Building on our AD rollback and automated forest recovery foundation, this release adds Entra ID support, Azure backup storage, built-in localization, and key usability upgrades like Dark Mode, making recovery faster, more flexible, and easier than ever.
What’s New in Netwrix Recovery for AD 3.0?
Entra ID Rollback
Seamlessly restore Entra ID configurations, ensuring uninterrupted operations in hybrid and cloud-native AD environments.
Expand this section to see how Entra ID object rollback works
Rollback operations are object-level and attribute-specific. The process ensures minimal disruption by targeting only the modified parts of an object, such as changed group membership or deleted application assignments.
Step-by-step:
-
Select Object:
From the Entra ID dashboard, select a backed-up object (e.g., a user) and click Rollback.
-
Choose Attributes to Restore:
The rollback wizard allows you to restore all attributes or only those that have changed.
-
Confirm and Execute:
Review your selection, confirm, and execute. A success message appears when complete.
-
A completed message is displayed when the rollback is successful. Click OK. The object has been rolled back.
Note: Before you can collect and roll back Entra ID objects, you must register an app in Entra ID and assign it the appropriate permissions:
-
Navigate to App registrations in Azure Portal.
-
Enter a user-facing name for the application. Under “Supported account types”, select the option that describes your organization. In this example, we selected “Accounts in this organization only - Single tenant”. Click Register when done. You are taken to /App registrations/[your app] page.
-
Click Manage and select API permissions. Click Add a permission. On the right side, the Request API permissions window opens. Click Microsoft Graph.
-
Register a new app and assign the following Microsoft Graph application permissions:
AdministrativeUnit.ReadWrite.All
Application.ReadWrite.OwnedBy
Directory.Read.All
,Directory.ReadWrite.All
Group.ReadWrite.All
User.DeleteRestore.All
-
Finally, grant admin consent for the tenant to enable read and write data, which allows you to rollback and restore Microsoft Entra ID objects.
Secure Azure Storage of Backups
Store Domain Controller (DC) backups to enable forest-level recovery in Azure using customizable protection models to enhance data security.
Localization Support
Support for English, French, Spanish, and German out of the box—making it easier to deploy and operate the product globally. Customization options extend support to additional languages.
Interactive Dashboard with Drill-down Recovery Insights
A new home page dashboard introduces four real-time widgets providing high-level visibility into backup activity and directory object counts. The Active Directory and Entra ID object widgets support interactive exploration and rollback initiation, while all widgets allow drill-down into detailed backup metrics.
Expand to learn more about the new interactive dashboard and its functionality
The Dashboard is accessible from the left navigation pane (Home) and displays four draggable, customizable cards:
1. Active Directory Object Count
- Shows total AD objects collected(backed up) in Recovery for Active Directory across all domains.
- By default, the pie chart displays the five most common object types(computer, OU, GPO, group, user).
- Each slice on the pie chart represents an object type in a distinct color and displays the total number of objects for that type.
- A slice also represents the share of an object type relative to the others in the pie chart.
- The key maps the colors used in the pie chart to an object type. You can hover over a slice to view the name of the object type it represents.
Add/Remove Object Types from the Pie Chart:
Click the gear icon to add or remove object types from the pie chart.
View object details:
Click an object type in the pie chart or the key to view details about the objects for that type. The Active Directory Metric Details - page is displayed.
This page has the following elements:
-
Bar chart
Displays the number of objects collected for the specific object type (e.g., users).- Each bar represents a domain.
- Hover your mouse over a bar to view the exact number of collected objects.
-
Lower pane
When you click a bar in the chart, the lower pane displays:- Object name
- Distinguished name (full Active Directory path)
- Object type
- Backup time
Note: The distinguished name represents the object’s full path in the Active Directory hierarchy and helps locate it in the domain tree.
-
Search field
Enter a text string to filter the object list and display matching results. -
Pagination options
Choose how many results to show per page:- 10 (default)
- 25
- 50
Use navigation arrows to move between pages.
-
Rollback function
Select an object and click Rollback to launch the Object Rollback wizard.
See the Rollback Objects topic (starting at Step 4) for guided steps.
2. Microsoft Entra ID Object Count
- Aggregates object counts from all Entra tenants.
- By default, the pie chart displays the three most common object types (users, devices, and groups).
- Each slice on the pie chart represents an object type in a distinct color and displays the total number of objects for that type.
- A slice also represents the share of an object type relative to the others in the pie chart.
- The key maps the colors used in the pie chart to an object type. You can hover over a slice to view the name of the object type it represents.
Add/Remove Object Types from the Pie Chart:
Click the gear icon to add or remove object types from the pie chart
View Object Details
Click an object type in the pie chart or the key to view details about the objects for that type. The Entra Metric Details page is displayed.
This page has the following elements:
-
Bar chart
Displays the number of objects collected for the specific object type (e.g., users).- Each bar represents a tenant.
- Hover your mouse over a bar to view the exact number of objects collected.
-
Lower pane
When you click a bar in the chart, the lower pane shows:- Object name
- Object type
- Backup time
-
Search field
Enter a string to filter the list and show only objects matching the search text. -
Pagination options
Select how many items to display per page:- 10 (default)
- 25
- 50
Use the navigation arrows at the bottom to move through pages of results.
-
Rollback function
Click the object you want to roll back, then click Rollback to launch the Object Rollback wizard.
See the Rollback Objects topic for full instructions.
3. Domain Collections
This card uses a bar graph to display information about the backup collections performed for Active Directory domains configured in Recovery for Active Directory.
- Visualization
- Each bar in the chart represents a domain.
- Blue bars indicate successful collections.
- Red bars indicate failed collections.
- Hover over a bar to view the exact number of successful or failed attempts.
Domain collections are a backup of all objects and their attributes in a domain, facilitating you to perform object rollback and restore operations in Recovery for Active Directory.
- Set Time Range
- Click the gear icon in the card header.
-
In the Time Range window, use the arrows or manually enter the number of days (default is 7).
-
Click Save to apply the selected time range to the chart.
-
View Object Details
- Click on a bar to view detailed information about the collection activity for that domain.
- This opens the Domain Collection Details page.
Domain Collection Details Page
This page includes:
-
Bar chart
- Each bar represents the number of objects collected on a specific day.
- Hover over a bar to see the exact object count collected by the job.
-
Lower pane
- Displays additional information about each backup job:
- Date and time the job ran
- Duration of the collection process
- Job status (success or failure)
- Total number of objects collected (backed up)
- Displays additional information about each backup job:
4. Server Backups
This card uses a bar graph to display information about the number of backup collections performed for domain controllers in the forest(s) configured in Recovery for Active Directory.
-
Visualization
- Each bar represents a domain controller.
- Blue bars indicate successful backups.
- Red bars indicate failed backups.
- Hover over a bar to view the exact number of successes or failures.
-
Set Time Range
- Click the gear icon in the card header.
-
In the Time Range window, use the arrows or manually enter the number of days to display (default is 7).
-
Click Save to update the chart.
-
View Backup Details
- Click a bar to open the Server Backup Details page for the selected domain controller.
- Click a bar to open the Server Backup Details page for the selected domain controller.
Server Backup Details Page
This page contains:
-
Bar chart
- Each bar shows the number of backup collections on a specific day.
- Hover over a bar to view the exact number of successful or failed collections.
-
Lower pane
- Displays detailed information about each collection job:
- Date and time the backup ran
- Duration of the collection
- Job status (success or failure)
- Total size of the backup
- Displays detailed information about each collection job:
Usability enhancements
Dark Mode
The feature provides enhanced usability, enabling teams to work efficiently in low-light environments.
UI Improvements
Simplified workflows and intuitive design improvements to streamline recovery processes.
Need help with this update?
There are many different ways to get help with our products!
Situation | Action |
---|---|
If you feel the product is broken and not working as intended… | Contact Support |
If you have a question you’d like to ask other experts… | Create a discussion in the community: Recovery for Active Directory > Discussions & Questions |
If you have a feature request… | Let our product team know directly: Recovery for Active Directory > Ideas |
If you have something cool to show… | Show everyone what you built: Recovery for Active Directory > Show & Tell |
What are your thoughts?
We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!