๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Cloud identity protection

What is Entra ID backup?

Capturing the configuration of Microsoft Entra ID, its Conditional Access policies, role assignments, app registrations, and group memberships, so changes can be detected, audited, and reverted. Lavawall® delivers it with audit-log correlation and per-object rollback.

Start free, no credit card See the module

Conditional Access · roles · app registrations · rollback

Definition

Entra ID backup is the practice of capturing Microsoft Entra ID configuration, including Conditional Access policies, role assignments, app registrations, group memberships, and custom security attributes, so changes can be detected, audited, and reverted. It is distinct from mailbox content backup and from on-premises Active Directory backup.

Entra ID backup is the practice (and product category) of capturing and storing the configuration state of Microsoft Entra ID (formerly Azure Active Directory) so that changes can be detected, audited, and reverted.

Microsoft's native protections remain limited. Most Entra object types lack recycle bin functionality, audit log retention defaults to 30 days, and no native "undo" exists for configuration modifications.

Entra ID warrants dedicated terminology because it serves as the identity foundation for Microsoft 365. Every authentication, authorisation decision, and Conditional Access evaluation routes through it. Configuration drift in Entra carries security consequences faster than configuration drift in any other M365 surface.

See what Lavawall® does

Built and used internally by ThreeShield, an audit firm in Calgary. Built for MSPs and lean IT teams. Cross-platform patching, M365 / Entra / Azure / Google Workspace breach detection, M365 configuration change monitoring and rollback, 15+ compliance frameworks, kernel-free application control, smart helpdesk, and multi-tenant remote support. One platform, native CAD billing.

What gets backed up

Entra ID backup captures the configuration objects that decide who can sign in and what they can do:

  • Conditional Access policies
  • Named locations and authentication strengths
  • Authentication methods policy
  • Role assignments
  • App registrations and service principals
  • Group memberships
  • Custom security attributes
  • Domain configuration

Why it matters

Real-world attackers weaponise Entra configuration rather than simply destroying it. An attacker who compromises a global admin doesn't usually delete things; they reconfigure things to maintain access and broaden their reach. Recovering from that without a backup means manual investigation and remediation, which is slow, error-prone, and dependent on how complete the audit log happens to be.

Specific incident patterns include:

  • Disabled MFA enforcement on admin accounts after credential phishing
  • Malicious OAuth app registration with high-privilege Graph scopes
  • Service principals promoted to privileged directory roles
  • Conditional Access policy carve-outs for specific user accounts the attacker controls
  • Authentication-methods-policy changes lowering required factor strength

How Lavawall® helps with Entra ID backup

Lavawall®'s M365 / Entra / Azure configuration backup and rollback module captures Conditional Access policies, named locations, authentication methods policy, role assignments, app registrations, service principals, group memberships, custom security attributes, and domain configuration.

Every change correlates with the M365 audit log to surface the user principal name, IP address, country, and audit event identifier, and severity is calculated at detection time. Rollback follows a strict plan, approve, execute lifecycle with dry-run preview, so you can revert a single object or a run of changes with a reviewed, logged workflow.

Beyond Entra, the same engine manages Intune profiles, M365 organisation settings, and Azure subscription resources such as Network Security Groups, Key Vault, RBAC, and managed identities, so one module protects the whole Microsoft cloud configuration surface.

Back up your Entra config free →

Frequently asked

Is Entra ID the same as Active Directory?
No. Active Directory is the on-premises directory service; Entra ID (formerly Azure Active Directory) is Microsoft's cloud identity service. They can be synced, but they're separate systems with separate object models, different APIs, and different backup tooling.
Does Microsoft back up Entra ID for me?
No. Microsoft maintains the platform, but the shared responsibility model puts protection of your data, including configuration data, on you. Most Entra object types have no recycle bin; even the ones that do delete after 30 days.
What about Microsoft Entra ID's native backup feature?
Microsoft has begun building Entra ID protection capabilities, but they're limited in scope and don't replace dedicated configuration-backup tooling.