Skip to content
PagesEIDGuard documentation

EIDGuard docs

On this page

EIDGuard documentation

EIDGuard is backup and restore for Microsoft Entra External ID (CIAM) tenants. There is no first-party backup for External ID; EIDGuard exports each tenant's configuration — users, groups, applications, identity providers, user flows, conditional access, branding and more — to versioned recovery points in your own Azure storage, verifies them against the live tenant on a schedule, and restores selectively when you need to.

It is delivered only through the Azure Marketplace, as a solution template that deploys into a resource group you own. Everything runs in your Azure subscription; the publisher never holds your data or your credentials. Your entitlement (which plan, how many tenants) comes from the accompanying SaaS subscription — see Activating your subscription.

Start here#

  1. Deploy from the marketplace into a new, empty resource group — uninstalling is deleting that group, after the short procedure in Before you delete the deployment (offboard the tenants, let the newest recovery point leave its immutable window).
  2. Run the Setup Wizard in the browser to turn on sign-in for the deployment, then onboard your first External ID tenant: Setup wizard walkthrough.
  3. Operate from the dashboard — backups, recovery points, restores, verification, certificate rotation, export: Web UI.

Reference#

Page What it answers
Setup wizard walkthrough First run, per-tenant onboarding, what gets created in your tenants
Web UI Every dashboard page and operation
Backing up multiple External ID tenants One deployment, several protected tenants
Plans and tenant limits What a plan counts, what happens at the limit, what survives an upgrade, what happens before you delete the deployment
Permission matrix Every Graph and Azure permission, who holds it and why
Monitoring and alerting The alert rules, the audit trail, what each email means
Private endpoints and Hybrid Worker Running with Key Vault and storage off the public internet
Outbound connectivity and firewall requirements Exactly what must be reachable, by which component, and the symptom when it is not
Deployment troubleshooting Deployment-time errors and their fixes
Activating your subscription What happens after you subscribe, and where to go next

Support#

Questions about your subscription or plan: sales@vambris.com.