Support Article — Entra ID Backup: Which User Attributes Are Included

 

Overview

Nexetic Backup for Entra ID backs up a defined, maintained set of user profile fields — not every field theoretically available through Microsoft's platform. This article lists what is included, what is intentionally excluded, and why, so you know exactly what to expect when evaluating or restoring user data.
 

What is included

The following categories of user information are captured on every backup run:

  • Core identity — display name, username (UPN), primary email, mail nickname, job title, department, company name, office location
  • Contact details — phone numbers, alternate email addresses, postal address fields, preferred language and locale
  • Employment metadata — employee ID, hire date, employee type, and related organizational fields
  • Account and security state — account enabled/disabled, password policy settings, last password change date, sign-in session validity, security identifier
  • Licensing — licenses assigned to the user and their assignment status
  • Hybrid identity (on-premises sync) — sync identifiers, sync status, and any sync errors reported by Microsoft, for organizations using hybrid Active Directory
  • Minor/consent-related fields and custom security attributes, where an organization uses them

Group memberships and directory role assignments for each user are backed up as well, through a separate mechanism dedicated to relationships — so access rights can be restored alongside the user.
 

What is not included

  • Profile photo is not backed up.
  • Manager assignment (the reporting-line relationship) is not currently captured as part of user backup.
  • Guest / external accounts are excluded by default. This can be enabled per organization on request if guest accounts need to be covered.
  • Passwords or password hashes are never included. This isn't a limitation specific to Nexetic — no backup vendor can retrieve them, because Microsoft does not expose them through any interface, for any provider.
     

Why a defined list instead of "everything"

Backing up a fixed, curated set of fields keeps backups predictable, fast, and consistent to restore. When Microsoft introduces new user attributes, they are evaluated and added deliberately rather than picked up automatically — this avoids unreviewed or low-value data silently entering backups.

 

Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more