Microsoft Entra ID

Scope Supported Objects Limitations

In brief

> [!NOTE]

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

Backups are created automatically once per day and retained for up to five days. Difference reports compare a selected backup with the current tenant state and show changes to supported properties and links.

Recovery scope levels

When you create a difference report or start recovery, you can scope the operation to all supported objects, selected object types, or specific object IDs. Some related objects are grouped for scoping. For example, service principals, OAuth2 permission grants, and app role assignments are grouped under a single filter in the Microsoft Entra admin center.

User

Recovery for user objects supports these properties:

Microsoft Entra Backup and Recovery doesn't support the recovery or re-creation of hard-deleted objects. Only soft-deleted or modified objects can be restored.

Soft-deleted supported objects can be restored for 30 days through soft-delete recovery processes. Backup and Recovery focuses on restoring supported backup state from retained backups and doesn't replace those recovery processes.

Objects managed in on-premises Active Directory Domain Services

Any changes made to on-premises synced objects (except group memberships) appear in difference reports, but are automatically excluded from recovery. Organizations that use hybrid identity with Microsoft Entra ID can use difference reports to identify changes to objects synchronized from on-premises. For certain object types, such as users and groups, you can move the source of authority from on-premises to the cloud. After conversion, all Backup and Recovery functionality is available for those objects. Back up and recover objects managed on-premises by using an alternative solution.