Identity continues to be the primary battleground for enterprise security, with 82% of threat detections involving identity techniques. Attackers no longer need to brute-force their way through defenses when they can simply log in and move laterally at AI speed.
The consequences of a compromised identity layer extend far beyond the identity provider. Indeed Active Directory, Entra ID, and Okta are the connective tissue that decides who can access enterprise resources and what they can do once inside. When the identity layer is compromised, the blast radius is not contained to the identity layer; it expands to every system the identity provider touches.
Webinar:
Roll Back the Future: How to go from a compromised identity environment to a clean and current state.
Until recently, recovering identity has meant choosing between clean and current. A restore to the last clean snapshot doesn't just remove the attacker's changes—it erases every account added, every access grant approved, every role changed, and every other legitimate business update made since. Rubrik's Roll Forward removes that trade-off.
Rubrik’s Identity Intelligence Fabric aggregates signals from systems like Workday, SailPoint, CrowdStrike, and Microsoft Defender to solve the context problem during detection and reconciliation. But a major obstacle remains: How does an organization recover cleanly while keeping legitimate IdP changes?
Why is Identity Recovery Uniquely Painful?
Recovering most applications or systems involves restoring the last clean copy. But recovering identity is different.
Consider what happens after an identity attack. The first job is restoring the identity provider to a known clean point in time. For Active Directory, that job is brutal. That means first rebuilding the forest one domain at a time, then completing an authoritative restore while keeping the other domain controllers offline. The following weeks require going through a checklist of tasks that includes resetting the krbtgt password twice to kill forged Kerberos tickets, resetting the DSRM and trust passwords, cleaning up the metadata, removing lingering objects, rebuilding the Global Catalog, and more.
All of these steps are manual and sequential. One mistake could reopen the door for an attacker or corrupt the directory. Even a flawless restore causes damage of its own: it resets every legitimate change made since that clean point.
There may be thousands of these legitimate changes because the directory is constantly evolving. Employees join and leave the company. Group memberships change as people take on new roles. New security groups are provisioned. GPOs are updated. Service accounts are rotated. The further back the organization goes, the more changes the directory might have undergone.
This is the cruel math of identity recovery: To remove the attackers' changes, you are forced to erase tens of thousands of legitimate ones. Mandiant's 2025 report puts the global median dwell time at 11 days and the average time to discover intrusions internally at around 29 days. This means the last clean snapshot is often weeks old.
Assume the clean point was 30 days ago. In a large enterprise, the volume of legitimate changes across that window can easily reach 30,000 to 40,000 individual changes, including new hires, role changes, and access grants. Selecting a clean point in time 30 days back makes every one of these legitimate changes disappear.
So the directory is recovered to a known clean point in time, but the business simultaneously faces a second outage.
To avoid that loss, IAM teams spend days or weeks manually reconciling every change, cross-referencing the identity provider against systems of record such as HR platforms, SaaS applications, and governance and privileged access systems. They work through changes one by one to determine which were made by the business and which were made by the attacker. The process is slow and error-prone. Every hour spent on it is an hour the organization operates with identities locked out of the systems they need. This manual process increases RTO and simultaneously collapses recovery point objectives.
Recover Clean and Current with Rubrik's Roll Forward
Rubrik customers who have been through cyber recovery say they want one thing: to recover identity to a state that is both clean and current, removing every change an attacker made while preserving every change the business made. They need this in hours, not weeks.
Until now, that meant choosing between two bad options: restore to a clean point and accept the data loss, or restore and reconcile by hand and accept the delay.
Rubrik’s Roll Forward capability can do both, which means that organizations no longer have to choose between a clean IdP and a current directory state. Rubrik recovers identity to a state that is simultaneously clean and current, so IAM teams can move fast without asking the business to absorb the cost. Now, IAM admins can quickly restore the enterprise, increasing resilience in the modern world full of increasingly sophisticated AI-based attacks.
How Roll Forward Works
Roll Forward with Rubrik works in four easy steps:
Establish the Clean Point in Time: Roll Forward integrates directly with Rubrik's threat hunting and threat monitoring capabilities, evaluating every snapshot to determine whether it is clean or malicious. That gives IAM and SOC teams a confirmed clean point in time to recover from.
Surface every change: Roll Forward helps IAM and SOC teams identify the complete set of changes between the clean state and the current state, providing teams a precise, comprehensive picture of every change that has happened between the two points.
Reconcile automatically: Roll Forward automates what used to be a painful, weeks-long process: reconciliation. Rubrik stitches together signals across your entire identity fabric—identity providers and HR systems of record like Workday, identity governance systems such as SailPoint, and SaaS applications—ultimately building an aggregated source of truth. Leveraging this, Rubrik classifies each change between these two snapshots as legitimate or malicious. That manual reconciliation used to take weeks; now it’s done in minutes.
Roll Forward legitimate changes: Finally, Rubrik restores legitimate changes. The restored directory reflects the current state of the business, not the state of the last backup or clean state.
The results for customers is phenomenal: a directory that is both clean and current, recovered quickly and recovered fully.
When is it Available to Customers?
Roll Forward for Active Directory is scheduled to arrive in Q3 with support for Entra ID and Okta to follow. The same clean-and-current recovery model is being extended across popular identity providers.
Ready to Recover Clean and Current?
Identity attacks aren't going to slow down. The question is how quickly organizations can recover IdPs to a clean and current state when an identity attack happens. In our upcoming webinar, join Rubrik to take a first look at how Identity Roll Forward changes the recovery equation. You’ll understand what it takes to move from a compromised identity environment to a clean, current state without starting from scratch. Register here.
Learn more about Rubrik Identity Resilience or contact us to schedule a demo.
SAFE HARBOR
Any unreleased services or features referenced on this page are not currently available and may not be made generally available on time or at all, as may be determined in our sole discretion. Any such referenced services or features do not represent promises to deliver, commitments, or obligations of Rubrik, Inc. and may not be incorporated into any contract. Customers should make their purchase decisions based upon services and features that are currently generally available.
NOTE
Please speak to Rubrik representatives to confirm the availability and functionality of Rubrik's products and services before making any purchase or renewal decisions.