Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Control Monkey: Entra ID Hard-Delete Gap in Microsoft's Native Backup

Control Monkey
10/05/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


And I want us to think for a moment of what a custom rule means. We worked for months about this custom rule. We fine-tuned that, it's hard on exactly what we wanted to have in our enter ID, and then somebody did this for us. Not a militia sector, not a rogue AI agent, the fat finger. Somebody just accidentally did this thing. Hard delete. And as I said here, it's a cliff, it's not a slope. We can't go back slowly. We can't do this. It's a true problem that we have right now with a lot of those objects types that are not there right now.

TL;DR

  • Microsoft's native Entra ID backup does not cover all object types, leaving custom roles and similar configurations without a true restore path.
  • A hard-deleted unsupported object cannot be gradually rolled back — recovery requires a full manual rebuild, creating significant operational risk.
  • The real evaluation question for identity teams is not whether backup exists, but which specific configurations are actually recoverable.

Summary

This short clip from a ControlMonkey presentation highlights a critical gap in Microsoft's native Entra ID backup: not all object types are covered. Speaker Gal focuses specifically on custom roles — configurations that teams may spend months fine-tuning — which are not protected by Microsoft's native backup. If a custom role is accidentally hard-deleted, there is no gradual rollback path. As Gal puts it, 'it's a cliff, not a slope.' The deletion is immediate and permanent for unsupported object types, turning what should be a simple restore into a full manual rebuild. The key takeaway for identity and security teams is that the existence of a backup capability does not guarantee complete coverage. Evaluating Entra ID backup requires understanding precisely which object types are protected and which are not. ControlMonkey positions its versioned snapshot approach as a way to close this gap and provide reliable recovery points for configurations that Microsoft's native tooling leaves unprotected.

Chapters

0:00 - Native Backup Coverage Gap
0:07 - Custom Role Risk Explained
0:33 - Hard Delete: No Recovery Path

Key Quotes

0:34 "It's a cliff, it's not a slope."
0:24 "Not a militia sector, not a rogue AI agent, the fat finger."
0:39 "It's a true problem that we have right now with a lot of those objects types that are not there right now."

FAQ

What types of Entra ID objects are not covered by Microsoft's native backup?

According to the clip, custom roles are one example of object types not protected by Microsoft's native Entra ID backup. When these objects are hard-deleted, recovery requires manual rebuilding rather than a simple restore.


Categories:
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Data Protection
  • Backup & Recovery
  • Getting Started
  • Demo
  • Entra ID backup
  • Microsoft identity recovery
  • Hard-delete risk
  • Custom role protection
  • Configuration backup gaps
  • Accidental deletion recovery
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Control Monkey: Entra ID Hard-Delete Gap in Microsoft's Native Backup

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version