Home > Supported and Unsupported Data Types > Entra External ID

Download this article

Entra External ID

The backup service for Entra External ID supports protecting the users, groups, app registrations, enterprise applications, custom user attributes, user flows, identity providers, custom authentication extensions, and custom branding.

Entra External ID data recovery supports restoring the users, groups, app registrations, enterprise applications, custom user attributes, user flows, identity providers, custom authentication extensions, and custom branding to the original location. Refer to the following table for the supported object types you can protect in Entra External ID.

Users

ComponentStatusComment
ProfilesSupported 
PhotoUnsupported
Assigned rolesSupportedOnly the eligible assignments and active assignments are supported. The expired assignments are unsupported. 
Custom security attributesUnsupported  
Administrative unitsSupported 
GroupsSupported 
ApplicationsSupported 
LicenseUnSupported 
DevicesUnsupported 
Azure role assignmentsUnsupported 
Authentication methodsPartially SupportedAlternative phone belongs to MFA. Backup and restore of MFA properties are not supported.Temporary Access Pass and QR code are not supported.
Extension attributesUnsupported 

Object Attributes

AttributeStatusComment
accountEnabledSupported 
ageGroupSupported 
businessPhonesSupported 
citySupported 
companyNameSupported 
consentProvidedForMinorSupported 
countrySupported 
createdDateTimeUnsupported 
creationTypeUnsupported 
deletedDateTimeUnsupported 
departmentSupported 
employeeHireDateUnsupported 
employeeIdSupported 
employeeOrgDataSupported 
employeeTypeSupported 
externalUserStateUnsupported 
externalUserStateChangeDateTimeUnsupported 
faxNumberSupported 
givenNameSupported 
identitiesSupported 
jobTitleSupported 
Last password change date timeUnsupported 
mailSupported 
mailNickname Supported 
mobilephoneSupported 
officeLocationSupported 
onPremisesImmutableIdSupported 
onPremisesProvisioningErrorsUnsupported 
otherMailsSupported 
passwordPoliciesSupported 
postalCodeSupported 
preferredDataLocationSupported 
preferredLanguageSupported 
showInAddressListUnsupported 
stateSupported 
streetAddressSupported 
surnameSupported 
usageLocationSupported 
userPrincipalName Supported 
userTypeSupported 
ManagerSupported 
SponsorsSupported 
Display nameSupported 
Object IDPartially SupportedThe object ID can be restored if the user has not yet been permanently deleted from your Microsoft Entra tenant.
Sign in sessions valid from date timeUnsupported
Authorization infoSupportedQR code is not supported.
Legal age group classificationUnSupported 

Groups

Data TypeStatus
PropertiesSupported
PhotoUnsupported
MembersSupported
OwnersSupported
Roles and administratorsUnsupported
Group membershipsSupported
ApplicationsSupported
Azure role assignmentsUnsupported
LicensesUnsupported

Object Attributes

AttributeStatusComment
deletedDateTimeSupported 
descriptionSupported 
groupTypesSupported 
deducedGroupTypeUnSupported 
mailEnabledSupported 
mailNicknameSupported 
mailSupported 
membershipRuleSupported 
membershipRuleProcessingStateSupported 
preferredDataLocationSupported 
preferredLanguageSupported 
resourceBehaviorOptionsSupported 
resourceProvisioningOptionsSupported 
securityEnabledSupported 
securityIdentifierSupported 
themeSupported 
visibilitySupported 
isAssignableToRoleSupported 
Membership typeSupported 
SourceSupported 
TypeSupported 
Object IDPartially supportedThe object ID can be kept if the group has not yet been permanently deleted from your Microsoft Entra ID.
Created atUnsupportedRead-only property in Microsoft Entra ID.
EmailSupported 
Direct membersSupported 
Group membershipsSupported 
Group nameSupported 
Group descriptionSupported 
Group writeback stateSupported 

App Registration

ComponentStatusComment
BrandingSupported 
AuthenticationSupported 
CertificatesSupported 
Client secretsSupported 
Federated credentialsSupported 
Token configurationSupported 
API permissionsPartially SupportedAdmin consent must be granted for API permissions after restore. Granting admin consent through restore is currently not supported.
Expose an APISupported 
App rolesSupported 
OwnersSupported 
Roles and administratorsUnsupported 
ManifestUnsupported 

Enterprise Application

ComponentStatus
PropertiesSupported
OwnersSupported
Roles and administratorsUnsupported
Users and groupsSupported
Single sign-onUnSupported
ProvisioningUnSupported
Application proxyUnsupported
Self-serviceUnsupported
Custom security attributesUnsupported

Custom User Attribute

Data TypeStatus
NameSupported
Data TypeSupported
DescriptionSupported
Attribute TypeSupported

User Flow

Data TypeStatus
Identity providersSupported
User attributesSupported
Custom authentication extensionsSupported
Page layoutsSupported
LanguagesUnsupported
ApplicationsSupported
CustomizeUnSupported
UseSupported

Identity Provider

Data TypeStatus
Built InSupported
CustomSupported

Object Attributes

AttributeStatus
StatusSupported
SettingsSupported

Custom Authentication Extensions

Data TypeStatus
Endpoint ConfigurationSupported
API AuthenticationSupported
ApplicationsSupported

Custom Branding

Data TypeStatus
Company brandingSupported
Branding themesUnSupported

Object Attributes

AttributeStatusComment
BasicsSupportedPage background color is not supported.
LayoutSupported 
HeaderSupported 
FooterSupported 
Sign-in formSupported 
TextSupported