TechnologySep 25, 202613 min read

Microsoft Entra ID Recovery, Expanded: Governance, Intune, and Cross-Tenant Recovery


 

Frontier AI capabilities are being democratized as fast for attackers as for defenders. Lone opportunists, ransomware affiliates, and nation-state crews now have access to the same tools that help security teams respond to an incident. AI does not just help a defender triage an alert faster; it helps an adversary write a flawless phishing message, clone a voice, or research a target's identity in seconds. 

The security industry has never had to reckon with this speed and scale of change, and it shows: more than 82% of phishing emails now contain AI-generated content, and the human element still contributes to nearly 60% of breaches, according to the 2025 Verizon Data Breach Investigations Report. 

Social engineering remains the cheapest way to get front-door access to critical systems like Microsoft Entra ID. A joint CISA and FBI advisory found that in nearly every 2025 Scattered Spider attack, the group used help-desk voice phishing to reset a target's password or multi-factor authentication and take over a Microsoft Entra ID account. When that account happens to belong to an Entra administrator, the blast radius turns catastrophic: administrative control over the entire tenant.

From there, attackers can deploy techniques like inbound federation and use the compromised admin's credentials to reach every identity and configuration in the tenant. That is the equivalent of a full Active Directory compromise. 

That takeover doesn't end when the account gets reset. The real cost shows up during recovery: governance policies, device baselines, and access configurations that Entra ID has no native way to roll back once an attacker deletes them. Rebuilding by hand can take weeks, and until it's done, the enterprise operates with security gaps it can't see. 

Protecting cloud identity providers (IdPs) like Entra ID is no longer optional for the enterprise. It is the front line. And Rubrik is expanding protection for Entra ID to help organizations recover quickly.

 

 

Why Entra ID Recovery is So Painful

When an Entra ID tenant is compromised, an attacker with admin access can delete identities, wipe configurations, and escalate privileges into every system connected to that tenant.

The trap most IAM teams miss: when an identity is deleted and recreated, it comes back as a new identity. Every piece of Microsoft 365 access tied to the original identity—mailboxes, OneDrive folders, permissions—was tied to the old identity, not the new one. Restoring the identity does not restore the connection. Access stays broken even after the user is back and they can’t access the resources needed to do their job.

Now compound that with governance loss. Access packages, device policies, and conditional access policies are typically hard-deleted in Entra ID, with no native rollback. Once an attacker removes them, there is no way to recover them natively. The result is weeks or months of manual reconstruction, security gaps while the right policies are missing, and real downtime costs while the enterprise rebuilds from scratch. Protecting and restoring Entra ID directly is the best way out of that scenario.

That’s why Rubrik expanded Entra ID protection to help organizations protect governance, devices, and recover cleanly to a new tenant.

 

 

New Enhancements to Rubrik Entra ID Protection

Rubrik already protects and recovers a wide range of Entra ID objects. Today, we are extending that protection across three critical areas.

1. Enhancements to Entra ID Governance: With this new launch, Rubrik expands the protection and recovery of Entra ID governance objects, specifically: 

  • Access packages, along with their assignment policies and role scopes;

  • Catalogs

  • Access review definitions

  • Privileged Identity Management (PIM) settings, including assignments and approvers 

 

All the Entra ID governance objects can be recovered during a full-tenant or granular recovery, enabling enterprises to restore the governance configuration automatically instead of rebuilding by hand.

 

 

Recovery Entra ID Objects

 

2. Enhancements to Microsoft Intune: Intune policies protect the baseline health and access constraints of endpoints in the organization. If device compliance and security baselines are wiped or missing during an incident, those devices are left unprotected, giving attackers an easy foothold to maintain persistence or re-enter the network. 

That’s why Rubrik has expanded Entra ID protection to secure and recover 17 Intune object types spanning compliance, configuration, endpoint security, app protection, provisioning, and Intune administrative roles. Recovery covers policy properties together with their assignments and dependencies, and gives customers the choice to overwrite, merge, or skip when conflicts arise during restore.

 

 

Entra ID Recovery Intune Objects

 

3. Cross-Tenant Recovery with Entra ID: Cross-Tenant Recovery is critical in managing the worst-case scenario: a fully compromised tenant, or an attacker in control of a global administrator account. In that situation, enterprises need to stand up a minimum viable business tenant fast, so they can manage the breach while working to recover the original one.

Rubrik's cross-tenant recovery now restores Entra objects from a compromised tenant into a separate, clean tenant, including users, groups, conditional access policies, and administrative units. It does not just move identities over. It re-establishes the relationships between them, including group memberships and role assignments, so a minimum viable business tenant comes up whole rather than as a collection of orphaned objects.

 

 

Entra ID Recovery Destination

 

The Value Delivered to our Customers

For customers managing a live incident, these capabilities change what recovery looks like.

Faster Recovery Time Objective (RTO): With governance and device policies recovering as easily as identities, IAM and security teams no longer rebuild access policies, Privileged Identity Management settings, and compliance baselines by hand and under pressure. What used to take days of manual reconstruction now takes minutes. This makes minimum viable tenant recovery faster.

Automatic Minimum Viable Business (MVB) Tenant Creation: With automated cross-tenant recovery, customers can bring identity operations back in a clean tenant while the compromised tenant is contained and investigated. Rubrik fully automates this process. Every minute matters during an active incident, and this removes the manual bottleneck.

Zero Compromise on Security: Restoring identities, governance, and Intune policies from a single platform means identities come back with the right privileges, devices come back on a known-good security baseline, and every guardrail stays intact. This gives CISOs peace of mind, ensuring that the recovery process has not compromised security constraints and continues to hold a robust security posture.

 

 

Where Rubrik is Headed Next

Identity resilience means bringing back the identity, access model, device trust, and data together. The job is not done only with recovering identities, Intune policies, or configuration policies: a recovered or recreated identity does not mean access to the user's mailbox and OneDrive content is restored.

Rubrik is closing this gap with Rubrik's Identity Resilience for Entra ID. Later this year, Rubrik will bring unified recovery capabilities across Entra ID and Microsoft 365 to our customers. This will reconnect the data that belongs to an identity, including mailboxes and OneDrive folders, as one coherent recovery action rather than a series of disconnected steps.

That means a full end-to-end recovery: identity, access model, device trust, and data, together. This is planned for general availability later this year.

 

 

See it in Action

These Entra ID protection enhancements are part of Rubrik Identity Resilience. 

Schedule a demo to see how Rubrik recovers identities, governance, and device trust together, and stands up a clean tenant when you need one most. Visit rubrik.com/identity to learn more.

 

 

 

SAFE HARBOR
Any unreleased services or features referenced on this page are not currently available and may not be made generally available on time or at all, as may be determined in our sole discretion. Any such referenced services or features do not represent promises to deliver, commitments, or obligations of Rubrik, Inc. and may not be incorporated into any contract. Customers should make their purchase decisions based upon services and features that are currently generally available.


NOTE
Please speak to Rubrik representatives to confirm the availability and functionality of Rubrik's products and services before making any purchase or renewal decisions.

 

Related Articles

Blogs by This Author