Cayosoft has been named a Representative Vendor in Gartner’s Market Guide for SaaS Backup, recognized for Microsoft Entra ID.
For years, moving a workload to cloud solutions like Microsoft 365 came with an implicit assumption: the provider runs the service, so the provider must also be responsible for getting data back after it’s deleted, corrupted, or encrypted. That assumption has shaped how many organizations planned — or didn’t plan — their SaaS backup strategy, often without documented ownership of retention, recovery testing, or restore scope.
Gartner states:
“Organizations are identifying gaps in SaaS data protection and recoverability due to limited native recovery features and rising data loss risks.”
The shared responsibility gap for Entra ID Backup and Recovery
Gartner defines the shared responsibility split plainly: “Under the shared responsibility model, SaaS providers are primarily responsible for service availability, while customers remain responsible for data protection and recovery. Native recovery capabilities are typically limited in retention, scope and control, creating gaps in recovery scenarios such as ransomware, large-scale deletion, misconfiguration and compliance-driven requests.”
For identity and IT teams managing Microsoft 365 and Microsoft Entra ID, that gap is already familiar. Entra ID sits underneath every other Microsoft 365 service — Exchange Online, Teams, and SharePoint all depend on it to authenticate and authorize access. When a privileged role assignment changes, a Conditional Access policy is altered, or an object is deleted, most native tools surface the change after the fact, and often make it difficult to undo it.
That gap has concrete costs. This is why, according to Gartner, organizations choose to implement SaaS backup technologies: “Their primary purpose is to enable recovery from data loss scenarios such as accidental deletion, corruption and malicious activity.”
For Entra ID, each of these failure modes plays out in ways that are easy to recognize and hard to walk back:
Scenario | Consequence |
A user or group is accidentally deleted | Entra ID’s Recycle Bin only covers a limited set of object types for 30 days. Recreating the object instead of restoring it assigns a new object ID, which silently breaks any Conditional Access scope, app role assignment, or PIM role eligibility tied to the original — with no alert raised. (Cayosoft: Recovery of hard-deleted Entra ID objects) |
A Conditional Access policy is misconfigured, or a break-glass exclusion is removed | MFA can be silently disabled tenant-wide for every admin, or the entire tenant can be locked out — native audit logs record only “policy updated,” without before/after values, and retain that for 30 days by default. (Cayosoft: Conditional Access policy best practices) |
A scripting error or directory sync misconfiguration triggers a bulk deletion affecting hundreds or thousands of objects at once | Native recovery tools are built to restore one object at a time; working through an incident at that scale manually extends recovery time well past what the business can tolerate. |
Native recovery in every case depends on catching the change within a fixed retention window, using tools that record that something changed but not what it was or how to undo it.
Where Cayosoft Guardian fits
Cayosoft Guardian is built for this layer with real-time monitoring and Entra ID backup and recovery, including visibility into changes across Active Directory, Teams, Intune, and Exchange Online.
Feature | Description |
Backup via provider-supported APIs | Continuously captures Entra ID object, attribute, and policy state through Microsoft Graph API, without agents or scheduled jobs. |
Recovery from data loss scenarios (deletion, corruption, misconfiguration, malicious activity) | One-click rollback restores a deleted or altered user, group, attribute, or policy to its last known-good state. |
Granular, object-level recovery | Recovery operates at the individual object or attribute level — a single group membership or policy field, not the whole tenant. |
Retention aligned to compliance requirements | Change history is retained continuously, beyond Entra ID’s fixed 30-day native window, and configurable to the organization’s compliance needs. |
Point-in-time recovery to a known-good state | Because state is captured continuously rather than on a backup schedule, rollback targets the moment immediately before a specific unwanted change. |
Centralized configuration, monitoring, and reporting | A single console monitors changes, manages rollback, and reports on recovery activity — extending to on-premises Active Directory for organizations running hybrid environments. |
Immutable storage and access controls | Change history and audit logs are stored securely, with role-based access controls governing who can view or act on them. |
SaaS backup is becoming a standard requirement
Today, more and more organizations are moving toward treating SaaS backup as a standard, planned-for requirement rather than an assumption resolved by the provider. For Entra ID backup and recovery specifically, that requirement extends beyond object recovery to the policies and role assignments that determine who can access what — changes native tools were never built to roll back. Closing that gap is what Cayosoft Guardian is built to do.
The full Gartner Market Guide for SaaS Backup is available through Gartner subscription access. [Read full report]
Where native recovery stops
Entra’s soft-delete is effective for accidental deletions caught within the 30-day window. Soft-deleted objects restore with their original objectId and all their relationships remain intact.
Hard-deleted objects fall outside that window. Once purged, Entra has no recovery path, and any recreation produces a new objectId. The relationship restoration that Guardian provides is specific to this scenario: recovery of objects that Entra cannot restore natively, combined with automatic repair of the access configuration that referenced them.
Conclusion
Hard-deleted Entra ID objects have always required more than just recreation. The object comes back, but the access control configuration — Conditional Access policies, application role assignments, PIM assignments — still points at an objectId that no longer exists. Finding and repairing those references has been manual work, and in environments with mature identity configurations, it adds up quickly.
Guardian now handles that repair as part of the restore. The object and its relationships are brought back together, and the access configuration reflects the intended state without a separate audit step.
Gartner, Market Guide for SaaS Backup, Sankalp Rastogi, 1 June 2026.
GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
FAQs
No. Only users, Microsoft 365 groups, cloud security groups, and applications support soft delete and land in the Recycle Bin. Every other object type is hard deleted the moment it’s removed, with no recovery path at all, it has to be manually re-created and reconfigured from scratch.
Yes. Recovery operates at the individual object or attribute level, so a specific policy field can be rolled back to its last known-good state without affecting the rest of the tenant.
Yes. Guardian’s console monitors and manages recovery for Entra ID and extends to on-premises Active Directory for organizations running hybrid identity infrastructure.
See Cayosoft in Action
Cayosoft is recognized by Gartner as an ITDR solution provider and provides solutions that make identities more resilient to attacks and guarantee a fast forest recovery, if needed. Learn how Cayosoft Guardian facilitates granular change tracking, post-breach analysis, and long-term AD security improvements. Schedule a demo to see the capabilities in depth.