⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Back to all articles
Microsoft 3656 min read

Microsoft Entra Backup and Recovery (Preview): A Built-In Safety Net for Identity

By Jamie Hamilton · Published · Updated

Microsoft has released one of the most requested Identity features in years, and it arrived quietly. Microsoft Entra Backup and Recovery is now in public preview.

For organisations relying on Microsoft 365, Entra ID and Conditional Access, it provides something that has been missing: native point-in-time recovery for critical Identity objects, without manual recreation or a third-party tool.

Why Identity recovery has always been hard

Microsoft has always protected the availability of Entra ID as a platform. What happens to your configuration inside the tenant has been your problem, and recovering from an Identity incident has traditionally meant:

  • •Recreating Conditional Access policies by reading audit logs
  • •Rebuilding applications or service principals after an accidental change
  • •Trying to reverse a provisioning mistake that ran at scale
  • •Reconstructing an access model after a privileged account was misused

All of those are slow, and all of them happen while whatever broke is still broken.

What the feature does

It is an always-on, Microsoft-managed service for recovering from accidental or malicious changes to your tenant. During public preview it takes daily backups of supported directory objects and lets administrators view available snapshots, generate difference reports showing what changed, and restore objects to a previous known good state.

Supported objects in preview:

  • •Users and groups
  • •Applications and service principals
  • •Managed identities
  • •Conditional Access policies
  • •Named locations
  • •Authentication and authorisation policies

One detail matters more than the rest. Backups cannot be disabled, deleted or modified by tenant administrators, including those holding the highest privileges. That is what makes this resistant to a compromised administrator account rather than only to honest mistakes, and it is the difference between a backup and a safety net.

Licensing and the retention limit

Not every tenant gets it. During public preview the requirements are a workforce Entra ID tenant, Microsoft Entra ID P1 or P2 licensing, and appropriate administrative roles. Tenants on Entra ID Free do not receive these backups, and External ID and Azure AD B2C tenants are not supported at preview.

For a tenant that qualifies: one backup daily, retained for five days, with recovery initiated from the Microsoft Entra admin centre.

Five days is the number to internalise. It is enough to cover a change that breaks something immediately, which is the common case. It is not enough to cover a change nobody notices for a fortnight, and it means this is a rollback mechanism rather than an archive.

What it is not

Worth being precise, because the name invites a broader reading than the feature supports.

It gives you native point-in-time recovery for Identity configuration, fast rollback of a misconfiguration, and visibility into what changed before you restore anything. It does not give you long-term retention or a historical archive, it is not Identity governance or access review or change control, and it does not cover other workloads: Exchange, SharePoint and OneDrive still need their own answer.

It reduces recovery time. It does not reduce the need for administrative discipline, and a tenant that relies on it instead of on change control has simply moved the problem.

Where it earns its place

The scenarios it is built for:

  • •A Conditional Access policy is edited and locks users out, which is the classic case and the one where five day retention is plenty
  • •A scripted change updates identities at scale in a way nobody intended
  • •An application or service principal is misconfigured and something stops authenticating
  • •Named locations or authentication policies are deleted
  • •A compromised privileged account makes unauthorised changes

In each of those the useful part is not only the restore. It is the difference report, because knowing exactly what changed is usually harder than putting it back.

Why Identity is the thing worth protecting

Identity is now the control plane for email and collaboration access, application sign-in, conditional security enforcement, and every external integration. When Identity breaks, the business stops, and it stops everywhere at once rather than in one system.

That is the argument for paying attention to a feature that will, if it works properly, never be visible to anybody.

Preview caveats

  • •Behaviour may change before general availability
  • •Preview services do not carry standard service level agreements
  • •It should not be treated as your only recovery mechanism

Its inclusion in the Entra admin centre and its always-on design both suggest Microsoft sees this as core rather than experimental, but preview is preview and the five day retention is a real constraint rather than a temporary one to plan around.

Frequently asked questions

What is Microsoft Entra Backup and Recovery?

An always-on, Microsoft-managed service, currently in public preview, that takes daily backups of supported Entra directory objects and lets administrators view snapshots, generate difference reports showing what changed, and restore objects to a previous known good state. It is Microsoft’s first native answer to recovering tenant configuration, which has historically been the customer’s problem.

What does it back up?

In preview it covers users and groups, applications and service principals, managed identities, Conditional Access policies, named locations, and authentication and authorisation policies. It does not cover other workloads: Exchange Online, SharePoint and OneDrive still need a separate backup answer, and this feature does not change that.

How long are Entra backups kept?

One backup is taken daily and retained for five days during public preview. That is the constraint worth planning around. Five days covers a change that breaks something immediately, which is the common case, and does not cover a change nobody notices for a fortnight. It is a rollback mechanism rather than an archive.

What licence do I need for Entra Backup and Recovery?

During public preview it requires a workforce Entra ID tenant with Microsoft Entra ID P1 or P2 licensing, plus appropriate administrative roles. Tenants on Entra ID Free do not receive the backups at all, and External ID and Azure AD B2C tenants are not supported at preview.

Can an administrator delete the backups?

No, and this is the most important property of the feature. Backups cannot be disabled, deleted or modified by tenant administrators, including those with the highest privileges. That makes them resistant to a compromised or malicious privileged account rather than only to honest mistakes, which is what separates a safety net from an ordinary backup an attacker would simply turn off first.

Does this replace third-party Microsoft 365 backup?

No. It covers Entra Identity objects only, so Exchange Online, SharePoint and OneDrive are outside its scope entirely and still need their own arrangement. It also offers five days of retention rather than long-term archival. It reduces recovery time for Identity incidents and does not change the shared responsibility position for your data.

Need help working out how this fits your Entra or Microsoft 365 environment?

Managed M365 support

or call 0403 401 250