Microsoft Entra ID

Backup Difference Report Recovery Model

In brief

For a full list of supported attributes, see [Supported objects and attributes](scope-supported-objects-limitations.md).

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

For a full list of supported attributes, see Supported objects and attributes.

Backups are created automatically once per day and retained for up to five days. Select from these retained backups when you create a difference report or start recovery.

Difference reports

Create a difference report to compare the current state of your tenant with a selected backup. Only changed objects appear in the report.report, with changed attributes and links shown for review. Apply filters to view changes for a specific object type or a specific object. If you don't apply a filter, all changed objects are included in the difference report.

Changes for users and groups synchronized from on-premises Active Directory appear in the difference report to help you track changed objects. However, you can't recover on-premises synced objects through Backup and Recovery, because the source of authority for these objects is on-premises Active Directory.

When you recover your tenant, apply filters to control which objects to recover:

  • By object type: Recover only objects of a certain type, such as users, groups, applications, service principals, or applications.Conditional Access policies.
  • By object ID: Supply the object type and object ID to recover a specific object.
  • All changes: Recover all changed objects to the state captured in the selected backup.

For supported objects that are soft-deleted, you can also use soft-delete recovery processes within the 30-day soft-delete window.

On-premises synchronized objects can't be recovered through Backup and Recovery, because the source of authority is on-premises Active Directory. Recover these objects in on-premises Active Directory instead. Changes to synced objects still appear in difference reports.

Microsoft Entra Backup and Recovery is available for workforce tenants only. Microsoft Entra External ID tenants and Azure AD B2C tenants aren't supported.