CYBBACK|for Microsoft Entra ID
Quick User Guide

Your first secured Entra ID backup
in under 10 minutes.

From sign-up to a fully encrypted, restorable snapshot of your Entra tenant — this guide walks you through every step, with screenshots and best practices.

AudienceIT admins & security teams
Reading time~ 8 minutes
Setup time~ 10 minutes
VersionEN — 2026
What you'll learn

6 steps to a production-ready backup

1
Get started

Sign up — trial or paid licence

CYBBACK offers two ways to get started. Both unlock the full Entra ID feature set.

Option A — Free trial

  1. Open cybback.com/essai-gratuit.
  2. Fill in your work email, company and a password. Click Start free trial.
  3. Confirm via the verification email.
  4. On the trial selection screen, pick Microsoft Entra ID. Your trial workspace is provisioned instantly.
Painless onboarding

Trial accounts get the full Entra ID feature set — encryption, BYOB, scheduling, cross-tenant restore. Switch to a paid plan at any moment without losing data.

Option B — Paid licence (Stripe checkout)

  1. Go to cybback.com/tarifs and pick the Entra ID plan that matches your tenant size.
  2. Click Subscribe. Stripe Checkout supports cards, SEPA and invoicing on annual plans.
  3. Your licence is active immediately — visible under Account → Subscription.
2
Connect Entra ID

Register the CYBBACK application

CYBBACK authenticates against Microsoft Graph using a dedicated app registration with the minimum required permissions. This takes 5 minutes in the Azure portal.

1. Create the app registration

  1. Open entra.microsoft.com as a Global Admin.
  2. Go to Identity → Applications → App registrations+ New registration.
  3. Name it CYBBACK Backup. Account types: Single tenant. Leave redirect URI empty. Click Register.
  4. Copy the Application (client) ID and Directory (tenant) ID from the overview page.

2. Grant API permissions

  1. In the new app, go to API permissions+ Add a permissionMicrosoft GraphApplication permissions.
  2. Select read-only permissions for: Directory.Read.All, User.Read.All, Group.Read.All, Application.Read.All, Policy.Read.All, Device.Read.All, RoleManagement.Read.Directory.
  3. For restore capability, also add the matching ReadWrite permissions.
  4. Click Grant admin consent at the top.

3. Create a client secret

  1. Go to Certificates & secrets+ New client secret.
  2. Set expiration (24 months recommended) and copy the Value immediately — Azure won't show it again.

4. Paste credentials into CYBBACK

  1. Open app.cybback.com/dashboard/entra-backupSettings.
  2. Paste Tenant ID, Client ID, Client Secret. Click Save credentials.
  3. CYBBACK runs an authentication test. Green badge = ready.
app.cybback.com/dashboard/entra-backup
Dashboard
Settings
Entra ID credentialsEncrypted at rest

Paste your tenant ID, application (client) ID and client secret.

Track secret expiration

Set a calendar reminder one month before your client secret expires. Backups will start failing silently if the secret is rotated without updating CYBBACK.

3
Encryption at rest

Enable AES-256-GCM encryption

Backup files are stored on CYBBACK's secure EU infrastructure by default. Add a second layer with client-side encryption: each file is encrypted before it leaves the worker.

  1. On the Settings tab of the Entra ID page, scroll to Security options.
  2. Toggle AES-256 Encryption ON.
  3. Click Save. Applies to new backups; previous backups remain readable.
Settings → Security options
AES-256 EncryptionRecommended

Encrypts your backup data with AES-256-GCM before being sent to storage.

EnabledYour next backups will be end-to-end encrypted
4
Bring Your Own Bucket

Use your own S3-compatible storage

Want full data sovereignty? Point CYBBACK at your S3-compatible bucket — AWS S3, Scaleway, OVH, Wasabi, MinIO, Backblaze B2, IBM COS. Your data, your provider, your region.

Provision the bucket

  1. In your S3 provider, create a private bucket (no public access, versioning recommended).
  2. Create an access key / secret key with permissions limited to that bucket.
  3. Note your endpoint URL and region.

Configure CYBBACK

  1. Open Dashboard → Storage.
  2. Select My own S3 storage.
  3. Fill the form, click Test connection, then Save.
Dashboard → Storage
S3 ConfigurationEncrypted at rest
 
Test before saving

Always click Test connection first. CYBBACK writes & deletes a probe file to validate credentials, region and permissions.

5
First backup

Run your first backup

You're now fully configured. Time to run your first Entra ID backup — manually for instant peace of mind, then schedule recurring runs.

Manual backup

  1. Go back to the Dashboard tab on the Entra ID page.
  2. Click Run backup now. The job appears with status pending, then running.
  3. Progress is streamed live: object types fetched, items captured, manifest written.

Schedule automatic backups

  1. From Dashboard → Schedules, click New schedule.
  2. Service: Microsoft Entra ID. Frequency: Daily / Weekly / Custom (cron).
  3. Pick a time window (e.g. 02:00 UTC) and click Save.
Incremental forever

The first backup is a full snapshot. Every subsequent backup uses Microsoft Graph delta queries — typically completing in under 60 seconds, even for large tenants.

Track your backups

6
Restore

Restore — recycle bin first, recreate beyond

CYBBACK uses a hybrid restore strategy unique to Entra ID: deleted objects under 30 days old are restored from Microsoft's native recycle bin (preserving SIDs and references); older objects are recreated from the backup with full attribute fidelity.

The 3-step restore flow

  1. Selection. Open the backup, browse the 23 object types (Users, Groups, Applications, Policies…), tick what you want to recover. Search by displayName or UPN.
  2. Options. Choose your safety net:
    • Dry-run — simulate, no Graph write.
    • Overwrite — re-apply backed-up attributes on existing objects.
    • Target tenant — restore into a different Entra tenant (provide its tenantId / clientId / clientSecret).
  3. Execution. A worker picks up the job, restores in the background, reports progress in real-time. You can close the tab — completion is emailed.
Dashboard → Entra ID → Restore
1. Selection
2. Options
3. Execution
Restore options147 users · 23 groups selected
Dry-runSimulate without writing to Entra
Overwrite existing objectsRe-apply backed-up attributes
Target alternate tenantCross-tenant restore (M&A scenarios)
 

Best practices

What can't be restored

Passwords, MFA secrets and certificate-based credentials are not recoverable — Microsoft never exposes them via Graph. Recreated users will need to reset their password and re-enroll MFA.

You're all set.

Need help? Our team replies within one business day on every plan.

Contact support →