Troye exposes the Entra ID backup blind spot

Issue 4 and 5 2025 Information Security, Infrastructure

Many organisations naively believe that Microsoft’s shared responsibility model covers Microsoft Entra ID – formerly Azure AD – but they do not. Troye argues that relying on Microsoft alone to secure your identity infrastructure is a recipe for disaster.


Helen Kruger.

“That is why we are urging South African businesses to adopt Redstor’s Entra ID Backup, a proactive and comprehensive solution designed to safeguard identity data and recover it in minutes, not weeks,” says Troye CEO, Helen Kruger.

Microsoft Entra ID is central to modern identity and access management, supporting everything from user authentication to conditional access policies. However, as experts have warned, Entra ID’s native tools provide limited backup and recovery options, with logs kept for only 30 days and no way to revert critical changes like permission misconfigurations or deleted roles.

That means a breach, insider threat, misconfiguration, or accidental deletion can cause catastrophic damage - without any reliable way to recover.

Redstor delivers immutable, cloud-native backups of your Entra ID environment, including user accounts, roles, group memberships, admin units, Intune policies, and conditional access configurations. With unlimited retention, you can restore any deleted or modified object at any time - even if months or years have passed - breaking Microsoft’s 30-day limitation.

Kruger says recovery is granular and fast. “You can restore individual user objects, specific permissions, or entire policy sets within seconds, or roll back unwanted changes using built-in change comparison tools.”

Redstor's support for Entra ID offers instant recovery of core identity components, automated change monitoring, and ransomware-resistant backups stored offsite with AES-256 encryption and immutable retention - ensuring compliance with standards like ISO 27001, GDPR, SOC 2, and HIPAA.

A recent MSP case study highlighted how a client's global admin account was compromised, resulting in over 1800 unauthorised changes across their Entra ID tenant. Without Redstor, remediation took days of manual effort and relied heavily on incomplete logs. After adoption, automatic restores eliminated that overhead and significantly reduced downtime.

This solution is essential for organisations using Entra ID - or Microsoft 365 - that cannot rely on Microsoft’s limited native recovery tools:

● Enterprises with high compliance or audit requirements

● Businesses vulnerable to insider threats, misconfiguration, or ransomware

● Organisations lacking built-in identity recovery tools

● MSPs and IT teams that want a multi-tenant, scalable backup solution

As a trusted Redstor partner in South Africa, Troye delivers everything needed to protect Entra ID from identity loss, offering full implementation and seamless integration into your Microsoft 365 and Entra ID environment, along with local support aligned to South African regulatory requirements, and expert training and consultancy to strengthen identity resilience and recovery readiness.

Find out more at www.troye.co.za




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
NEC XON detects and stops ransomware attack
NEC XON Information Security IoT & Automation
Ransomware attacks rarely begin with chaos. More often, they start quietly, with probing, mapping, and patient reconnaissance inside a target’s network. That was the situation facing a global recruitment firm when cybercriminals attempted to navigate its systems.

Read more...
Sara AI Pentesting available in South Africa
Information Security News & Events
Synack and Wolfpack Information Risk are offering Sara AI Pentesting to organisations across South Africa, helping companies move from point-in-time testing to continuous security validation with AI and human expertise.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...
From drone market growth to application-level commercialisation
IoT & Automation Infrastructure
After years of pilot projects and technology validation, the question for the market is shifting from whether drones can fly safely and collect data, to where they can deliver repeatable operational value at scale.

Read more...
Cybersecurity in a digitally connected security industry
SA Technologies Information Security IoT & Automation
As more organisations move towards digital visitor management, cloud-based access control, mobile applications, biometric verification, and connected security platforms, cybersecurity must be viewed as part of the full security environment.

Read more...
Enterprises must prepare for digital conflict
Information Security
Cyberattacks can be launched remotely and at scale. A coordinated attack launched from anywhere in the world can disrupt supply chains, shut down utilities, or expose millions of customer records within minutes.

Read more...
AI-enabled NVR for Milestone XProtect
Surveillance Infrastructure Products & Solutions
As surveillance environments continue to grow in scale and complexity, organisations need infrastructure that is easy to deploy, simple to manage, and ready for AI-driven workloads.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.