top of page

Entra Just Got a Restore Button — and Copilot Spend Just Got a Spotlight



Two Microsoft 365 admin changes landed within days of each other this month, and neither made a big splash on its own. Put together, though, they point at the same shift: Microsoft is building governance and cost accountability directly into the tools IT teams already use every day, rather than leaving it to manual audits, spreadsheets, or third-party add-ons — right as agentic AI and Copilot licensing costs are scaling faster than most admins can track by hand.


The first change is Microsoft Entra Backup and Recovery, which reached general availability on June 30, 2026 for tenants licensed with Entra ID P1 or P2. It's a built-in, always-on solution that automatically takes a daily snapshot of critical directory objects — users, groups, applications, service principals, managed identities, Conditional Access policies, named locations, agent IDs, and authentication policies — and retains it for seven days. Admins can browse available snapshots, generate difference reports to see exactly what changed, and run recovery jobs to restore individual objects or whole sets of them. This closes a real gap: Entra ID has had recycle-bin-style recovery for individual users and groups for years, but there was previously no native way to snapshot and restore a Conditional Access policy or an app registration. If an admin accidentally pushed a CA policy change that locked the whole org out of sign-in, recovery meant manually rebuilding it from audit logs. Now it's a restore job.


The second, related move is Microsoft extending Conditional Access to cover AI agent identities more precisely, now in public preview. Administrators can target agent user accounts using Custom Security Attributes, apply policies based on a dedicated Agent Risk signal, require compliant devices (including Windows 365 for Agents), and enforce device platform and network conditions — the same Zero Trust machinery already applied to human identities, now purpose-built for agents. This builds on Entra Agent ID, which gives AI agents first-class identity objects in Entra rather than treating them as generic service principals, and reached general availability earlier this year. Microsoft's own guidance on this is candid that the recommended default control for agentic flows right now is simply "block" until an org has verified its policies in report-only mode — a sign of how early and fast-moving this space still is.


The third piece is on the cost side. Beginning in July 2026, Viva Insights is rolling out GitHub Copilot Spend and Usage Dashboards, giving non-technical roles a native view of Copilot seats, monthly active users, spend trends, and license assignments without exporting CSVs or building a custom Power BI report. Managers with at least five direct reports get scoped visibility into their own team; global analysts and global admins get full-tenant visibility by default. The stated goal is straightforward: catch over-provisioned and under-provisioned licenses, reduce wasted spend, and give managers and admins the same kind of usage accountability for AI tooling that most orgs already expect for other licensed software.


Taken together, these three updates describe the same pattern from two directions — identity and cost. Entra is making the AI agents your organization is standing up into governable, recoverable, policy-bound identities instead of shadow service accounts. Viva Insights is making Copilot licensing spend visible to the people who actually decide whether to keep paying for it. Neither fixes governance by itself, but both remove a "we don't have the tooling for this yet" excuse.


For IT leaders managing M365 and Entra environments, this raises some immediate, practical questions:


- Does your current Entra ID P1/P2 licensing actually cover the retention window you'd need in a real incident, and have you updated your incident-response runbooks to reference the new Backup and Recovery blade rather than the old manual-reconstruction process?

- Have you actually inventoried the AI agents already running in your tenant, and tagged them with Custom Security Attributes, before broader Conditional Access enforcement for agents moves from public preview to a default expectation?

- Now that Copilot spend and utilization are visible by default to any manager with five or more reports, do you have a defined process for what happens when a manager spots a dormant license — reclaim it, re-train the user, or ignore it — or will this just generate dashboard noise without a decision behind it?

- Is your organization still treating "who holds a Copilot license" and "which AI agents have an identity in our tenant" as two separate governance conversations, even though Microsoft is now managing both inside the same Entra/Viva ecosystem?

At OFER AI, this is a useful real-world example of something we talk about often: governance tooling catching up to deployment, rather than leading it. Most organizations already have AI agents and Copilot licenses in production; what's changing is whether IT actually has visibility and recovery options for them. That's precisely the kind of practical, in-the-trenches question our model-vetting rubric's governance and cost-control categories are meant to help organizations work through — not in the abstract, but against what a platform like Entra and Viva actually expose today.



In upcoming deep dives, we'll be looking at:


  • What a practical, tiered rollout of Conditional Access for AI agents looks like — starting in report-only mode, moving to enforcement, without breaking legitimate automated workflows along the way.

  • How to turn a Copilot spend dashboard into an actual decision-making cadence (monthly review, defined thresholds for reclaiming seats) instead of a dashboard nobody acts on.

  • Whether "identity governance" and "spend governance" for AI tooling should be owned by the same team inside an organization, given that Microsoft is now surfacing both inside the same admin ecosystem.


If your team has already worked through standing up Conditional Access policies for AI age

nts, or has a Copilot license-reclamation process that's actually working, that's exactly the kind of practical experience we want in our Notes from the Field segment — the lessons that don't show up in a Microsoft roadmap announcement. Click on the button below to apply to be a Subject Matter Expert Panelist for an upcoming Deep Dive.


Sources

Postscript — related videos

  • Azure Update, episode of July 10, 2026 — covers the Entra Backup and Restore rollout alongside other Azure identity and infrastructure updates from the same week. Watch here.

  • "UPDATES! 7.1.26 | New in Intune - MS Entra Backup and Recovery now GA - Tenant Graph now live" — walks through the Backup and Recovery GA rollout from an admin's perspective. Watch here.



 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

Join us on mobile!

Download the “” app to easily stay updated on the go.

Scan QR code to join the app

SUBSCRIBE & JOIN

Sign up to receive Open Forum news and updates.

Subscribing to our newsletter is free of charge and notifies you of new blog posts, upcoming events and new online programs.  Becoming a member provides you with other benefits.

SCROLL

Becoming a member is free of charge and gives you access to additional content, the ability to register for in-person and online events as well as online programs.  Members can participate in roundtable discussions, deep dives and be heard. Tiered plans are only available to site members. 

Become part of the AI Solution.  Join Now.

bottom of page