Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Druva: Ransomware Risk to Power BI and Identity Data

Druva
08/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


So either compromise credential, compromise rate or a token. One of those two main things. Once they come in, Entra ID becomes the next place for them to affect it as they build that discovery model of what they're going to do to hold you at ransom. They know exactly what, who, what, when, why and where. And if you have these sensitive dashboard files in here, that's what they're going to go after. Even if you get your tenant back, let's say you experienced a systemic identity attack and Microsoft work to get these criminals out and they've given you your access to your tenant back. The first thing you have to do is try and figure out what is different. If you have no physical prior point of time, you have no idea what it was set to before. This applies to Entra ID, Active Directory, SharePoint. Right. You have no idea what was affected. That's where you find where the risk comes in and where the identity layer and the exposure to all of your data in there begins to creep into the Power Platform and Power BI.

TL;DR

  • Microsoft data shows 80% of ransomware attacks originate from compromised identities — credentials, accounts, or tokens — making identity the primary attack surface.
  • Attackers use Entra ID to map your environment and target high-value assets like Power BI dashboards and sensitive data models before executing ransomware.
  • Without a prior point-in-time backup, organizations recovering from an identity attack have no way to determine what changed across Entra ID, Active Directory, or SharePoint.

Summary

This short-form clip, excerpted from a longer Druva webinar, illustrates how ransomware attackers exploit compromised identities to infiltrate Microsoft environments and ultimately target Power BI workspaces. According to Microsoft's own Digital Defense Report, 80 percent of ransomware attacks originate at the identity layer — through stolen credentials, compromised accounts, or hijacked tokens. Once inside, attackers use Entra ID to map the environment, identifying sensitive dashboards, reports, and data models before executing their ransom strategy. The clip emphasizes a critical recovery blind spot: even after Microsoft restores tenant access following a systemic identity attack, organizations have no baseline to compare against if they lack a prior point-in-time backup. Without that reference, IT teams cannot determine what configurations, permissions, or data were altered across Entra ID, Active Directory, SharePoint, or the Power Platform. Druva positions backup and recovery as the essential missing layer that closes this visibility gap, enabling organizations to understand exactly what changed and restore to a known-good state after an identity-based attack.

Chapters

0:00 - Identity as the Primary Attack Vector
0:15 - Entra ID Discovery and Targeting
0:38 - The Recovery Blind Spot
1:07 - Risk Exposure Across Power Platform

Key Quotes

0:00 "Microsoft reported in last year's digital defense report that of all the ransomware attacks, 80 percent of those were attributed to the identity layer."
0:29 "They know exactly what, who, what, when, why and where. And if you have these sensitive dashboard files in here, that's what they're going to go after."
0:54 "If you have no physical prior point of time, you have no idea what it was set to before."

FAQ

Why are Power BI workspaces specifically targeted in ransomware attacks?

Attackers use Entra ID to build a discovery model of the environment, identifying where sensitive data lives. Power BI dashboards and reports often contain high-value business intelligence, making them prime targets for exfiltration or destruction during a ransom event.

Why isn't Microsoft restoring tenant access enough to recover from an identity attack?

Tenant restoration only returns access — it doesn't tell you what changed. Without a point-in-time backup, there is no baseline to compare against, so organizations cannot determine what configurations, permissions, or data were modified across Entra ID, Active Directory, SharePoint, or Power Platform.


Categories:
  • » Webinar Library » Druva
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Identity & Access Management (IAM)
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Identity & Access
  • Cloud Security
  • Backup & Recovery
  • Security Operations
  • short_form
  • Ransomware recovery
  • Identity security
  • Microsoft Power BI
  • Entra ID
  • SaaS data protection
  • Backup and recovery
  • Compromised credentials
  • Microsoft 365 security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Druva: Ransomware Risk to Power BI and Identity Data

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Sep
                        29

                        Embrace AI Adoption While Maintaining Robust Security Measures

                        09/29/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/29/2026
                          12:00 PM
                          09/29/2026
                          Embrace AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embrace-ai-adoption-while-maintaining-robust-security-measures/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version