Identity Protection

Microsoft Active Directory

Active Directory is the identity backbone of the enterprise. When a cyberattack or catastrophic failure compromises the Active Directory Forest, every authentication-dependent service goes with it, and the complexity of manual forest recovery has historically made this one of the most feared and time-consuming incidents an IT team can face. Microsoft lists over 40 manual steps in the process. Veeam eliminates that complexity entirely.

Automated Active Directory Forest Recovery — Automated recovery of an entire Active Directory forest is now available through a guided recovery wizard that walks administrators through each step of the restoration process, including selecting the recovery point, defining domain controllers for every domain, choosing source backups, and configuring target settings. By combining Active Directory–specific recovery intelligence with a familiar VM restore workflow, the solution minimizes complexity and helps reduce operational risk during critical recovery scenarios.

During backup operations, a guest component automatically collects and preserves Active Directory forest metadata, ensuring that all information required for a successful forest rebuild is readily available when needed. The recovery process then orchestrates VM restoration and all required post-recovery activities automatically, bringing identity services back online with minimal administrative effort and no manual recovery steps.

This release supports recovery to both VMware vSphere and Microsoft Hyper-V environments and covers single-domain, multi-domain, and multi-tree Active Directory forests. Available with paid Veeam Universal License editions (Essentials, Advanced, and Premium), this capability transforms forest-level recovery from a complex, expert-driven operation into a repeatable and guided process that can be executed with confidence by trained administrators.

Microsoft Entra ID

Restoring Microsoft Entra ID has never been more complete — this release preserves and reconstructs complex object relationships automatically, eliminates manual reconfiguration after restore, and extends protection to previously uncovered object types including Organization Contacts, device objects, and BitLocker recovery keys. Administrators gain precise, context-aware recovery across the full identity directory, with JSON export providing a reliable audit and recovery path for every protected object regardless of platform restore limitations.

Persistent original ID — Restoring Entra ID objects could result in new identifiers being assigned, breaking relationships between complex objects. With this release, such relationships are preserved and reconstructed during restore operations: the system now identifies object references and automatically re-links them - either directly when the original ID is retained, or by matching against previously stored IDs when objects are recreated. This capability eliminates the need for manual reconfiguration, reducing the risk of incomplete restores, preventing security gaps, and accelerating recovery of complex identity environments.

Export to JSON — A new restore option is now introduced allowing administrators to export any protected directory object, including users, groups, and other objects, to a JSON file. Each export captures all object properties, relationships, and the exact schema version as it existed at the time of backup, with no conversion of older restore points.

Organization Contacts — Entra ID now protects Organization Contacts, a directory object type managed by administrators and synchronized from on-premises directories or Exchange Online. Although these contacts are read-only in Microsoft Graph, they are now fully covered by backup, including delta backups to capture incremental changes efficiently and all standard comparison methods for the object so administrators can review and analyze changes across restore points.

Add public key during application restore — Some object properties, such as certificates or license keys, are stored encrypted in the backup or cannot be protected at all due to platform limitations, which previously prevented them from being fully restored. Entra ID now supports context-aware restore that detects when an object requires supplementary information and prompts for it through the restore wizard, applying the supplied data precisely where needed as the object is recreated. For application restores, this means the wizard can pre-fill the public key, allowing administrators to provide the certificate or key inline and complete the restore without manual post-restore steps.

Devices and BitLocker Keys — with v13.1 users now can protect device objects alongside their associated BitLocker recovery keys. Because device objects cannot be restored back into Entra ID, this scenario centers on review and export: administrators can view device metadata, most importantly the Intune policy a device is assigned to and access the underlying data through JSON export. BitLocker keys can be viewed and copied directly, and device metadata can be exported to JSON, giving administrators the visibility and recovery information they need without a full object restore.

RBAC Support — For Entra ID now applies a role-based access control (RBAC) permission model to Entra ID backup and restore operations. Administrators can grant granular, role-scoped permissions that govern who can configure and run backup jobs and perform restores, ensuring that each operation is carried out only by appropriately authorized users and aligning Entra ID data protection with least-privilege access practices.