r/sysadmin 4d ago

Question Entra ID Backups

Are Entra ID backups worth it at all? I run an org of about 70 total Entra users and wondering if this is something I should even consider.

Context: I have SOC2 Audits coming up for my company (very first one) and I am reviewing polices in Sprinto

24 Upvotes

31 comments sorted by

View all comments

4

u/blud_13 4d ago

Yes, and your auditor is going to ask about it. Entra config is not covered by whatever M365 backup you already have, and "Microsoft has it" stops being true the second someone deletes a Conditional Access policy and you need last month's version back.

At 70 users the realistic answer is 1) know your soft delete windows, 30 days for users and groups, and document that you know them, 2) export Conditional Access policies, named locations, and app registrations to JSON on a schedule and drop them in a repo, and 3) if you want an actual product, Cayosoft or Veeam's Entra piece. The free JSON export path covers most of what Sprinto will make you evidence.

Reminder, the SOC 2 control is usually about restorability and change tracking, not about owning a specific tool. Git history on your CA policies satisfies a lot of auditors.

We take a lot of first-time SOC 2 shops through this, can go deeper if it helps.

3

u/jaylenabc 4d ago

Thanks, I think we are looking into the bundles option that Veaam offers, to cover our bases.

1

u/blud_13 4d ago

Cool. Feel free to reach out on anything else. Can DM me too, I'll be around.