TenuVault backs up 39 Intune object types in nine areas. Each object is saved as it is in Microsoft Graph (beta), with its settings and, where Intune has them, its assignments.
The area and type names below are the ones the Back up dialog shows under Custom. See Choose what to back up.
- Assignments: whether the backup holds the object’s assignments (the groups and filters it targets). Restoring assignments is a separate choice. See Restore modes and assignments.
- Everything except apps: every type is included in this choice except Apps. Everything includes all 39 types.
- Built-in objects that Intune creates itself are skipped. The backup log reports how many were skipped.
| Type | Assignments | Notes |
|---|
| Device configuration profiles | Yes | Including custom profiles with OMA-URI settings. Windows update rings are device configuration profiles, so they are included here. Encrypted OMA-URI values are read in plain text and stored inside the encrypted backup. |
| Settings catalog and endpoint security policies | Yes | With all settings, including settings catalog based endpoint security policies |
| Administrative templates | Yes | With every configured setting and its values |
| Reusable settings | No | The reusable setting itself |
| BIOS configurations | Yes | |
| Type | Assignments | Notes |
|---|
| Compliance policies | Yes | With their actions for noncompliance |
| Settings catalog compliance policies | Yes | With settings and actions for noncompliance |
| Compliance scripts | Yes | |
| Type | Assignments | Notes |
|---|
| Security baselines and template profiles | Yes | Template-based profiles with their settings. Settings catalog based endpoint security policies are under Device configuration. |
| Type | Assignments | Notes |
|---|
| Windows PowerShell scripts | Yes | |
| macOS shell scripts | Yes | |
| macOS custom attributes | Yes | |
| Remediations | Yes | Remediations provided by Microsoft are skipped |
| Type | Assignments | Notes |
|---|
| Feature update profiles | Yes | |
| Expedited quality update profiles | Yes | |
| Hotpatch quality update policies | Yes | |
| Driver update profiles | Yes | |
Update rings are device configuration profiles and are backed up with Device configuration.
| Type | Assignments | Notes |
|---|
| App categories | No | Built-in categories are skipped |
| Apps | Yes | App details, assignments, categories, and dependency and supersedence links. Installer files are never downloaded. Left out of Everything except apps. |
| Policy sets | Yes | With the items each set contains |
Apps are the slowest type to back up. Because installer files are never downloaded, Win32 and line-of-business apps cannot be recreated from a backup; store, web and Microsoft 365 apps can. See What cannot be restored.
| Type | Assignments | Notes |
|---|
| App configuration policies for managed devices | Yes | |
| App configuration policies for managed apps | Yes | With the apps they target |
| iOS app protection policies | Yes | With the apps they target |
| Android app protection policies | Yes | With the apps they target |
| Windows app protection policies | Yes | With the apps they target |
| Type | Assignments | Notes |
|---|
| Enrollment configurations | Yes | Including the tenant defaults, with their priority order |
| Windows Autopilot deployment profiles | Yes | |
| Apple user enrollment profiles | Yes | |
| Apple automated device enrollment tokens and profiles | No | Token details and enrollment profiles, kept for reference. Restore does not recreate them; upload the Apple token again in Intune. |
| Android Enterprise enrollment profiles | No | The profile settings. A restored profile gets a new enrollment token that is valid for 90 days. |
| Device categories | No | |
| Terms and conditions | Yes | |
| Type | Assignments | Notes |
|---|
| Assignment filters | No | |
| Scope tags | Yes | Built-in scope tags are skipped |
| Intune roles | Yes | Custom roles with their role assignments, including members and scopes. Built-in roles are skipped. |
| Compliance notification templates | No | With their messages in every language |
| Company Portal branding | Yes | With the logos and images |
| Device clean-up rules | No | |
| Multi admin approval policies | No | |
- App installer files. Apps are saved as their Intune details only.
- Built-in objects Intune recreates itself: remediations provided by Microsoft, built-in app categories, built-in scope tags and built-in Intune roles.
- The Apple automated device enrollment token. Its details and profiles are kept for reference, but the token has to be uploaded again in Intune.
- Android Enterprise enrollment tokens. A restored profile gets a new token.
- The groups that assignments target. Assignments are saved as references to groups; the groups themselves are not part of the backup.
- Anything not listed on this page, such as enrolled devices and their inventory.
- Types you leave out with Everything except apps or Custom.
- Types your app registration has no permission for. App registrations created with an older version of the setup script may lack the permissions for newer types. The backup skips those types and says so in the log and in Backup Details. Run the setup script again to add the permissions. See Create the app registration.
Some backed-up items cannot be restored in full, for example apps that need an installer. See What cannot be restored.