EIDGUARD FOR MICROSOFT ENTRA EXTERNAL ID

Recover Your Microsoft Entra External ID Tenant.

Microsoft provides no native backup or restore for most Entra External ID configuration. EIDGuard continuously captures versioned recovery points, detects configuration drift, and restores your tenant from a known-good state.

Runs in your Azure tenant.Your data never leaves it.
Contoso External ID
AB
OVERVIEW

Recovery posture

Latest backupToday, 02:00 Verified
Protected objects27,97317 resource types
Configuration drift3Review changes
Backup activity30 days
Jul 07Jul 16Jul 25Aug 05
Recent driftView all
MUser flowB2C_1_SignUpSignIn
+API connectorCRM enrichment
Claim mappingextension_LoyaltyId
Backup complete27,973 objects protected
Drift detected3 changes require review
RUNS IN YOUR AZURE TENANT Microsoft Azure Microsoft Graph Protected Azure storage Customer-owned data

Your identity platform is production infrastructure. Its configuration is not recoverable by default.

Microsoft Entra External ID protects availability—but for most tenant configuration, it does not provide a native backup, point-in-time history, or restore workflow.

01Accidental deletion
02Malicious changes
03Tenant corruption
04Insider threats
05Failed migrations
06Configuration mistakes
EIDGUARD CLOSES THE GAP

Back up the configuration. Verify the baseline. Recover with intent.

See how recovery works

From live tenant to known-good state.

A continuous, Azure-native recovery workflow designed for identity operations—not just data retention.

01

Daily backup

Capture supported tenant configuration on an automated schedule.

02

Recovery point

Write versioned JSON to protected Azure Blob Storage in your tenant.

03

Drift verification

Compare live state with your last known-good baseline—scheduled or on demand.

04

Alerting

Notify operators when jobs fail, certificates expire, or drift appears.

05

Selective recovery

Preview and restore only what changed—or rebuild the tenant.

Every stage of tenant recovery, engineered as one system.

Protect the configuration layer that defines customer access, user journeys, applications, and trust.

01

Backup

Versioned JSON recovery points stored in your own protected Azure Blob Storage, with full data ownership preserved.

Explore backup
02

Recovery

Selective or full restore with dependency-aware ordering, GUID remapping, and WhatIf preview.

Explore recovery
03

Drift detection

Scheduled or on-demand comparison of live configuration against a known-good recovery point, with exact change detail.

Explore drift detection
04

Operations

Automated scheduling, monitoring, certificate expiration tracking, role-based access, and email notifications.

Explore operations

A recovery service should be transparent about access, protection, and control.

EIDGuard deploys into your own Azure tenant. It connects to Entra External ID through tenant-approved Microsoft Graph permissions, and backup data is protected in your Azure storage—it never leaves your environment.

Customer-hosted deployment Tenant-approved access Customer-owned data
SECURITY MODELIn your Azure tenant
Entra External IDMicrosoft Graph
tenant approved
EIDGuardYour Azure tenant
Azure StorageProtected backups
Key VaultProtected credentials
Encrypted connectionsTenant-controlled permissionsAuditable operations

Read-only backup access

Tenant-approved collection permissions cannot modify tenant configuration.

Separate restore access

Recovery permissions are isolated until an authorized restore is initiated.

Certificate authentication

No interactive account or stored password is required.

Azure Key Vault

Service credentials and operational secrets remain protected in Azure.

Blob versioning

Every backup is retained as a recoverable point in time.

Purge protection

Critical recovery material cannot be silently destroyed.

Least privilege

Tenant administrators control the Microsoft Graph permissions granted to EIDGuard.

Encrypted connectivity

Tenant connections and recovery data are protected in transit and at rest.

Built to be exercised, inspected, and trusted.

Recovery confidence comes from visible operations and verifiable history.

EverySupported resource type protected
DailyDrift verification + on-demand checks
100%Deployed in your Azure tenant
ZeroData leaving your tenant

Recovery operations, without the black box.

See every backup, configuration change, certificate, job, and recovery plan from one operator-focused console.

EIDGuard overview: 100% backup health, 27,973 protected objects, three of three tenants current, and a list of recent backup and compare jobs.

Availability is not recoverability.

Microsoft runs the service. EIDGuard gives your team a governed path back to a known-good configuration.

MICROSOFTEntra External ID
No native backup
No native restore
No configuration history
No drift monitoring
No recovery points
No recovery planning
VAMBRISEIDGuard
RECOVERY READY
Daily automated backups
Versioned recovery points
Selective restore
Full tenant rebuild
Configuration drift detection
Recovery planning

Connect your tenant. Set your policies. Start protecting.

EIDGuard deploys into your own Azure tenant. Your team retains full ownership of the data and control over the Microsoft Graph access granted to the service.

STEP 01

Connect your Entra External ID tenant

Authorize EIDGuard with tenant-approved Microsoft Graph permissions.

STEP 02

Configure backup and recovery policies

Choose schedules, retention, alerts, and recovery controls—all running inside your Azure subscription.

EIDGUARD IN YOUR AZURE TENANT Service connected
Entra tenantCustomer-owned
Microsoft GraphApproved access
EIDGuardIn your Azure tenant
Azure StorageProtected history
RecoveryPolicy-governed
Tenant-approved access Certificate auth Protected Azure storage Audit logging

Priced by the tenants you protect.

Every plan includes every capability. The only thing that changes is how many Entra External ID tenants EIDGuard protects.

Starter
$199per month

Up to 3 protected tenants

Deploy Solution
Enterprise
Contact us

More than 5 protected tenants

Talk to sales
Daily automated backups On-demand backups and drift checks Configuration drift detection Selective restore with WhatIf preview Full tenant rebuild Every supported resource type Certificate expiry monitoring Runs in your own Azure tenant
EIDGuard runs in your own Azure subscription—Azure resource costs are billed to you directly by Microsoft.

Protect your customer identity platform before you need to recover it.

Connect your Entra External ID tenant, configure backup policies, and establish your first known-good recovery point.