azureblog.co.uk
← cd ~/posts

Entra Backup and Recovery is here: an undo button for your tenant

Entra ID now keeps daily backups of your critical directory objects and lets you compare and roll back changes. It's on by default, but you need to know how it works before you need it.

3 min read✓ checked 24 Jun 2026Entra ID · What's new
On this page
  1. How it works
  2. What's covered
  3. Recovering from a bad change
  4. Things to plan for
  5. Practise before you need it
  6. Why tamper-proof matters

For years, recovering from a bad change in Entra ID meant hoping the object was soft-deleted, or rebuilding it from documentation, exports or memory. A deleted policy or a mangled set of group memberships could take hours to reconstruct. Entra Backup and Recovery, now generally available, changes that.

  1. 01Daily backup, 7 days kept
  2. 02Pick a snapshot
  3. 03Create a difference report
  4. 04Review every change
  5. 05Recover objects
Always review the difference report before recovering.

How it works

  • Always on. Entra takes one backup a day automatically. There's nothing to enable.
  • Seven days of history. Backups from the last seven days are kept, stored in the same geography as your tenant.
  • Tamper-proof. Nobody, including Global Administrators, can turn backups off, delete them or edit them. That matters if an attacker gets privileged access.
  • Licensing. It needs a workforce tenant with Entra ID P1 or P2. External ID and B2C tenants aren't supported.
  1. Oldest backup still kept
  2. Last known-good state
  3. Conditional Access policy edited by mistake
  4. Backup now includes the bad change
  5. Difference report against day −3, then restore
Seven daily backups, always on. Pick the one from before the change.

What's covered

Users, groups, applications, , Conditional Access policies, , the authentication methods policy and selected authorization policy settings. Agent identities are covered too, because they're built from user and service principal objects.

It restores supported properties and links on objects that still exist. It doesn't bring back hard-deleted objects. For deleted users, groups and apps, the existing 30-day soft-delete recycle bin is still your first stop.

Recovering from a bad change

  1. In the Entra admin center, open Backup and recovery.
  2. Under Backups, pick a snapshot from before the change.
  3. Create a Difference report. It shows exactly which attributes and links differ from the current state.
  4. Review it carefully, then use Recover objects to restore everything, specific object types or specific object IDs.
  5. Track progress under Recovery history.
Always review the difference report first. A recovery rolls back every change to the selected objects since that backup, including legitimate ones made by other admins.
What went wrong?
Object deleted (user, group, app)Restore from the 30-day recycle bin first
Object still exists but properties or links are wrongEntra Backup and Recovery: difference report, then restore
Change older than seven daysRebuild from your own exports or configuration as code
Which recovery tool do you need?

Things to plan for

  • Roles. There are two new built-in roles: Backup Reader to view backups and differences, and Backup Administrator to run recoveries. Put the administrator role behind .
  • Hybrid objects. For objects synced from Active Directory, you can produce difference reports but can't recover them in Entra. Fix those at the source in AD.
  • Seven days is short. If a bad change goes unnoticed for a week, it's beyond reach. Keep your audit log alerts for high-impact changes, like Conditional Access edits.
  • Practise. Make a harmless change in a test tenant and recover it, so the process isn't new on the day it matters.

Practise before you need it

  • Run a difference report against yesterday's backup, just to see what normal change looks like
  • In a test tenant, change a Conditional Access policy and restore it
  • Decide who may restore, and require PIM activation for that role
  • Write the steps into your incident runbook
  • Keep your own exports of critical configuration for anything older than seven days

Why tamper-proof matters

An attacker with Global Administrator can delete objects, weaken policies and cover their tracks. Backups they can't switch off or edit give you a known-good state to compare against, which is useful for investigation as well as recovery.

Does a restore overwrite everything?

No. You choose what to restore after reviewing the difference report, so you can roll back one policy or a set of group memberships without touching anything else.

Can I extend retention beyond seven days?

Not today. For longer history, keep your own snapshots, for example with tenant configuration management stored in Git.

You've reached the end of Locking down admin accessBack to the path →