Photo by Pavitra Baxi on Unsplash

Photo by Pavitra Baxi on Unsplash

Backup and Restore in Entra ID

Safety Rope

Article from ADMIN 93/2026
By
Data backup is often overlooked in Microsoft Entra ID. User accounts, groups, and Conditional Access policies need targeted protection. We tell you which objects are backed up automatically, where you need to take action, and how you can effectively combine backups and documentation.

At first glance, Microsoft Entra ID does not appear to be a traditional data storage system and does not seem to require a backup. To begin, though, you need to clarify what "data" means in today's world. In the conventional sense, the term encompasses all the content that users create and modify on a daily basis. When it comes to Entra ID and data backup, this term takes on a different meaning, primarily referring to user accounts, group accounts, and policies. Quickly it becomes clear that Entra ID also has valuable content that you need to back up regularly.

How Secure?

Microsoft makes a clear distinction between different object types (e.g., users or groups), so you have no one-size-fits-all answer to the question of how secure objects are in Microsoft Entra ID. One key factor is the source of truth (i.e., the original origin of an object). If the user lifecycle is in the local Active Directory, for example, the behavior is clearly defined: If you delete a synchronized user in Entra ID, the account first ends up in the recycle bin for user objects, where it remains for 30 days before being permanently removed.

Within this period, either you manually restore the user object or it is automatically recreated by the next sync, provided it remains within the synchronization scope. Note that an automatic restoration will leave the object ID unchanged. As a result, the user account will pop up again at all locations where it was previously used, such as in Conditional Access (CA) policies. If the object is deleted, Microsoft first removes it from these configurations; however, it still becomes available again after the next sync.

The entire process also works in reverse: If you remove a user from the synchronization scope, Entra ID moves them to the Recycle Bin. If you later add the user account back to the scope, the account is not recreated, but restored with the original


...

Use one of the options below to read the full article

Buy this article as PDF

Download Article PDF now with Express Checkout
Price $2.95
(incl. VAT)

Buy ADMIN Magazine

Related content

comments powered by Disqus