Skip to content

What gets backed up

Every Intune object type TenuVault backs up, grouped by area, and what is not covered.

TenuVault backs up 39 Intune object types in nine areas. Each object is saved as it is in Microsoft Graph (beta), with its settings and, where Intune has them, its assignments.

The area and type names below are the ones the Back up dialog shows under Custom. See Choose what to back up.

  • Assignments: whether the backup holds the object’s assignments (the groups and filters it targets). Restoring assignments is a separate choice. See Restore modes and assignments.
  • Everything except apps: every type is included in this choice except Apps. Everything includes all 39 types.
  • Built-in objects that Intune creates itself are skipped. The backup log reports how many were skipped.
TypeAssignmentsNotes
Device configuration profilesYesIncluding custom profiles with OMA-URI settings. Windows update rings are device configuration profiles, so they are included here. Encrypted OMA-URI values are read in plain text and stored inside the encrypted backup.
Settings catalog and endpoint security policiesYesWith all settings, including settings catalog based endpoint security policies
Administrative templatesYesWith every configured setting and its values
Reusable settingsNoThe reusable setting itself
BIOS configurationsYes
TypeAssignmentsNotes
Compliance policiesYesWith their actions for noncompliance
Settings catalog compliance policiesYesWith settings and actions for noncompliance
Compliance scriptsYes
TypeAssignmentsNotes
Security baselines and template profilesYesTemplate-based profiles with their settings. Settings catalog based endpoint security policies are under Device configuration.
TypeAssignmentsNotes
Windows PowerShell scriptsYes
macOS shell scriptsYes
macOS custom attributesYes
RemediationsYesRemediations provided by Microsoft are skipped
TypeAssignmentsNotes
Feature update profilesYes
Expedited quality update profilesYes
Hotpatch quality update policiesYes
Driver update profilesYes

Update rings are device configuration profiles and are backed up with Device configuration.

TypeAssignmentsNotes
App categoriesNoBuilt-in categories are skipped
AppsYesApp details, assignments, categories, and dependency and supersedence links. Installer files are never downloaded. Left out of Everything except apps.
Policy setsYesWith the items each set contains

Apps are the slowest type to back up. Because installer files are never downloaded, Win32 and line-of-business apps cannot be recreated from a backup; store, web and Microsoft 365 apps can. See What cannot be restored.

TypeAssignmentsNotes
App configuration policies for managed devicesYes
App configuration policies for managed appsYesWith the apps they target
iOS app protection policiesYesWith the apps they target
Android app protection policiesYesWith the apps they target
Windows app protection policiesYesWith the apps they target
TypeAssignmentsNotes
Enrollment configurationsYesIncluding the tenant defaults, with their priority order
Windows Autopilot deployment profilesYes
Apple user enrollment profilesYes
Apple automated device enrollment tokens and profilesNoToken details and enrollment profiles, kept for reference. Restore does not recreate them; upload the Apple token again in Intune.
Android Enterprise enrollment profilesNoThe profile settings. A restored profile gets a new enrollment token that is valid for 90 days.
Device categoriesNo
Terms and conditionsYes
TypeAssignmentsNotes
Assignment filtersNo
Scope tagsYesBuilt-in scope tags are skipped
Intune rolesYesCustom roles with their role assignments, including members and scopes. Built-in roles are skipped.
Compliance notification templatesNoWith their messages in every language
Company Portal brandingYesWith the logos and images
Device clean-up rulesNo
Multi admin approval policiesNo
  • App installer files. Apps are saved as their Intune details only.
  • Built-in objects Intune recreates itself: remediations provided by Microsoft, built-in app categories, built-in scope tags and built-in Intune roles.
  • The Apple automated device enrollment token. Its details and profiles are kept for reference, but the token has to be uploaded again in Intune.
  • Android Enterprise enrollment tokens. A restored profile gets a new token.
  • The groups that assignments target. Assignments are saved as references to groups; the groups themselves are not part of the backup.
  • Anything not listed on this page, such as enrolled devices and their inventory.
  • Types you leave out with Everything except apps or Custom.
  • Types your app registration has no permission for. App registrations created with an older version of the setup script may lack the permissions for newer types. The backup skips those types and says so in the log and in Backup Details. Run the setup script again to add the permissions. See Create the app registration.

Some backed-up items cannot be restored in full, for example apps that need an installer. See What cannot be restored.