๐ Secure Bits ๐ก
๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐ฟ๐ฎ ๐๐ฎ๐ฐ๐ธ๐๐ฝ ๐ฎ๐ป๐ฑ ๐ฅ๐ฒ๐ฐ๐ผ๐๐ฒ๐ฟ๐ ๐ถ๐ ๐ป๐ผ๐ ๐ถ๐ป ๐ฃ๐๐ฏ๐น๐ถ๐ฐ ๐ฃ๐ฟ๐ฒ๐๐ถ๐ฒ๐ โ and it fills a major gap in identity resilience.
Someone disables a Conditional Access policy. A bulk import overwrites user attributes. A service principal loses its permissions. Until now, recovery meant digging through audit logs and manually reconstructing the state before.
๐๐ป๐๐ฟ๐ฎ ๐๐ฎ๐ฐ๐ธ๐๐ฝ ๐ฎ๐ป๐ฑ ๐ฅ๐ฒ๐ฐ๐ผ๐๐ฒ๐ฟ๐ changes that. It automatically creates ๐ฑ๐ฎ๐ถ๐น๐ ๐ฏ๐ฎ๐ฐ๐ธ๐๐ฝ๐ of critical directory objects โ users, groups, apps, service principals, CA policies, auth methods โ and retains ๐ฑ ๐ฑ๐ฎ๐๐ of history. No global admin can disable or modify them.
๐ ๏ธ ๐ช๐ต๐ฎ๐ ๐ถ๐ ๐ฑ๐ผ๐ฒ๐
You can browse backups, run ๐ฑ๐ถ๐ณ๐ณ๐ฒ๐ฟ๐ฒ๐ป๐ฐ๐ฒ ๐ฟ๐ฒ๐ฝ๐ผ๐ฟ๐๐ to see what changed, and recover objects to a previous state โ all from the Entra admin center. Recovery can target all objects, specific object types, or individual objects by ID.
The recovery model is straightforward:
– Object added since backup โ soft-deleted
– Object modified โ reverted to backup state
– Object soft-deleted โ restored
๐ ๐๐ฐ๐ฐ๐ฒ๐๐ ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น
Two new built-in roles โ ๐๐ฎ๐ฐ๐ธ๐๐ฝ ๐ฅ๐ฒ๐ฎ๐ฑ๐ฒ๐ฟ and ๐๐ฎ๐ฐ๐ธ๐๐ฝ ๐๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ผ๐ฟ โ support least-privilege access. Your security team can review backup state without triggering recovery.
โ ๏ธ ๐๐ถ๐บ๐ถ๐๐ฎ๐๐ถ๐ผ๐ป๐
Hard-deleted objects cannot be recovered. On-prem synced objects are excluded from recovery. Not all properties are covered yet โ manager, sponsor, and group ownership changes are out of scope.
For organizations navigating ๐ก๐๐ฆ๐ฎ and identity security requirements, a native, tamper-proof backup of the identity control plane is a welcome addition.
Requires at least Entra ID P1. Available now in preview.
๐ฌ How do you handle recoverability of your Entra ID tenant today?
๐๐ถ๐ต๐ฉ๐ฐ๐ณ ๐ฐ๐ง ๐ต๐ฉ๐ฆ ๐ฑ๐ฐ๐ด๐ต:
