TechnologySep 15, 202614 min read

Clean and Current: The New Identity Resilience Imperative


Today, 82% of cyber detections are malware-free. That means attackers can log in using stolen credentials.

When adversaries compromise IdPs like Active Directory (AD) or Microsoft Entra ID, IAM teams are forced into an impossible choice. Do you restore from a recent snapshot and bring the attacker's persistence mechanisms back online with it? Or do you reach back far enough to be certain the environment is clean and fall weeks (or months) behind, losing records of new hires, terminated employees (with system access), and DNS and group membership changes. 

Nearly every enterprise has felt this trade-off between clean or current. Legacy tooling was not built for this reality. It can detect but not cleanly recover or reconnect user groups and policies. This leaves the workforce authenticated but disconnected from tools and forces administrators to choose between two states: clean or current.

But you need both.

 

Identity Resilience is Much More than a Bolted-On Fix

At Rubrik's AI + Identity Summit, we unveiled the solution to this paradox. Across multiple connected stages, Rubrik brings businesses back online: you get continuous, threat-informed visibility into which snapshots can be trusted (through a verified clean recovery), a reconciled and current environment, and Microsoft 365 data and access that identity exists to protect.

Our Identity track focused on three key sessions:

  • Identity Is Everyone's Problem and Nobody's Job: How identity estates got so complex, what a resilient one looks like, and who should be on the hook for building it.

  • Four Security Leaders on What Makes Identity Resilience So Hard: Which snapshot do you go back to, who has the authority to make that call, and how do you know the snapshot is clean? Four perspectives from four leaders.

  • Making Identity the First Thing Back: Identity Resilience is a discipline of its own; if identity fails, everything fails. Discover how Rubrik can protect your identity estate.
     

Catch the replay if you missed the live sessions.

 

We don't make you choose between clean and current. We get you both.

 

The First Step to Identity Recovery: Finding Attacker Footprints

Before a recovery can begin, someone has to answer the hardest question: which snapshot is clean? 

Today, that answer comes from a security team manually inspecting snapshots after an incident is underway. This process can add days while systems stay down.

Rubrik automatically marks post-incident snapshots as suspicious and recommends the latest clean restore point by integrating high-fidelity alerts from platforms like Microsoft Defender for Identity and CrowdStrike directly into recovery workflows. Alongside this alert integration, domain controller backups are continuously scanned against identity intelligence for indicators of compromise, with options for on-demand YARA and hash-based threat hunting to quarantine infected snapshots before restoration. This threat-informed classification embeds status visibility directly into recovery wizards and powers pre-flight checks during forest recoveries—preventing replication failures by ensuring clean domain controller restores within a consistent time window.

 

Recovering Clean: Identity-First Recovery and Expanded Entra ID Protection

With a trustworthy restore point identified, the recovery team faces the next question: how do we get back online fast, on a mechanism we can trust?

Identity-First Recovery (IFR) changes the model by decoupling identity from the operating system entirely. Rubrik surgically extracts the ntds.dit database and SYSVOL data and reintroduces them into a new Windows instance. The result is an environment-agnostic recovery. Recovery is malware-free by design because the infected OS and registry never make the trip. Today, IFR is scoped to forest restoration.

Identity protection does not end at the directory. Rubrik is expanding its Entra ID protection to cover devices, governance, and cross-tenant recovery. With Microsoft Intune protection, teams can back up and restore device configurations, compliance rules, and security controls so restored users have compliant, authenticating devices. 

Rubrik is also extending protection to Entra ID Governance, enabling point-in-time recovery for Privileged Identity Management roles, access packages, and review configurations that lack native rollback. 

Finally, Cross-Tenant Recovery (CTR) will enable teams to rebuild identities, groups, and apps in a separate target tenant during worst-case scenarios, automatically resolving domain and object ID failures along the way.

 

Roll Forward: Keep the Good and Kill the Bad

Restoring to a clean snapshot solves the security problem and creates a business one. 

Every legitimate change made between that snapshot and the moment of compromise (such as new hires, offboarded employees, DNS updates, or group membership changes) disappears along with the attacker's footprint. Today, reconciling the gap between a clean restore and the latest business data is manual. Administrators must cross-reference tickets and reapply changes one at a time, a process that can consume months.

Roll Forward closes that gap. After a clean restore, Rubrik labels every change using a green, yellow, and red classification model. Changes that match verified activity in IGA platforms like Sailpoint, HR systems like Workday, or ITSM tools are marked green. Changes flagged by security telemetry from CrowdStrike or Microsoft Defender, or matched against known indicators of compromise, are marked red. Everything else is yellow, flagged for manual review. Administrators can then analyze and approve changes before the clean environment goes live, or bring the environment back online immediately and roll forward the approved changes into the running system afterward.

Either way, the goal is the same: keep the legitimate business activity, discard the attacker's, and do it in hours rather than months.

 

Reconnecting Identity to Microsoft 365

A recovered identity that cannot access email or files won’t get a business running again. Reconnecting a restored Entra ID user to their Exchange mailbox and OneDrive requires a sequence of steps that sits outside standard identity administration. Get the order wrong and Exchange provisions a permanent empty mailbox while OneDrive lands in a conflict state that only Microsoft Support can untangle. When the mailbox or OneDrive data has been purged outright, there is often no path back.

Unified Identity and Microsoft 365 Data Recovery is designed to remove that manual burden. Rubrik holds both the identity snapshot and the Microsoft 365 data backup, so it can automatically detect which situation an administrator is facing and execute the right recovery path. When a mailbox and OneDrive are still present but disconnected, Rubrik retrieves and links the ExchangeGuid and reasserts OneDrive ownership before restitching access. When the data has been purged, Rubrik restores it directly from its own Microsoft 365 backup using the nearest snapshot, so the recovered mailbox reflects the business as it stood right before the incident.

 

What Identity Resilience Actually Unlocks

A resilient identity estate benefits the entire organization. 

For security teams, identity resilience means less time waiting on a manual handoff to know which snapshot is safe to use, because threat intelligence is built into the recovery workflow. 

For IAM administrators, it means recovering identities, endpoint policies, and governance controls together. 

For the business, it means the months of manual reconciliation that have historically followed a major identity incident compress into hours.

These benefits collapse if recovery is limited to one identity provider, as attackers exploit blind spots between isolated Active Directory, Entra ID, and Okta backups. Patchwork point solutions trigger multi-day sync delays or leave attacker persistence mechanisms wide open. Rubrik orchestrates the restoration sequence across providers by managing these environments as a single, cohesive estate. This ensures underlying relationships and policies resolve without forcing teams to untangle dependencies under pressure.

 

What’s Next with Rubrik Agent Cloud Plus Identity Resilience

Identity resilience does not stop at human identities. AI agents carry their own identities and entitlements. A compromised admin account gives an attacker access to every AI agent tied to that human principal. Attacks extend beyond the human identity to exfiltrate data and gain persistence.

Starting today, customers using both Rubrik Agent Cloud and Rubrik Identity Resilience get a more complete view of the attacker’s actions. When an identity is compromised, joint customers can trace the changes the compromised principal made directly in the IdP and what it did through its access to AI agents.

For example, if a compromised account interacted with an M365 Copilot agent, Rubrik surfaces exactly what that agent did in the environment. This drastically accelerates investigation and recovery times. Teams can map the full blast radius and undo the malicious actions taken by both the compromised identity and its agents, bringing the business back online securely and quickly.

 

 

Bring Resilience to Your Identity Control Plane

For decades, identity resilience has asked administrators to accept a trade: get clean or get current. That trade-off was a byproduct of tools that could restore a snapshot but could not reconcile it with the business that kept moving while it was down, and could not reconnect it to the systems IdPs protected. 

The answer to "clean or current" was always supposed to be both. And now, that’s not a compromise you’ll have to make.

Contact your AE or talk to us to learn more about how you can recover identity clean, current, and connected to your resources.

 

SAFE HARBOR
Any unreleased services or features referenced on this page are not currently available and may not be made generally available on time or at all, as may be determined in our sole discretion. Any such referenced services or features do not represent promises to deliver, commitments, or obligations of Rubrik, Inc. and may not be incorporated into any contract. Customers should make their purchase decisions based upon services and features that are currently generally available.

NOTE
Please speak to Rubrik representatives to confirm the availability and functionality of Rubrik's products and services before making any purchase or renewal decisions.

 

Related Articles

Blog by This Author