Microsoft Entra ID

Create Review Difference Reports

In brief

You need at least the **Microsoft Entra Backup Reader** role to review difference reports. To review and create difference reports, you need the **Microsoft Entra Backup Administrator** role. The **Global Administrator** role also includes these permissions.

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

You need at least the Microsoft Entra Backup Reader role to review difference reports. To review and create difference reports, you need the Microsoft Entra Backup Administrator role. The Global Administrator role also includes these permissions.

The tenant must also have Microsoft Entra ID P1 or P2 licenses.

Scope a difference report

When you create a difference report, scope it to control which objects are included in the comparison:

  • All supported objects: Includes all supported object types in the tenant.
  • By object type: Includes only selected object types.types, such as Conditional Access policies, service principals, or groups.
  • By object ID: Includes only specific objects by their object IDs with their object types specified. Specify up to 100 object IDs across supported object types.

You set the scope when you create the report. You can't change it afterward.

:::image type="content" source="media/create-review-difference-reports/create-difference-report-backups-page.png#lightbox" alt-text="Screenshot of the Backups page showing available backups with a Create difference report button in the toolbar.":::

Backups are created automatically once per day and retained for up to five days. Only backups within this retention window appear for selection. The report compares the selected backup with the current tenant state.

  1. (Optional) Apply filters to limit the scope of objects included in the report. Choose one of these options:

    • Include all objects in their previous state: Compares all supported objects in the tenant.

Review a difference report

A difference report reflects the current tenant state at the time the report was created and doesn't update automatically. If more changes occur before recovery, create a new difference report.

  1. Go to Backup and recovery > Difference reports. The list shows each report's status, backup details (ID, timestamp, and availability), and scoping criteria. It also shows creation and completion times, and the number of objects and links in the report.

    :::image type="content" source="media/create-review-difference-reports/difference-reports-list.png#lightbox" alt-text="Screenshot of the Difference Reports list page showing report statuses, backup timestamps, and filtering details for three difference reports.":::