Restore an Entra ID user

Restoring an Entra ID user recreates or updates its attributes, manager link, role assignments, group ownerships, group and admin unit memberships, and licenses.

Prerequisites

Before you begin, make sure the Entra ID service account used to create the connector has the global admin role assigned.

Restore an Entra ID user

1. Open the Connectors page and select the connector. 

2. Locate the user in the connector.

3. (Optional) To restore an older version of the object, select the Snapshots Viewer icon and select an earlier snapshot. You are now viewing data from that point in time.

4. Select ••• > Restore.

Tip: To preview attributes and relationships or compare versions, select ••• > Object metadata. You can also start the restore directly from this previewer. 

5. Click Yes to confirm.

Restore all Entra ID users

To recover large amounts of data, restore users from the connector level.

Before you begin, ensure the Entra ID service account that was used to create the connector is assigned the global admin role.

Note: We recommend restoring all users and groups together to maintain their relationships. Linked users and groups (subobjects) are also restored as part of the operation.

1. Open the Connectors page.

2. Point to the connector and click the Restore icon.

3. Click Next.

4. Select a snapshot.

5. Choose the items to restore and click Next.

6. Review the summary and click Restore

What happens when a user is restored

Attributes restored

The user's attributes, licenses, and photo are recreated if missing, or updated if the user still exists.

Relationships reestablished

A relationship can only be reestablished if the linked object still exists in Entra ID.

The following relationships are reestablished:

  • Memberships — links to groups and admin units the user belongs to.
  • Ownerships — links to groups the user owns.
  • Role assignments — links to roles assigned to the user.
  • Manager — the link to the user's manager.

Note: Group-inherited role assignments aren't visible in the Keepit UI, but they are backed up and restored.

New ID and creation time

If the user no longer exists in Entra ID, they receive a new object ID and creation time. If the user is in the Deleted users folder and hasn't been permanently deleted, Keepit restores them with the original ID and creation time.

Note: Restoring users recreates them with new IDs, but restoring from the same snapshot doesn't create duplicates. Keepit identifies users by their attributes and overwrites any existing matching user in Entra ID.

This diagram shows the relationships that are restored:


 Restore limitations

The following limitations apply when restoring Entra ID users:

  • Memberships to distribution groups or mail-enabled security groups can't be restored due to an API limitation. In these cases, the restore job is marked as incomplete and the affected memberships are skipped.
  • Users who are permanently deleted and then restored can't sign in until an admin resets their password in Entra ID.
  • Due to a Microsoft Graph API limitation, users with on-premises sync enabled can't be restored.
  • Authentication methods are not restored.
  • If the user doesn't have a valid usageLocation value set, Microsoft Graph blocks the license reassignment. The Graph API for license assignment requires that users have a valid usageLocation attribute set before licenses can be assigned. For more information, see Microsoft documentation.