Entra Just Got a Restore Button — and Copilot Spend Just Got a Spotlight
- Craig A. Shuey

- Jul 12
- 5 min read

Two Microsoft 365 admin changes landed within days of each other this month, and neither made a big splash on its own. Put together, though, they point at the same shift: Microsoft is building governance and cost accountability directly into the tools IT teams already use every day, rather than leaving it to manual audits, spreadsheets, or third-party add-ons — right as agentic AI and Copilot licensing costs are scaling faster than most admins can track by hand.
The first change is Microsoft Entra Backup and Recovery, which reached general availability on June 30, 2026 for tenants licensed with Entra ID P1 or P2. It's a built-in, always-on solution that automatically takes a daily snapshot of critical directory objects — users, groups, applications, service principals, managed identities, Conditional Access policies, named locations, agent IDs, and authentication policies — and retains it for seven days. Admins can browse available snapshots, generate difference reports to see exactly what changed, and run recovery jobs to restore individual objects or whole sets of them. This closes a real gap: Entra ID has had recycle-bin-style recovery for individual users and groups for years, but there was previously no native way to snapshot and restore a Conditional Access policy or an app registration. If an admin accidentally pushed a CA policy change that locked the whole org out of sign-in, recovery meant manually rebuilding it from audit logs. Now it's a restore job.
The second, related move is Microsoft extending Conditional Access to cover AI agent identities more precisely, now in public preview. Administrators can target agent user accounts using Custom Security Attributes, apply policies based on a dedicated Agent Risk signal, require compliant devices (including Windows 365 for Agents), and enforce device platform and network conditions — the same Zero Trust machinery already applied to human identities, now purpose-built for agents. This builds on Entra Agent ID, which gives AI agents first-class identity objects in Entra rather than treating them as generic service principals, and reached general availability earlier this year. Microsoft's own guidance on this is candid that the recommended default control for agentic flows right now is simply "block" until an org has verified its policies in report-only mode — a sign of how early and fast-moving this space still is.
The third piece is on the cost side. Beginning in July 2026, Viva Insights is rolling out GitHub Copilot Spend and Usage Dashboards, giving non-technical roles a native view of Copilot seats, monthly active users, spend trends, and license assignments without exporting CSVs or building a custom Power BI report. Managers with at least five direct reports get scoped visibility into their own team; global analysts and global admins get full-tenant visibility by default. The stated goal is straightforward: catch over-provisioned and under-provisioned licenses, reduce wasted spend, and give managers and admins the same kind of usage accountability for AI tooling that most orgs already expect for other licensed software.
Taken together, these three updates describe the same pattern from two directions — identity and cost. Entra is making the AI agents your organization is standing up into governable, recoverable, policy-bound identities instead of shadow service accounts. Viva Insights is making Copilot licensing spend visible to the people who actually decide whether to keep paying for it. Neither fixes governance by itself, but both remove a "we don't have the tooling for this yet" excuse.
For IT leaders managing M365 and Entra environments, this raises some immediate, practical questions:
- Does your current Entra ID P1/P2 licensing actually cover the retention window you'd need in a real incident, and have you updated your incident-response runbooks to reference the new Backup and Recovery blade rather than the old manual-reconstruction process?
- Have you actually inventoried the AI agents already running in your tenant, and tagged them with Custom Security Attributes, before broader Conditional Access enforcement for agents moves from public preview to a default expectation?
- Now that Copilot spend and utilization are visible by default to any manager with five or more reports, do you have a defined process for what happens when a manager spots a dormant license — reclaim it, re-train the user, or ignore it — or will this just generate dashboard noise without a decision behind it?
- Is your organization still treating "who holds a Copilot license" and "which AI agents have an identity in our tenant" as two separate governance conversations, even though Microsoft is now managing both inside the same Entra/Viva ecosystem?
At OFER AI, this is a useful real-world example of something we talk about often: governance tooling catching up to deployment, rather than leading it. Most organizations already have AI agents and Copilot licenses in production; what's changing is whether IT actually has visibility and recovery options for them. That's precisely the kind of practical, in-the-trenches question our model-vetting rubric's governance and cost-control categories are meant to help organizations work through — not in the abstract, but against what a platform like Entra and Viva actually expose today.
In upcoming deep dives, we'll be looking at:
What a practical, tiered rollout of Conditional Access for AI agents looks like — starting in report-only mode, moving to enforcement, without breaking legitimate automated workflows along the way.
How to turn a Copilot spend dashboard into an actual decision-making cadence (monthly review, defined thresholds for reclaiming seats) instead of a dashboard nobody acts on.
Whether "identity governance" and "spend governance" for AI tooling should be owned by the same team inside an organization, given that Microsoft is now surfacing both inside the same admin ecosystem.
If your team has already worked through standing up Conditional Access policies for AI age
nts, or has a Copilot license-reclamation process that's actually working, that's exactly the kind of practical experience we want in our Notes from the Field segment — the lessons that don't show up in a Microsoft roadmap announcement. Click on the button below to apply to be a Subject Matter Expert Panelist for an upcoming Deep Dive.
Sources
Microsoft Entra Backup and Recovery is now generally available — Microsoft Tech Community, June 30, 2026
Microsoft Entra releases and announcements — Microsoft Learn, updated June 30, 2026
What's new in Microsoft Security: June 2026 — Microsoft Security Blog, June 30, 2026
Microsoft Entra ID July 2026: Built-in Backup, AI Agent Conditional Access, BYOD — BigHat Group, July 7, 2026
Zero Trust for AI Agents: Security in Microsoft Entra — candede.com, June 28, 2026
Microsoft Viva Insights Rolls Out GitHub Copilot Spend and Usage Dashboards: What M365 Admins Need to Know — Mo Wasay, July 10, 2026
Connect to the Microsoft Copilot Dashboard for Microsoft 365 — Microsoft Learn, July 2026
RM566470 - Microsoft Viva: Insights for GitHub Copilot spend and usage — Microsoft 365 Message Center Archive, June 23, 2026
Postscript — related videos
Azure Update, episode of July 10, 2026 — covers the Entra Backup and Restore rollout alongside other Azure identity and infrastructure updates from the same week. Watch here.
"UPDATES! 7.1.26 | New in Intune - MS Entra Backup and Recovery now GA - Tenant Graph now live" — walks through the Backup and Recovery GA rollout from an admin's perspective. Watch here.




Comments