After you review the identity activity analysis results, you can generate a recovery plan to restore affected identities to a clean pre-compromise state. The Cyber Recovery Plan wizard walks you through selecting identities to recover and confirming restore settings before Druva executes the jobs.
Before you begin
You must have the Cloud Admin role. Cloud Admin (Read-only) cannot execute recovery plans.
You must have an open analysis with results. See Create an identity activity analysis.
Only one recovery plan can run at a time for a given identity. If a recovery is already in progress, wait for it to complete before starting a new one.
Open the cyber recovery plan wizard to generate cyber recovery plan
Navigate to Identity Resiliency > Identity Behavioral Insights > Recent Analyses, click on the Primary Identity for which you want to open the cyber recovery plan wizard.
From the Identity Activity Details page, click View Cyber Recovery Plan. The Cyber Recovery Plan wizard opens with two steps: Restore Identity and Restore Settings.
Step 1: Restore Identity
The Restore Identity tab includes two sections:
Containment Recommendation section that provides pointers for recommended actions to prevent unauthorized access.
The Recovery Actions section lists all identities affected by the analyzed activity. The Recovery Actions table displays the following details:
Identity: Name of the affected identity or object
Identity Type: The object type (User, Service Principal, groups, apps, idps, inline hooks)
Activity: The suspicious event that affected this identity. It can be a Create, Modified, or Delete event action.
Recovery Type: The recommended action: Recover, Rollback, or Delete. Delete is recommended when there is suspicious create event action on identity.
Rollback is recommended when there is suspicious modified event action on identity.
Recover is recommended when there is suspicious delete event action on identity.
Recovery Snapshot: The latest clean snapshot is displayed if available. You can overwrite the snapshot per your requirement using the Compare Snapshot option. Snapshot Unavailable is displayed if no backup exists for this identity.
From the Recovery Actions table, select the checkboxes next to the identities you want to include in the recovery plan. You can include all or a subset.
If an identity shows Snapshot Unavailable, you must either select a different snapshot using the Compare snapshot option or deselect that identity to proceed.
Click Next to proceed to step 2: Restore Settings.
❗Important: Identities with a Delete recovery type will be removed from the primary environment. Review these rows carefully before proceeding.
Step 2: Restore Settings
Review the Restore Settings for the identity provider. The options available depend on the identity provider.
Click Restore to continue. The Recovery Plan Summary dialog shows the full scope of the recovery before it runs:
Total count of identities selected for recovery
Number of recovery jobs Druva will create
Recovery Snapshot used for recovery
Recovery Action details. It can be Recover, Delete, or Rollback
Druva groups identities that share the same recovery snapshot into a single recovery job, so the number of jobs may be less than the number of identities.
Delete jobs are grouped by object type. Each delete job is limited to a maximum of 20 objects.
Click Proceed to Restore to start the recovery. After confirmation, Druva creates the recovery jobs and you are taken to the Recovery Jobs page. See [Monitor recovery jobs].
Compare snapshots
Use this option to review what changed between two backup points, or to choose a different recovery snapshot:
Select Compare in the Recovery Snapshot column for the identity.
In the Compare Snapshot dialog:
Latest Snapshot: The most recent backup of the identity.
Selected Recovery Snapshot: The pre-selected recommended snapshot.
Select Compare to load a side-by-side comparison.
Turn on Show only the difference to focus the view on changed attributes only.
Select Use Selected Snapshot to apply your choice and close the dialog.
The Recovery Actions table updates to show the snapshot date you selected. An indicator icon appears on the row to mark that you changed the recommendation.
Next Step

