Rubrik Logo
CXO Visionaries
CXO ExperiencesArrow Icon
CXO NewsletterZero LabsCommunity
Rubrik
LinkedInTwitterFacebookYouTubeInstagram

Call us at 1-844-478-2745

Submit Interest

ABOUT RUBRIK

CompanyLeadershipInvestor RelationsNewsroom & Press ReleasesCareersBlog

NEW TO RUBRIK

What is RubrikProductsSolutionsPartnersCustomersResources

POPULAR LINKS

Cyber RecoveryBackup & RecoveryRansomware RecoveryCloud Database Backup and Recovery ServiceCloud Disaster RecoverySaaS Backups

CompanyLeadershipInvestor RelationsNewsroom & Press ReleasesCareersBlog
What is RubrikProductsSolutionsPartnersCustomersResources
Cyber RecoveryBackup & RecoveryRansomware RecoveryCloud Database Backup and Recovery ServiceCloud Disaster RecoverySaaS Backups

CompanyLeadershipInvestor RelationsNewsroom & Press ReleasesCareersBlog
What is RubrikProductsSolutionsPartnersCustomersResources
Cyber RecoveryBackup & RecoveryRansomware RecoveryCloud Database Backup and Recovery ServiceCloud Disaster RecoverySaaS Backups
  • Legal
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
  • Trust
  • CA Residents only: Do not sell or share my personal information | Do not share my sensitive information

© 2026 Rubrik – Zero Trust Data Security™

Technical Blog Hub

They Don't Break In, They Log In: Recovering Identity and SaaS

 

SaaSIdentity ResilienceTechnology, ITTechnical Blog
SEP 30, 20266 min read
They Don't Break In, They Log In: Recovering Identity and SaaS
Share
Background
Technical Blog Hub

They Don't Break In, They Log In: Recovering Identity and SaaS

 

SaaSIdentity ResilienceTechnology, ITTechnical Blog
SEP 30, 20266 min read
They Don't Break In, They Log In: Recovering Identity and SaaS
Share

Table of Contents

The Morning Nobody Can Sign In

Tuesday, 7:40 a.m. The service desk is overwhelmed. Administrators cannot sign in. Finance accounts are locked.

Three weeks earlier, someone called the service desk posing as an employee and obtained a password reset. From that account, the attacker registered a federated domain in Entra ID (Microsoft's cloud directory), a technique documented by Microsoft in the Storm-0501 campaign [1] that lets an attacker forge sign-in tokens for any user. They added their own MFA (multi-factor authentication) methods, created two "service" accounts, and waited.

This morning, they disabled the legitimate administrators.

The servers are intact. So are the backups. But the backup console authenticates against the same directory. So do email, the CRM and the ticketing tool.

Nobody broke down the door. The attacker logged in, and stayed. A recovery plan that cannot restore identity cannot, in practice, restore anything.

Why Identity Became Target Number One

For an attacker, a valid credential beats any kind of vulnerability: no antivirus alert, no firewall in the way. ThFor an attacker, a valid credential beats any kind of vulnerability: no antivirus alert, no firewall in the way. They work in silence, because to every security stack you have built, this looks like normal behavior.

At the Co-operative Group (Co-op), attackers posed as staff and talked employees into handing over account access [2]. At Jaguar Land Rover , reporting points to service desk voice phishing and to infostealer credentials held by a third party with Jira access, some reportedly dating from 2021 and still valid [3].

Once attackers hold rights on the IdP (the identity provider, whether Active Directory, Entra ID or Okta), they plant persistence:

  • Dormant accounts and quiet delegations that survive a password reset.    
  • Modified GPOs, the group policies pushed to every workstation and server.    
  • App registrations with long-lived secrets that outlive locked-out humans.    
  • Non-human identities (NHIs): service accounts, API keys and automation tokens that are rarely covered by MFA or reviewed. In Storm-0501, the bridge from on-premises to cloud was an Entra Connect sync account.    

 

Then comes recovery day. A manual Active Directory recovery can involve up to 22 sequential steps, from isolating domain controllers to resynchronizing the cloud. And which backup is clean? If the attacker has been inside for three weeks, yesterday's snapshot already contains their accounts. Restoring can mean reinstalling the intruder.

 

Practitioner Tip

"Before your next DR test, list every identity that can modify your directory: admins, service accounts, sync accounts, app registrations. If producing that list takes more than a day, you have found your first gap."

The Shared Responsibility Myth in SaaS

Microsoft 365, Salesforce, Jira and Dynamics 365 are hosted, redundant and monitored, so many assume their data is protected, a belief we have spent years helping customers unlearn.

Under the shared responsibility model, the provider guarantees the availability of the service. Recovering your data after deletion, encryption or tampering remains your job.

Native tools are built for user error, not incidents. A recycle bin recovers a file deleted by mistake, not the work of a compromised administrator who purges thousands of objects, then the recycle bin itself.

Storm-0501 shows how far this goes: snapshots, restore points and backup vaults deleted through documented APIs, with valid credentials. No malware. Where resources were genuinely immutable, the attacker could not delete them.

The table below compares the three approaches most organizations rely on today.

Criteria

Native recycle bin

Manual export

Immutable third-party backup

Retention

Short, set by the provider

Ad hoc, discipline-dependent

Set by your policy and obligations

Granularity

Per object, within the window

Bulk exports, laborious fine-grained restore

Object, folder, user or full tenant

Air-gap

None: same tenant, same admin rights

Partial, if stored outside the tenant

Isolated, out of tenant admins' reach

Identities covered

No

Rarely, permission metadata is lost

Yes, if directory and relationships are protected

Recovery time

Fast for one object, useless at scale

Long and unpredictable

Orchestrated and testable in advance

The tenant, your organization's dedicated instance at the provider, is the key word in that table. Any protection administered from a compromised tenant is within the attacker's reach.

The Hidden Link: No Identity, No SaaS Recovery

Imagine a perfect copy of your email data. You try to restore it, but the user has been deleted from the directory, along with their groups and permissions. In short, the data is there, but nobody can reach it.

In SaaS, data only has value with its identity context: owner, memberships, permissions, sharing. A restored Salesforce record with no profile, or a Jira project with no access group, is unusable. And because most SaaS applications delegate authentication to the IdP through SSO (single sign-on), a compromised IdP makes the whole SaaS portfolio unreachable, including backups and snapshots.

Identity is not one scope among others. It is the prerequisite for every recovery.

Minimum Viable Business (MVB) is the minimum set of activities, applications, data and identities without which the company can no longer invoice, run payroll or serve customers. Organizations often struggle because they cannot recover a clean identity directory. Co-op shows that even when ransomware never executes because it was detected in time, the loss can still be huge: you cut your systems to prevent data loss, but you are unable to restart an MVB.

Co-op lived it. The group detected the intrusion and shut down parts of its own network before ransomware could be deployed. Operations were still disrupted for weeks: stock went first to rural stores where the Co-op is the only shop, and funeral services ran on manual process. An improvised MVB, and still £206 million in lost revenue [4]. Stopping the attack is not the same as stopping the loss.

 

Practitioner Tip

"Define your MVB with the business, not for it. Ask each process owner two questions: what do you need back first, and whose account do you need to do it?"

How Rubrik Covers Both on One Platform

Understanding the problem is one thing; closing it is another. According to Rubrik Zero Labs [5], 90% of IT and security leaders point to identity attacks as their number one concern. Rubrik addresses identity and SaaS from a single platform:

  • Identity Resilience for AD, Entra ID and Okta. A unified inventory of human and non-human identities, immutable snapshots, removal of attacker persistence, and orchestrated recovery that Rubrik says takes “hours rather than weeks”.    
  • Identity Roll Forward. Re-applies legitimate changes made after the snapshot without reintroducing the attacker's, a direct answer to the clean-snapshot challenge.        
  • Identity Continuity. Built on the Strata.io acquisition, it covers continuity for human identities and AI agents.        
  • Microsoft Defender integration. Links identity threat detection to automated rollback.        
  • SaaS Data Protection. Immutable, air-gapped copies of Microsoft 365, Salesforce, Jira and Dynamics 365 with granular restore. Identity Restitching reconnects restored data to its identity relationships, and Autonomous Business Recovery sequences recovery around the MVB.

The recovery flow fits in one sentence: the threat is detected, a clean directory snapshot is identified, legitimate changes are rolled forward, SaaS data is restitched to its identities, and the MVB restarts in the agreed order.

This simplifies the whole process: one tool protects every workload in the same way, from a single place. You don’t have to manually maintain multiple tools and make sure that they are perfectly aligned (RTO, RPO, dependencies).

Looking Ahead: AI Agents

AI agents are identities like any other, only faster.

In April 2026, a coding agent in staging at PocketOS, a SaaS platform for car rental firms, hit a credential mismatch, found an over-scoped API token in an unrelated file and deleted the production volume. Nine seconds. The backups lived in the same volume and vanished with it [6].

Agent governance is a resilience issue. Three building blocks are emerging: an inventory of agents and their permissions, guardrails bounding what they can do, and the ability to undo a destructive action the way you restore a deleted object.

Organizations already governing their NHIs rigorously have a head start. The rest will meet their agents the day one goes off the rails.

Turning a Platform Into a Tested Recovery Plan

A platform is not a plan. On incident day, what is missing is rarely the tool; it is the practice, the decision, the order of operations and the person authorized to act.

At Stordata, a Rubrik partner, we work on four fronts:

  • Map the MVB with the business. Identify vital processes and the identities behind them, including service accounts nobody remembers.
  • Run a real identity recovery exercise. Not a file restore test: a timed directory recovery in an isolated environment, with the teams mobilized on the day.
  • Embed identity recovery in the disaster recovery plan (DRP). Runbooks, RACI and crisis-cell alignment, so directory recovery stops being improvisation.
  • Run it as a managed service. Monitoring, periodic testing, reviews and MVB updates as the organization changes.

In a large enterprise, the hard part is as much organizational as technical. IAM, backup and SOC teams are separate. Who decides a snapshot is clean? Who triggers directory recovery? These calls must be settled before the incident, through your approval channels.

Regulation adds pressure. DORA (the EU's digital operational resilience regulation for financial services) and NIS2 (the directive covering essential and important entities) require recovery capability to be demonstrated and tested. An untested directory recovery is hard to defend to an auditor.

 

Practitioner Tip

"Run your first identity recovery exercise with IAM, backup and SOC in the same room. The technical steps are documented; the handovers between teams are where hours are lost."

Three Questions to Ask Your Team on Monday Morning

  • Who leads? If our IdP were compromised this morning, who would lead recovery, and how would we know which backup is clean?
  • What can act? How many non-human identities hold admin rights, and are they covered by our backups?
  • Has it been proven? Have we ever restored our Minimum Viable Business under real conditions, identities included?

Final Thought

Recovery plans were built around servers and data. Attackers have moved on. The next generation of recovery plans has to start with the directory, because every other recovery depends on it.

If any of the three answers above is “I don't know”, that is where to start.

Contributed by

Benjamin Durand
Benjamin Durand

Head of Offers and Alliances, Stordata

Benjamin Durand is a strategic leader at STORDATA who has specialized in storage and backup infrastructure across both on-premises and cloud environments for over a decade. He brings a unique perspective to data security, having managed Rubrik platforms from both the customer side and as a trusted partner advisor. A highly certified expert, Benjamin holds credentials as a Rubrik Systems Administrator, Cyber Resiliency Specialist, and Cloud Specialist. He is a frequent contributor to the global technical community, dedicated to evolving service offerings and managing strategic partnerships that drive modern recovery architectures.

Share Your Insights

Have an interesting story or technical findings to share? Reach out to create a blog with us.

Learning & Certifications

Access free and instructor-led training and certification paths to master Rubrik products and maximise your data security expertise.

Explore coursesNext
Background

Share Your Insights

Have an interesting story or technical findings to share? Reach out to create a blog with us.

Learning & Certifications

Access free and instructor-led training and certification paths to master Rubrik products and maximise your data security expertise.

Explore coursesNext