Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Druva: Ransomware Risk to Power BI and Identity Data

Druva
08/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


So either compromise credential, compromise rate or a token. One of those two main things. Once they come in, Entra ID becomes the next place for them to affect it as they build that discovery model of what they're going to do to hold you at ransom. They know exactly what, who, what, when, why and where. And if you have these sensitive dashboard files in here, that's what they're going to go after. Even if you get your tenant back, let's say you experienced a systemic identity attack and Microsoft work to get these criminals out and they've given you your access to your tenant back. The first thing you have to do is try and figure out what is different. If you have no physical prior point of time, you have no idea what it was set to before. This applies to Entra ID, Active Directory, SharePoint. Right. You have no idea what was affected. That's where you find where the risk comes in and where the identity layer and the exposure to all of your data in there begins to creep into the Power Platform and Power BI.

TL;DR

  • Microsoft data shows 80% of ransomware attacks originate from compromised identities — credentials, accounts, or tokens — making identity the primary attack surface.
  • Attackers use Entra ID to map your environment and target high-value assets like Power BI dashboards and sensitive data models before executing ransomware.
  • Without a prior point-in-time backup, organizations recovering from an identity attack have no way to determine what changed across Entra ID, Active Directory, or SharePoint.

Summary

This short-form clip, excerpted from a longer Druva webinar, illustrates how ransomware attackers exploit compromised identities to infiltrate Microsoft environments and ultimately target Power BI workspaces. According to Microsoft's own Digital Defense Report, 80 percent of ransomware attacks originate at the identity layer — through stolen credentials, compromised accounts, or hijacked tokens. Once inside, attackers use Entra ID to map the environment, identifying sensitive dashboards, reports, and data models before executing their ransom strategy. The clip emphasizes a critical recovery blind spot: even after Microsoft restores tenant access following a systemic identity attack, organizations have no baseline to compare against if they lack a prior point-in-time backup. Without that reference, IT teams cannot determine what configurations, permissions, or data were altered across Entra ID, Active Directory, SharePoint, or the Power Platform. Druva positions backup and recovery as the essential missing layer that closes this visibility gap, enabling organizations to understand exactly what changed and restore to a known-good state after an identity-based attack.

Chapters

0:00 - Identity as the Primary Attack Vector
0:15 - Entra ID Discovery and Targeting
0:38 - The Recovery Blind Spot
1:07 - Risk Exposure Across Power Platform

Key Quotes

0:00 "Microsoft reported in last year's digital defense report that of all the ransomware attacks, 80 percent of those were attributed to the identity layer."
0:29 "They know exactly what, who, what, when, why and where. And if you have these sensitive dashboard files in here, that's what they're going to go after."
0:54 "If you have no physical prior point of time, you have no idea what it was set to before."

FAQ

Why are Power BI workspaces specifically targeted in ransomware attacks?

Attackers use Entra ID to build a discovery model of the environment, identifying where sensitive data lives. Power BI dashboards and reports often contain high-value business intelligence, making them prime targets for exfiltration or destruction during a ransom event.

Why isn't Microsoft restoring tenant access enough to recover from an identity attack?

Tenant restoration only returns access — it doesn't tell you what changed. Without a point-in-time backup, there is no baseline to compare against, so organizations cannot determine what configurations, permissions, or data were modified across Entra ID, Active Directory, SharePoint, or Power Platform.


Categories:
  • » Webinar Library » Druva
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Identity & Access Management (IAM)
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Identity & Access
  • Cloud Security
  • Backup & Recovery
  • Security Operations
  • short_form
  • Ransomware recovery
  • Identity security
  • Microsoft Power BI
  • Entra ID
  • SaaS data protection
  • Backup and recovery
  • Compromised credentials
  • Microsoft 365 security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Druva: Ransomware Risk to Power BI and Identity Data

              Upcoming 360 View Events

              • Nov
                19

                360View: Govern, Secure & Recover Your Microsoft 365 Environment

                11/19/202601:00 PM ET
                More events

                XStreaminars (watch here)

                • Oct
                  28

                  EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure

                  10/28/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Oct
                    13

                    Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                    10/13/202601:00 PM ET
                    • Oct
                      15

                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                      10/15/202611:00 AM ET
                      • Oct
                        20

                        Harnessing Data Governance for AI with Cyera and Snowflake

                        10/20/202611:00 AM ET
                        • Oct
                          27

                          Maximize Security, Value, and Returns on Your Microsoft Investment

                          10/27/202611:00 AM ET
                          • Oct
                            27

                            The HUMAN Experience: Real-Time Insights into Page Intelligence

                            10/27/202601:00 PM ET
                            More events

                            Upcoming Webinar Calendar

                            • 10/13/2026
                              01:00 PM
                              10/13/2026
                              Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                              https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                            • 10/15/2026
                              11:00 AM
                              10/15/2026
                              Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                              https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                            • 10/20/2026
                              11:00 AM
                              10/20/2026
                              Harnessing Data Governance for AI with Cyera and Snowflake
                              https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                            • 10/27/2026
                              11:00 AM
                              10/27/2026
                              Maximize Security, Value, and Returns on Your Microsoft Investment
                              https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                            • 10/27/2026
                              01:00 PM
                              10/27/2026
                              The HUMAN Experience: Real-Time Insights into Page Intelligence
                              https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                            • 10/28/2026
                              01:00 AM
                              10/28/2026
                              [APAC:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                              https://www.truthinit.com/index.php/channel/2125/apac-ensuring-comprehensive-security-for-ai-applications/
                            • 10/28/2026
                              06:00 AM
                              10/28/2026
                              [EMEA:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                              https://www.truthinit.com/index.php/channel/2127/emea-ensuring-ai-security-across-all-platforms/
                            • 10/28/2026
                              01:00 PM
                              10/28/2026
                              [AMERICAS:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                              https://www.truthinit.com/index.php/channel/2126/securing-ai-across-the-americas-strategies-and-insights/
                            • 10/28/2026
                              01:00 PM
                              10/28/2026
                              EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure
                              https://www.truthinit.com/index.php/channel/2179/envzero-near-zero-time-to-resolution-live-agentic-remediation-for-failed-and-drifted-infrastructure/
                            • 11/04/2026
                              11:00 AM
                              11/04/2026
                              Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                              https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                            • 11/04/2026
                              11:00 AM
                              11/04/2026
                              Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                              https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                            • 11/05/2026
                              02:00 PM
                              11/05/2026
                              HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                              https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                            • 11/05/2026
                              02:00 PM
                              11/05/2026
                              Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                              https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                            • 11/19/2026
                              01:00 PM
                              11/19/2026
                              360View: Govern, Secure & Recover Your Microsoft 365 Environment
                              https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                            Truth in IT
                            • Sponsor
                            • About Us
                            • Terms of Service
                            • Privacy Policy
                            • Contact Us
                            • Preference Management
                            Desktop version
                            Standard version