Applies to EIDGuard for Microsoft Entra External ID
On this page
Every EIDGuard recovery point covers 29 Microsoft Entra External ID resource
types, read through Microsoft Graph by the tenant's read-only backup app. This
article lists them, marks the two that are captured for reference rather than
restored, and explains what no backup can contain.
Identity and access
Resource
Captured with it
Users
Identities, custom sign-up attribute values and extensions
Groups
Members and owners
App registrations
Owners, federated identity credentials and extension properties
Enterprise apps and service principals
App role assignments and OAuth2 permission grants
Directory roles
Role assignments and custom role definitions
Administrative units
Members and scoped role assignments
Sign-in experience
Resource
Captured with it
User flows
Linked applications
User flow attributes
Identity providers
Configuration; client secrets cannot be exported
Custom authentication extensions
API connectors
Configuration; credentials are restored as placeholders
Company branding
Localizations; logo images are captured as references only
Conditional Access
Resource
Captured with it
Conditional Access policies
Recreated policies arrive disabled
Named locations
Custom authentication strengths
Authentication context class references
Tenant policies and settings
Resource
Captured with it
Authentication methods and authorization policies
Cross-tenant access policy
Default and partner settings
Token lifetime and claims mapping policies
Token issuance, home realm discovery and activity-based timeout policies
App management policies
Including the tenant default
Permission grant policies
Include and exclude sets
Feature rollout policies
Including the objects they apply to
Admin consent request policy
Security defaults enforcement policy
Group settings
Tenant-wide directory settings
Organization settings
Captured for reference only
Resource
Why
Domains
Domain verification cannot be restored
Devices
Exported for audit; device trust material cannot be restored
What no backup contains
Microsoft Graph does not export user passwords, app client secrets and
certificate private keys, per-user MFA and passkey registrations, identity
provider client secrets, federation signing keys, or branding image files, so
no backup of any kind contains them. A restore recreates the objects with
placeholders and lists each follow-up under Manual actions required;
Restoring from a recovery point covers
what to do about each one.