Today’s adversaries aren't brute-forcing a perimeter breach; they’re logging in to enterprise systems with stolen credentials and moving laterally at AI speed. Simultaneously, defenders remain trapped by five critical friction points:
Painful AD Restores: Manual Active Directory (AD) recovery takes 28 days on average. In some cases, this results in a net-new environment or starting from a clean point in time but losing critical data.
Fragile Okta & Active Directory (AD) Alignment: Restoring Okta in isolation breaks identity mappings, workflows, and lifecycle management tied to the underlying AD user store.
Drowning in Siloed Context: Security teams struggle to classify and correlate risk alerts with the IAM team across 60+ dashboards, turning attack signal reconciliation into a manual nightmare.
The Clean vs. Current Dilemma: Rebuilding IdPs from scratch takes time and means losing legitimate IdP changes, while the business stays down. But staying in a current state preserves the attacker's footholds.
Unprotected Entra ID Governance Policies & Endpoint Baselines: Hard-deleted Entra ID governance policies and Intune device configurations have no native rollback path.
Those five friction points share a root cause: recovery was built around backups and applications, not around a directory that changes constantly and never stands alone. Closing that gap determines whether a compromised identity gets contained in hours, or festers for weeks while teams work around each other instead of together.
Last week, Rubrik introduced major innovations across the Identity Resilience portfolio. Rubrik now decouples the OS and the ntds.dit (the Active Directory database). Additionally, Rubrik unifies third-party risk signals, addresses the problem of recovering clean and losing wanted IdP changes, and has deepened protection across Microsoft Entra ID and Okta. If Identity has become the new single point of failure, make it resilient with Rubrik.
Identity-First Recovery (IFR): When you Need the Directory, not the Whole Machine
More than 90% of global businesses run Active Directory, and industry research shows it is involved in nearly 9 in 10 intrusions. A full Active Directory Forest Recovery (ADFR) is one of the hardest tasks in disaster recovery: a 29-step, manual playbook that can take weeks. More importantly, traditional recovery binds the AD database to the operating system. That coupling creates two problems:
Target machines rarely match source machines closely enough
If target machines aren’t scanned, malware may be accidentally reintroduced
IFR decouples the OS and the ntds.dit, the Active Directory database. Rubrik extracts the ntds.dit file and SYSVOL data, reintroduces them into a fresh Windows install (across cloud and on-prem), and has a mechanism to scan the target system OS for malware so that organizations ensure a clean target. IFR works across cloud and on-premises targets regardless of hypervisor or patch level, as long as the target machine’s OS matches the source. In internal testing, IFR cut recovery times by up to 56% for Active Directory databases of around 500 MB.
Read our blog to learn more.
Unified Okta and Active Directory Recovery
Okta sits at the front door of more than 20,000 enterprises, deciding which identities can reach which applications. That makes it one of the most consequential systems a security team runs and one of the most attractive targets for a bad actor. Most enterprises connect Okta to Active Directory as the underlying user store. This means that restoring the Okta tenant in isolation, while leaving Active Directory unprotected or out of sync, risks a flawed recovery or reinfection.
That’s why Rubrik announced deeper Okta protection with three new capabilities: coverage for Okta Lifecycle Management (LCM) configurations, recovery for Okta Workflows, and cross-tenant recovery for Okta. Treating Okta and Active Directory as one system with hybrid recovery, not two silos, is the difference between a coordinated recovery that takes minutes and a fragmented scramble that takes weeks. A coordinated recovery streamlines incident management, helps organizations hit Recovery Time Objective (RTO) targets, and reduces Total Cost of Ownership (TCO).
The Identity Intelligence Fabric: Say Goodbye to Manual Context Reconciliation
Recent industry research puts the average enterprise around 61 security tools and 58 dashboards. More tools were supposed to mean more security. Instead, they produced more silos. That meant admins had to manually cross-reference tickets and IdP changes mid-incident, under pressure.
The Rubrik Identity Intelligence Fabric removes this need for manual reconciliation. It gathers signals from the ITDR, IGA, and HRIS tools an enterprise already runs and aggregates identity context in a single layer. Rubrik Identity Resilience ingests alerts from CrowdStrike and Microsoft Defender, and correlates them against an enterprise's activity log, so a critical signal, such as a Golden Ticket or DCSync attack, becomes a single decisive trigger for IAM and security teams to start recovery together.
On the reconciliation side, new integrations with Workday and SailPoint aggregate HR and IGA context, so organizations can cross-reference IdP modifications against approved HR changes or access requests. This helps organizations separate malicious changes from legitimate ones.
That’s how the Rubrik Identity Intelligence Fabric enables faster detection, reconciliation so that SOC and IAM teams look at the same picture and avoid manual work with spreadsheets.
Read our blog to learn more.
Roll Forward: Recover to Clean and Current
Recovering an application usually means restoring the last clean copy. Recovering identity is different, because a directory never stops changing. Employees join and leave, group memberships shift, GPOs change, and service accounts rotate. At the same time, Industry data puts the global median attacker dwell time at around 11 days, so the last confirmed clean snapshot is often weeks old. If your last clean point was 30 days ago, 30,000 to 40,000 legitimate changes may have occurred.
This means that Security teams get stuck in a paradox: roll back to a clean snapshot and wipe weeks of business progress, or stay in a current but potentially compromised state.
Webinar:
Roll Back the Future: How to go from a compromised identity environment
to a clean and current state
Roll Forward removes that trade-off. With Roll Forward, organizations can establish a confirmed clean point in time using Rubrik's threat hunting and threat monitoring, surface changes made since, and reconcile those changes automatically using context from IdPs, HRIS and governance tools. Then organizations roll forward only the legitimate modifications. The directory that comes back online reflects the current state of the business, not the state of the last backup. Attackers are evicted and organizations keep known good IdP changes, preserving weeks of work.
Sign up for our webinar and read our blog to learn more.
Entra ID Protection: Governance, Devices, and a Clean Tenant
A joint CISA and FBI advisory found that in nearly every 2025 Scattered Spider attack, the group used help-desk voice phishing to take over a Microsoft Entra ID account. When that account belongs to an administrator, the blast radius becomes the entire tenant, and Entra ID governance objects such as access packages, catalogs, and Privileged Identity Management settings are typically hard-deleted with no native rollback.
Rubrik is expanding Entra ID protection across three areas
Governance protection now covers access packages, catalogs, access review definitions, and PIM settings, restorable during a full-tenant or granular recovery.
Intune recovery now spans 17 object types across compliance, configuration, endpoint security, and app protection, so devices come back on a known-good security baseline.
Cross-tenant recovery restores users, groups, conditional access policies, and administrative units into a separate, clean tenant. It then re-establishes the relationships among these identity elements so a minimum viable business tenant comes up whole rather than as a collection of orphaned objects.
Organizations can restore AD and Entra ID together and restitch associated M365 data from a single platform, so this helps reduce RTO, TCO, and tool sprawl.
Read our blog to learn more.
Ready to See It in Action?
These five capabilities share one goal: identity recovery that is fast, clean, and complete, strengthening your identity resilience posture. From accelerating ADFR to removing the need for manual reconciliation across authoritative systems, to deepening Okta and Entra ID protection, we help our customers strengthen their identity resilience posture.
Schedule a demo to see these in action, or visit rubrik.com/identity to learn more.
SAFE HARBOR
Any unreleased services or features referenced on this page are not currently available and may not be made generally available on time or at all, as may be determined in our sole discretion. Any such referenced services or features do not represent promises to deliver, commitments, or obligations of Rubrik, Inc. and may not be incorporated into any contract. Customers should make their purchase decisions based upon services and features that are currently generally available.
NOTE
Please speak to Rubrik representatives to confirm the availability and functionality of Rubrik's products and services before making any purchase or renewal decisions.