Azure AD B2C

The backup service for Azure AD B2C supports protecting the app registrations, identity providers, user attributes, user flows, and users. Azure AD B2C data recovery only supports restoring the supported data types to the original location.

Refer to the tables below for supported and unsupported object types you can protect in the Azure AD B2C service.

App Registration

The data recovery state for app registrations is the same as that of the Microsoft Entra ID service. For details, refer to App Registration.

Identity Provider

Refer to the list below for the data recovery state for identity providers.

Social Identity Provider

Refer to the list below for the social identity providers protected in the Azure AD B2C service:

Amazon

AttributesBackupRestore
Origin URLSupportedSupported
Callback URLSupportedSupported
NameSupportedSupported
Client IDSupportedSupported
Client secretUnsupportedUnsupported

Facebook

AttributesBackupRestore
Origin URLSupportedSupported
Callback URLSupportedSupported
NameSupportedSupported
Client IDSupportedSupported
Client secretUnsupportedUnsupported

Google

AttributesBackupRestore
Origin URLSupportedSupported
Callback URLSupportedSupported
NameSupportedSupported
Client IDSupportedSupported
Client secretUnsupportedUnsupported

LinkedIn

AttributesBackupRestore
Origin URLSupportedSupported
Callback URLSupportedSupported
NameSupportedSupported
Client IDSupportedSupported
Client secretUnsupportedUnsupported

Twitter

AttributesBackupRestore
Origin URLSupportedSupported
Callback URLSupportedSupported
NameSupportedSupported
Client IDSupportedSupported
Client secretUnsupportedUnsupported

OpenID Identity Provider

AttributesBackupRestore
NameSupportedSupported
Metadata URLSupportedSupported
Client IDSupportedSupported
Client secretUnsupportedUnsupported
ScopeSupportedSupported
Response typeSupportedSupported
Response modeSupportedSupported
Domain hintSupportedSupported*Note: The domain hint cannot be restored if the value is empty.
User IDSupportedSupported
Display nameSupportedSupported
Given nameSupportedSupported
SurnameSupportedSupported
EmailSupportedSupported

User Attribute

Refer to the table below for the data recovery state for user attributes:

Object TypesObject TypesBackupRestore
Build-In AttributeBuild-In AttributeUnsupportedUnsupported
Custom AttributeNameSupportedSupported
Custom AttributeData TypeSupportedSupported
Custom AttributeDescriptionSupportedSupported

User Flow

Refer to the table below for the data recovery state for user flows:

PropertyBackupRestore
Enable JavaScript enforcing page layoutUnsupportedUnsupported
Multifactor authenticationSupportedSupported*Note: The multifactor authentication of SMS or phone call is unsupported.
Conditional accessSupportedSupported
Token lifetimeSupportedSupported
Token compatibility settingsSupportedSupported
Session behaviorSupportedSupported
Password configurationSupportedSupported
CaptchaUnsupportedUnsupported
Identity providersSupportedSupported
User attributesSupportedSupported
Application claimsUnsupportedUnsupported
API connectorsSupportedSupported

Object Attributes

AttributesBackupRestore
Type of methodSupportedSupported
MFA enforcementSupportedSupported
Enforce conditional access policiesSupportedSupported
Access & id token lifetimeSupportedSupported
refresh token lifetimeSupportedSupported
refresh token sliding window lifetimeSupportedSupported
lifetime lengthSupportedSupported
Issuer (iss) claimSupportedSupported
Subject (sub) claimUnsupportedUnsupported
Claim representing user flowUnsupportedUnsupported
Web app session lifetimeSupportedSupported
Web app session timeoutSupportedSupported
Single sign-on configurationSupportedSupported
Require ID Token in logout requestsSupportedSupported
Enforce SSO logout validationUnsupportedUnsupported
Enable keep me signed in sessionSupportedSupported
Keep me signed in sessionSupportedSupported
Self-service password resetSupportedSupported
Forced password resetSupportedSupported
Password complexitySupportedSupported
Local accountsSupportedSupported
Social identity providersSupportedSupported
Custom identity providersSupportedSupported

User

Refer to the table below for the data recovery state for users:

Object TypesObject TypesBackupRestore
OverviewDisplay nameSupportedSupported
OverviewLast nameSupportedSupported
OverviewFirst nameSupportedSupported
OverviewUser principal nameSupportedSupported
OverviewUser typeSupportedSupported
OverviewAuthorization infoSupportedSupported
OverviewJob titleSupportedSupported
OverviewCompany nameSupportedSupported
OverviewDepartmentSupportedSupported
OverviewEmployee IDSupportedSupported
OverviewEmployee typeSupportedSupported
OverviewEmployee hire dateSupportedSupported
OverviewOffice locationSupportedSupported
OverviewManagerSupportedSupported
OverviewSponsorsSupportedSupported
OverviewStreet addressSupportedSupported
OverviewCitySupportedSupported
OverviewState or provinceSupportedSupported
OverviewZIP or postal codeSupportedSupported
OverviewCountry or regionSupportedSupported
OverviewBusiness phoneSupportedSupported
OverviewMobile phoneSupportedSupported
OverviewEmailSupportedSupported
OverviewOther emailsSupportedSupported
OverviewFax numberSupportedSupported
OverviewMail nicknameSupportedSupported
OverviewAge groupSupportedSupported
OverviewConsent provided for minorSupportedSupported
OverviewAccount enabledSupportedSupported
OverviewUsage locationSupportedSupported
OverviewpreferredLanguageSupportedSupported
OverviewpreferredDataLocationSupportedSupported
OverviewpasswordPoliciesSupportedSupported
Assigned rolesAssigned rolesSupportedSupported
GroupGroupSupportedSupported
ApplicationApplicationSupportedSupported
LicenseLicenseUnsupportedUnsupported
DeviceDeviceUnsupportedUnsupported
Azure role assignmentAzure role assignmentUnsupportedUnsupported
Authentication methodphoneAuthenticationMethodSupportedSupported
Authentication methodemailAuthenticationMethodSupportedSupported