Azure AD B2C
The backup service for Azure AD B2C supports protecting the app registrations, identity providers, user attributes, user flows, and users. Azure AD B2C data recovery only supports restoring the supported data types to the original location.
Refer to the tables below for supported and unsupported object types you can protect in the Azure AD B2C service.
App Registration
The data recovery state for app registrations is the same as that of the Microsoft Entra ID service. For details, refer to App Registration.
Identity Provider
Refer to the list below for the data recovery state for identity providers.
Social Identity Provider
Refer to the list below for the social identity providers protected in the Azure AD B2C service:
Amazon
| Attributes | Backup | Restore |
|---|
| Origin URL | Supported | Supported |
| Callback URL | Supported | Supported |
| Name | Supported | Supported |
| Client ID | Supported | Supported |
| Client secret | Unsupported | Unsupported |
Facebook
| Attributes | Backup | Restore |
|---|
| Origin URL | Supported | Supported |
| Callback URL | Supported | Supported |
| Name | Supported | Supported |
| Client ID | Supported | Supported |
| Client secret | Unsupported | Unsupported |
Google
| Attributes | Backup | Restore |
|---|
| Origin URL | Supported | Supported |
| Callback URL | Supported | Supported |
| Name | Supported | Supported |
| Client ID | Supported | Supported |
| Client secret | Unsupported | Unsupported |
LinkedIn
| Attributes | Backup | Restore |
|---|
| Origin URL | Supported | Supported |
| Callback URL | Supported | Supported |
| Name | Supported | Supported |
| Client ID | Supported | Supported |
| Client secret | Unsupported | Unsupported |
| Attributes | Backup | Restore |
|---|
| Origin URL | Supported | Supported |
| Callback URL | Supported | Supported |
| Name | Supported | Supported |
| Client ID | Supported | Supported |
| Client secret | Unsupported | Unsupported |
OpenID Identity Provider
| Attributes | Backup | Restore |
|---|
| Name | Supported | Supported |
| Metadata URL | Supported | Supported |
| Client ID | Supported | Supported |
| Client secret | Unsupported | Unsupported |
| Scope | Supported | Supported |
| Response type | Supported | Supported |
| Response mode | Supported | Supported |
| Domain hint | Supported | Supported*Note: The domain hint cannot be restored if the value is empty. |
| User ID | Supported | Supported |
| Display name | Supported | Supported |
| Given name | Supported | Supported |
| Surname | Supported | Supported |
| Email | Supported | Supported |
User Attribute
Refer to the table below for the data recovery state for user attributes:
| Object Types | Object Types | Backup | Restore |
|---|
| Build-In Attribute | Build-In Attribute | Unsupported | Unsupported |
| Custom Attribute | Name | Supported | Supported |
| Custom Attribute | Data Type | Supported | Supported |
| Custom Attribute | Description | Supported | Supported |
User Flow
Refer to the table below for the data recovery state for user flows:
| Property | Backup | Restore |
|---|
| Enable JavaScript enforcing page layout | Unsupported | Unsupported |
| Multifactor authentication | Supported | Supported*Note: The multifactor authentication of SMS or phone call is unsupported. |
| Conditional access | Supported | Supported |
| Token lifetime | Supported | Supported |
| Token compatibility settings | Supported | Supported |
| Session behavior | Supported | Supported |
| Password configuration | Supported | Supported |
| Captcha | Unsupported | Unsupported |
| Identity providers | Supported | Supported |
| User attributes | Supported | Supported |
| Application claims | Unsupported | Unsupported |
| API connectors | Supported | Supported |
Object Attributes
| Attributes | Backup | Restore |
|---|
| Type of method | Supported | Supported |
| MFA enforcement | Supported | Supported |
| Enforce conditional access policies | Supported | Supported |
| Access & id token lifetime | Supported | Supported |
| refresh token lifetime | Supported | Supported |
| refresh token sliding window lifetime | Supported | Supported |
| lifetime length | Supported | Supported |
| Issuer (iss) claim | Supported | Supported |
| Subject (sub) claim | Unsupported | Unsupported |
| Claim representing user flow | Unsupported | Unsupported |
| Web app session lifetime | Supported | Supported |
| Web app session timeout | Supported | Supported |
| Single sign-on configuration | Supported | Supported |
| Require ID Token in logout requests | Supported | Supported |
| Enforce SSO logout validation | Unsupported | Unsupported |
| Enable keep me signed in session | Supported | Supported |
| Keep me signed in session | Supported | Supported |
| Self-service password reset | Supported | Supported |
| Forced password reset | Supported | Supported |
| Password complexity | Supported | Supported |
| Local accounts | Supported | Supported |
| Social identity providers | Supported | Supported |
| Custom identity providers | Supported | Supported |
User
Refer to the table below for the data recovery state for users:
| Object Types | Object Types | Backup | Restore |
|---|
| Overview | Display name | Supported | Supported |
| Overview | Last name | Supported | Supported |
| Overview | First name | Supported | Supported |
| Overview | User principal name | Supported | Supported |
| Overview | User type | Supported | Supported |
| Overview | Authorization info | Supported | Supported |
| Overview | Job title | Supported | Supported |
| Overview | Company name | Supported | Supported |
| Overview | Department | Supported | Supported |
| Overview | Employee ID | Supported | Supported |
| Overview | Employee type | Supported | Supported |
| Overview | Employee hire date | Supported | Supported |
| Overview | Office location | Supported | Supported |
| Overview | Manager | Supported | Supported |
| Overview | Sponsors | Supported | Supported |
| Overview | Street address | Supported | Supported |
| Overview | City | Supported | Supported |
| Overview | State or province | Supported | Supported |
| Overview | ZIP or postal code | Supported | Supported |
| Overview | Country or region | Supported | Supported |
| Overview | Business phone | Supported | Supported |
| Overview | Mobile phone | Supported | Supported |
| Overview | Email | Supported | Supported |
| Overview | Other emails | Supported | Supported |
| Overview | Fax number | Supported | Supported |
| Overview | Mail nickname | Supported | Supported |
| Overview | Age group | Supported | Supported |
| Overview | Consent provided for minor | Supported | Supported |
| Overview | Account enabled | Supported | Supported |
| Overview | Usage location | Supported | Supported |
| Overview | preferredLanguage | Supported | Supported |
| Overview | preferredDataLocation | Supported | Supported |
| Overview | passwordPolicies | Supported | Supported |
| Assigned roles | Assigned roles | Supported | Supported |
| Group | Group | Supported | Supported |
| Application | Application | Supported | Supported |
| License | License | Unsupported | Unsupported |
| Device | Device | Unsupported | Unsupported |
| Azure role assignment | Azure role assignment | Unsupported | Unsupported |
| Authentication method | phoneAuthenticationMethod | Supported | Supported |
| Authentication method | emailAuthenticationMethod | Supported | Supported |