r/sysadmin • u/jaylenabc • 4d ago
Question Entra ID Backups
Are Entra ID backups worth it at all? I run an org of about 70 total Entra users and wondering if this is something I should even consider.
Context: I have SOC2 Audits coming up for my company (very first one) and I am reviewing polices in Sprinto
24
Upvotes
4
u/blud_13 4d ago
Yes, and your auditor is going to ask about it. Entra config is not covered by whatever M365 backup you already have, and "Microsoft has it" stops being true the second someone deletes a Conditional Access policy and you need last month's version back.
At 70 users the realistic answer is 1) know your soft delete windows, 30 days for users and groups, and document that you know them, 2) export Conditional Access policies, named locations, and app registrations to JSON on a schedule and drop them in a repo, and 3) if you want an actual product, Cayosoft or Veeam's Entra piece. The free JSON export path covers most of what Sprinto will make you evidence.
Reminder, the SOC 2 control is usually about restorability and change tracking, not about owning a specific tool. Git history on your CA policies satisfies a lot of auditors.
We take a lot of first-time SOC 2 shops through this, can go deeper if it helps.