Datto Backup for Microsoft Entra ID – July 2026

New Features

Export

You can now export your Microsoft Entra data from Datto backups.
Read Entra export for details.

Enhancements

Support for additional policy types and named locations

This release expands the scope of Entra backup with support for new Microsoft Entra policy types and named locations, providing broader coverage and more complete protection of your identity and access management configuration.
Read What is backed up with Datto Backup for Microsoft Entra ID for the full list of protected object types.

Conditional access policies

Entra backup now captures, protects, and restores your conditional access policies, authentication strength, and conditional access context.
These policies are critical to your zero-trust security posture, controlling how and when users can access resources based on identity signals, device state, location, and risk levels.
Read Conditional access policies for the properties captured in backup.

Authentication methods policy

The authentication methods policy, which governs which authentication methods are available tenant-wide (such as FIDO2, Microsoft Authenticator, and Temporary Access Pass), is now included in backup coverage.
Restore support is also included for authentication methods policy configurations.
In addition, granular per-method configuration settings are now backed up individually, ensuring detailed recovery fidelity for each authentication method.
Read Authentication methods configuration for the properties captured in backup.

Named locations

Backup, export, and restore are now supported for Country-based and IP Range Named Locations.

Custom security attributes

Backup and export are now supported for attribute sets and custom security attribute definitions.

Notes and considerations

  • Sufficient Microsoft Graph API permissions are required to back up Conditional Access policies and Authentication Methods resources.
    Ensure your service principal has the Policy.Read.All and Policy.ReadWrite.AuthenticationMethod permissions as appropriate.
  • Existing backup schedules will automatically include the new resource types from this release onward.
    No reconfiguration is needed.