The Morning Nobody Can Sign In
Tuesday, 7:40 a.m. The service desk is overwhelmed. Administrators cannot sign in. Finance accounts are locked.
Three weeks earlier, someone called the service desk posing as an employee and obtained a password reset. From that account, the attacker registered a federated domain in Entra ID (Microsoft's cloud directory), a technique documented by Microsoft in the Storm-0501 campaign [1] that lets an attacker forge sign-in tokens for any user. They added their own MFA (multi-factor authentication) methods, created two "service" accounts, and waited.
This morning, they disabled the legitimate administrators.
The servers are intact. So are the backups. But the backup console authenticates against the same directory. So do email, the CRM and the ticketing tool.
Nobody broke down the door. The attacker logged in, and stayed. A recovery plan that cannot restore identity cannot, in practice, restore anything.
Why Identity Became Target Number One
For an attacker, a valid credential beats any kind of vulnerability: no antivirus alert, no firewall in the way. ThFor an attacker, a valid credential beats any kind of vulnerability: no antivirus alert, no firewall in the way. They work in silence, because to every security stack you have built, this looks like normal behavior.
At the Co-operative Group (Co-op), attackers posed as staff and talked employees into handing over account access [2]. At Jaguar Land Rover , reporting points to service desk voice phishing and to infostealer credentials held by a third party with Jira access, some reportedly dating from 2021 and still valid [3].
Once attackers hold rights on the IdP (the identity provider, whether Active Directory, Entra ID or Okta), they plant persistence:
- Dormant accounts and quiet delegations that survive a password reset.
- Modified GPOs, the group policies pushed to every workstation and server.
- App registrations with long-lived secrets that outlive locked-out humans.
- Non-human identities (NHIs): service accounts, API keys and automation tokens that are rarely covered by MFA or reviewed. In Storm-0501, the bridge from on-premises to cloud was an Entra Connect sync account.
Then comes recovery day. A manual Active Directory recovery can involve up to 22 sequential steps, from isolating domain controllers to resynchronizing the cloud. And which backup is clean? If the attacker has been inside for three weeks, yesterday's snapshot already contains their accounts. Restoring can mean reinstalling the intruder.
Practitioner Tip "Before your next DR test, list every identity that can modify your directory: admins, service accounts, sync accounts, app registrations. If producing that list takes more than a day, you have found your first gap." |
The Shared Responsibility Myth in SaaS
Microsoft 365, Salesforce, Jira and Dynamics 365 are hosted, redundant and monitored, so many assume their data is protected, a belief we have spent years helping customers unlearn.
Under the shared responsibility model, the provider guarantees the availability of the service. Recovering your data after deletion, encryption or tampering remains your job.
Native tools are built for user error, not incidents. A recycle bin recovers a file deleted by mistake, not the work of a compromised administrator who purges thousands of objects, then the recycle bin itself.
Storm-0501 shows how far this goes: snapshots, restore points and backup vaults deleted through documented APIs, with valid credentials. No malware. Where resources were genuinely immutable, the attacker could not delete them.
The table below compares the three approaches most organizations rely on today.
Criteria | Native recycle bin | Manual export | Immutable third-party backup |
|---|---|---|---|
Retention | Short, set by the provider | Ad hoc, discipline-dependent | Set by your policy and obligations |
Granularity | Per object, within the window | Bulk exports, laborious fine-grained restore | Object, folder, user or full tenant |
Air-gap | None: same tenant, same admin rights | Partial, if stored outside the tenant | Isolated, out of tenant admins' reach |
Identities covered | No | Rarely, permission metadata is lost | Yes, if directory and relationships are protected |
Recovery time | Fast for one object, useless at scale | Long and unpredictable | Orchestrated and testable in advance |
The tenant, your organization's dedicated instance at the provider, is the key word in that table. Any protection administered from a compromised tenant is within the attacker's reach.
The Hidden Link: No Identity, No SaaS Recovery
Imagine a perfect copy of your email data. You try to restore it, but the user has been deleted from the directory, along with their groups and permissions. In short, the data is there, but nobody can reach it.
In SaaS, data only has value with its identity context: owner, memberships, permissions, sharing. A restored Salesforce record with no profile, or a Jira project with no access group, is unusable. And because most SaaS applications delegate authentication to the IdP through SSO (single sign-on), a compromised IdP makes the whole SaaS portfolio unreachable, including backups and snapshots.
Identity is not one scope among others. It is the prerequisite for every recovery.
Minimum Viable Business (MVB) is the minimum set of activities, applications, data and identities without which the company can no longer invoice, run payroll or serve customers. Organizations often struggle because they cannot recover a clean identity directory. Co-op shows that even when ransomware never executes because it was detected in time, the loss can still be huge: you cut your systems to prevent data loss, but you are unable to restart an MVB.
Co-op lived it. The group detected the intrusion and shut down parts of its own network before ransomware could be deployed. Operations were still disrupted for weeks: stock went first to rural stores where the Co-op is the only shop, and funeral services ran on manual process. An improvised MVB, and still £206 million in lost revenue [4]. Stopping the attack is not the same as stopping the loss.
Practitioner Tip "Define your MVB with the business, not for it. Ask each process owner two questions: what do you need back first, and whose account do you need to do it?" |
How Rubrik Covers Both on One Platform
Understanding the problem is one thing; closing it is another. According to Rubrik Zero Labs [5], 90% of IT and security leaders point to identity attacks as their number one concern. Rubrik addresses identity and SaaS from a single platform:
- Identity Resilience for AD, Entra ID and Okta. A unified inventory of human and non-human identities, immutable snapshots, removal of attacker persistence, and orchestrated recovery that Rubrik says takes “hours rather than weeks”.
- Identity Roll Forward. Re-applies legitimate changes made after the snapshot without reintroducing the attacker's, a direct answer to the clean-snapshot challenge.
- Identity Continuity. Built on the Strata.io acquisition, it covers continuity for human identities and AI agents.
- Microsoft Defender integration. Links identity threat detection to automated rollback.
- SaaS Data Protection. Immutable, air-gapped copies of Microsoft 365, Salesforce, Jira and Dynamics 365 with granular restore. Identity Restitching reconnects restored data to its identity relationships, and Autonomous Business Recovery sequences recovery around the MVB.
The recovery flow fits in one sentence: the threat is detected, a clean directory snapshot is identified, legitimate changes are rolled forward, SaaS data is restitched to its identities, and the MVB restarts in the agreed order.
This simplifies the whole process: one tool protects every workload in the same way, from a single place. You don’t have to manually maintain multiple tools and make sure that they are perfectly aligned (RTO, RPO, dependencies).
Looking Ahead: AI Agents
AI agents are identities like any other, only faster.
In April 2026, a coding agent in staging at PocketOS, a SaaS platform for car rental firms, hit a credential mismatch, found an over-scoped API token in an unrelated file and deleted the production volume. Nine seconds. The backups lived in the same volume and vanished with it [6].
Agent governance is a resilience issue. Three building blocks are emerging: an inventory of agents and their permissions, guardrails bounding what they can do, and the ability to undo a destructive action the way you restore a deleted object.
Organizations already governing their NHIs rigorously have a head start. The rest will meet their agents the day one goes off the rails.
Turning a Platform Into a Tested Recovery Plan
A platform is not a plan. On incident day, what is missing is rarely the tool; it is the practice, the decision, the order of operations and the person authorized to act.
At Stordata, a Rubrik partner, we work on four fronts:
- Map the MVB with the business. Identify vital processes and the identities behind them, including service accounts nobody remembers.
- Run a real identity recovery exercise. Not a file restore test: a timed directory recovery in an isolated environment, with the teams mobilized on the day.
- Embed identity recovery in the disaster recovery plan (DRP). Runbooks, RACI and crisis-cell alignment, so directory recovery stops being improvisation.
- Run it as a managed service. Monitoring, periodic testing, reviews and MVB updates as the organization changes.
In a large enterprise, the hard part is as much organizational as technical. IAM, backup and SOC teams are separate. Who decides a snapshot is clean? Who triggers directory recovery? These calls must be settled before the incident, through your approval channels.
Regulation adds pressure. DORA (the EU's digital operational resilience regulation for financial services) and NIS2 (the directive covering essential and important entities) require recovery capability to be demonstrated and tested. An untested directory recovery is hard to defend to an auditor.
Practitioner Tip "Run your first identity recovery exercise with IAM, backup and SOC in the same room. The technical steps are documented; the handovers between teams are where hours are lost." |
Three Questions to Ask Your Team on Monday Morning
- Who leads? If our IdP were compromised this morning, who would lead recovery, and how would we know which backup is clean?
- What can act? How many non-human identities hold admin rights, and are they covered by our backups?
- Has it been proven? Have we ever restored our Minimum Viable Business under real conditions, identities included?
Final Thought
Recovery plans were built around servers and data. Attackers have moved on. The next generation of recovery plans has to start with the directory, because every other recovery depends on it.
If any of the three answers above is “I don't know”, that is where to start.
Contributed by

Benjamin Durand
Head of Offers and Alliances, Stordata


