Chat now with support
Chat with Support

Welcome, Quadrotech customers to Quest Support Portal click here for for frequently asked questions regarding servicing your supported assets.

On Demand Recovery Current - User Guide

About On Demand Recovery Before You Start On Demand Recovery Console Overview Working with On Demand Recovery Backup Unpacking Restoring objects Integration with Recovery Manager for Active Directory Reporting Advanced Search How does On Demand Recovery Handle Object Attributes? What is not protected by Auzure AD Connect in a hybrid environment but can be restored by On Demand Recovery?

Restoring Application Proxy settings

On Demand Recovery supports the recovery of Application Proxy settings, Connector groups, and Connector group membership.

Supported scenarios

The following scenarios are supported in On Demand Recovery:

  • Restoring changes to Application Proxy configuration.
  • Restoring connector group membership if an Application Proxy is moved into another connector group.
  • If an Application Proxy is moved into another connector group and the previous connector group was deleted, On Demand Recovery puts the Application Proxy back to the connector group with the same name.
  • If an Application Proxy is put into another connector group and the previous connector group is deleted and there is no connector group with the same name, the new connector group with this name will be automatically recreated and the Application Proxy will be put into it.
Limitations

All of the Application Proxy settings can only be restored at once, granular restore of Application Proxy settings is not supported.

Configuration data restored for an Application Proxy item

On Demand Recovery restores the following configuration data for an Application Proxy item:

Connector Groups

For deleted connector groups, On Demand Recovery restores the following attributes:

  • name
  • region

Other connector group data is currently backed up but cannot be restored.

OnPremisesPublishing Settings

An onPremisesPublishing object represents the set of properties for configuring Application Proxy for an on-premises application.

  • externalUrl
  • internalUrl
  • externalAuthenticationType
  • isTranslateHostHeaderEnabled
  • isTranslateLinksInBodyEnabled
  • isOnPremPublishingEnabled
  • isHttpOnlyCookieEnabled
  • isSecureCookieEnabled
  • isPersistentCookieEnabled
  • applicationServerTimeout
  • useAlternateUrlForTranslationAndRedirect

For details, see https://docs.microsoft.com/en-us/graph/api/resources/onpremisespublishing?view=graph-rest-beta.

Connectors

Connector data is currently backed up but cannot be restored.

  • id
  • machineName
  • externalIp
  • status
  • connectorGroupId
Prerequisites

Backing up Application Proxy settings is not enabled by default. You must select this option when configuring backup options.

To backup Application Proxy settings and connector groups

  1. Click Manage Backups on the Dashboard screen.
  2. Select the tenant from the list and click Edit.

    The Configure backup dialog opens.

  3. Select the Back up Application Proxy settings and connector groups option and specify the service account credentials for the tenant. The specified account must be a member of the Application Administrator Azure AD or Global Reader role.
  4. Click Save.

For details, see How does On Demand Recovery handle object attributes?

Backup and Restore of MFA Settings

On Demand Recovery supports backing up and restoring the following multifactor authentication (MFA) settings:

  • Authentication Requirement State
  • Authentication Methods. Possible values:
    • One Way SMS
    • Two Way Voice Mobile
    • Two Way Voice Office
    • Phone App Notification
    • Phone App One Time Password
  • Default Authentication Method
  • Authentication Phone
  • Authentication Email
  • Alternate Authentication Phone
  • Alternate Authentication Email

For more details, see the How does On Demand Recovery handle object attributes? section.

Note:

  • If a user that uses Microsoft Authenticator as an additional authentication method is permanently deleted, then all authentication methods for this user cannot be restored. On Demand Recovery does not restore binding of the application to the user.
  • On Demand Recovery does not restore user passwords.
Prerequisites

Backing up MFA settings is not enabled by default. You must select this option when configuring backup options.

To backup MFA settings

  1. Click Manage Backups on the Dashboard screen.
  2. Select the tenant from the list and click Edit.
    The Configure backup dialog opens.
  3. Select the Back up MFA settings, conditional access policies and data related to inactive mailboxes option and specify service account credentials for the tenant. The specified account must have at least one of the following roles in Azure portal; Exchange administrator or User administrator.
  4. Click Save.

Note:

  • It is possible to determine the scope of customer IP addresses that can access the customer Azure AD tenant using Azure Active Directory (Azure AD) conditional access. This option significantly reduces security risks and can be recommended for customers who want to backup MFA settings. For further information, contact Quest Support.
  • Multifactor authentication must be disabled for the On Demand Recovery service account or you should add On Demand Recovery IP addresses to the list of 'Trusted IPs'.

To configure Trusted IP settings

  1. Sign in to Azure portal.
  2. Go to Azure Active Directory > Security > MFA > Getting started.
  3. Click Additional cloud-based MFA settings under Configure.
  4. On the multi-factor authentication page, click service settings.
  5. In the trusted ips section, in the Skip multi-factor authentication for requests from following range of IP address subnets field, type the addresses from On Demand Recovery. For a single IP address, use a notation such as, xxx.xxx.xxx.xxx/32.
  6. Click save.

For more details, see Configure Azure Multi-Factor Authentication settings.

Restoring group licenses

On Demand Recovery restores group licenses, which means reassignment of a license to a group after its recreation or restore from the Recycle Bin. Granular restore of the assignedLicenses attribute is supported as well.

Supported scenarios

The following scenarios are supported by On Demand Recovery:

  • If a group is moved to the Recycle Bin, group licenses are restored simultaneously with the group object.
  • Direct and inherited licenses for users are now distinguished.
  • Inherited licenses are reassigned automatically by restoring membership.
  • If the licenseAssignmentStates attribute is not present in old backups, user object assignments in Azure AD are used to distinguish inherited and direct licenses.
  • The same logic is applied to the Differences report to show only one change if a group which is giving licenses was changed or deleted. In this case, the report will contain only the "Group change" or "Group deletion" action.
NOTE: If you are restoring a permanently deleted user from an old backup, the user license may be assigned twice; by group and directly.

Restoring SharePoint Online resource access

On Demand Recovery supports restoring SharePoint Online resource access for Azure AD users and groups in the following scenarios:

  • If the access was given by sending a link to the item.
  • If the access was given by adding an Azure AD user or group to a SharePoint Online group.

On Demand Recovery provides the spoGroupsMemberOf attribute for this purpose.

Prerequisites

This feature requires SharePoint Online backups.

To enable SharePoint Online backups

Make sure that the permissions required to work with SharePoint Online are granted to the Recovery module.

  1. To grant the required permission, click Go on the tenant tile and check that the Recovery module has the Granted status in the Resource Processing for SharePoint Online section.
  2. If the status is not Granted, click the Grant Consent link. Backups that were created after consent was granted will contain the SharePoint Online data.
NOTE: If a shared link SharePoint Online item was deleted before the restore operation, On Demand Recovery will not restore access to the item and you will get a warning message.
Limitations

The following scenarios are not supported by On Demand Recovery:

Related Documents