How to restore Groups from Entra ID backup

Step 1. Sign into the backup portal

Open your web browser and go to the following address: https://shield-cloud.nexetic.com/
Select Sign in with Microsoft 365. Insert your Microsoft 365 admin credentials for the tenant you want to restore data from.

entraid-signin-new.png

Resellers can also sign in via Nexetic Portal.

Step 2. Select Backup for Entra ID

EntraID-select-menu.png

Click the icon in the top-left corner of the page and select Backup for Entra ID.

 

Step 3. Select Groups page

Click Groups in the top navigation. You can see the list of all groups that have been backed up from the customer's Entra ID tenant.

entraid-groups-restore-new.png

Step 4. Locate the group(s)

You can sort the groups by their Name, Object id or Last modification date. You can also filter the groups by typing any part of the group name in the Search box.

entraid-groups-search.png

Step 5. Select the groups

You can restore all groups, selected groups or just a single group. When you click any group's name, you can view attributes, members, memberships and role assignments that have been backed up for the selected group. Check Step 6 of this support article for more info about group's details in backup.


OPTION A: Select all groups

You can select all groups to be restored at once by checking the box in the top-left corner of the group grid. All groups in the Entra ID tenant get selected - not just the ones displayed on the current page.

Click the Restore selected button.

Next proceed to Step 7 of this support article to see how to select the restore options.

entraid-groups-select-all2.png

OPTION B: Select multiple groups

Select single groups to be restored by checking the boxes next to each group's name.

Click the Restore selected button.

Next proceed to Step 7 of this support article to see how to select the restore options.

entraid-groups-select2.png

OPTION C: Select and view attributes for a single group

You may want to see more details for a user, such as user's group memberships and admin role assignments. Sometimes it may also be helpful to view and compare the object versions between different dates.

Review Step 6. below to learn more.

 

Step 6. View the group attributes and versions

Select the group by clicking the group name. You can see all the attributes that exist for the selected group. Note that you may need scroll down to see the full attributes list.

The latest version from backup is always displayed by default. You can click the arrows to browse the different time points / version dates for the object. The version from the selected time point is always displayed. Red font indicates a changed value for that attribute; i.e. object attributes marked with red font are changed in this version from the previous version.

entraid-groups-changed-attribute.png

If you already know which date's version you want to restore, you can proceed by clicking Restore this version.

There are three links: View members, View memberships, and View role assignments. From there you can see the member list for the group, group memberships as well as the admin role assignments for the group.

entraid-groups-objects2.png

Step 6.1. View group members

By clicking View members, you can see the members in the group. You can filter the Members list view by date. You can select any day and time from the calendar to view the list of group members as it was on the selected time point. If the Member list is empty, there were no users in the group at the selected time.

Changes to the memberships are recorded in Members log. From there you can detect the timing of the changes, which will help you to choose the correct version date & time from the calendar.

You can proceed to start the restoration by clicking Restore this version (you may need to scroll down to see the Restore button)

entraid-groups-members.png

Step 6.2. View memberships

By clicking View memberships, you can see the memberships that the group has. You can also filter the Membership list view by date and time. You can select any day and time from the calendar to view the version of the selected time point. If the Membership list is empty, there were group memberships for the selected group at the selected time.

Changes to the memberships are recorded in Membership log. From there you can detect the timing of the changes, which will help you to choose the correct version date & time from the calendar.

You can proceed to start the restoration by clicking Restore this version.

entraid-memberships-list.png

Step 6.3. View role assignments

By clicking View role assignments, you can see the admin roles that have been assigned for the group. You can select any day and time from the calendar to view the role assignments for the group at that time.

Changes to the role assignments are recorded in Role assignments log.

You can proceed to start the restoration from this window, too, by clicking Restore this version.

entraid-groups-role-assignments.png

Step 7. Select restore options

Select the snapshot date & time from the calendar. You can still change the date & time even if you already chose them on any of the previous screens.

Make your choices for the following options:

  • To restore the group with it's attributes, current name and object ID, choose With object. If the group doesn't exist in Entra ID, it will be recreated. If the group already exists in Entra ID, the existing group will be overwritten.
    • If you don't select 'With object', you can still restore members, memberships and role assignments to the already existing group.
  • If you select As new, a new group with a new name and object ID is created during the restore process. You need to input a name for the object that will be created. If you don't select 'As new', the restoration target is the already existing group in Entra ID.
    • NOTE: The 'RESTORE AS NEW' OPTION IS NOT AVAILABLE WHEN YOU RESTORE MULTIPLE GROUPS AT A TIME. If you restore multiple groups at a time and a group already exists in Entra ID, it will be overwritten. If the group doesn't exist, a new group will be created with the same name and object ID that it was backed up with. 
  • If you want to restore members belonging to the group, select With members.
  • If you want to restore the group in it's group hierarchy (in case of nested groups), select With memberships.
  • If you want to restore admin role assignments for the group, select With role assignments.
  • If you want to restore the objects to another Entra ID tenant, select To another tenant.
    • First you need to add the target tenant where you want to restore the data to - check the instruction.
    • Now you can see the existing target tenant(s) in the 'To another tenant' drop-down menu - in case of having multiple target tenants added, select the one you want to restore the data to.
    • The available domain names for the selected target tenant can be seen under the 'With domain' menu and you can select the domain from there. Screenshots can be found from the above mentioned support article.

entraid-groups-restore-options3.png

For example, if you want to recreate the group in Entra ID with the existing group name and object ID, with all it's attributes, in the correct group hierarchy, with members and role assignments, tick the boxes 'With object', 'With members', 'With memberships' ja 'With role assignments'.

If you want to restore missing group members, group hierarchy and admin role assignments for the already existing group, tick the boxes 'With members', 'With memberships' and 'With role assignments'. 

Once you have selected the options, start the restoration by clicking Restore.

Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more