Your first secured Entra ID backup in under 10 minutes.
From sign-up to a fully encrypted, restorable snapshot of your Entra tenant — this guide walks you through every step, with screenshots and best practices.
Fill in your work email, company and a password. Click Start free trial.
Confirm via the verification email.
On the trial selection screen, pick Microsoft Entra ID. Your trial workspace is provisioned instantly.
Painless onboarding
Trial accounts get the full Entra ID feature set — encryption, BYOB, scheduling, cross-tenant restore. Switch to a paid plan at any moment without losing data.
Option B — Paid licence (Stripe checkout)
Go to cybback.com/tarifs and pick the Entra ID plan that matches your tenant size.
Click Subscribe. Stripe Checkout supports cards, SEPA and invoicing on annual plans.
Your licence is active immediately — visible under Account → Subscription.
2
Connect Entra ID
Register the CYBBACK application
CYBBACK authenticates against Microsoft Graph using a dedicated app registration with the minimum required permissions. This takes 5 minutes in the Azure portal.
Paste Tenant ID, Client ID, Client Secret. Click Save credentials.
CYBBACK runs an authentication test. Green badge = ready.
app.cybback.com/dashboard/entra-backup
Dashboard
Settings
Entra ID credentialsEncrypted at rest
Paste your tenant ID, application (client) ID and client secret.
Track secret expiration
Set a calendar reminder one month before your client secret expires. Backups will start failing silently if the secret is rotated without updating CYBBACK.
3
Encryption at rest
Enable AES-256-GCM encryption
Backup files are stored on CYBBACK's secure EU infrastructure by default. Add a second layer with client-side encryption: each file is encrypted before it leaves the worker.
On the Settings tab of the Entra ID page, scroll to Security options.
Toggle AES-256 Encryption ON.
Click Save. Applies to new backups; previous backups remain readable.
Settings → Security options
AES-256 EncryptionRecommended
Encrypts your backup data with AES-256-GCM before being sent to storage.
EnabledYour next backups will be end-to-end encrypted
4
Bring Your Own Bucket
Use your own S3-compatible storage
Want full data sovereignty? Point CYBBACK at your S3-compatible bucket — AWS S3, Scaleway, OVH, Wasabi, MinIO, Backblaze B2, IBM COS. Your data, your provider, your region.
Provision the bucket
In your S3 provider, create a private bucket (no public access, versioning recommended).
Create an access key / secret key with permissions limited to that bucket.
Pick a time window (e.g. 02:00 UTC) and click Save.
Incremental forever
The first backup is a full snapshot. Every subsequent backup uses Microsoft Graph delta queries — typically completing in under 60 seconds, even for large tenants.
Track your backups
Real-time: the Events page streams every operation across all services via SSE.
Notifications: success / failure / drift alerts via email, Slack and webhooks.
Drift detection: alerts when an unusual number of users, groups or apps disappear between two runs — perfect to catch accidental mass deletions.
6
Restore
Restore — recycle bin first, recreate beyond
CYBBACK uses a hybrid restore strategy unique to Entra ID: deleted objects under 30 days old are restored from Microsoft's native recycle bin (preserving SIDs and references); older objects are recreated from the backup with full attribute fidelity.
The 3-step restore flow
Selection. Open the backup, browse the 23 object types (Users, Groups, Applications, Policies…), tick what you want to recover. Search by displayName or UPN.
Options. Choose your safety net:
Dry-run — simulate, no Graph write.
Overwrite — re-apply backed-up attributes on existing objects.
Target tenant — restore into a different Entra tenant (provide its tenantId / clientId / clientSecret).
Execution. A worker picks up the job, restores in the background, reports progress in real-time. You can close the tab — completion is emailed.
Always start with a dry-run — especially in production tenants.
Restore users early. Group memberships, role assignments and license bindings depend on user objects existing first. CYBBACK orders the restore queue automatically.
Cross-tenant restore requires an app registration with admin-consented permissions in the target tenant.
What can't be restored
Passwords, MFA secrets and certificate-based credentials are not recoverable — Microsoft never exposes them via Graph. Recreated users will need to reset their password and re-enroll MFA.
You're all set.
Need help? Our team replies within one business day on every plan.