
Microsoft Entra Backup & Recovery is now generally available for tenants with Entra ID P1 or P2. Daily snapshots, seven-day retention, immutable storage — including Conditional Access policies and application registrations. The safety net that was long missing now exists.
There is a scenario every IT administrator knows, even if nobody wants to think about it. An admin adjusts a Conditional Access policy, forgets to add an IP range to a named location, and suddenly a hundred users at a branch office can no longer sign in. Or a misconfiguration in authentication methods locks accounts out at the exact moment MFA is required for all access. Until recently, the only way back was manual reconstruction from audit logs — time-consuming, error-prone, and sometimes impossible.
Microsoft has now closed this gap in identity management. Entra Backup & Recovery became generally available in June 2026 for all customers with an Entra ID P1 or P2 licence. It is the first native backup solution built specifically for the configuration of your identity directory — not for files or mailboxes, but for the policy and access structure of your entire organisation.
The scope of Entra Backup & Recovery goes beyond user accounts. Daily snapshots include: users, groups, applications, service principals, managed identities, Conditional Access policies, named locations, agent IDs, and authentication and authorisation policies. The latter covers settings for Multi-Factor Authentication, registration policies for authentication methods, and default sign-in behaviour for the entire tenant.
This is fundamentally different from the Recycle Bin feature that has existed in Entra ID for years. The Recycle Bin restores individually deleted objects but has no concept of configuration history. If someone changed a Conditional Access policy yesterday and that change causes sign-in problems today, there was no native way back. That limitation no longer exists.
The system is designed so that administrators need to do nothing to benefit from it. Entra Backup & Recovery is always on, runs automatically in the background, and takes a snapshot of all supported objects once per day. That snapshot is retained for seven days. Authorised administrators can browse available snapshots from the Entra portal and see what the configuration looked like at any point in time.
A critical characteristic is that snapshots are immutable. Even a Global Administrator cannot modify or delete backups, and the feature itself cannot be disabled. This makes the backup resistant to scenarios in which an attacker tries to erase traces after a compromise, and it prevents a hurried recovery attempt from accidentally overwriting the only available backup.
One of the most valuable additions in the GA release is the difference report. This lets you place two points in the backup history side by side and see exactly which objects and settings changed between those two moments. That is particularly useful in incidents where the cause of a sign-in problem is not immediately clear.
Say users report midday that a specific application is no longer accessible. With the difference report you compare the morning configuration with the current state and immediately see whether a Conditional Access policy, an application registration, or a named location was modified. What used to be hours of trawling through audit logs is reduced to minutes.
The recovery process offers granularity at the level of individual objects. You do not have to roll back the entire tenant to undo a single failed change. The available options are: restore all objects in a snapshot to their state at that moment, restore all objects of a particular type, or restore a single specific object.
That flexibility is essential for production environments. An IT administrator who wants to roll back a single Conditional Access policy does not have to make a decision about the rest of the configuration. The operation is targeted, auditable, and reversible.
The first scenario is an unintentional configuration change. An admin updates a named location in Entra, forgets to include a subnet, and a branch office suddenly falls outside the trusted locations. The result: employees who normally sign in directly are now asked for an additional MFA step or, in the absence of the right method, blocked entirely. With Backup & Recovery, the named location can be restored to yesterday's state in a handful of clicks without touching any other policies.
The second scenario is bulk deletion via automation. A script with overly broad permissions accidentally deletes a set of groups or service principals. The Recycle Bin helps for individual objects, but with large-scale deletions a snapshot offers immediate recovery of the complete situation in a single operation, including memberships and policy relationships.
The third scenario is identity sabotage during a security incident. When an attacker has had temporary access to an admin account, it is unclear which changes were made. The difference report provides a chronological overview of all configuration changes during the period of the incident, so the security team can determine exactly what was changed, when it happened, and which objects need to be restored.
Entra Backup & Recovery is automatically active for all tenants with Entra ID P1 or P2. There are no settings to enable. Still, there are three concrete steps every administrator should carry out this week.
First, go to the Entra portal and verify that snapshots are already available for your tenant. The feature appears under Identity > Backup and Recovery. Confirm that the first daily snapshot has been created and that the retained timeline is as expected.
Second, determine who has restore rights. A restore operation by default requires an admin role with write permissions on the objects in question. Ensure that at least two administrators know the procedure and that their access to the Entra portal is secured with phishing-resistant authentication, preferably a passkey or a hardware FIDO2 key.
Third, schedule a recovery test. A backup that has never been tested does not operationally exist. Run at least one recovery test per quarter for a non-critical object, so your team knows how the recovery process works when it genuinely matters. Document the test and its result as part of your incident response procedures.
The arrival of native backup in Entra ID fills a gap that existed for years. IT teams managing Microsoft 365 environments now have a reliable safety net for their identity configuration. Want to set up a recovery test, document the rights structure around Backup & Recovery, or review your complete Entra ID management framework? Contact Zarioh for a no-obligation conversation.
Zarioh Digital Solutions
IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Security

Security

Security