We have found in many cases that backups do not exist for users. If I'm not mistaken, when I talked to support about this, I was told that it only backs up when they change something. Current NIST guidelines recommend using a strong random password with MFA and NOT changing it regularly, so we have many clients that have not added or changed a password in quite some time. I think it would be beneficial, if your system did one of the two items listed below. Backup more frequently regardless of changes Instead of deleting backups older than a certain time period indiscriminately, only delete if a new backup exists. In both of these cases, you should not be left with a user that has no backup. IMHO, this changes should be high priority.