On Demand Recovery

Establish a complete Entra ID recovery plan that minimizes downtime and user disruption with On Demand Recovery. Run difference reports between backups and live Entra ID to spot cloud-only users, attributes, and unwanted changes or deletions. Quickly search and restore exactly what you need, or recover multiple users, groups, and group memberships in bulk without PowerShell. This Entra ID recovery solution reduces the risk of data loss or outages from human error and saves valuable IT time and resources.

Modern, enterprise-grade Entra ID backup and recovery

Complete Active Directory and Entra ID recovery are essential in today’s hybrid environments. On Demand Recovery extends your on-premises AD recovery strategy to the cloud by backing up Entra ID users, groups, attributes, and policies, including cloud-only objects. Run difference reports to compare backups with what’s live, quickly pinpoint risky changes or deletions, and restore only what’s needed. This centralized, SaaS-based approach reduces complexity, minimizes human error, and helps keep business-critical services available across your hybrid AD and Entra ID estate.

textimage-On-Demand-Recovery

Entra ID under constant attack

600
M+

identity attacks on Microsoft Entra every day

7000
+

password attacks blocked every second across Entra

66
%

of attack paths now involve identity compromise

Key Benefits

SVG

Minimize downtime from identity incidents

Restore access faster during accidental deletions or cloud disruptions to maintain business continuity with this Entra ID recovery solution.
SVG

Scale hybrid identity recovery with cloud agility

Support fast-growing Entra ID and on-prem AD environments without adding infrastructure or administrative overhead.
SVG

Improve governance and auditing accuracy

Gain reliable visibility and auditable records across hybrid directories to support compliance and faster investigations.
SVG

Simplify operations for IT teams

Reduce operational workload by centralizing hybrid identity recovery into a single, guided SaaS workflow.
SVG

Ensure complete hybrid identity protection

Protect the full identity estate: cloud-only, hybrid and on-prem AD through coordinated, cross-directory recovery.
SVG

Reduce risk from accidental or malicious changes

Quickly reverse harmful changes or deletions to maintain a secure, predictable identity configuration.

Highlighted Features

SVG
Restore hybrid and cloud identity objects
Restore on-prem AD, Entra ID, and Microsoft 365 users, groups, apps, and devices to maintain business continuity.
SVG
Entra ID backup for cloud-only attributes
Back up roles, licenses, MFA info, group memberships, and app attributes for secure, complete Entra ID recovery.
SVG
Centralized hybrid recovery dashboard
Manage hybrid identity recovery with a single dashboard integrated with Recovery Manager for Active Directory.
SVG
Difference reporting for on-prem and cloud
Compare backups with live on-prem AD and Entra ID to identify changes and restore only what’s required.
SVG
Bulk recovery for hybrid directories
Recover multiple on-prem AD, Entra ID, and Microsoft 365 objects simultaneously without PowerShell.
SVG
Granular search and selective restore
Search modified or deleted hybrid objects and restore specific users, attributes, or cloud-only items.

Knowledge Center

Body

Ready to protect your Entra ID identities?

FAQ

While Microsoft provides native tools like Entra ID Recycle Bin and access logs, these features do not offer full, point-in-time backup or true attribute-level recovery. Native options cannot restore many cloud-only attributes such as licenses, MFA contact data, application role assignments, directory role membership, group memberships, or Azure application custom attributes. They also can’t recover large numbers of identities at once or compare previous backups with the live directory to pinpoint harmful changes. On Demand Recovery closes these gaps by providing scheduled backups, difference reporting, granular and bulk restore, and hybrid AD coverage. This ensures organizations can quickly reverse accidental or malicious changes, avoid outages, and maintain a secure, consistent identity environment across both on-prem AD and Entra ID.

Identity systems like Entra ID and on-prem AD are prime targets during cyberattacks because compromising users, groups, or authentication settings gives attackers direct access to critical applications. Threat actors often delete accounts, remove MFA, change group memberships, or elevate privileges to persist and spread laterally. Native tools offer limited rollback for these changes, making recovery slow and risky. This Entra ID recovery solution enhances cyber resilience by keeping secure, point-in-time backups of cloud-only and hybrid identity objects, including roles, licenses, MFA contact data, and group memberships. During an attack, IT teams can compare backups to the live directory, identify unauthorized changes, and rapidly restore clean identities at scale, minimizing disruption and re-establishing a trusted identity state.

Quest On Demand Recovery is a SaaS-based identity backup and recovery solution designed to protect Microsoft Entra ID and hybrid Active Directory environments. It helps organizations quickly restore users, groups, attributes, devices, and cloud-only identity objects that are accidentally deleted, modified, or impacted by misconfiguration. By comparing backups with the live directory, it identifies unwanted changes and lets you restore exactly what’s needed without requiring PowerShell. The solution supports granular restores, bulk recovery, difference reporting, and a centralized dashboard for managing on-prem AD and Entra ID identities. By preventing downtime and minimizing the impact of human error or malicious activity, this Entra ID recovery solution ensures business continuity across your hybrid identity environment.

On Demand Recovery is designed for modern hybrid identity environments that span both on-premises AD and Entra ID. It integrates seamlessly with Recovery Manager for Active Directory to deliver a single recovery workflow for cloud-only, hybrid, and on-prem identity objects. You can restore users, groups, memberships, devices, Azure applications, conditional access-related attributes, and more, regardless of where they originated. This unified approach ensures that identities remain consistent across cloud and on-prem directories, reduces operational complexity, and closes the recovery gaps left by native tools like Microsoft’s Recycle Bin. The ability to recover both full objects and specific attributes ensures precise, reliable restoration across hybrid identity systems.

On Demand Recovery is a SaaS-based service that performs scheduled, point-in-time backups of Entra ID and hybrid Active Directory objects, including cloud-only attributes, licenses, roles, MFA contact info, group memberships, and Azure application attributes. Backups are stored securely in Azure Storage using end-to-end encryption. When a restore is needed, ODR compares the selected backup to the live directory using difference reporting, allowing administrators to see exactly which objects or attributes changed. Entra ID recovery can be performed granularly, restoring only specific values, or in bulk for large incidents. For hybrid environments, ODR integrates with Recovery Manager for Active Directory to coordinate cloud and on-prem object restores from a single interface.