Article

Expanding Eon Data Protection to Microsoft Entra ID

Eon Data Protection now extends to Microsoft Entra ID, protecting the identity layer with independent, granular recovery.

Eylon Ami
Written by
Eylon Ami
Updated on: 
Sep 23, 2026
0
 min read
Expanding Eon Data Protection to Microsoft Entra ID

Join 10k Infra & Data Pros

Subscribe to our newsletter for the latest on data protection, analytics, and AI.

Quick Summary

  • Back up your Entra ID tenant, covering users, groups, devices, directory roles, licenses, app registrations, service principals (Enterprise Applications) and administrative units
  • Recover deleted users and groups with their memberships, ownership, licenses and role assignments reattached
  • Browse the directory as it stood at an earlier point in time, then choose what to bring back
  • Protect identity and Microsoft 365 data from one console, each with its own backup policy

Even with your data intact, an attacker who reaches the directory can stall your recovery. Eon now helps you restore the control plane.

Your data is only as resilient as the identities that control it

Microsoft holds a deleted user, Microsoft 365 group, cloud security group or app registration in a recycle bin for 30 days, and hard deletes every other object type the moment it goes. Once those 30 days pass, Microsoft says neither an administrator nor Microsoft Support can bring the user back.

Nor can you count on the full 30 days. An admin with the right role can purge the recycle bin early, and an attacker holding that role can empty it on the way out.

The gap bites hardest when an admin rebuilds an account by hand.

A recreated user carries a new object ID, and SharePoint authorizes on that ID rather than on the name, so colleagues hit Access Denied on files the user owns. Microsoft documents the mismatch, and its own guidance is to restore the original account inside the 30-day window so the ID survives.

An identity and the data it points at fail together. Recovering a mailbox helps nobody when the account that owns it no longer exists in a form your permissions recognize.

What Eon protects

Connect your tenant, and Eon captures the directory as a graph of objects and the relationships between them.

Users, groups, devices, directory roles, licenses, app registrations, service principals (Enterprise Applications) and administrative units all come across, each with its full Microsoft Graph representation. Alongside them Eon records the edges that make those objects useful, including group membership, ownership, role assignments with their scope, and license assignments.

Every snapshot carries its time, so you can look at the directory as it stood before an incident and compare it against what your tenant holds now.

Those backups sit air-gapped and immutable, outside the tenant they protect, so a compromised admin account cannot reach them.

What recovery looks like

Pick the users and groups you need, and they come back with the access they had. Memberships, ownership, licenses and role assignments come back attached, so the account works on return instead of arriving as an empty shell. Recover a group together with its members and the memberships connecting them survive the trip. Every restore also reports what it could not return, including the MFA registrations and secrets Microsoft never exposes, so your team knows what is left to do by hand.

For the mechanics, including how we model the graph and what each restore path costs you in fidelity, read How Eon backs up and restores Microsoft Entra ID.

One platform for identity and the data it governs

Entra ID sits alongside Microsoft 365 in the same Eon console. Each runs as its own source, with its own backup policy and its own snapshots, and you decide whether they share a vault or use separate ones.

Your team protects the identity layer and the content it governs from one place, under the same access controls, so recovering from an incident means working in one tool.

Book a demo to see Entra ID protection running against a live tenant, and bring the account your last rehire complained about.

FAQ

No items found.
Eylon Ami
Eylon Ami

R&D