provide the NTP Server and System Timezone and click " " to proceed.

5. Summary:

Review the summary of the configuration. You can navigate back to modify any parameter. Click the Complete Setup. Note: If a failure occurs during the Nexus setup wizard configuration, logs can be downloaded from https://<IP>/api/host/ settings/logs/download to investigate the issue.

2.5.7 Panzura Nexus Web UI Walkthrough

This section provides a guided walkthrough of the web UI to help administrators and users quickly familiarize themselves with the interface. It highlights key navigation components, essential menus, and commonly used actions, enabling you to understand where critical features are located and how to access them efficiently.

Use this walkthrough as a starting point before exploring advanced configuration or management workflows.

Icon Parameters Description
DASHBOARD Dashboard The dashboard provides a comprehensive view of Systems Overview and Data Insights policies, offering visibility into all configured policies and the data populated from them. As part of the data ingestion process, system data is continuously collected from multiple sources, processed, and mapped to the relevant policies and rules. This ensures that the dashboard reflects the most current and accurate information available. In addition, the dashboard highlights how system data retrieved through rules contributes to
Icon Parameters Description
Data Insights policies, providing a unified and actionable view of both configuration and operational data.
Storage Systems Storage Systems Configure CloudFS by supplying the master node credentials and establishing SMB connections. This process sets up and enables the integration between CloudFS and Panzura Nexus.
(1) AI Systems AI Systems Configure the Microsoft Copilot to establish connection with Panzura Nexus.
(2) Identity Management Identity Management Configure the AD credentials to establish connection with Panzura Nexus.
Rules Rules Define rules that determine how the policies are executed.
(3) Policies Policies Configure custom policies (like Data Insights) using Storage Systems, AI Systems, IAM, and rules.
(1) Jobs Jobs View to track full scans, export operations, and monitor the current status.
(11) Reports Reports View Data Insights full scans, policies, and related events, including both ongoing and completed tasks.
CONFIGURATION Settings Quick access to Settings like - License Management, Email Notifications, Network, Preferences, and NTP Configuration.
(12) Settings
MAINTENANCE Maintenance Manage and monitor core system maintenance tasks and operational activities.
(1) System Operations
(4) Alerts Tracks live processing metrics and system thresholds, generating notifications for important events or conditions.
(5) Audits Displays audit events generated by CloudFS, allowing administrators to review activity and trace operational actions within the environment.
User Profile Displays details of the user logged into the Panzura Nexus along with Build version, Help icon which
Icon Parameters Description
displays the Online Help, Replay
Tour which displays the guided tour of the Panzura Nexus UI and Logout option.
and Next and Previous To navigate to the previous or next pages.
Submit To save the configuration changes.

2.6 Panzura Nexus Dashboard

A centralized management and analytics platform designed to provide unified visibility and control across global file system deployments. It enables administration teams to monitor system health, track performance, and gain actionable insights across distributed environments from a single interface. By simplifying operations and enhancing observability, dashboard helps organizations ensure data availability, optimize performance, and confidently manage their hybrid and multi-site infrastructure.

Dashboard is divided into two sections:

  • System Overview
  • Data Insights

2.6.1 System Overview

Provides a unified summary of all key configurations and system health across the Panzura Nexus environment, enabling quick assessment and centralized management.

Overview

Provides a consolidated view of the configured Storage Plugins, AI Plugins, IAM Plugins, Rules, and Policies across Nexus. It displays the overall status and summarizes the total number of configuration instances, giving administrators quick insight into how the system is set up and managed.

You can view details of each instances by navigating over the tile.

Parameter Description
Storage Plugins Number of configured storage integrations.
AI Plugins Active AI-powered processing modules.
IAM Plugins Identity and access management integrations.
Rules Total rules currently applied across the system.
Policies Defined governance and control policies.
Ingested File Count Total number of files successfully ingested.
Total File Size Combined size of all ingested data.
Ingestion Failed Files Number of files that failed during ingestion.

A dashboard showing a system overview with metrics for plugins, rules, policies, and file ingestion statistics. This could be useful for illustrating data management, cloud storage monitoring, or software system administration.

CPU & Memory

Monitors real-time system performance, including CPU activity, load trends, and memory utilization.

Metric Description
CPU Usage Displays total CPU consumption over time, helping identify
spikes, sustained load, or idle periods.
CPU Usage by Mode Breaks down CPU utilization by mode:
User Time spent running user processes
System Kernel-level operations
I/O Wait (iowait) Time waiting for disk I/O
Nice Adjusted priority processes
IRQ / SoftIRQ Hardware and software interrupt handling
Steal Time taken by virtualized environments
System Load Average Shows system load across 1-minute, 5-minute, and 15-minute
intervals, indicating overall demand on CPU resources.
Memory Usage Visualizes memory allocation:
Used Memory actively in use
Buffers Temporary data for system operations
Cached Memory used for caching frequently accessed data
Free Available unused memory
Memory Usage % Provides a quick view of overall memory utilization, with
thresholds indicating normal, warning, and critical levels.

A dashboard displaying various system performance graphs including CPU usage, system load average, and memory utilization metrics. This is useful for illustrating server monitoring, resource management, and real-time system health analytics.

Disk Track disk utilization, capacity, and I/O performance across devices and mount points.

Metric Description
Disk Space Usage Shows disk usage across key mount points over time, helping
identify capacity trends and potential storage constraints.
Disk Available Lists current disk availability by device, including:
Device Disk or partition name
Filesystem Type Format (e.g., xfs, ext4, vfat)
Instance / Job Source of the metric data
Timestamp Latest recorded value
Disk I/O - Read Displays read throughput (MB/s) per device, useful for
identifying read-heavy workloads and performance
bottlenecks.
Disk I/O - Write Displays write throughput (MB/s) per device, highlighting
write activity and potential saturation points.

A dashboard displaying system metrics including disk space usage, disk availability, and disk I/O read and write rates. This is useful for illustrating server monitoring, system performance, and resource management.

Network & System

Monitor system stability, disk latency, and network activity to ensure overall operational health.

Metric Description
Disk I/O Time Shows the percentage of time disks are busy handling I/O
requests. Higher values may indicate disk contention or
performance bottlenecks.
Uptime Displays how long the system has been running without
interruption, helping track stability and recent restarts.
Swap Usage Tracks swap memory utilization over time. Consistent or high
swap usage may indicate memory pressure.
Network Traffic - Received Displays incoming network traffic (bytes/sec) on active
interfaces, useful for understanding inbound data flow.
Network Traffic - Transmitted Displays outgoing network traffic (bytes/sec), helping
monitor outbound communication and load.
Network Errors Tracks errors encountered on network interfaces, which may
indicate packet loss, misconfiguration, or hardware issues.
Network Connections Shows the number of active network connections, providing
insight into system load and connectivity patterns.

A system overview dashboard displaying real-time performance metrics including disk I/O, uptime, swap usage, and network traffic.

2.6.2 Data Insights

Data Insights in the Panzura Nexus Dashboard provides a consolidated view of the policy which displays graphs for following:

  • Event Counts by Processing Status and total file count ingestion and total file size The chart illustrates time series chart displaying number of events categorized by processing status(processing, complete, and failed) over time, along with the overall event volume. A time series line chart displays event counts categorized by processing status alongside total file count and size. This is useful for monitoring system performance and data ingestion workflows.
  • Total File Ingestion Stats

The chart illustrates the time series showing the total count and size of files ingested into the Al systems for the selected

policy. A line chart shows the increasing total file count and file size during a file ingestion process. This could be useful for illustrating system scaling, data processing trends, or resource monitoring.

  • File Ingestion Stats Over Time

The chart illustrates time series showing aggregated file count and file size over time based on the file ingestion activity into the AI system for the selected policy. A line chart showing time series data for file count and file size during ingestion. This could be useful for monitoring system load and data volume trends.

  • File Count Distribution by File Type

The chart illustrates time series showing total file count across different file types for the selected policy, accompanied by corresponding pie charts for additional visualization on the dashboard. A line chart showing the time series growth of total file counts for various file extensions. This is useful for illustrating data storage trends and file type distribution over time.

  • File Size Distribution by File Type

The chart illustrates the time series showing total file size across different file types for the selected policy, accompanied by corresponding pie charts for additional visualization on the dashboard. File Size Distribution by File Type (1) A line graph showing the cumulative file size in GiB for various file types over time. This could be useful for illustrating data storage growth, bandwidth usage, or file type distribution trends.

  • File Count Distribution by User

The chart illustrates the time series of total file counts across different users under the selected policy, accompanied by corresponding pie charts for additional visualization on the dashboard. A line chart showing the time series distribution of total file counts for User 1 and User 2. This could be useful for illustrating user activity trends and file accumulation over time.

  • File Size Distribution by User

The chart illustrates the time series showing total file size across different users for the selected policy, accompanied by corresponding pie charts for additional visualization on the dashboard. A line chart displays the increasing file size for User 2 compared to the constant size for User 1. This could be useful for illustrating data usage trends and storage consumption over time.

2.7 Getting Started with Panzura Nexus Configuration

Panzura Nexus Web UI Configuration

Before starting with Panzura Nexus configuration, ensure the audit settings for CloudFS are in place. If not, refer to the section and make the settings.

  1. Login to the Panzura Nexus web UI and configure the CloudFS Storage plugin.

Refer to the Configure Storage Systems section. 2. Configure AI Systems - Microsoft Copilot Plugin.

Refer to the Configure AI Systems section. 3. Configure Identity Management.

Refer to the Configure Identity Management section. 4. Set up Rules and Data Insight policies: a. Rules: To create specific filters or criteria to determine which data should be processed. Refer to Configure Rules section b. Policies: A policy defines how CloudFS events are processed by applying configured plugins and rules to collect and upload data and metadata to Copilot. Refer to Configure Data Insight Policy section 5. After the policy is created, perform the following steps: a. Activate the policy by clicking the icon. b. Log in to the Microsoft cloud admin site with global administrator access. c. Search for the Connector name "Nexus" in the Connector list. d. Click "Give visibility to Copilot" and confirm. 6. To have conversation with the data ingested into Copilot, configure the chat agent using following steps. Refer to Configure Microsoft Copilot Agent section.

2.8 Panzura Nexus Plugin Configuration

Panzura Nexus requires specific configuration parameters to function correctly. Providing these details in the web UI enables seamless integration and secure access to data sources.

2.8.1 Configure Storage Systems

Click on " + " on the right-corner to create a producer plugin and provide the following master node and SMB connection details and review them in the Summary section:

Master Node Information

Parameters Description
Name CloudFS plugin name.
Description CloudFS plugin description.
CloudFS Master Node Fully qualified domain name (FQDN) or IP address for
CloudFS master node.
Note: If the domain name has .local, instead of using FQDN
use IP address.
CloudFS User Administrator username.
Password Administrator password.
CloudFS SMB Node Hostname / IP address of the SMB node.
Note: If the domain name has .local, instead of using FQDN
use IP address.
Domain Domain where CloudFS and Panzura Nexus are deployed.
SMB User SMB username.
SMB Password SMB user password.
SMB Connections Number of SMB connections allowed.

Note: When Nexus reads CloudFS file content or metadata, the file access time (atime) is not updated.

2.8.2 Configure AI Systems

This information is required for Panzura Nexus to create a Copilot connector, enabling both data and metadata ingestion. Click " + " on the right-corner to create consumer plugin and provide the Microsoft Copilot settings details. Review the details in Summary section:

Parameters Description
Name Provide a user-friendly name for the Copilot plugin.
Description Microsoft Copilot plugin description.
Tenant ID The Tenant ID is obtained while enabling Microsoft 365
Copilot licensing. This value is required for establishing
secure integration between Nexus and Copilot.
Client ID The Client ID is generated during the application registration
process in Microsoft Entra ID. It is used to authenticate the
Nexus connection.
Parameters Description
Client Secret ID The Client Secret is also created during application
registration in Microsoft Entra ID and is used along with the
Client ID for secure authentication.

2.8.3 Configure Identity Management

Click "+" on the right-corner to create IAM plugin to ensure that on-prem Active Directory identities remain synchronized with Microsoft Entra ID, enabling seamless authentication and access management. By configuring the Entra ID Connector, organizations can automatically provision and sync end-user privileges, allowing users to securely access CloudFS data insights through Copilot. This provides a unified identity experience across on-prem and cloud environments. Provide the Active Directory connection details:

Parameters Description
Name Provide a user-friendly name for the Active Directory (AD)
integration.
Description Description of the AD configuration or purpose.
AD Domain Name Fully qualified domain name (FQDN) of the Active Directory
domain.
AD User Username with permission to query and sync from Active
Directory.
AD User Password Password for the AD user account.
AD Host FQDN or IP address of the Active Directory server.

2.8.4 Configure Rules

A Rule defines the specific filters or criteria used to determine which data should be processed - for example, allowing only selected file types such as PDF or DOCX. Events that do not match the defined criteria are ignored.

Click "+" on the right-corner to create a rule. Provide the following details:

Parameters Description
Name Name of the rule being created.
Description Description of the rule and its purpose.
Select Criteria Select the desired criterion from the dropdown to define
filtering conditions.
Add Criterion Adds a new criterion to the rule. Available Criterions are:
File Extension
File Path pattern
File Size
File Timestamps
Inclusive Criterion When enabled, the selected criterions are included in the
rule.
Add Another Criterion Allows adding multiple criterions to refine the rule further.

Rule Criterion: Several rule criterions can be created with extensions, path patterns, file size operators, timestamps types, date operators, etc.

File Criterions Parameters
File Extensions Following extensions are supported
  • .docx, .doc, .txt, .pdf, .jpeg, .jpg, .jpe, jfif, .png, and .dwg. Note: Can enter their own specific extensions. | | File Path | Path Pattern - User PCRE to enter the file path pattern. Case Sensitive - When enabled, the path pattern mentioned should be acceptable. Inclusive Criterion - When enabled, the files that satisfy the rule are included. | | File Size | Size Operator - Supported file size are "Greater than", "Less than", "Equal to", and "between". Size Value - Min 1MB. | | File Timestamps | Timestamp Type - Created and Modified Note: "Accessed" type is not supported. Date Operator - Before, After, and Between Start Date - File timestamp. |

To edit an existing rule:

  1. From the Rules, click the Edit icon.
  2. Update the fields and save the changes.

To delete the rule:

  1. From the Rules, click the Delete icon.
  2. Click "Delete Rule" on the confirmation message. The rule is deleted.

2.8.5 Configure Policies

A Policy combines the configured plugins and associated rules to determine how incoming CloudFS events are processed. When an event occurs, the policy governs how data and metadata are collected and uploaded to Copilot based on the defined configuration. Note: Admin user should be able to map one or more policies to intended users and/or groups.

Click + in right-corner to create Data Insight Policy using details of the plugins (CloudFS and Microsoft Copilot) configured. This procedure is divided into 5 stages:

Name Description
Step 1- Select Plugins
Name Name of the policy being created.
Description Description of the policy.
Source Select source as the CloudFS plugin.
Destination Select destination as the Copilot plugin.
Identity System Select the Active Directory plugin.
Step 2- Configuration
Restrict the file-system scope (Include Directories) Copy the absolute share path of the CloudFS file owner node
starting with "/cloudfs/". For example, "/cloudfs/
fileowner_node/sharename" or "/cloudfs/fileowner_node/.
This field accepts one or more values and is case-sensitive.
Override Additional ACLs Disable: The additional users and groups will be appended
to the existing ACL.
Enable: The existing ACLs will be overridden with Users and Groups selected.
Users The field is now searchable using a minimum of three characters of a SAM account name. The specified user(s) will have access to all the data ingested in Microsoft Copilot. Note: To avoid file ingestion failures caused by file-system ACLs, use an additional user account that is synced to Entra ID.
Groups The field is now searchable using a minimum of three characters of a SAM account name.
Note: To ensure all domain users can access the ingested data, search and add the 'Everyone' group to the group mapped to the AD 'Domain Users' group.
Parse Documents with OCR When enabled, the Optical Character Recognition (OCR) images included in the .docx and .pdf files will also be parsed.
Note: This parameter is disabled by default.
Step 3- Define Rules
Rules and Groups The existing rules are listed here. Using the "+" button, new rules can be created. Drag the required rules to create a group for the policy.
Step 4- Schedule
Scheduling Options Live Access Monitoring: Monitors real-time events, updates, data, and metadata changes on the file system. This parameter is enabled by default.
Schedule Incremental Scan: The policy scan can be scheduled using the following parameters. They appear when the checkbox is selected.
- Minute
- Hour
- Day
- Month
- Weekday
Note: By default, newly created policy is in "Inactive" state.
Step 5- Summary Review all details provided while creating the policy and click Submit to save the changes.

Note: The AI Systems Connector name is displayed. Once the policy is activated, a Connector is created in the AI system (viz: Microsoft Copilot) with the name <Panzura-Nexus-policy-id>. This Connector is unique to each policy, and all the data will be ingested into this Connector. Refer to the screenshot.

A screenshot of a TextExtensionPolicy configuration interface showing details like Description, Source, and AI Connector Name. This could be useful for illustrating software configuration settings or cloud data management policies.

Important note: Do not alter the Connector name within the AI System. Any modification will immediately invalidate the Connector and prevent it from functioning properly.

Following operations can be performed on the policy:

File Criterions Parameters
Activate Once the policy is created, activate using the icon to be operational. Activating the policy will start all the components and microservices.
Activating a policy has following parameters:
Activate in Dry Run Mode - This option is used as a precheck for any new rules/policies created to check for the files are getting filtered correctly. Note that, no data is ingested in Microsoft Copilot.
Start immediate full scan - To start the full scan of files immediately only if no other scan is already running. Note: When a new policy is created and activated for the first time, it integrates with the Microsoft website to create a connector, which may take some time.
Start Scan This option is disabled when the policy is created. After activating the policy, this option is enabled. Start scan comprises of two scan options:
Full Scan - Scans all the files available on the SMB share.
Incremental Scan - Scan the files that were modified, created or had ACL changes, since the last scan.
Delete Policy A confirmation message appears and by enabling the "I acknowledge" toggle button, the policy can be deleted.
Close It closes the Actions panel.
Deactivate This option is available only when the policy is active and it needs to be deactivated.

Edit the policy

Using the Edit icon, you can make updates to the existing policy.

  1. Click on policy which needs to be updated.
  2. Using the Edit icon on the right-corner, make the required changes to the policy and click Save.

Notes:

The following points are with respect to any changes made to the policy and when the policy is effective:

  1. Any changes made to the policy are saved automatically; there is no need to deactivate and re-activate the policy.
  1. Policy updates cannot be made while an active scan is running on the policy.
  2. Updating rules associated with an active policy moves the policy into an updating state. Changes made in the Configuration tab take effect immediately.
  3. Override Additional ACLs when enabled will override the User and Groups provided while configuring the policy.
  4. Any changes to the policy or previously ingested files will take effect only after a full scan is executed.
  5. Only one plugin configuration should be created per CloudFS ring. Creating multiple plugin configurations from the same CloudFS ring can result in policies being stuck in the "Activating" state.

Delete the policy:

Click on the Delete icon to remove the policy.

2.9 Panzura Nexus Statistics

Provides a centralized interface for monitoring system activity, data ingestion, and operational events. It offers visibility into realtime processing, audit events, alerts, jobs, and reports, enabling administrators to track system behavior and respond to conditions efficiently.

2.9.1 Jobs

The Jobs page displays current and scheduled jobs and processes executed in the system. It enables administrators to track job execution, review outcomes, and troubleshoot issues by providing detailed timing, status, and message information for each job.

Job page displays manual scans, schedule scans, policy deletion jobs, report and audit export / download/ pdf/cvs/json.

Current tab

Each job entry in Current tab includes the following:

Column Description
Job Name Name of the Job on which the operation is performed.
Message Describes the operation performed or the reason for job
completion or cancellation.
Scheduled Time The date and time when the job was scheduled to run.
Status Indicates the job outcome, such as Succeeded or Cancelled.
Status consists of following fields: Enqueued, Running,
Cancelled, Succeeded, Failed, Timedout, and Paused.
Start Time The actual date and time when the job execution began.
End Time The date and time when the job completed or was stopped.

The right pane provides tools to help manage and analyze job records:

Action Description
Filters Narrow down jobs based on criteria such as status or time.
Refresh Reloads the job list to display the latest updates.
Enter Full Screen Expands the view for easier monitoring of jobs.
Toggle Columns Shows or hides columns to customize the table layout.

Actions on Jobs

The Nexus web UI allows administrators to pause, resume, or cancel job execution as needed. These actions are available only on a scanned job.

  • Pause: Temporarily halts a running job. This can be useful if system resources need to be reallocated or if an operation must be temporarily stopped without cancelling it.
  • Resume: Restarts a paused job from the point where it was halted, allowing the job to continue processing without starting over.
  • Cancel: Only jobs with a status of "Paused" can be cancelled using this option. Jobs with a status of "Cancelled", "Failed", or "Succeeded" cannot be cancelled.

These controls give administrators flexibility in managing long-running or resource-intensive jobs. Note: The Pause, Resume, and Cancel options are not available for Backup jobs.

Scheduled tab

This tab displays different status of the job in a Calendar format. Types of status are: Elapsed, Cancelled, and Scheduled.

Job CURRENT SCHEDULED
( March 2026 Elapsed Scheduled Cancelled
Sun Mon Tue Wed Thu Fri Sat
1 3 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
23 23 24 26 27 28
29 30 31

2.9.2 Reports

The Reports section provides summarized insights and structured outputs that support review, compliance, and operational analysis. It allows administrators to generate and view detailed reports based on selected policies and scans.

Data Insights Policy - Scan Report

The Scan Report displays results for a selected Policy Name and Scan, presenting file-level insights generated during policy scans.

To view the Scan Report:

  1. Select a Policy Name from the Select Scan panel.
  2. Choose the corresponding Time and click Fetch Report Data. The report data is displayed in the main table view.

The Scan Report table describes the following:

Column Description
File Path Displays the location of the file identified during the scan.
File Size Indicates the size of the file included in the report.
Created Date Indicates the date of the file created.
Status Indicates the status of the report.
Status of the reports are: Completed, Failed, In progress,
Pause, and Cancelled

The following tables describe the details of the controls on the Reports Categories.

Controls Description
Search Searches within the report results displayed on the page.
Open Filters > Policy Name Selector Allows selection of a policy to view its associated scan
reports.
Scan Selector Enables selection of a specific scan for the chosen policy.
Close Panel Closes the Select Scan panel.

Actions on the Scan report available for that report are:

Parameters Description
Export Options Export options are PDF, CSV, and JSON
Refresh All Refresh all the rows.
Enter Fullscreen Displays a full screen view of the report.
Toggle columns Add and remove columns as required.

Data Insights Policy - Catalog Items

Catalog Items refer to the set of files ingested into AI systems that can be selected for deletion. Each Catalog Item displays following:

Parameters Description
File Path Displays the location of the file identified during the scan.
MIME Type Indicates the format of a file or data.
File Size Indicates the size of the file included in the report.
Created Date Indicates the created date of the item.
Modified Date Indicates the modified date of the item.

These attributes are shown in the context of the selected policy, allowing users to manage and remove specific items as needed. Additional metadata columns are available through the "Toggle Columns" option in the upper-right corner of the Catalog page. These columns provide detailed information about ingestion status, scan history, file ownership, access control processing, and storage location for each catalog item.

Parameters Description
File Path Displays the location of the file identified during the scan.
MIME Type Indicates the format of a file or data.
File Size Indicates the size of the file included in the report.
Created Date Indicates the created date of the item.
Modified Date Indicates the modified date of the item.
Ingestion State Indicates the status of the ingestion process for the catalog
item. Failed or Partial success state indicates that one or
more ACL entries could not be resolved because the
associated users or groups are not synchronized to Microsoft
Entra ID.
Parameters Description
Error Message Displays details about the error encountered during ingestion.
Failed ACLs Displays the unresolved ACL entries that caused the ingestion failure.
Note: Failed ACLs containing SIDs associated with wellknown RIDs below 1000 are no longer displayed in Microsoft Entra ID, as these identities are not expected to exist in Entra ID.
Checksum Displays the checksum value used to verify file integrity.
Last Ingested Date Indicates when the item was last ingested.
Last Scan Type Indicates the type of scan that last processed the item.
Last Scan ID Displays the unique identifier of the last scan.
Last Modified By Indicates the user who last modified the item.
User Displays the user associated with the item.
Group Displays the group associated with the item.
Storage Node Displays the storage location where the item resides.

To view the Catalog Items:

  1. Select a Policy Name from the Select Scan panel.
  2. Choose the corresponding Time and click Fetch Report Data. The report data is displayed in the main table view.

To delete the Catalog Items:

  1. Select catalog item(s) from the table.
  2. Click on the Delete icon to delete the Catalog Item.

To view the ACL permission: ACL permission is the permission granted to individual files and groups.

  1. On the Data Insights Policy - Catalog, click on the "View Access Permissions" icon.
  2. A pop-up opens which displays the path of the file and read access granted to individuals or groups.

Access Permissions

/cloudfs/tt-nexus-mnode/mshare/Perf Data S...Resumes PDF/Accountant/t.pdf

Read Access Granted Tabasum Tamboli dl-eng

2.10 Panzura Nexus Configuration

Configuration section provides access to system-level options that control how the application operates. It allows administrators to manage and customize core functionalities to ensure the system works according to organizational requirements.

2.10.1 Settings

The Settings option under Configuration is used to define and manage specific system parameters. This includes configuring features such as email server details, authentication options, and other operational preferences required for system monitoring and notifications.

License Management

Nexus requires a valid license to operate. Licensing for Nexus is based on the source storage file system capacity (for example, Managed Capacity (MC) in a CloudFS deployment).

Key principles for Nexus license management:

  • License is primarily tied to storage system capacity (e.g., CloudFS managed capacity).
  • Additional license types (such as AI request quota or user/node limits) are supported through the same token format.
  • Licensing is enforced using a token string mechanism that you register in the Nexus System Management UI.
  • If a valid license is not present or is invalid, Nexus raises a critical alert and may change behavior depending on the configured enforcement model.

ABOUT LICENSE TOKEN

Nexus uses a token-based license key:

  • The license is an alphanumeric encrypted string with a fixed length of 32 bytes (before encoding) and is presented as a 49-character Base32 string for administrators.
  • The token encodes:
  • Product identifier.
  • License type (capacity, AI requests, users, nodes, etc.).
  • License value (e.g., TB, requests/month).
  • Environment (Dev, Eval, Prod).
  • Expiry information.
  • System binding information (system ID hash).
  • Reserved space for future attributes.

INSTALLING LICENSE FROM WEB UI

Prerequisites:

  • Contact Panzura Support / Sales team to get access to the license key.

How to install (add) license

  1. Click Install License to install license when installing it for the first time or click "+" to open Install License pop-up.
  2. Paste the license key into the License Key field and click Install. The license key is added in the table.

The License Management tables displays the following parameters:

License Status Key Type Capacity Expiry Date
Red / Green License key format
XXXX-XXXXXXXX-
XXXXXXXX- Storage Unit
Managed Capacity Greater than or
equal to Storage
Systems Capacity Date, HH:MM:SS
License Status Key Type Capacity Expiry Date
XXXXXXXX-
XXXXXXXX-
XXXXXXXX

License Status: RED - Indicates that the license is expired. GREEN - Indicates that license is valid. Alerts for License Management The following alerts are generated in Alerts Management >> Live or Historical.

  1. License is not installed.
  2. License key is expired.
  3. If Storage Systems capacity exceeds the license token.

Note: Add a new token when you want to extend the capacity or it is expired.

Email Notifications

This section allows administrators to configure SMTP details for sending system alert notifications via email. In this configuration, SMTP authentication is enabled to ensure secure access to the mail server.

Email Notifications fields consists of following fields:

Parameters Description
SMTP Server Enter the hostname or IP address of the SMTP server used to
send alert emails.
SMTP Port Specify the port number used by the SMTP server.
Sender Email Address Enter email address to receive alert notifications.
Username / Password - Enter the username for SMTP server authentication.
- Enter the password associated with the SMTP username.
Receiver Email Address Enter one or more email addresses to receive alert
notifications.
Use Encryption Enable to encrypt outgoing emails using SMTPS.

After submitting the configuration, a summary is displayed with Send Test Email. You can test the connection. A settings interface displaying an Email Notifications configuration menu with fields for SMTP server and email addresses. This is useful for illustrating software configuration, email setup, or administrative settings.

Network Configuration

The Network Configuration consists of following parameters:

Parameters Description
System Configuration - Hostname
- FQDN
LAN Configuration - LAN Interface
- IP Assignment
- LAN IP Address
- LAN Subnet Mask
- LAN Gateway
- LAN MTU
- Primary DNS
- Secondary DNS
WAN Configuration - Use same as LAN
Note: Select "Use same as LAN" to apply LAN settings to WAN traffic, or configure a dedicated WAN interface if your deployment requires separate network settings.

A screenshot of a software settings menu showing network and system configuration options for an Azure platform. This is useful for illustrating network administration, cloud platform settings, or software user interfaces.

Note: Modifying the Network configuration will restart all Nexus services, which may cause a brief interruption in system operations.

Edit Network Configuration

The Network Configuration configured during setup wizard can be updated using the Edit icon.

View Available Interfaces

The Available Interfaces display details such as:

  • Interface
  • Type
  • IP Address
  • Subnet Mask
  • Gateway

Available Network Interfaces (1)

Interface Type IP Address Subnet Mask Gateway

Preferences

The Preferences section allows administrators to configure system-wide settings that enhances user experience and optimize system behavior.

Parameter Description
Log Level Select the desired verbosity for system logs. Available
options include:
- DEBUG
- INFO
- WARN
- ERROR
This setting controls the level of detail recorded in logs
across all system components, such as the engine, web
server, and plugins. Changing the log level takes effect
system-wide.
Session Timeout Specify how long a user session remains active before
requiring re-login. The value is set in days and applies to all
users. Changes to this setting take effect immediately for all
active sessions, enhancing security by ensuring sessions do
not remain open indefinitely.
These preferences help administrators tailor system behavior
and security according to organizational needs.
Local Backup Retention Specifies the maximum number of local backups that are
kept. The default value is 5 . If this limit is exceeded, the
oldest local backup is automatically deleted.
Cloud Backup Retention Specifies the maximum number of cloud backups that are
kept. The default value is 10 . If this limit is exceeded, the
oldest cloud backup is automatically deleted.

NTP Configuration

The NTP (Network Time Protocol) Configuration section allows administrators to set the system's time synchronization parameters. Accurate timekeeping is essential for system operations, event logging, and security.

Parameter Description Example
NTP Servers Specify the NTP server(s) that the
system will use to synchronize its
clock. time.google.com
System Timezone Set the system's timezone to ensure
that all logs, scheduled tasks, and
timestamps reflect the correct local
time. The timezone is displayed in
standard format. America/Los_Angeles

These settings are editable and can be adjusted as needed to maintain consistent and accurate time across all system components.

Note: Modifying the NTP configuration will restart all Nexus services, which may cause a brief interruption in system operations.

2.10.2 Register the application in Microsoft Entra ID

Follow the steps to register the application in Microsoft Entra ID:

  1. Login to Microsoft cloud services website using admin credentials.
  2. Navigate to Admin center > All admin centers > Microsoft Entra which redirects to the Microsoft Entra admin console.
  3. From the left-side menu, Entra ID > App registrations > Owned applications tab > click +New registration. Provide the following details to create the application:
  4. Name: A display name to the app.
  5. Select "Accounts in this organizational directory only (org_name only - Single tenant)".
  6. Click Register. The application is created. From the Overview of the created application, note the following: Tenant ID Client ID (Application ID).
  7. From the left menu, under Manage > API permissions, click +Add a permission.
  8. A new pane titled "Request API permissions" opens. Select Microsoft Graph, then choose Delegated permissions and add the required permissions. Next, select Application permissions and add the necessary permissions. Use the permissions listed in the following tables:

Delegated permissions

Permission name ExternalItem.Read.All Files.Read.All Sites.Read.All User.Read

Application permissions

Permission name AiEnterpriseInteraction.Read.All AppCatalog.ReadWrite.All ExternalConnection.ReadWrite.All ExternalItem.ReadWrite.All

Permission name

Group.Read.All

User.Read.All

Application.ReadWrite.All

Organization.Read.All 4. Click "Grant admin consent for (org_name)". Click Yes on the confirmation message. The status is updated against each permission. 5. Navigate to Manage > Certificates & secrets > Client secrets tab. Click "+New client secret". Provide a user-facing Name to the client secret and select the Expires value from the dropdown. Note: The client secret expires and can be configured for a maximum of 2 years. 6. The client secret is displayed in the table. Note the "Value" using "Copy to clipboard". The "Value" is the Client Secret, and this value is required while configuring AI Systems in Nexus.

Refer to the following links for more details: License options for Microsoft 365 Copilot Register an application in Microsoft Entra ID Add and manage application credentials in Microsoft Entra ID Add permissions to access Microsoft Graph

2.10.3 Agents

This topic covers the step-by-step manual guidance to set up Microsoft Custom Connector and register the app in the Entra ID.

Configure Microsoft Copilot Custom Agent (Manually)

This Microsoft Copilot Custom Agent allows users to search and explore files ingested in Panzura Nexus using natural language. It helps quickly find relevant information and get meaningful answers from stored content.

Note: The following procedures describe how to configure a custom agent using Microsoft Copilot. Ensure all prerequisites are met before you begin.

Prerequisites:

  1. Before performing this procedure, make sure that the following parameters are kept handy. Refer to the section to Register the application in Microsoft Entra ID to get the following parameters.
  • Tenant ID
  • Client ID
  • Client secret
  • AI Connector ID: Note this ID from Nexus web UI > Policies.
  1. You need access to the following portals:
  • Azure Entra ID
  • Microsoft Copilot Studio
  • Microsoft 365 Copilot
  • Microsoft Cloud Admin for approving the agent

Important Note: The setup requires navigating between multiple browser sessions and includes several transitions between steps. Do not close any of the browser sessions during the process, and read the instructions carefully to ensure each step is followed in the correct order.

A. Steps to create Custom Connector

On the Custom Connector page, perform the following actions:

  1. Navigate to Microsoft Copilot Studio.
  2. Click "Tools" from the menu on the left pane.
  3. Click "+ New Tool" > Select Custom Connector.
  4. Click "+ New custom Connector" and select Create from Blank.
  5. On the General tab, provide the following details:
  • Connector Name: (pre-filled)
  • Description: Provide the description
  • Scheme: HTTPS
  • Host: graph.microsoft.com
  1. Click the Security tab and configure:
  • Authentication type: OAuth 2.0
  • Identity Provider: Azure Active Directory
  • Client ID, Client secret, Tenant ID
  • Resource URL: https://graph.microsoft.com
  • Enable on-behalf-of login: true
  • Scope: User.Read Files.Read Sites.Read.All, ExternalItem.Read.All
  • Redirect URL: Generated after clicking Create Connector. Make a note of this URL. Click Create Connector.

Note: Do not switch to another tab without clicking Create Connector. Otherwise, values entered in the Security tab may be lost. You will have to come back to this site after executing steps 5-9. 7. Log in to Microsoft Entra ID and navigate to:

Entra ID > App registrations.

  1. Locate the app created in Register the application in Microsoft Entra ID.
  2. Click Authentication > "Redirect URI configuration" tab.
  3. Click the + Add Redirect URI. A new pane opens on the right side to select a platform. Click Web and add the copied Redirect URL. Do not delete the URLs that are already present.
  4. Click Configure. Exit from the Microsoft Entra ID portal.
  5. Go back to the make.powerapps.com tab where you were in step 4 and click the Definition tab. Enable the Swagger editor. Remove existing content and paste the following Swagger definition: Note: This is a long block of code. Scroll down carefully as you might miss a step, an instruction or an important note.
swagger: '2.0'
info:
    title: panzura-nexus-conn-schema-v03
    description: Retrieve results from Panzura CloudFS
    version: '1.0'
x-ms-connector-metadata:
    - propertyName: Website
    propertyValue: https://panzura.com
    - propertyName: Privacy policy
    propertyValue: https://panzura.com/privacy-policy
    - propertyName: Categories
    propertyValue: Standard
    - propertyName: iconBackground
    propertyValue: '#40E0D0'
host: graph.microsoft.com
basePath: /
schemes:
    - https
consumes:
    - application/json
produces:
    - application/json
paths:
    /v1.8/search/query;
    post:
    operationId: SearchNexus
    summary: Search Nexus Data
    description: Retrieve results from Panzura CloudFS
    parameters:
        - name: body
        in: body
        required: true
        schema:
            $ref: '#/definitions/SearchRequest'
            x-ms-description: Search query parameters
            x-ms-summary: Search Request
    responses:
        '200':
        description: Success
        schema:
            type: object
            properties:
                value:
                    description: value
                    type: array
                    items:
                    type: object
                    properties:
                    searchTerms:
                    description: searchTerms
                    type: array
                    items:
                    type: string
                    hitsContainers:
                    description: hitsContainers
                    type: array
                    items:
                    type: object
                    properties:
                    hits:
                    description: hits
                    type: array
                    items:
                    type: object
                    properties:
                    hitId:
                    description: hitId
                    type: string
                    contentSource:
                    description: contentSource
                    type: string
                    rank:
                    description: rank
                    type: integer
                    format: int32
                    summary:
                    description: summary
                    type: string
                    resource:
                    description: resource
                    type: object
                    properties:
                        '@odata.type':
                    description: '@odata.type'
                    type: string
                    x-ms-client-name: odataType
                    properties:
                    description: properties
                    type: object
                    properties:
                    documentId:
                    type: integer
                    format: int32
                    description: documentId
                    fileID:
                    type: string
                    description: fileID
                    hitHighlightedProperties:
                    type: string
                    description: hitHighlightedProperties
                    id:
                    type: string
            description: id
                    immutableEntryId:
                    type: string
                    description: immutableEntryId
                    label_FileExtension:
                    type: string
                    description: label_FileExtension
                    label_FileName:
                    type: string
                    description: label_FileName
                    label_LastModifiedBy:
                    type: string
                    description: label_LastModifiedBy
                    label_LastModifiedDateTime:
                    type: string
                    description: label_LastModifiedDateTime
                    label_Title:
                    type: string
                    description: label_Title
                    label_URL:
                    type: string
                    description: label_URL
                    owner:
                    type: string
                    description: owner
                    path:
                    type: string
                    description: path
                    substrateLocationId:
                    type: string
                    description: substrateLocationId
                    url:
                    type: string
                    description: url
                    total:
                    description: total
                    type: integer
                    format: int32
                    moreResultsAvailable:
                    description: moreResultsAvailable
                    type: boolean
            '@odata.context':
            description: '@odata.context'
                type: string
                x-ms-client-name: odataContext
            x-ms-examples:
            application/json:
                value:
                    value: []
                    '@odata.context': https://graph.microsoft.com/v1.0/$metadata#search
            '400':
            description: Bad Request
            default:
            description: Error
            consumes:
            - application/json
            produces:
            - application/json
x-ms-description: Retrieve results from Panzura CloudPS
x-ms-examples:
            application/json:
                value:
                    query: query string
                    filter: ''
                    size: 50
                    offset: 0
                    contentSource: /external/connections/nexus
x-ms-summary: Search Nexus Data
x-ms-visibility: important
/v1.0/external/connections/{connection-id}/items/{item-id}:
get:
    operationId: GetExternalItem
    summary: Get External Item In Chunks
    description: =-
        Retrieve an external item in chunks to handle large files. Each call
        returns a portion of the content.
    parameters:
    - name: connection-id
        in: path
        description: The ID of the external connection
    required: true
    type: string
    x-ms-summary: Connection ID
    x-ms-visibility: important
    - name: item-id
    in: path
    description: The ID of the external item
    required: true
    type: string
    x-ms-summary: Item ID
    x-ms-visibility: important
    - name: chunk
    in: query
    description: >-
        The chunk index to retrieve (0-based). Required for chunked
        retrieval.
    required: true
    type: integer
    format: int32
    minimum: 0
    default: 0
    x-ms-summary: Chunk Index
    x-ms-visibility: important
    - name: chunkSize
    in: query
    description: >-
        Size of each chunk in bytes. Default is 76000 (75KB). Minimum 1024,
        maximum 10485760 (10MB).
    required: false
    type: integer
    format: int32
    minimum: 1024
    maximum: 10485760
    default: 76000
    x-ms-summary: Chunk Size (bytes)
    x-ms-visibility: advanced
    - name: useChunking
    in: query
    description: >-
        Enable or disable chunking. When false, returns full item like the
        non-chunked endpoint.
    required: false
    type: boolean
    default: true
    x-ms-summary: Enable Chunking
    x-ms-visibility: advanced
    - name: $select
    in: query
    description: OData $select query parameter to specify properties to return
    required: false
    type: string
    x-ms-summary: Select Properties
    x-ms-visibility: advanced
responses:
    '200':
    description: Success - Returns a chunk of the external item
    headers:
    X-Item-Chunk-Index:
        type: integer
        format: int32
        description: The chunk index returned
    X-Item-Total-Chunks:
        type: integer
        format: int32
        description: Total number of chunks available
    X-Item-Is-Last-Chunk:
        type: boolean
        description: Whether this is the last chunk
    X-Item-Chunk-Size:
        type: integer
        format: int32
        description: Size of this chunk in bytes
    X-Item-Total-Size:
        type: integer
        format: int32
        description: Total size of the content in bytes
    schema:
        $ref: '#/definitions/ChunkedExternalItemResponse'
    x-ms-examples:
        application/json:
        value:
            id: '12345'
            properties:
            fileExtension: .pdf
            fileName: doc.pdf
            fileSize: 1824800
            lastModifiedDateTime: '2024-01-15T10:30:00Z'
            owner: [email protected]
            path: /documents/doc.pdf
            title: Large Document
            url: https://example.com/doc.pdf
            acl:
                type: user
                    value: [email protected]
                    accessType: grant
            content:
            type: text
            value: First 75000 of the document content...
            isPartial: true
            chunkInfo:
                startByte: 0
                endByte: 102399
                chunkIndex: 0
                totalChunks: 10
                charsInChunk: 75000
            chunkMetadata:
                chunkIndex: 0
                chunkSize: 76800
                totalChunks: 14
                isLastChunk: false
                chunkingEnabled: true
                totalSizeBytes: 1024800
                originalContentLength: 1250000
                '@odata.type': '#microsoft.graph.externalItem'
    '400':
    description: Bad Request - Invalid chunk parameters
        schema:
            type: object
            properties:
                error:
                    type: object
                    properties:
                    code:
                        type: string
                        enum:
                            - InvalidChunkIndex
                            - InvalidChunkSize
                    message:
                        type: string
    '404':
    description: Item not found
        schema:
            type: object
            properties:
                error:
                    type: object
                    properties:
                    code:
                        type: string
                    message:
                        type: string
    default:
        description: Error
    x-ms-description: >
        Retrieve large external items in manageable chunks to avoid size
        limitations
    x-ms-summary: Get External Item In Chunks
    x-ms-visibility: important
definitions:
SearchRequest:
type: object
required:
    - query
    properties:
    query:
    description: query string
    type: string
    x-ms-visibility: important
    filter:
    description: Key:value pair composed with and-or conditions
    type: string
    default: ''
    size:
    description: size
    type: integer
    format: int32
    default: 50
    offset:
    description: offset
    type: integer
    format: int32
    default: 0
    contentSource:
    description: external content source
    type: string
    default: /external/connections/nexus
    example:
    query: query string
    filter: ''
    size: 50
    offset: 0
    contentSource: /external/connections/nexus
ChunkedExternalItemResponse:
    type: object
    properties:
    id:
    description: The unique identifier of the item
    type: string
    properties:
    description: The properties of the external item
    type: object
    additionalProperties: true
    acl:
    description: Access control list for the item
    type: array
    items:
        type: object
        properties:
            type:
                type: string
                enum:
                    - user
                    - group
                    - everyone
            value:
                type: string
            accessType:
                type: string
                enum:
                    - grant
                    - deny
    content:
    description: Chunked content of the external item
    type: object
    properties:
        type:
            type: string
            description: Content type (e.g., text, html)
        value:
            type: string
            description: The chunked content value
            isPartial:
                type: boolean
            description: Indicates if this is a partial content chunk
            chunkInfo:
                type: object
            properties:
                startByte:
                    type: integer
                    format: int32
                    description: Starting byte position of this chunk
                    endByte:
                        type: integer
                        format: int32
                        description: Ending byte position of this chunk
                    chunkIndex:
                        type: integer
                        format: int32
                        description: The index of this chunk (0-based)
                    totalChunks:
            type: integer
                format: int32
                description: Total number of chunks
                charsInChunk:
                    type: integer
                    format: int32
                    description: Number of characters in this chunk
    activities:
    description: Activities associated with the item
    type: array
    items:
        type: object
    chunkMetadata:
    description: Metadata about the chunking operation
    type: object
    properties:
        chunkIndex:
            type: integer
            format: int32
            description: The chunk index returned
            chunkSize:
                type: integer
                    format: int32
                    description: Size of each chunk in bytes
            totalChunks:
                type: integer
                format: int32
            description: Total number of chunks
            isLastChunk:
                type: boolean
            description: Whether this is the last chunk
            chunkingEnabled:
                type: boolean
            description: Whether chunking is enabled
            totalSizeBytes:
                type: integer
                format: int32
                description: Total size of the content in bytes
            originalContentLength:
                type: integer
                format: int32
            description: Original content length in characters
    '@odata.type':
        description: OData type

Note: As soon as the code is pasted in Swagger, two methods are displayed on the right side under default:

  • POST: Search Nexus Data
  • GET: Get External Item in Chunks

Disable the Swagger editor toggle. You are directed to Power apps again, scroll down and the click Code.

  1. On to the Code tab, toggle the Code Disabled and enable it. Paste the following code and click Update connector to deploy it.
using System;
using System.Net;
using System.Net.Http;
using System.Threading.Tasks;
using Newtonsoft.Json.Linq;
using System.Text;
using System.Linq;
using System.Collections.Specialized;
public class Script : ScriptBase
{
    // Configuration constants for chunking
    private const int DEFAULT_CHUNK_SIZE_BYTES = 60000; // 60K chunk
    private const string CHUNK_QUERY_PARAM = "chunk";
    private const string CHUNK_SIZE_PARAM = "chunkSize";
    private const string USE_CHUNKING_PARAM = "useChunking";
    public override async Task=HttpResponseMessage> ExecuteAsync()
    {
    // Handle possible base64 encoding for OperationId
    string opId = this.Context.OperationId;
    try
    {
    byte[] data = Convert.FromBase64String(opId);
    opId = Encoding.UTF8.GetString(data);
    }
    catch { }
    if (opId == "SearchNexus")
    {
        return await HandleSearchWrapper().ConfigureAwait(false);
    }
    if (opId == "GetExternalItem")
    {
        return await HandleGetExternalItemChunked().ConfigureAwait(false);
    }
    // Fallback: unknown operation
    HttpResponseMessage error = new HttpResponseMessage(HttpStatusCode.BadRequest);
    error.Content = CreateJsonContent($"Unknown operation ID '{opId}'");
    return error;
    }
    private async Task<HttpResponseMessage> HandleGetExternalItem()
    }
    // Extract path parameters from context
    var pathParams = this.Context.Request.RequestUri.AbsolutePath;
    // For now, forward the request directly to Graph API
    var outbound = new HttpRequestMessage(
    HttpMethod.Get,
    $"https://graph.microsoft.com{pathParams}");
// Preserve query parameters
if (this.Context.Request.RequestUri.Query != null)
{
    outbound.RequestUri = new Uri($"https://graph.microsoft.com{pathParams}{this.Context.Request.RequestUri.Query}");
}
// Forward authorization header
    if (this.Context.Request.Headers.TryGetValues("Authorization", out var authHeaders))
    {
        outbound.Headers.TryAddWithoutValidation("Authorization", authHeaders);
    }
    // Forward the request
        return await this.Context.SendAsync(outbound, this.CancellationToken)
        .ConfigureAwait(false);
    }
private async Task<HttpResponseMessage> HandleGetExternalItemChunked()
{
    HttpStatusCode statusCode = HttpStatusCode.InternalServerError;
    try
    {
    // Parse query parameters
    NameValueCollection queryParams = System.Web.HttpUtility.ParseQueryString
    (this.Context.Request.RequestUri.Query);
    // Get chunking parameters
    int chunkIndex = 0;
    if (!string.IsNull0rEmpty(queryParams[CHUNK_QUERY_PARAM]))
    {
    int.TryParse(queryParams[CHUNK_QUERY_PARAM], out chunkIndex);
    }
    int chunkSize = DEFAULT_CHUNK_SIZE_BYTES;
    if (!string.IsNull0rEmpty(queryParams[CHUNK_SIZE_PARAM]))
    {
    int.TryParse(queryParams[CHUNK_SIZE_PARAM], out chunkSize);
    chunkSize = Math.Max(1024, Math.Min(chunkSize, 10 * 1024 * 1024));
    // Min 1KB, Max 10MB
    }
    bool useChunking = true;
if (!string.IsNull0rEmpty(queryParams[USE_CHUNKING_PARAM]))
{
    bool.TryParse(queryParams[USE_CHUNKING_PARAM], out useChunking);
}
/*
//Debugging: Enable this to send api params back to caller
var pathParams = this.Context.Request.RequestUri.AbsolutePath;
    if (pathParams.EndsWith("/chunked", StringComparison.OrdinalIgnoreCase))
    {
        pathParams = pathParams.Substring(0, pathParams.Length - "/chunked".Length);
    }
    JObject wrappedBody = new JObject {
    ["PathParams"] = pathParams,
    ["UseChunking"] = useChunking,
    ["chunksize"] = chunkSize,
    ["chunkIndex"] = chunkIndex
};
var response = new HttpResponseMessage(HttpStatusCode.OK);
response.Content = CreateJsonContent(wrappedBody.ToString());
return response;
*/
    // If chunking is explicitly disabled, fall back to original behavior
    if (!useChunking || chunkIndex == 0 && chunkSize <= 0)
{
    return await HandleGetExternalItem().ConfigureAwait(false);
}
// Fetch the full item from Microsoft Graph
    var fullItemResponse = await FetchFullExternalItemForChunking(queryParams).
    ConfigureAwait(false);
    if (!fullItemResponse.IsSuccessStatusCode)
    {
        return CreateEmptyContentResponse(fullItemResponse.StatusCode); // Error... Return empty response
    }
        statusCode = fullItemResponse.StatusCode;
// Parse the full response
string responseContent = await fullItemResponse.Content.ReadAsStringAsync().ConfigureAwait(false);
    // If response is empty or invalid JSON, return empty response
if (string.IsNullOrWhiteSpace(responseContent))
{
    return CreateEmptyContentResponse();
}
    var fullItem = JObject.Parse(responseContent);
// Apply chunking logic
return ApplyChunkingToResponse(fullItem, chunkIndex, chunkSize);
}
catch (Exception ex)
{
    // JSON parsing or processing error - return empty but successful
    return CreateEmptyContentResponse(statusCode);
    }
}
private HttpResponseMessage CreateEmptyContentResponse
    (HttpStatusCode statusCode = HttpStatusCode.InternalServerError)
    {
        // Create a response with empty content but successful status
        var emptyResponse = new JObject
        {
            ["id"] = "empty",
["@odata.context"] = "https://graph.microsoft.com/v1.0/§metadata#external/connectors/externalItem/$entity",
["content"] = new JObject
{
    ["type"] = "text",
["value"] = "" // Empty string
},
["chunkMetadata"] = new JObject
{
    ["chunkIndex"] = 0,
["chunkSize"] = DEFAULT_CHUNK_SIZE_BYTES,
["totalChunks"] = 1,
["isLastChunk"] = true,
["chunkingEnabled"] = true,
["totalSizeBytes"] = 0,
["errorSuppressed"] = true,
["originalErrorCode"] = ((int)statusCode).ToString() // Include original error code in metadata
}
};
var response = new HttpResponseMessage(HttpStatusCode.OK);
    response.Content = CreateJsonContent(emptyResponse.ToString(Newtonsoft.Json.Formatting.None));
        // Add custom headers indicating empty response
    response.Headers.Add("X-Item-Chunk-Index", "0");
    response.Headers.Add("X-Item-Total-Chunks", "1");
    response.Headers.Add("X-Item-Is-Last-Chunk", "true");
    response.Headers.Add("X-Item-Chunk-Size", DEFAULT_CHUNK_SIZE_BYTES.ToString());
    response.Headers.Add("X-Item-Total-Size", "0");
    response.Headers.Add("X-Item-Empty-Response", "true");
    response.Headers.Add("X-Item-Error-Suppressed", "true");
response.Headers.Add("X-Item-Original-Error-Code", ((int)statusCode).ToString()); // Log original error
        return response;
        }
private async Task<HttpResponseMessage>FetchFullExternalItemForChunking(NameValueCollection
originalQueryParams)
    {
        // Extract path from original request
        var pathParams = this.Context.Request.RequestUri.AbsolutePath;
    if (pathParams.EndsWith("/chunked", StringComparison.OrdinalIgnoreCase))
    {
        pathParams = pathParams.Substring(0, pathParams.Length - "/chunked".Length);
    }
    // Remove chunk-related query parameters but keep others
    var cleanQuery = new NameValueCollection();
    foreach (string key in originalQueryParams.AllKeys)
    {
        if (key != CHUNK_QUERY_PARAM && 
        key != CHUNK_SIZE_PARAM &&
        key != USE_CHUNKING_PARAM)
        {
            cleanQuery[key] = originalQueryParams[key];
        }
    }
    // Rebuild query string
    string queryString = "";
    if (cleanQuery.Count > 0)
    {
        queryString = "?" + string.Join("&",
        cleanQuery.AllKeys.Select(key => $"{key}={Uri.EscapeDataString(cleanQuery[key]}}");
    }
    }
    // Forward request to Graph API
    var outbound = new HttpRequestMessage(
    HttpMethod.Get,
    $"https://graph.microsoft.com{pathParams}{queryString}");
    // Forward authorization header
    if (this.Context.Request.Headers.TryGetValues("Authorization", out var authHeaders))
    {
        outbound.Headers.TryAddWithoutValidation("Authorization", authHeaders);
    }
    // Add accept header
    outbound.Headers.Add("Accept", "application/json");
    // Forward the request
    return await this.Context.SendAsync(outbound, this.CancellationToken)
    .ConfigureAwait(false);
    }
private HttpResponseMessage ApplyChunkingToResponse(JObject fullItem, int chunkIndex, int chunkSize)
{
    try {
        // Create chunked response structure
        var chunkedItem = new JObject
    {
        ["id"] = fullItem["id"],
        ["@odata.context"] = fullItem["@odata.context"],
        ["chunkMetadata"] = new JObject
    {
        ["chunkIndex"] = chunkIndex,
        ["chunkSize"] = chunkSize,
    ["totalChunks"] = 0, // Will calculate below
    ["isLastChunk"] = false,
["chunkingEnabled"] = true
    }
    };
// Copy all properties except content (we'll handle content separately)
    foreach (var property in fullItem.Properties())
    {
        if (property.Name != "content" &&
        property.Name != "@odata.context" &&
        property.Name != "id")
    {
        chunkedItem[property.Name] = property.Value;
    }
    }
    // Handle content chunking
    if (fullItem["content"] != null)
    {
        var content = fullItem["content"];
        var contentValue = content["value"]?.ToString();
if (!string.IsNullOrEmpty(contentValue))
    {
        // Calculate chunk boundaries
        int totalBytes = Encoding.UTF8.GetByteCount(contentValue);
        int totalChunks = (int)Math.Ceiling((double)totalBytes / chunkSize);
        // Update chunk metadata
        chunkedItem["chunkMetadata"]["totalChunks"] = totalChunks;
        chunkedItem["chunkMetadata"]["totalSizeBytes"] = totalBytes;
        chunkedItem["chunkMetadata"]["originalContentLength"] = contentValue.Length;
    if (chunkIndex >= totalChunks)
    {
        // Requested chunk beyond available chunks - return empty content
        chunkedItem["content"] = new JObject
    {
        ["type"] = content["type"],
        ["value"] = "",
        ["isPartial"] = false,
        ["chunkInfo"] = new JObject
        {
            ["startByte"] = 0,
            ["endByte"] = -1,
            ["chunkIndex"] = chunkIndex,
            ["totalChunks"] = totalChunks,
            ["charsInChunk"] = 0
    }
};
chunkedItem["chunkMetadata"]["isLastChunk"] = true;
}
// Check if this is the last chunk
bool isLastChunk = (chunkIndex >= totalChunks - 1);
chunkedItem["chunkMetadata"]["isLastChunk"] = isLastChunk;
    // Extract the appropriate chunk
    string chunkedContent = GetContentChunk(contentValue, chunkIndex, chunkSize, totalBytes);
    // Create chunked content object
    var chunkedContentObj = new JObject
    {
        ["type"] = content["type"],
["value"] = chunkedContent,
    ["isPartial"] = totalChunks > 1,
    ["chunkInfo"] = new JObject
    {
        ["startByte"] = chunkIndex * chunkSize,
        ["endByte"] = Math.Min((chunkIndex + 1) * chunkSize, totalBytes) - 1,
        ["chunkIndex"] = chunkIndex,
        ["totalChunks"] = totalChunks,
        ["charsInChunk"] = chunkedContent.Length
    }
    };
    chunkedItem["content"] = chunkedContentObj;
        }
            else
            {
            // Content exists but value is empty or null
                chunkedItem["content"] = content;
                chunkedItem["chunkMetadata"]["totalChunks"] = 1;
                chunkedItem["chunkMetadata"]["isLastChunk"] = true;
                chunkedItem["chunkMetadata"]["totalSizeBytes"] = 0;
            }
        }
        else
        {
            // No content property
            chunkedItem["content"] = new JObject
            {
                ["type"] = "text",
                ["value"] = ""
            };
            chunkedItem["chunkMetadata"]["totalChunks"] = 1;
            chunkedItem["chunkMetadata"]["isLastChunk"] = true;
            chunkedItem["chunkMetadata"]["totalSizeBytes"] = 0;
        }
    // Return successful response
var response = new HttpResponseMessage(HttpStatusCode.OK);
    response.Content = CreateJsonContent(chunkedItem.ToString(Newtonsoft.Json.Formatting.None));
    // Add custom headers for chunking information
    response.Headers.Add("X-Item-Chunk-Index", chunkIndex.ToString());
response.Headers.Add("X-Item-Total-Chunks", chunkedItem["chunkMetadata"]["totalChunks"].ToString());
    response.Headers.Add("X-Item-Is-Last-Chunk", chunkedItem["chunkMetadata"]["isLastChunk"].ToString());
    response.Headers.Add("X-Item-Chunk-Size", chunkSize.ToString());
response.Headers.Add("X-Item-Total-Size", chunkedItem["chunkMetadata"]["totalSizeBytes"].ToString());
            return response;
        }
        catch (Exception)
        {
            // If anything goes wrong during chunking, return empty response
            return CreateEmptyContentResponse(HttpStatusCode.InternalServerError);
        }
    }
    private int AdjustForUtf8Boundary(byte[] bytes, int start, int end)
    {
        // Bounds check FIRST
        if (end >= bytes.Length)
        {
            return bytes.Length; // Return the actual length, not an index
        }
        int adjustedEnd = end;
        // Now we can safely check bytes[adjustedEnd]
        while (adjustedEnd > start && (bytes[adjustedEnd] & 0xC0) == 0xB0)
        {
            adjustedEnd--;
        }
        return adjustedEnd;
    }
private string GetContentChunk(string fullContent, int chunkIndex, int chunkSizeBytes, int totalBytes)
    {
        // Convert string to bytes for accurate byte-based chunking
        byte[] contentBytes = Encoding.UTF8.GetBytes(fullContent);
        int startByte = chunkIndex * chunkSizeBytes;
        if (startByte >= totalBytes || startByte >= contentBytes.Length)
        {
            return string.Empty;
        }
        // endByte should be EXCLUSIVE, not inclusive
        int endByte = Math.Min(startByte + chunkSizeBytes, totalBytes);
        // Adjust for UTF-8 boundaries - but make sure we don't go out of bounds
        if (endByte < contentBytes.Length)
        {
            endByte = AdjustForUtf0Boundary(contentBytes, startByte, endByte);
        }
        else
        {
            endByte = contentBytes.Length; // Use the actual length
        }
        // Final bounds check
        if (endByte <= startByte || startByte >= contentBytes.Length)
        {
            return string.Empty;
        }
        int chunkLength = endByte - startByte;
        byte[] chunkBytes = new byte[chunkLength];
        Array.Copy(contentBytes, startByte, chunkBytes, 0, chunkLength);
        return Encoding.UTF0.GetString(chunkBytes);
    }
    private int GetUtf0SequenceLength(byte firstByte)
    {
        if ((firstByte & 0x00) == 0) return 1; // 0xxxxxxx
        if ((firstByte & 0xE0) == 0xC0) return 2; // 110xxxxx
        if ((firstByte & 0xF0) == 0xE0) return 3; // 1110xxxx
        if ((firstByte & 0xF0) == 0xF0) return 4; // 11110xxx
        return -1; // Invalid UTF-8
    }
private HttpResponseMessage CreateErrorResponse(string code, string message, HttpStatusCode statusCode)
{
    var errorResponse = new HttpResponseMessage(statusCode);
    errorResponse.Content = CreateJsonContent(new JObject
    {
        ["error"] = new JObject
        {
            ["code"] = code,
            ["message"] = message
        }
    }.ToString());
    return errorResponse;
    }
    private async Task<HttpResponseMessage> HandleSearchWrapper()
    {
        // Read original request body
        string rawBody = await this.Context.Request.Content.ReadAsStringAsync().ConfigureAwait(false);
        var input = JObject.Parse(rawBody);
        // Extract fields
        int size = Math.Min((int?)input["size"] ?? 50, 50);
        int from = (int?)input["offset"] ?? 0;
        string queryString = (string)input["query"];
        if (queryString == null)
        {
            queryString = "nexus, this is a null string";
        }
        string contentSourceParam = (string)input["contentSource"] ?? "/external/connections/nexus";
        // Build contentSources array from comma-separated string
        JArray contentSourcesArray = new JArray();
        if (!string.IsNullOrEmpty(contentSourceParam))
        {
            // Split by comma and trim each entry
            var contentSources = contentSourceParam.Split(',')
                .Select(source => source.Trim())
                .Where(source => !string.IsNullOrEmpty(source));
            foreach (var source in contentSources)
            {
                contentSourcesArray.Add(source);
            }
        }
        // If no valid content sources were found, use default
        if (contentSourcesArray.Count == 0)
        {
            contentSourcesArray.Add("/external/connections/nexus");
        }
// Build wrapped search request
J0bject wrappedBody = new J0bject
{
    ["requests"] = new JArray
    {
        new JObject
        {
            ["entityTypes"] = new JArray("externalItem"),
            ["contentSources"] = contentSourcesArray,
            ["query"] = new JObject
            {
            ["queryString"] = queryString,
            ["semanticSearch"] = new JObject
            {
            ["semanticEnabled"] = true,
            ["captions"] = new JObject { ["enabled"] = true, ["highlightEnabled"] = true },
            ["answers"] = new JObject { ["enable"] = true, ["top"] = 1 }
            },
            },
            ["from"] = from,
            ["size"] = size,
            ["fields"] = new JArray
            {
            "id", "title", "hitsSnippet", "subject", "authors",
            "filename", "owner", "url", "modifiedTime", "modifiedBy",
            "tags", "categories", "content", "fileId", "size",
            "aclOwner", "fileExtension", "comments", "hidden",
            "readOnly", "systemFile", "archiveFile", "aclOwner",
            "aclPrimaryGroup", "aclReadAllowedTo", "aclFullControlTo",
            "aclWriteAllowedTo", "aclModifyAllowedTo",
            "aclReadAndExecuteAllowedTo", "aclSpecialPermsTo",
            "aclReadDeniedTo", "aclFullControlDeniedTo",
            "aclWriteDeniedTo", "aclModifyDeniedTo",
            "aclReadAndExecuteDeniedTo", "aclSpecialPermsDeniedTo"
        }
    }
};
string filter = (string)input["filter"] ?? null;
if (!string.IsNullOrEmpty(filter))
{
    filter = "({searchTerms}) " + filter;
    wrappedBody["requests"][0]["query"]["queryTemplate"] = filter;
}
string[]? fields = null;
if (input.TryGetValue("fields", out var token) && token is JArray arr)
{
    fields = arr.Values<string>().ToArray();
}
if (fields != null)
{
    var fieldsArray = (JArray)wrappedBody["requests"][0]["fields"];
    foreach (var field in fields)
    {
        fieldsArray.Add(field);
    }
}
/*
//Debugging: Enable this to send constructued search/query request body back to caller
var response = new HttpResponseMessage(HttpStatusCode.OK);
response.Content = CreateJsonContent(wrappedBody.ToString());
return response;
/*
// Build outbound request
var outbound = new HttpRequestMessage(HttpMethod.Post,
"https://graph.microsoft.com/v1.0/search/query");
outbound.Content = CreateJsonContent(wrappedBody.ToString());
if (this.Context.Request.Headers.TryGetValues("Authorization", out var authHeaders))
{
    outbound.Headers.TryAddWithoutValidation("Authorization", authHeaders);
}
// Forward the request
return await this.Context.SendAsync(outbound, this.CancellationToken).ConfigureAwait(false);

Note: Wait for some time for connector creation.

  1. Navigate to the Test tab:
  • Click + New Connection. Pick the appropriate Microsoft account if asked.
  • Click Create
  • Locate the connector in Power Apps either by searching it or sorting it by its latest modified time. The Status should be "Connected".
  • On the left pane, click on the More > Discover All > (scroll down to look-out for) Data > Custom Connector > Search the app and click Edit.
  • Edit the connector again.
  • Go to the Test tab by clicking on the dropdown on the top-left pane and now click "Update Connector". On the Test tab, provide the following:
  • query: Based on your ingested data, give a search string that fetches the data
  • contentSource: /external/connections/Al Connector ID.

Note: Provide the connector name given in Panzura Nexus webUI > Policies > AI Connector ID.

  • Click Test Operation

Once a 200 response is received, the connector is ready for use with the Agent.

Share the Custom Connector

  1. After the Test response is received as 200, close the Test step.
  2. You are directed to Custom Connector list.
  3. Search the Custom Connector and go to Share tab.
  4. On Add people field, provide the names of the people you want to share the Connector.

B. Steps to create Custom Agent

  1. Login to Microsoft Copilot Studio using administrator credentials.
  2. On the left-side navigation, click Agents Create blank agent.

Note: Wait for the agent provisioning to complete. A message "Your agent has been provisioned" appears at the top of the page. 3. On the Agent Overview page, click Edit and then provide the following details:

  • Name: Agent's name
  • Description: Details about the agent and click Save.
  • Select your agent's model: GPT 5 - Reasoning
  • Instructions: Click Edit to add a new set of instructions.
  • Add the following Instructions and click Save to apply the instructions.
Guideline about using the Tools:
If the tool inputs cannot be generated or deciphered, explicitly mention to the user to rephrase the question. Never ask user
what query string to use or what should be the tool input. Chunks can be fetched beginning at chunk 0. Never ask user which chunk
to fetch.
Instructions for using "Search Nexus" Tool:
Generate multiple queries with OR embedded between the queries. Example query with two terms:
"Nile seawall" and "Dubai Airport" will generate the query string: "\"Nile seawall\"
OR \"Dubai Airport\"".
Never ask user what query string to use for search. If you cannot generate the query, ask user to rephrase the question.
"offset" input to the tool can be used for pagination. First time query should use "offset" as 0.
When user asks for more results, use the previous query string you generated and add

"offset" as equal to the number of previously fetched results. Never ask user what value to use as offset. If you cannot decipher the offset, use offset as 0 .

  • If only filter condition is applied, use query input as- "*".
  • Use default filter as "size=-1" if no filter condition can be deciphered or applied.
  • Multiple conditions can be combined by using spaces between the conditions. eg: Files owner by a user abc with filename as xyz - owner:abc filename:xyz eg: Files owned by two users abc and def - owner:abc owner:def
  • For timestamp fields ">" or "<" can be used with the time format as YYYY-MM-DD.

Do not append : to the timestamp key. Use only ">" or "<" condition as a separator between timestamp key and value. eg: Files created after 30th November 2024 and modified before 15th December 2025 - createTime modifiedTime < 2025-12-15

  • For numeric fields, ">" or "<" conditions can be used without using ":" as a condition seperator. eg: File size less than 30000 bytes - size < 30000
  • Two values for the same condition can be provided by using multiple space separated key:value pairs. eg: Files owned by two users abc and def - owner:abc owner:def
  • Two conditions with different keys are always ANDed. Use spaces between the conditions. eg: Files owner by a user abc and Filename as xyz - owner:abc filename:xyz Following are the metadata properties which can be used for filters. Filter keys with their meanings. Map key with user intent
  • filename: File name filename. Use this with or without extension.
  • extension: File type or file format or file extension
  • owner: Owner
  • createdBy: created by
  • modifiedBy: Last Modified by
  • authors: content authors
  • size: File Size
  • modifiedTime: File Modified time or last updated in YYYY-MM-DD format
  • createTime: File Creation time in YYYY-MM-DD format
  • size: Size of the file
  • categories: filter using document category
  • tags: filter using document tags
  • title: filter using document title
  • subject: filter using document subject
  • comments: filter using document comments
  • hidden: boolean flag. Only true or false can be passed. Is file hidden?
  • readonly: boolean flag. Only true or false can be passed. Is file readonly?
  • systemFile: boolean flag. Only true or false can be passed. Is file system file?
  • archiveFile: boolean flag. Only true or false can be passed. Is file an archive file?
  • ac1Owner: ACL Owner
  • ac1PrimaryGroup: ACL primary Group
  • ac1ReadAllowedTo: List of users and groups to which Read is allowed
  • ac1FullControlTo: List of users and groups to which Full control is allowed
  • ac1WriteAllowedTo: List of users and groups to which Write is allowed
  • ac1ModifyAllowedTo: List of users and groups to which Modify is allowed
  • ac1ReadAndExecuteAllowedTo: List of users and groups to which Read and Execute is allowed
  • ac1SpecialPermsTo: List of users and groups to which special permissions are given
  • ac1ReadDeniedTo: List of users and groups to which Read is denied
  • ac1FullControlDeniedTo: List of users and groups to which Full control is denied
  • ac1WriteDeniedTo: List of users and groups to which Write is denied
  • ac1ModifyDeniedTo: List of users and groups to which Modify is denied
  • ac1ReadAndExecuteDeniedTo: List of users and groups to which Read and Execute is denied
  • ac1SpecialPermsDeniedTo: List of users and groups to which special permissions are denied
  • "": No filter condition can be deciphered from user query or user intent

ACL stands for Access control list. Deny takes precedence over Allow. Following ownership, allow and deny properties are available through the tool output

  • Ownership: ac1Owner, ac1PrimaryGroup
  • Allowed: ac1ReadAllowedTo, ac1WriteAllowedTo, ac1ModifyAllowedTo, ac1ReadAndExecuteAllowedTo, ac1FullControlTo, ac1SpecialPermsTo
  • Denied: ac1ReadDeniedTo, ac1WriteDeniedTo, ac1ModifyDeniedTo, ac1ReadAndExecuteDeniedTo, ac1FullControlDeniedTo, ac1SpecialPermsDeniedTo

If number of results returned by the tool is 0 , inform user that you could not find any documents in enterprise data. "url" returned by "Search Nexus" tool can be treated as a source or reference. Always show references if the url is not part of column in tabular listing. When generating results insert references at appropriate places. Do not use id or fileId for citation.

Instructions for using "Get External Item" Tool:

Invoke this tool when user wants summary or contents of a specific document or file.
The "fileId" returned in SearchNexus api is used as a "item-id" input. The "contentSource"
returned in SearchNexus api is used as "connection-id". A large document can be fetched in chunks.
- Chunk number starts with 0. API returns the total
number of chunks and the content size. path returned by the tool can be treated as a source or
reference and should be displayed as link. Do not use fileId for citation.
# Response Formatting
- Multi column table should be displayed in markdown template. Include serial number as first column.
- Render all section headings in bold using Markdown
- Always show references

C. Steps to setup Custom Connector as tool

  1. On the Overview tab, scroll down to Tools. Click "Add tool", enter "Search Nexus data" in the Search box. Locate the Tool created in A. Steps to create Custom Agent section from the search results.
  2. Click on the connector. Wait for some time on the Add Tool window until the Connection turns green, and then click "Add and configure". You are redirected to the Copilot Studio's Agent tab.
  3. On the Inputs tab, click on the " + Add input".
  • Add the following Search Request one by one:
  • query (already added)
  • key value pair composed with and/or conditions
  • offset
  • String external contentSource
  • Change the value of String external contentSource by selecting Custom value from the dropdown. Provide the value as /external/connections/AI_Connector_ID. Note: Provide the connector name given in Nexus webUI > Policies > AI Connector ID .
  • Click Save.
  1. Navigate back to Agents Overview Tools tab.
  • On Add Tool, enter "Get External Item in Chunks" in the Search box. Locate the Tool created in A. Steps to create Custom Agent section.
  • Select Get External Item in Chunks Tool from the search results.
  • Click on the connector and then click "Add and configure". You are redirected to the Copilot Studio's Agent tab.
  • Go to the inputs section. On the Inputs tab, click on the " + Add Input" and then add the following "-chunkSize". You can see four inputs: chunk index, Connection-id and Item id, both to be filled as "Dynamically fill with AI" and provide Chunk Size (bytes) custom value of 60000 and click Save.
  • On the right pane, click "New test session" and start your interaction with the agent. If a popup appears for Allow, click Allow and continue.

D. Publish the Custom Agent

  1. In Microsoft Copilot Studio, click on the Channels tab of your Custom Agent.
  2. Click "Microsoft 365 Copilot and Microsoft Teams". The right pane opens; click "Add Channel".
  3. If the option appears to force a new version, select the checkbox. On the popup, click "Publish".

Note: Publishing may take some time. A message appears as The channel was added. 4. Click Availability options.

  • Note: Make sure Custom Connector is shared with the intended users / groups to whom you are publishing the custom agent.
  • To share the custom agent with specific users or groups:
  • Choose "Show to my teammates and shared users" for limited rollout.
  • In the newly opened popup window, under New Users, type the desired user or group name.
  • Select the desired permission level for the new user in the right pane.
  • Select more users or groups in the New Users input box if desired.
  • Select Share. This would show message "Successfully changed the sharing settings for your agent" after it succeeds.
  • You can select Cancel now, if no more users or groups need to be added. Close the Channel Details pane.
  • Select the Publish button on the top right corner. In the "Publish this agent" pop-up, select "Force newest version" checkbox and hit Publish.
  • To publish organization-wide, select "Show to everyone in my org".
  • Select "Submit to org catalog".
  • If asked "Give everyone access to this agent?", select "Yes".

This sends the agent for Microsoft 365 admin approval. A message "Your agent is submitted and waiting for approval from your Teams admin." will be shown.

  • Follow the next step 5 below and come back to this "Show in Teams app store for org" pane.
  • Select the Refresh button in front of the message "Your agent is submitted and waiting for approval from your Teams admin."
  • You should see the success message "Your request completed successfully." at the top.
  • Close channel details pane.
  1. To approve the agent, access the Microsoft admin site using Global Administrator credentials.
  • Click Agents > Overview.
  • Under Top actions for you > Manage requests, find the Custom Agent.
  • Click the vertical ellipsis (1) and select Publish to Store.
  • In the "Publish new agent" wizard,
  • Select Users stage:
  • Select All users for "Select users or groups who can install the agent".
  • Provide your choices for the optional inputs if desired and hit Next.
  • Apply template stage:
  • Provide your choices for the optional inputs if desired and hit Next.
  • Accept permissions stage:
  • Review permissions and hit Next.
  • Review and finish stage:
  • Review your choices and hit Publish.
  • A message "You published <your custom agent's name>" will be shown.
  • Select Done.

E. Chat with the Custom Agent

  1. Navigate to https://m365.cloud.microsoft/chat .
  2. Under Agents > All agents, search for the custom connector. The agent appears on the left pane.
  3. Click on the agent and start the conversation. If a popup appears stating "Connect to continue", click Allow.
  4. If the connection is lost, click Open Connection Manager, allow third-party cookies, and retry.
  5. Return to the "All agents" chat window to view results.

If you encounter a 403 error during your conversation with the Agent, you can use the following workaround.

2.10.4 Support for Comprehensive Indexing and Search for Large Files

Panzura Nexus ensures that searches include information from every part of your documents, even in very large files such as lengthy reports, manuals, or data-heavy spreadsheets. No matter where the information is located-at the beginning, middle, or end becomes searchable through Microsoft Copilot.

Key Benefits are:

  1. Delivers complete and accurate search results, covering every section of each accessible document.
  2. Includes all content in searches automatically, with no changes needed to settings or workflow.
  3. Ensures smaller files remain fully searchable.

Note: Search results display only files permitted by user access rights. For large files, if retrieval of the first chunk fails, the file ACL is not available because ACL data is fetched from the first chunk.

2.11 System Operations

The Maintenance page provides access to System Operations (system diagnostic tools), focused on downloading logs for troubleshooting purposes.

2.11.1 Download Logs

This feature automates the collection of telemetry and runtime data across the entire infrastructure stack. Instead of manually accessing individual nodes or containers, this tool aggregates logs into a single, compressed bundle for offline analysis or submission to technical support.

Log Bundle Contents When you initiate a download process, the system captures three primary categories of data:

  • System Logs: OS-level events, kernel logs, and hardware alerts.
  • Container Logs: Standard output (stdout) and error logs (stderr) from all active microservices and application runtimes.
  • Database (DB) Logs: Transaction logs, slow query logs, and connection audits to help identify bottlenecks or data integrity issues.

Use Download Diagnostic Logs to start the log download process. To start the download process, click Download Diagnostic Logs. The system opens a Configure Log Bundle pop-up where you can customize and download a specific set of diagnostic logs based on time range and categories.

Configure Log Bundle

Date Range

Logs will be collected for the selected time window.

From * To *
03/18/2026 03/20/2026

Bundle Categories

  • Journalctl Logs
  • Systemd service logs
  • System Info
  • CPU, memory, disk, OS details
  • NATS State
  • Message bus monitoring
  • OpenSearch State
  • Search cluster health & indices

Select All

  • ☐ Nexus Configuration
  • ☐ Config files (secrets masked)
  • ☐ Network Info
  • ☐ IP, routes, DNS, docker networks
  • ☐ Database State
  • ☐ ScyllaDB nodetool & schema
  • ☐ Prometheus State
  • ☐ Metrics, targets, alerts, node & NATS exporters

DOWNLOAD (1 SELECTED)

The Configure Log Bundle pop-up consists of the following:

Parameter Description
Date Range Selection The system collects logs for the selected time range. The date range defaults to two days.
Bundle Categories You can select different categories to collect logs.

Bundle Categories include:

Sub-Category Description
Journalctl Logs (Default checked) Provides systemd service logs
System Info (selected) Provides CPU, memory, disk, OS details
NATS State Provides message bus monitoring
OpenSearch State Provides search cluster health & indices
Nexus Configuration Provides configuration files (secrets masked)
Network Information Provides IP, routes, DNS, docker networks
Sub-Category Description
Database State Provides status of ScyllaDB nodetool & schema

2.11.2 Backup & Restore

The Backup & Restore feature helps protect critical data and maintain business continuity. It allows you to create backups and restore the system to a previously saved state, and is primarily used for disaster recovery in scenarios such as system failure or system corruption.

Backups

The Backup tab allows you to create backups of system configuration and critical data. These backups can be used to recover the system in case of failures or system corruption.

Follow these key guidelines to maintain effective backups and data security:

  • The backup duration depends on the size of the data and system load.
  • Download, restore, or delete a backup only when its status is "Completed".
  • The default retention values for local and cloud backups are 5 and 10 , respectively.
  • Only one backup operation (download, restore, or delete) is supported at a time.
  • Before initiating a backup, pause all active scans to maintain ingested-data consistency. Backups captured during active scans may cause scan jobs to remain in the "Running" state after restore and require manual intervention.
  • If files were ingested through full/incremental scans or live events after the backup was taken, restoring that backup may cause those files to become orphaned. The files will still exist in Copilot, but they will no longer be present in the Nexus Catalog and will be recovered during the next incremental scan.

Maintenance A screenshot of a software maintenance interface showing a list of system backups and a backup now button. This could be useful for illustrating software administration, data management, or cloud backup procedures.

The backup can be taken in two ways:

  • Local: Use the Backup Now option to manually create a backup and store it on the local Nexus host filesystem.
  • Cloud: Use the Backup Now option to manually create a backup and store it in the configured cloud storage location.

Create Backup

How to use Backup Now:

Note: The Local Backup is taken on the Nexus Host. Make sure to copy it either on the configured cloud (AWS S3) environment or to another storage device.

  1. Click Backup Now and provide a name for the backup.
  2. Select either of the options (Local or Cloud) and click Confirm.
  • Local
  • Cloud (Not setup) - Refer Configure Cloud Backup for more details.

The Overwrite if exists toggle can be enabled to overwrite an existing backup. The system starts the backup process and displays the backup status as "Running" until it completes.

Configure Cloud Backup using Setup AWS S3 Config

To take a backup in the cloud environment, configure AWS S3. The Setup AWS S3 Config option is used to configure Amazon S3 storage for uploading and storing system backups in the cloud. The following table describes the fields required to configure S3 storage for backups:

Field Description
Access Key ID Access key for your AWS account used to authenticate S3
access.
Secret Access Key Secret key associated with the access key ID for secure
authentication.
Bucket Enter the name of your S3 bucket to store backups.
Path Folder path within the bucket for storing backups (for
example, backups/ ).
Region Specify the AWS region that hosts your S3 bucket (for
example, us-east=1).

EDIT AWS S3 CONFIGURATION The S3 configuration can be edited using the Edit Configuration option. Editing the S3 configuration updates the storage settings for all future backups.

  1. Click on the Edit AWS S3 Config button.
  2. Make the required changes (if any) and click Confirm. The changes will be saved for later use.

ACTIONS PERFORMED ON BACKUPS

The following actions can be performed on the backup:

  • Download Backup
  • Restore Backup
  • Delete Backup

HOW TO DOWNLOAD THE BACKUP The system backup can be downloaded after the status is "Completed".

  1. From the Backups list, select the backup which is to be downloaded.
  2. Click on the Download icon.

HOW TO RESTORE THE BACKUP The backup can be restored to return the system to a known stable state. This option is available only for cloud backups. Note: Local backup can only be restored using Upload and Restore option.

  1. Choose the backup from the list and click the Restore icon.
  2. The action navigates to the Restore tab.
  3. Click Restore again. The restore process is initiated.

For more details on the Restore, refer to Restore Tab.

The system backup can be deleted using the Nexus web UI.

  1. Select the backup from the list and click the Delete icon.
  2. A pop-up message appears, click Delete Backup. The backup is deleted from the list.

Restore tab

The Restore feature allows you to recover the system using a previously created backup archive. By uploading a supported backup file (.tar.gz), you can restore system configuration and critical data to a known stable state. This is useful for recovering from system failures or system corruption. During the restore process, the selected backup is applied to a new virtual machine where Nexus is configured.

Follow these key guidelines to ensure a successful restore:

  1. Restore operation to the same virtual machine is not supported.
  2. The source and target virtual machines must be running the same build version. For example, if the backup is taken from Nexus version 1.1.0 - xxx12, restore it only on a virtual machine running Nexus version 1.1.0 - xxx12.
  3. If files were ingested through full/incremental scans or live events after the backup was taken, restoring that backup may cause those files to become orphaned. The files will still exist in Microsoft Copilot, but they will no longer be present in the Nexus Catalog and will be recovered during the next incremental scan.

BACKUPS RESTORE

Upload & Restore

Upload a backup archive to restore from.

Only .tar.gz files are accepted.

Drag & drop a .tar.gz file here

or click to browse

STEPS TO RESTORE THE FILE

  1. On the Restore tab, click the Drag & drop a .tar.gz file here.
  2. Select the appropriate file and click Upload & Restore to begin the file upload process.
  3. Once the restore process is successfully completed, click Continue to Nexus to access the Nexus. The restored system should be operational and available for use.

Restore Complete

All services have been restored successfully.

Backup

Duration 20m 38s

SERVICE

system-config

scylladb

nats

opensearch

grafana

Startus

Restored

Restored

Restored

All services are healthy.

Continue to Nexus

  1. If you have paused the scan before taking the backup, then after the restore is complete, resume that scan job.
  2. Navigate to each of the Policies and perform an Incremental Scan to capture any delta changes that occurred between the backup date taken and the restore date.

STEPS TO RESTORE BACKUP FROM CLOUD ENVIRONMENT

  1. Navigate to System Operations > Backup & Restore.
  2. Configure the Amazon S3 settings by entering the Amazon S3 configuration details.
  1. Click Confirm. After successful validation, Nexus retrieves and displays all available backups from the configured Amazon S3 location.
System Operations BACKUPS RESTORE
Download Logs 1 row selected
Backup & Restore Name Created At Status Size Location
Location
184pwarm Jun 09, 2028 18:11:34 Completed 167.5M Local
Cloud
Cloud
Cloud
Cloud
Cloud
Cloud

2.12 System Management Audits

The System Management Audits section monitors and tracks all the activities of the logged-in user and the system. The following parameters are displayed for Audits:

Timestamp User Task Status Message
Date, [year], [hh:mm:ss] Logged in user Description of the task performed by the logged in user Success, In
Progress, or Failed [Displays the appropriate message.]

Actions on Audits

The following actions can be performed on the generated audit logs:

Action Description
Export Options The audits can be exported in following formats: - PDF
  • CSV
  • JSON | | Open Filters | Displays available filters to view the logs. | | Refresh | Refresh the current page. | | Enter Fullscreen | Views the current page in full screen. | | Toggle columns | Displays a set of parameters that can be displayed or hidden on the web UI. |

System Management Audits Monitor and track all user and system activities

| 0 | Search on this page... | | | | | | | | | | | | | | | | | | | | | | | | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Timestamp | User | Task | Status | Message | | | | | | | | | | | | | | | | | | | | | | Mar 23, 2026 10:56:13 | admin | admin user login | Success | User 'admin' logged in successfully | | | | | | | | | | | | | | | | | | | | | | | Mar 21, 2026 05:55:39 | admin | admin user login | Success | User 'admin' logged in successfully | | | | | | | | | | | | | | | | | | | | | | | | Mar 20, 2026 23:28:31 | admin | admin user login | Success | User 'admin' logged in successfully | | | | | | | | | | | | | | | | | | | | | | | | Mar 20, 2026 20:30:37 | admin | Delete custom agent newone | Success | Custom agent 'newone' deleted successfully. | | | | | | | | | | | | | | | | | | | | | | | | Mar 20, 2026 20:30:15 | admin | Delete custom agent new | Success | Custom agent 'new' deleted successfully. | | | | | | | | | | | | | | | | | | | | | | | | Mar 20, 2026 20:28:57 | admin | Create custom agent %s | In Pr... | Request in progress | | | | | | | | | | | | | | | | | | | | | | | | Mar 20, 2026 20:10:54 | admin | admin user login | Success | User 'admin' logged in successfully | | | | | | | | | | | | | | | | | | | | | | | | Mar 20, 2026 20:08:00 | admin | Create custom agent new | Failed | Failed to create custom connector: Failed to create connector: Connector creation failed... | | | | | | | | | | | | | | | | | | | | | | | | Mar 20, 2026 20:07:48 | admin | Create custom agent new | Success | Solution created successfully for agent 'new' | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

2.13 User Profiles in Panzura Nexus

2.13.1 User Profile

The User Profile section displays following details:

Field Description
User name Displays the user logged into the Panzura Nexus.
Build version Displays the build number and version currently installed.
Help Displays the online Help.
Replay Tour Displays the guided tour of the Panzura Nexus UI and
configurations.
Logout User is logged out of the Panzura Nexus.

2.14 Alerts in Panzura Nexus

2.14.1 Alerts

The Alerts section tracks live processing and historical events based on system conditions, generating notifications when predefined thresholds or important conditions are met. Alerts help administrators stay informed about configuration gaps, system states, and operational issues.

Each alert captures key details such as severity, creation time, and resolution status to support timely review and remediation. The Alerts table lists all generated alerts in descending order of creation time.

Column Description
Title Describes the alert condition or event, such as missing
configurations or rules.
Severity Indicates the alert severity level (for example, Info).
Raised On The date and time when the alert was generated.
Status Displays the current state of the alert, such as Resolved,
along with the resolution time.

Types of Alerts

The following types of Alerts are displayed:

  • Live
  • Historical

Live Alerts

These alerts provide real-time visibility into system events, policies, and license status. They help administrators quickly identify issues, assess severity, and take corrective action. By monitoring alerts as they occur, you can ensure system health, maintain compliance, and respond promptly to critical conditions. If an alert is not relevant or has already been addressed, you can suppress it by selecting the alert and clicking the Suppress Alert button. This helps reduce noise and keeps the focus on active, unresolved issues. A screenshot of an Alerts Management dashboard displaying a critical live alert regarding a missing license. This could be useful for illustrating software monitoring, system administration, or error management interfaces.

Historical Alerts

These alerts show a record of past alert events that have already occurred in the system. They include details like the alert title, severity, time raised, and resolution status. This view helps you analyze trends, troubleshoot recurring issues, and review how incidents were handled over time.

If you previously suppressed an alert from the Live ALerts and need to restore it, you can select the suppressed alert from the Historical view and click the Unsuppress Alert button. This will reactivate the alert and make it visible in the Live Alerts section if the condition still exists.

Alerts Management LIVE HISTORICAL Alert History Title Security Raised On Status Plugin nexus-plugin-nexusauto-global-copilot-1773997423370913979 is in failed state FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK FALK F

2.15 Glossary

Term Definition
Panzura Nexus Panzura Nexus is the integration layer that connects CloudFS with Microsoft Copilot, enabling secure AI-powered search and insights on enterprise file system data.
Microsoft Copilot Microsoft Copilot is an AI companion that integrates across apps and systems to provide intelligent assistance, insights, and conversational support for everyday tasks.
IAM - Microsoft Entra ID Supports on-premises AD for identity mapping, with Entra ID Connector linking AD identities to Microsoft Entra ID for consistent CloudFS and Copilot security.
Rules A Rule defines the specific filters or criteria used to determine which data should be processed - for example, allowing only selected file types such as PDF or DOCX.
Data Insight Policy A policy defines how CloudFS events are processed by applying configured plugins and rules, governing the collection and upload of data and metadata to Copilot based on the defined configuration.
Connector A Microsoft Entra ID Connector is required to synchronize organization end-user accounts and enable access to CloudFS data insights through Copilot.
CloudFS CloudFS serves as the primary data source for Panzura Nexus. It contains the enterprise's unstructured file datasets -including file content (data), metadata, directory structures, and ACLs.
Panzura Nexus native image A deployment environment for the Panzura Nexus platform, which can be an on-premises virtual machine or a cloud instance.
File Owner The file system that owns the file.
Data Owner The CloudFS node that has claimed ownership of the file or directory.
Bot owner The Bot Owner is the System Administrator account (userbased) from the Power Platform environment that gets assigned as the owner of the Copilot agent in Copilot Studio, alongside the Service Principal.
Source virtual machine This term refers in context of backup and restore feature The CloudFS node that has claimed Ownership of the file or directory.
Target virtual machine The CloudFS node that has claimed Ownership of the file or directory.