Skip to main content

Entra ID Page

The Entra ID page lists the Entra tenants that Identity Recovery backs up. It displays the backup schedule settings for each added Entra tenant. You can also add and configure a new Entra tenant.

Click Configuration in the left pane. Then click the Entra ID tab on the Configuration page to open the Entra tenants page.

Tenant Page

The table displays the following information:

  • Tenant – Fully-qualified name of the tenant

  • Last Collection Time – The most recent time the collection (backup) occurred

  • Duration – The time the collection took to complete

  • Status – Collection state as idle, waiting, error, or success

  • Details – Information about any errors that occurred during the last backup

  • Actions – Displays the icons used to collect, edit, and delete the respective tenant configuration

    • Run backup – Click the Play icon to start a new collection (backup) on the respective tenant if you need a collection outside the configured schedule
    • Edit configuration – Edit the settings of the tenant. Click the Edit icon for a tenant to open the Edit Tenant Configuration wizard and edit the tenant's settings. See the Edit Tenant Configuration topic for additional information.
    • Delete configuration – Click the Delete icon for a tenant to delete it

To add a tenant, click the Add tenant configuration button. See the Add a Tenant topic for additional information.

Add a Tenant

To add a tenant, provide tenant details and configure the backup schedule.

Step 1 – Click the Add tenant configuration button on the Entra Id page to launch the Add Tenant Configuration wizard.

Add Tenant Configuration wizard - Entra Id page

Step 2 – Enter a tenant [example.tenant.com] in the Tenant field.

Step 3 – Enter the Client Id [CLIENTID] for backups, rollbacks, and recoveries in the Client ID field.

Step 4 – Enter the secret for the application registration in the Secret field.

note

The application registration must have the following Microsoft Graph access:

API / Permissions nameTypeDescriptionAdmin consent requiredStatus
AccessReview.ReadWrite.AllApplication Manage all access reviewsYesGranted
AdministrativeUnit.ReadWrite.AllApplication Read and write all administrative unitsYesGranted
Agreement.ReadWrite.AllApplication Read and write all terms of use agreementsYesGranted
Application.ReadWrite.AllApplication Read and write all applicationsYesGranted
Application.ReadWrite.OwnedByApplication Manage apps that this app creates or ownsYesGranted
CrossTenantInformation.ReadBasic.AllApplication Read cross-tenant basic informationYesGranted
Device.ReadWrite.AllApplication Read and write devicesYesGranted
Directory.ReadWrite.AllApplication Read and write directory dataYesGranted
Domain.ReadWrite.AllApplication Read and write domainsYesGranted
Group.ReadWrite.AllApplication Read and write all groupsYesGranted
IdentityProvider.ReadWrite.AllApplication Read and write identity providersYesGranted
Policy.Read.AllApplication Read your organization's policiesYesGranted
Policy.ReadWrite.ConditionalAccess ApplicationRead and write your organization's conditional access policiesYesGranted
PrivilegedAccess.ReadWrite.AzureAD ApplicationRead and write privileged access to Azure AD rolesYesGranted
PrivilegedAccess.ReadWrite.AzureADGroupApplication Read and write privileged access to Azure AD groupsYesGranted
PrivilegedAccess.ReadWrite.AzureResourcesApplication Read and write privileged access to Azure resourcesYesGranted
RoleManagement.ReadWrite.DirectoryApplication Read and write all directory RBAC settingsYesGranted
User.DeleteRestore.AllApplication Delete and restore all usersYesGranted
User.ReadWrite.AllApplication Read and write all users' full profilesYesGranted

Step 5 – Click Next.

Add Tenant Configuration wizard - Backup Schedule page

Step 6 – Select the days of the week in the Run the backup on section to indicate when to run backups.

Step 7 – Select a start time (UTC) in the Start the backup at field to begin the backup. The default time is 12:00 AM.

Step 8 – In the Repeat every field, enter a frequency, in minutes, to set the time between the start of each domain backup. Consider the size of the environment when configuring this option. Click Next.

note

If you change the start time from the default and select a frequency (in minutes), the backups run at the configured frequency but skip from midnight until the selected start time.

Add Tenant Configuration wizard - Notifications page

Step 9 – To set notifications, select the Send email notifications checkbox and enter the email address of one or more users and/or groups to receive the job start and end notifications. Use a semicolon (;) to separate multiple recipients. See the Notifications Page topic for additional information.

If you don't want notifications, skip this step.

Step 10 – Click Next.

Add Tenant Configuration wizard - Confirm page

Step 11 – The Confirm page displays a summary of the settings you provided on the pages of the wizard. Use the Back button to return to a previous page and change any setting. Click Done to finish the wizard.

The new tenant appears on the Entra Id page.

Backups begin as scheduled. On the first scheduled instance, Identity Recovery performs a complete backup of the tenant. Then, subsequent backups only include the incremental changes that occurred since the previous backup.

Edit Tenant Configuration

Step 1 – On the Entra Id page, click the Edit configuration icon for a tenant. The Edit Tenant Configuration wizard opens.

Step 2 – Modify the settings you want to change for the tenant configuration.

Step 3 – The Confirm page displays a summary of the settings you provided on the pages of the wizard. Use the Back button to return to a previous page and change any setting. Click Done to finish the wizard.

Identity Recovery updates the tenant configuration and backups resume as scheduled.