Welcome
TenuVault is a desktop app for Windows and macOS that backs up your Microsoft Intune configuration, restores it when something goes wrong, and shows you what changed between backups.
It runs on your own computer. You sign in as yourself, through an app registration in your own tenant, so TenuVault can only do what your Intune role allows. Your configuration and backups never pass through a TenuVault server.
How it works
Section titled “How it works”- You create a small app registration in your tenant with a PowerShell script. It has delegated permissions only and no secret.
- You sign in to your tenant from the app with your normal admin account. MFA and Conditional Access apply as usual.
- TenuVault reads your Intune configuration through Microsoft Graph and stores each backup encrypted, either on your device or in your own Azure storage account.
- When you need to, you compare backups, spot drift, and restore single items or whole sets back to the tenant.
Start here
Section titled “Start here”| If you want to | Go to |
|---|---|
| Install TenuVault and take your first backup | Getting started |
| Understand what TenuVault can access and where your data goes | Security and privacy |
| Check which Intune objects are covered | What gets backed up |
| Put a change back or recover a deleted policy | Restore items |
| Compare plans | Plans and features |
| Roll TenuVault out to several admins | Deploy TenuVault in your organization |
| Fix a problem | Troubleshooting |
- Website: tenuvault.com/desktop
- Downloads: GitHub releases
- Source code, public for review: github.com/ugurkocde/tenuvault-desktop