Last updated: 1 October 2026
Entra ID backup is in beta. We test it in our own tenant and update this page when it changes.
Update log
| Date | What changed |
|---|---|
| 1 Oct 2026 | First published. Covers users, groups and directory roles. |
Main features
| Feature | Detail |
|---|---|
| Objects covered | Users, groups, directory roles |
| Backup frequency | Daily by default, up to 3× a day. On-demand snapshots supported |
| Retention | Unlimited, no storage cap |
| Search | Snapshots are indexed — find and export a single object without restoring |
| Restore security | Step-up authentication to Microsoft required before anything is written back |
| Storage | Immutable on AWS S3, with Bring Your Own Storage options |
| Licensing | No extra cost for existing Microsoft 365 customers during the beta |
What we've verified
Tested by deleting and purging real objects in our own tenant, then restoring and comparing against what we recorded beforehand.
| Item | Result |
|---|---|
| User account and profile | Restored |
| Directory role assignment | Restored |
| Membership of a group that still exists | Restored |
| Membership, rebuilt by restoring the group | Restored, where the members still exist |
| Membership of a group that was also deleted | Not restored — rebuild manually |
| Group ownership, restoring the group | Restored, where the owner still exists |
| Group ownership, restoring the owner | Not restored — reinstate manually |
| Object IDs | Restored objects get new IDs and a new creation date |
New object IDs are a Microsoft constraint, not a CloudAlly one — once an object is purged, nothing can recreate it with its original ID. Relationships are matched on that ID, from whichever side you restore: a link comes back as long as the object at the other end kept its original ID. Deletions that take out both ends are the case that needs rebuilding by hand. Ownership is the one exception to the symmetry: the backed-up user object holds the groups a user belongs to but not the ones they own, so ownership is only written when you restore the group.
Not in this release
- Conditional Access policies
- App registrations and enterprise applications
- Administrative units
- Merge or restore-missing-only modes — Replace is the only option
- Compare-before-restore between two snapshots
- Itemised job results showing what was skipped
Need Help with CloudAlly?
We set up, manage, and support CloudAlly backup solutions for Microsoft 365, Google Workspace, and Salesforce. If you have questions or need expert guidance, we're here to help.
Speak to an expertWas this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article