Microsoft Entra ID

The backup service for Microsoft Entra ID supports protecting the app registrations, enterprise applications, administrative units, roles and administrators, groups, users, device – bitLocker recovery keys, audit logs, and sign-in logs.

Microsoft Entra ID data recovery supports restoring the app registrations, enterprise applications, administrative units, and roles and administrators to the original location. It also supports restoring groups and users to the original location or to a new location. Refer to the tables below for supported and unsupported components and attributes of the object types you can protect in the Microsoft Entra ID.

Microsoft Entra ID service supports protecting the Device – BitLocker Recovery Keys. You can copy the BitLocker key from the backup. After December 2023 release, the Microsoft Entra ID service can also protect the extension attributes of the following objects: Users, Groups, Administrative Units, App Registrations, and Devices.

*Note: Due to the API limitation that some properties stored outside of the main data store for the resource are not supported as part of change tracking, the changes of some properties cannot be detected for incremental backup. Only a full backup can cover such changes. For more details on the limitation, refer to the Microsoft article: .

App Registration

Refer to the table below for the data recovery state for app registrations:

- The **Photo** and **Secrets** cannot be kept. The restore job will generate new secrets and key IDs and will record the information in the job report. - The **Created date** and the **Created on** **behalf of** cannot be restored.
ComponentDetails
BrandingSupported
AuthenticationSupported
CertificatesSupported
Client secretsSupported
Federated credentialsSupported
Token configurationSupported
API permissionsPartially Supported*Note: The API grant status is currently unsupported.*Note: In the data center operated by 21Vianet in China, the existing API permissions are supported. The API permissions that are temporarily or permanently deleted are partially supported.
Expose an APISupported
App rolesSupported
OwnersSupported
Roles and administratorsUnsupported
ManifestUnsupported
Extension attributesSupported*Note: Extensions attributes are unsupported in the data center operated by 21Vianet in China.

Object Attributes

AttributeStatusComment
publisherDomainSupported
requiredResourceAccessSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
signInAudienceSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
spaSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
tagsSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
tokenEncryptionKeyIdSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
verifiedPublisherSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
webSupported
createdOnBehalfOfUnsupported
publicClientSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
passwordCredentialsSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
parentalControlSettingsSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
optionalClaimsSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
addInsSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
apiSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
appIdPartially SupportedThe appId can be kept if the app has not yet been permanently deleted from your Microsoft Entra tenant.In 21v environment, the existing attribute is a read-only property. The attribute that is temporarily or permanently deleted is unsupported.
applicationTemplateIdUnsupported
createdDateTimePartially SupportedThe createdDateTime can be kept if the app has not yet been permanently deleted from your Microsoft Entra tenant.In 21v environment, the existing attribute is a read-only property. The attribute that is temporarily deleted is supported. The attribute that is permanently deleted is unsupported.
descriptionSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
disabledByMicrosoftStatusSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
identifierUrisSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
infoSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
isDeviceOnlyAuthSupportedSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
isFallbackPublicClientSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
keyCredentialsSupported
notesSupported
groupMembershipClaimsSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
NameSupported
LogoSupported
Home page URLSupported
Terms of service URLSupported
Privacy statement URLSupported
Service management referenceUnsupported
OAuth 2.0 authorization endpoint (v2)Unsupported
OAuth 2.0 token endpoint (v2)Unsupported
OAuth 2.0 authorization endpoint (v1)Unsupported
OAuth 2.0 token endpoint (v1)Unsupported
OpenID Connect metadata documentUnsupported
Microsoft Graph API endpointUnsupported
Federation metadata documentUnsupported
WS-Federation sign-on endpointUnsupported
SAML-P sign-on endpointUnsupported
SAML-P sign-out endpointUnsupported

Enterprise Application

Refer to the table below for the data recovery state for enterprise applications:

Note that the following properties cannot be restored:

- App owner organization ID - Sign-in audience - Key credentials - Oauth2 permission scope
ComponentDetails
PropertiesSupported
OwnersSupported
Roles and administratorsUnsupported
Users and groupsSupported
Single sign-onSupported
ProvisioningSupported*Note: Provisioning is unsupported in the data center operated by 21Vianet in China.
Application proxyUnsupported
Self-serviceUnsupported

Object Attributes

AttributeStatusComment
accountEnabledSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
addInsSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
alternativeNamesSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
appDescriptionSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
appIdSupportedThe attribute is a read-only property in the data center operated by 21Vianet in China.
applicationTemplateIdSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
appOwnerOrganizationIdSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
appRoleAssignmentRequiredSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
descriptionSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
disabledByMicrosoftStatusSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
homepageSupported
keyCredentialsPartially SupportedThe attribute relates to the SSO configuration of the enterprise application. If the enterprise application has not yet been permanently deleted, the setting can be restored. Otherwise, you have to choose to allow AvePoint to generate a certificate for SSO configuration or import the certificate manually while configuring restore settings.The attribute is unsupported in the data center operated by 21Vianet in China.
loginUrlSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
logoutUrlSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
notificationEmailAddressesSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
oauth2PermissionScopesSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
passwordCredentialsPartially SupportedThe passwordCredentials can be kept if the app has not yet been permanently deleted from your Microsoft Entra tenant.The attribute is unsupported in the data center operated by 21Vianet in China.
preferredSingleSignOnModeSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
preferredTokenSigningKeyThumbprintSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
replyUrlsSupported
samlSingleSignOnSettingsSupported
servicePrincipalNamesSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
servicePrincipalTypeSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
signInAudienceSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
tagsSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
tokenEncryptionKeyIdSupported
NameSupported
Object IDPartially SupportedThe object ID can be kept if the app has not yet been permanently deleted from your Microsoft Entra tenant.In the data center operated by 21Vianet in China, the object ID is a read-only property. The object IDs that are temporarily deleted can be restored. The object IDs that are permanently deleted cannot be restored.
Enabled for users to sign-inSupported
LogoSupported
Assignment requiredSupported
Visible to usersSupported
NotesSupported
PermissionPartially SupportedThe admin consented permissions can be kept if the app has not yet been permanently deleted from your Microsoft Entra tenant.

Administrative Units

Data TypeStatus
PropertiesSupported
UsersSupported
GroupsSupported
DevicesSupported
Roles and administratorsUnsupported
Extension attributesSupported*Note: Extension attributes are unsupported in the data center operated by 21Vianet in China.
membershipRuleSupported*Note: The membershipRule is unsupported in the data center operated by 21Vianet in China.
membershipTypeSupported*Note: The membershipType is unsupported in the data center operated by 21Vianet in China.
membershipRuleProcessingStateSupported*Note: The membershipRuleProcessingState is unsupported in the data center operated by 21Vianet in China.

Object Attribute

AttributeStatus
DescriptionSupported
VisibilitySupported*Note: The attribute is unsupported in the data center operated by 21Vianet in China.

Roles and Administrators

Object TypeStatus
AssignmentSupported*Note: Currently, only the eligible assignments and active assignments are supported. The expired assignments are unsupported.
DescriptionSupported
Role settingsSupported

Object Attributes

AttributesStatus
descriptionSupported
isBuiltInSupported
isEnabledSupported
rolePermissionsSupported
templateIdPartially Supported*Note: The templateId can be kept if the roles and administrators have not yet been permanently deleted from your Microsoft Entra tenant.
versionSupported
visibilitySupported

Groups

Refer to the table below for the data recovery state for groups:

- The backup service for Microsoft Entra ID can protect the following types of Microsoft Entra groups: **Microsoft 365 Group**, **Distribution List**, **Security Group**, and **Mail-Enabled Security Group**. - The Microsoft 365 Groups with dynamic users are supported, but the **Dynamic distribution** group type is not supported. - The Phone, Mail, and Sensitivity Label cannot be restored. - The assigned labels cannot be restored. - The created time and expiration time cannot be kept. - If the group is synchronized from the on-premises active directory, the synchronization information cannot be restored. It will be restored as the cloud only group. - The assigned licenses can be restored if there are enough available licenses.
Data TypeStatus
PropertiesSupported
PhotoSupported*Note: The photo is unsupported in the data center operated by 21Vianet in China.
MembersSupported
OwnersSupported
Roles and administratorsUnsupported
Administrative unitsSupported
Group membershipsSupported
ApplicationsSupported
Azure role assignmentsSupported*Note: To protect the Azure role assignments, you must grant the service app the User Access Administrator role in the corresponding subscription.*Note: The Azure role assignments are unsupported in the data center operated by 21Vianet in China.
Extension attributesSupported

Object Attributes

AttributeStatusComment
classificationSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
deletedDateTimeSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
descriptionSupported
groupTypesSupported
deducedGroupTypeUnsupported
mailEnabledSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
mailNicknameSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
mailSupported
membershipRuleSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
membershipRuleProcessingStateSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
preferredDataLocationSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
preferredLanguageSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
resourceBehaviorOptionsSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
resourceProvisioningOptionsSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
securityEnabledSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
securityIdentifierSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
themeSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
visibilitySupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
isAssignableToRoleSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
Membership typeSupported
SourceSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
TypeSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.
Object IDPartially SupportedThe object ID can be kept if the group has not yet been permanently deleted from your Microsoft Entra ID.In the data center operated by 21Vianet in China, the object ID is partially supported. The object IDs that are temporarily deleted can be restored. The object IDs that are permanently deleted cannot be restored.
Created atUnsupportedRead-only property in Microsoft Entra ID.
EmailSupported
Direct membersSupported
Group membershipsSupported
Group nameSupported
Group descriptionSupported
Group writeback stateSupportedThe attribute is unsupported in the data center operated by 21Vianet in China.

Users

Refer to the table below for the data recovery state for users:

- The guest users can also be protected in the Microsoft Entra Users category. - The creation time of the user profile and the creation type cannot be kept. - If the user is synchronized from the on-premises active directory, the synchronization information cannot be restored. It will be restored as the cloud only user. - For the users who have not yet been permanently deleted, the restore job will fail if any role assignments are not supported for restore.
ComponentStatus
ProfilesSupported
PhotoSupported*Note: Due to the API limitation, the photo cannot be reverted to empty. Therefore, the restore job will skip the photo if the photo in the backup is empty.
Assigned rolesSupported*Note: Currently, only the eligible assignments and active assignments are supported. The expired assignments are unsupported.
Administrative unitsSupported
GroupsSupported
ApplicationsSupported
LicenseSupported
DevicesUnsupported
Azure role assignmentsSupported*Note: To protect the Azure role assignments, you must grant the service app the User Access Administrator role in the corresponding subscription.*Note: The Azure role assignments are unsupported in the data center operated by 21Vianet in China.
Authentication methodsPartially Supported*Note: The Alternative Phone belongs to MFA. The backup and restore of MFA properties are not supported.*Note: The authentication methods are fully supported in the data center operated by 21Vianet in China.
Extension attributesSupported

Object Attributes

AttributesStatusComment
accountEnabledSupported
ageGroupSupported
businessPhonesSupported
citySupported
companyNameSupported
consentProvidedForMinorSupported
countrySupported
createdDateTimeUnsupportedRead-only property in Microsoft Entra ID.
creationTypeUnsupportedRead-only property in Microsoft Entra ID.If the user account was created as a local account for an Azure Active Directory B2C tenant, the value is LocalAccount or nameCoexistence.
deletedDateTimeUnsupported
departmentSupported
employeeHireDateUnsupportedRead-only property in Microsoft Entra ID.
employeeIdSupported
employeeOrgDataSupported
employeeTypeSupported
externalUserStateUnsupportedRead-only property in Microsoft Entra ID.
externalUserStateChangeDateTimeUnsupportedRead-only property in Microsoft Entra ID.
faxNumberSupported
givenNameSupported
identitiesSupported
jobTitleSupported
lastPasswordChangeDateTimeUnsupportedRead-only property in Microsoft Entra ID.
mailSupported
mailNickname Supported
mobilephoneSupported
officeLocationSupported
onPremisesImmutableIdSupported*Note: The attribute is unsupported in the data center operated by 21Vianet in China.
onPremisesProvisioningErrorsUnsupported
otherMailsSupported
passwordPoliciesSupported*Note: The attribute is unsupported in the data center operated by 21Vianet in China.
postalCodeSupported
preferredDataLocationSupported*Note: The attribute is unsupported in the data center operated by 21Vianet in China.
preferredLanguageSupported*Note: The attribute is unsupported in the data center operated by 21Vianet in China.
showInAddressListUnsupported
stateSupported
streetAddressSupported
surnameSupported
usageLocationSupported
userPrincipalName Supported
userTypeSupported*Note: The attribute is unsupported in the data center operated by 21Vianet in China.
ManagerSupportedRead-only property in Microsoft Entra ID.
Display nameSupported
Object IDPartially SupportedThe object ID can be kept if the user has not yet been permanently deleted from your Microsoft Entra tenant.In the data center operated by 21Vianet in China, the object ID is partially supported. The object IDs that are temporarily deleted can be restored. The object IDs that are permanently deleted cannot be restored.
Sign in sessions valid from date and timeUnsupportedRead-only property in Microsoft Entra ID.
Authorization infoSupported
Legal age group classificationSupported