Entra Backup and Recovery is here: an undo button for your tenant
Entra ID now keeps daily backups of your critical directory objects and lets you compare and roll back changes. It's on by default, but you need to know how it works before you need it.
On this page
For years, recovering from a bad change in Entra ID meant hoping the object was soft-deleted, or rebuilding it from documentation, exports or memory. A deleted Conditional Access policy or a mangled set of group memberships could take hours to reconstruct. Entra Backup and Recovery, now generally available, changes that.
- 01Daily backup, 7 days kept
- 02Pick a snapshot
- 03Create a difference report
- 04Review every change
- 05Recover objects
How it works
- Always on. Entra takes one backup a day automatically. There's nothing to enable.
- Seven days of history. Backups from the last seven days are kept, stored in the same geography as your tenant.
- Tamper-proof. Nobody, including Global Administrators, can turn backups off, delete them or edit them. That matters if an attacker gets privileged access.
- Licensing. It needs a workforce tenant with Entra ID P1 or P2. External ID and B2C tenants aren't supported.
- Oldest backup still kept
- Last known-good state
- Conditional Access policy edited by mistake
- Backup now includes the bad change
- Difference report against day −3, then restore
What's covered
Users, groups, applications, service principals, Conditional Access policies, named locations, the authentication methods policy and selected authorization policy settings. Agent identities are covered too, because they're built from user and service principal objects.
It restores supported properties and links on objects that still exist. It doesn't bring back hard-deleted objects. For deleted users, groups and apps, the existing 30-day soft-delete recycle bin is still your first stop.
Recovering from a bad change
- In the Entra admin center, open Backup and recovery.
- Under Backups, pick a snapshot from before the change.
- Create a Difference report. It shows exactly which attributes and links differ from the current state.
- Review it carefully, then use Recover objects to restore everything, specific object types or specific object IDs.
- Track progress under Recovery history.
Things to plan for
- Roles. There are two new built-in roles: Backup Reader to view backups and differences, and Backup Administrator to run recoveries. Put the administrator role behind PIM.
- Hybrid objects. For objects synced from Active Directory, you can produce difference reports but can't recover them in Entra. Fix those at the source in AD.
- Seven days is short. If a bad change goes unnoticed for a week, it's beyond reach. Keep your audit log alerts for high-impact changes, like Conditional Access edits.
- Practise. Make a harmless change in a test tenant and recover it, so the process isn't new on the day it matters.
Practise before you need it
- Run a difference report against yesterday's backup, just to see what normal change looks like
- In a test tenant, change a Conditional Access policy and restore it
- Decide who may restore, and require PIM activation for that role
- Write the steps into your incident runbook
- Keep your own exports of critical configuration for anything older than seven days
Why tamper-proof matters
An attacker with Global Administrator can delete objects, weaken policies and cover their tracks. Backups they can't switch off or edit give you a known-good state to compare against, which is useful for investigation as well as recovery.
Does a restore overwrite everything?
No. You choose what to restore after reviewing the difference report, so you can roll back one policy or a set of group memberships without touching anything else.
Can I extend retention beyond seven days?
Not today. For longer history, keep your own snapshots, for example with tenant configuration management stored in Git.