Entra ID
Conditional Access policies, named locations, authentication methods and strengths, security defaults, guest and consent settings, cross-tenant access.
365 Rewind saves the configuration of your tenant: policies, connectors, filters, allow and block lists and settings. Compare two backups to see exactly what changed, and restore a single item to the way it was.
coverage: every type of configuration in the catalog is backed up and compared, across the Microsoft 365 workloads
backups read the tenant and change nothing; a restore uses a separate sign-in
backups are encrypted on your machine before they are stored, hosted or local
restore one policy or fifty; what you did not select is left alone
The settings that decide who can sign in, where mail flows and what is blocked. The things that are painful to rebuild from memory.
Conditional Access policies, named locations, authentication methods and strengths, security defaults, guest and consent settings, cross-tenant access.
Mail flow rules, inbound and outbound connectors, accepted and remote domains, DKIM signing, organization and transport settings.
Anti-phishing, anti-spam and anti-malware policies and rules, Safe Links and Safe Attachments, the tenant allow and block list.
Retention and data loss prevention policies, sensitivity labels and label policies, audit settings.
The tenant-wide sharing and access settings that Microsoft Graph exposes. Site-level configuration follows later.
Meeting, messaging, calling and channel policies, guest and external access settings, client settings.
The catalog grows: Intune, Power Platform and the Microsoft 365 admin center are being added. The coverage page lists every area of every admin center after you sign in, including the areas that no product can back up today.
Every type is backed up and compared from the start. Restore is switched on for a type only when it has been proven against a live tenant, so the number of types the app can restore grows with each release. Until then a walk-through takes you through putting the saved values back by hand.
Per tenant, and you can change it later. The choice applies to future backups.
You pick the items, and you choose how they go back: the Windows app applies them as you, a script does it under your own eyes, or you make each change by hand.
Open a backup or a comparison and check what you want back: one policy, a connector, a handful of rules.
The plan lists the items in the order they will run, and the roles and permissions the restore will ask for.
In the Windows app, with a separate sign-in that asks only for what those items need. With a restore script that you read and run yourself, and that previews first. Or by hand, with a walk-through.
Each item reports what happened. The next backup confirms that the tenant matches what was restored.
These rules are built into the app. They are not options you have to remember to switch on.
Items that exist in the tenant but not in the backup are reported, never removed.
A recreated Conditional Access policy returns in report-only mode; mail flow rules, connectors and threat policy rules return disabled. You turn them on when you have checked them.
The app records the state before and after each item in a journal on your machine and can undo the restore from it.
If an item fails, the restore stops there and says so. It does not press on and hope.
The app runs as the administrator who signed in. Tokens stay in memory, are never written to disk and are never sent to the portal.
A restore plan holds the saved settings only. How they are applied is fixed in the app. The restore script is one fixed file that you can read; your settings travel in it as data, never as commands.
Sign in to see your tenants, their backups and what changed.