Let’s face it, user errors are a reality, and the threat of malicious actors breaching Active Directory –both on-premises and in Azure – is on the rise. Protecting your data has never been more important, yet no native tooling exists to tracks changes, store previous values or enable administrators to rollback those changes immediately.
Microsoft provides limited tools to recover a deleted user account, but what about when an AD object is changed? Restoring the object and associated permissions, groups, roles and applications can be a manual, expensive and error-prone process.
As Microsoft MVP Brien Posey outlined recently in his paper there are four items related to Recycle Bins that are critical for IT teams to understand if they want to avoid Azure AD outages, or at least to fix them before they impact end users.
-
Microsoft Won’t Restore Your AD Directory Data
-
The Active Directory Recycle Bin Only Protects Against Deletions
-
The Recycle Bin Won’t Always Protect You Against Accidental Deletions
-
Not All Object Types Are Protected