Microsoft Entra Backup and Recovery is now generally available. Is it enough?

Infrastructure and operationsAugust 21, 2026 | 4 minutesBy Paul Robichaux

Every so often Microsoft ships a thing admins have been asking for since roughly forever. In the last few weeks, we’ve gotten two of them: the ability to change the organizer for a meeting and Entra Backup and Recovery, now generally available. This new backup capability is turning up in every workforce tenant with a Microsoft Entra ID P1 or P2 license. If you've ever been responsible for an identity estate, you've wanted this. Credit where it's due; it’s great to see Microsoft recognizing the need for customer-led data protection around identity.

What's now included 

Once a day, Microsoft snapshots the most important objects in your directory: users, groups, applications, service principals, managed identities, Conditional Access policies, named locations, and the authentication and authorization policies that tie them together. It keeps seven days of that history.

You can run a difference report to see what actually changed between a backup and your live tenant before you commit to anything. And, the part I like best, no admin, no matter how many roles they've collected, can switch the backups off or delete them. Anyone who has watched an intruder go looking for the backups first will appreciate that.

For the everyday case, like unwinding a Conditional Access change somebody made on Tuesday that nobody noticed until Thursday, this is a genuine capability and a long way ahead of leaning on soft delete. Plus, it’s free! (At least for now.)

It also raises the obvious follow-up, and it's the one I'd want answered before making this my only plan: is seven days, in the same tenant, run by the same operator, enough?

Four questions before you rely on it alone 

How long is your actual detection window? 

A seven-day retention window assumes you catch the problem within a week. A misconfiguration found during a compliance review, a privilege escalation that unfolds slowly, or an admin account that's been quietly exploited for a month doesn't fit inside that window.

Keepit for Microsoft Entra ID keeps backup data for up to 99 years, so retention becomes a decision your organization makes, rather than a constraint you inherit.

Where does the backup actually live?

Microsoft's backups sit inside Microsoft's own infrastructure, in the same geo-location as your tenant. That's a reasonable design choice, but it also means the backup and the thing it's protecting share an operator. That’s a first-class violation of the time-honored principle that you never keep your backups where you keep your production data.

Keepit stores backup data on an independent, vendor-neutral cloud, in dedicated infrastructure completely separate from Microsoft's own. If Entra ID itself is unavailable or deeply compromised, your recovery path doesn't depend on the same vendor's uptime.

Can you restore into a different tenant? 

Entra Backup and Recovery restores in place, back into the tenant it came from. That's the right default for the scenario it's built for, but it doesn't cover the case where the primary tenant itself is the problem. It also doesn’t support cloning a tenant as a sandbox for disaster-recovery practice.

We added cross-tenant restore to Keepit for Microsoft Entra ID earlier this year for exactly that reason, so teams can rebuild directory objects and configuration in a separate tenant to test, verify, and recover without experimenting on a live environment.

Does it cover your whole identity surface, and the rest of your SaaS estate? 

Entra Backup and Recovery's scope is core directory objects and policy. It doesn't extend to Intune device configuration profiles, Intune compliance policies, or BitLocker recovery keys, which Keepit backs up alongside the rest of Entra ID. And its scope stops at Entra ID.

If you're already backing up Microsoft 365, Google Workspace, or Salesforce elsewhere, the native tool adds one more console and one more recovery runbook to manage during an incident, on top of the ones you already have. 

The bigger picture 

Microsoft frames Backup and Recovery as one layer of a broader tenant recoverability strategy, alongside configuration exports and operational readiness. That's the right way to look at it, and it's exactly where a dedicated, independent backup platform earns its place: extending the retention window, keeping a copy outside Microsoft's own infrastructure, giving you a clean tenant to restore into, and putting Entra ID under the same roof as the rest of your SaaS applications.

If you're already backing up Entra ID with Keepit, none of this changes what you need to do. If you're currently relying on the native tool alone, it's a good moment to check those four questions against what your organization actually needs. 

See how Keepit for Microsoft Entra ID closes the gap

Author

Paul Robichaux is Senior Director of Product Management at Keepit and a Microsoft MVP (Most Valuable Professional) – a title he has been awarded every year since 2003. Paul has worked in IT since 1978 and held a number of CTO and senior product development positions in the software industry.

Paul is a prolific contributor to the Microsoft community: He is the author of an impressive amount of books and articles about Microsoft technologies, including the best-selling Office 365 for IT Pros, a contributing editor for Practical 365, and produces a continuous stream of videos, podcasts, and webinars.  He is based in Alabama in the United States.

Find Paul on LinkedIn and Twitter