As organisations move deeper into Microsoft 365, cloud platforms, and multiple SaaS applications, attackers have shifted their focus to targeting the credentials, tokens, and admin roles that control access to everything.

A single identity-based compromise can quickly become a devastating operational issue, affecting your entire organisation’s ability to access email, files, applications, infrastructure, and business-critical services, all at once.

Identity resilience is not just a cyber security concern, it has become an operational necessity.

Cyber attacks are not the only risk … accidental misconfiguration, deleted users or groups, failed policy changes, expired certificates, broken federation trusts, service principal issues, administrator error, or problems introduced during tenant changes can be just as disruptive.

Credential Compromise

Password spraying, phishing, and adversary-in-the-middle (AiTM) proxy attacks continue to get around legacy MFA methods. Entra ID sign-in logs routinely show millions of failed authentication attempts per day across enterprise tenants. Once credentials are obtained, attackers move laterally to privileged accounts.

Token Theft and Session Hijacking

Modern AiTM toolkits such as Evilginx and Modlishka capture OAuth tokens rather than passwords, bypassing MFA entirely. A stolen refresh token can provide weeks of persistent access. Without Continuous Access Evaluation, sessions established under a valid token remain active even after the credential risk is detected.

Privileged Identity Abuse

Global Administrator and other highly privileged Entra ID roles are primary targets. An attacker who successfully gains Global Admin access can create new accounts, modify Conditional Access policies, add federated identity providers, and exfiltrate directory data within minutes.

The 2023 Storm-0558 campaign demonstrated how identity and token-based trust underpin Microsoft 365 services. By using forged authentication tokens to access Exchange Online mailboxes, the attackers highlighted the potential impact that identity-layer compromise can have across cloud platforms and business-critical services.

Insider Threats and Misconfigurations

Accidental or malicious changes to Conditional Access policies, application registrations, or federation trust settings can degrade the security posture of an entire tenant quickly. A misconfigured guest access setting can expose sensitive SharePoint content to any authenticated Microsoft account.

Entra ID as a Resilience Platform

Microsoft Entra ID sits at the centre of identity resilience for most Microsoft-centric organisations, controlling sign-in, access policies, and privileged roles. Building resilience requires combining strong prevention with the ability to recover fast when something goes wrong.

Ten important actions for identity resilience inside Entra ID:

1. Mandate phishing-resistant MFA (FIDO2/WHfB/CBA) for all administrator accounts

Traditional MFA methods such as TOTP codes and SMS are vulnerable to AiTM attacks. Entra ID supports phishing-resistant credential types that bind the authentication assertion to the relying party’s origin such as FIDO2 Security Keys, Windows Hello for Business, Certificate-Based Authentication (CBA) and Passkeys.

2. Activate Privileged Identity Management (PIM) for all privileged Entra ID and Azure roles

Convert standing privileged access into just-in-time elevation, with mandatory justification, MFA, and approval workflows. Key configurations include requiring phishing-resistant MFA for role activation; setting maximum activation durations to limit the window of privilege exposure; enabling PIM alerts for suspicious activation patterns; regularly running PIM Access Reviews to remove stale eligible assignments; and maintaining dedicated emergency access accounts.

3. Deploy risk-based Conditional Access policies using Identity Protection signals

Require specific credential types for sensitive resources to override weaker MFA methods; force re-authentication at defined intervals to limit the ‘blast radius’ of stolen session tokens; ensure only Intune-enrolled, policy-compliant devices can access corporate resources; block authentication from unexpected geographies or anonymous VPN exit nodes; apply token protection / device-bound session controls where supported.

4. Enable Continuous Access Evaluation across Microsoft 365 workloads

Address the gap between a risk event and token revocation enabling near-real-time token revocation by establishing a persistent channel between Entra ID and CAE-capable workloads including Exchange Online, SharePoint Online, and Teams. Without CAE, an access token remains valid until its lifetime expires (up to one hour) even if the user’s account is disabled or their password is changed.

5. Enable and test Resilience Defaults for Conditional Access

Ensure Conditional Access policies are configured to behave safely during Microsoft Entra service disruption. Resilience Defaults allow Entra ID to use previously collected session information to maintain access where appropriate, reducing the risk of a complete productivity outage if real-time policy evaluation is unavailable: review which policies should use resilience defaults and which high-risk scenarios should still require real-time evaluation; test contingency access paths for mission-critical applications; and document when, how and by whom any emergency access policy can be used.

6. Configure and test break-glass accounts

A critical and frequently overlooked part of identity resilience. Break-glass accounts provide access to the Entra ID tenant when normal administrative authentication paths are unavailable, for example if MFA is down, the Authenticator app is compromised, or all PIM-eligible admins are locked out. Microsoft now recommends strong authentication such as FIDO2/passkeys or certificate-based authentication for emergency access accounts.

7. Stream all Entra ID logs to a SIEM and build detection rules for critical changes

Good monitoring closes the gap between an event occurring and a team responding to it: stream all Entra ID audit logs, sign-in logs, and risk detections to Microsoft Sentinel or a third-party SIEM; build detection rules for Admin role assignments, new federation trust additions, Conditional Access policy modifications, and bulk user deletions; (for hybrid environments) integrate with Microsoft Defender to detect on-premises lateral movement; test your identity incident response playbook quarterly, include scenarios for token theft, admin lockout, and phishing compromise.

8. Migrate service principals to Managed Identities or Workload Identity Federation

Non-Human Identities (NHIs) are a growing attack surface. Managed Identities remove the need to store secrets in code or configuration, as the identity is managed by Azure and rotated automatically. Where managed identities are not possible, Workload Identity Federation allows workloads such as GitHub Actions, Kubernetes, and AWS IAM to authenticate using federation rather than client secrets.

9. Conduct quarterly Access Reviews for privileged roles and guest users

Orphaned accounts and excessive permissions build up over time and expand the attack surface. Microsoft Entra ID Governance provides tools such as entitlement management, access reviews, lifecycle workflows and verified ID to help manage this systematically.

10. Run an annual identity-resilience focused tabletop exercise or adversary simulation

As resilience is only proven when it’s tested! Run at least one annual exercise that validates how your organisation would detect, contain and recover from an identity compromise affecting Microsoft Entra ID. Document your gaps, update incident runbooks, and always retest again after any major identity, governance, or Microsoft 365 changes.

Prevention and detection matter, but resilience is measured by how quickly an organisation regains control after a successful attack.

The Limits of Native Recovery

While Entra ID provides several built-in recovery capabilities, these features are primarily designed for operational recovery rather than comprehensive backup and restore. The following questions highlight some of the key limitations organisations should consider when assessing their identity resilience and recovery strategy.

Does Entra ID provide point-in-time restore for configurations?

No point-in-time restore of configuration: Conditional Access policies, named locations, authentication methods policies, and app registrations have no native versioning. If a policy is changed or deleted, there is no built-in way to roll it back to a prior state.

Are Entra ID audit logs retained indefinitely?

Limited retention windows: Audit log retention is capped, and once it expires, the forensic trail of what an attacker changed is gone.

Does soft-delete protect against large-scale or tenant-wide attacks?

No protection against bulk or tenant-wide deletion: Soft-delete covers individual objects for a limited window, but does not address scenarios where an attacker systematically alters dozens of policies, role assignments, and app consents over an extended dwell time.

How easy is it to rebuild Entra ID configurations after a major incident?

Manual reconstruction is slow: Without an external baseline, rebuilding a Conditional Access configuration or app registration estate from memory or scattered documentation can take days, during which the organisation may be running with weakened controls.

Why a Dedicated Backup Layer Matters

Prevention remains essential, but organisations also need to know how they would detect, contain and recover from identity compromise when controls fail or configurations are maliciously changed. Security is no longer enough to keep your identity resilient, you must also be able to recover it.

Microsoft Entra ID is a live operational environment with changes to users, groups, roles, policies and applications taking effect immediately across the organisation. Identity resilience necessitates being able to return your Entra ID to its known state quickly and accurately when something goes wrong.

Having a dedicated backup for Entra ID is crucial should any of your identity objects be deleted, misconfigured, maliciously changed, or overwritten.

  • Faster recovery
  • Longer retention than native logs
  • Coverage beyond soft-delete
  • Consistency with broader Microsoft 365 protection

Trust Autodata with your Entra ID Backup

Autodata’s Managed Entra ID Backup enables you to:

✅ Easily identify directory changes when restoring data

✅ Reduce risk and stay compliant through automated backup processes

✅ Pinpoint broken or missing application registrations

✅ Successfully restore objects without Recycle Bins / beyond 30-day retention

We ensure your Entra ID tenant is fully resilient to meet your recovery objectives and compliance goals by:

Accelerating Change Detection

  • Quickly identify changes and how they were created, whether by human error, threat actors, or automated attacks
  • Access point-in-time copies of your IAM data should you need to conduct forensic investigations
  • Confidently revert or restore changes

Simplifying Governance, Risk and Compliance

  • Automated backups reduce human-error risks to ensure consistent resiliency practices
  • Access to audit logs allow you to only restore the data you need
  • Rapidly Restores Your Business

Rapidly Restoring Your Business

  • Precise identification of application registration changes mitigates damage
  • Object-level recovery means you choose what to restore
  • Bring your business back online in seconds with comprehensive recovery

Managing & Deploying Everything for You

We provide you with a secure backup service, offloading all your maintenance, updates and security fixes to our experts.

Other/Hybrid Identity Environments

Microsoft Entra ID is the dominant identity platform for Microsoft-aligned organisations, but it is not the only one. Okta is also widely deployed, particularly in organisations with a more varied application landscape. Understanding where each platform fits, and how they are sometimes used together, is relevant to any identity resilience assessment.

  • Microsoft Entra ID: Best suited to organisations fully leveraging the Microsoft stack, where seamless integration with Microsoft 365, device compliance through Intune, and centralised policy management through Conditional Access are priorities. For most midmarket organisations, Entra ID is bundled into existing Microsoft licensing, making it the default identity platform.
  • Okta: Better suited to organisations with a more heterogeneous IT environment, where flexible single sign-on and identity management across a wide range of SaaS platforms , many of them outside the Microsoft ecosystem , is the priority. Okta is licensed per user, which tends to position it as a deliberate choice for larger or more SaaS-diverse organisations rather than a default.
  • Hybrid deployments: Some enterprises run both: Entra ID for managing the internal Microsoft stack, and Okta for external identities and federation with non-Microsoft SaaS applications. This pattern is more common among larger enterprises than midmarket organisations, reflecting the additional licensing and operational overhead of running two identity platforms in parallel.

If you’re running Okta, whether alongside or independently of Entra ID, get in touch with us today to discuss how best to protect and backup all your identity systems to achieve full identity resilience.

Authors

Related Reads

Blog
A white circle with lines in it.
A digital interface showing a glowing open padlock icon surrounded by warnings such as DATA LEAK, SECURITY BREACH, EXPLOIT, and VIRUS DETECTED, symbolising a cyber security breach.
09 • 06 • 2026

Why Rapid Recovery Begins On-Premise with True Immutability

18 min read

Blog
A white circle with lines in it.
A large, colourful cloud icon with neon hues hovers above glowing digital lines and rectangular shapes, symbolising cloud computing and data exchange in a vibrant, futuristic style.
06 • 04 • 2026

Cloud Storage TCO: How to Overcome Hidden Fee Fatigue

9 min read

Blog
A white circle with lines in it.
A futuristic digital illustration of a server surrounded by glowing clouds, floating data icons, and shield symbols, representing cloud computing and cyber security in vibrant neon colours.
05 • 02 • 2026

Data Protection vs Data Resilience: The Difference

9 min read

We Partner with Leading Global Technology Vendors