Considerations and Limitations

When you plan to deploy and configure Veeam Backup for Microsoft Entra ID, keep in mind the following limitations and considerations.

Backup Proxies

When managing general-purpose backup proxies, consider the following:

  • During Veeam Backup & Replication installation, a default general-purpose backup proxy is automatically added to the backup infrastructure. Do not remove or disable this proxy — otherwise, you will not be able to protect Microsoft Entra ID tenants and their logs.

Backup Repositories

When connecting a remote Microsoft Entra ID backup repository to the backup infrastructure, consider the following:

  • The repository must run PostgreSQL version 14 or later.
  • Veeam Backup for Microsoft Entra ID supports connecting one remote Microsoft Entra ID backup repository only.
  • Veeam Backup for Microsoft Entra ID supports PostgreSQL password authentication only.

Tenant Backup and Restore

  • Veeam Backup for Microsoft Entra ID does not support backup of Microsoft Entra ID tenants located in China, Azure Government tenants, external tenants or Azure Active Directory B2C tenants.
  • You cannot protect multiple tenants by one backup job. Also, you cannot protect the same tenant by multiple backup jobs.
  • Veeam Backup for Microsoft Entra ID does not support restore of Microsoft Entra built-in roles, distribution security groups or mail-enabled security groups.
  • By default, Veeam Backup for Microsoft Entra ID does not back up relationships between items of protected Microsoft Entra ID tenants and Azure management groups. To back up these relationships, you must perform additional configuration steps described in this Veeam KB article.
  • You cannot restore more than 1000 tenant items during one restore session. Also, you cannot restore different item types simultaneously.
  • You can restore a service principal that represents an application only together with this application and during one restore session. If you restore the application and the principal separately, the restored application gets a new ID assigned, and the restore of the service principal will fail.
  • Veeam Backup for Microsoft Entra ID supports restore of Hybrid identity users — to learn how to restore these users, see Restoring Synchronized Users (Hybrid Identity).
  • Veeam Backup for Microsoft Entra ID does not support restore of device configuration profiles of the editionUpgradeConfiguration resource type using application permissions — these profiles can be restored using delegated permissions only. Also, the License and the ProductKey properties are restored to their predefined placeholder values; after restore, these properties must be updated in the Intune Admin Center manually.

Log Backup and Restore

  • Veeam Backup for Microsoft Entra ID does not support storing backed-up sign-in and audit logs in multi-bucket repositories. For more information, see section Object Storage Repository.
  • Veeam Backup for Microsoft Entra ID does not support backup of sign-in logs with a free Microsoft Entra ID license.
  • To create a log backup, you must first back up the tenant whose logs you want to protect; keep in mind that the latest restore point of the tenant backup must be created within 30 days before the log backup.

Page updated 3/31/2026

Page content applies to build 13.0.1.2067