Overview of Entra Backup and Recovery

By John Savill's Technical Training

Share:

Key Concepts

  • Entra Backup and Recovery: A native service for Microsoft Entra ID that provides point-in-time snapshots of tenant objects.
  • Snapshots: Daily automated backups maintained for the last five days.
  • Difference Report: A diagnostic tool to compare current object states against a specific snapshot.
  • Soft Delete: The default state for deleted objects, allowing restoration from the recycle bin within 30 days.
  • Hard Delete: The permanent removal of an object, bypassing the recycle bin.
  • Protected Actions: A security feature requiring specific authentication contexts (e.g., phishing-resistant MFA) to perform sensitive operations like hard deletion.

1. Entra Backup and Recovery Overview

Microsoft has introduced a native backup and restore capability for Entra ID, available to customers with P1 or P2 licenses. The service automatically generates daily snapshots of the tenant, retaining them for five days.

  • Supported Objects: The service covers common objects including users, groups, service principals (enterprise apps), app registrations, conditional access policies, and named locations.
  • Functionality: It is designed to restore the state/properties of objects rather than just recovering deleted items. This is particularly useful for remediating accidental bulk updates or malicious attribute corruption caused by malware or unauthorized access.
  • Accessibility: Features are available via the Entra portal GUI and a dedicated API, allowing third-party tools to integrate these recovery capabilities.

2. Restoration and Difference Reporting

The service provides granular control over the recovery process:

  • Difference Reports: Users can generate a report comparing a snapshot to the current tenant state. The first report takes time to load metadata, but subsequent reports are faster.
  • Granular Recovery: Within the difference report, administrators can view specific attribute changes (e.g., old vs. new values). Recovery can be applied to all objects, specific object classes, or individual object IDs.

3. Soft Delete vs. Hard Delete

It is critical to distinguish between attribute corruption and object deletion:

  • Soft Delete: When an object is deleted, it enters the recycle bin for 30 days. It retains its original GUID and properties. Restoration is straightforward via the portal or Graph API.
  • Hard Delete: This permanently removes the object from the recycle bin. Once hard-deleted, the object cannot be restored, and any recreation results in a new object ID.

4. Protecting Against Malicious Hard Deletion

To prevent attackers from bypassing recovery by performing a "hard delete," administrators should implement Protected Actions:

  • Methodology: Navigate to Roles and Admins > Protected Actions. Select the action Microsoft directory deleted items delete.
  • Authentication Context: Link this action to a specific Conditional Access (CA) policy.
  • Security Framework: The CA policy can enforce strict requirements, such as:
    • Phishing-resistant MFA.
    • Requirement for a known, compliant device (e.g., a Secure Access Workstation).
    • Specific device property checks.

5. Synthesis and Conclusion

The new Entra backup and recovery service provides a robust safety net for configuration and attribute integrity. By combining this with the existing Soft Delete mechanism and securing the Hard Delete process via Protected Actions, organizations can create a comprehensive defense-in-depth strategy.

Main Takeaway: Use Entra Backup to revert attribute corruption (malicious or accidental) and use Protected Actions to prevent the permanent destruction of identity objects. Administrators are encouraged to test these workflows in a development tenant to understand the granularity of the recovery process.

Chat with this Video

AI-Powered

Load the transcript when you're ready to chat so the initial page stays lighter.

Ready to summarize another video?

Summarize YouTube Video