Deploy TenuVault in your organization
Roll TenuVault out to your admins with Intune, control updates by policy and restrict who can sign in.
This page is for rolling TenuVault out to several admins: installing it on managed devices, controlling automatic updates, and deciding who can sign in.
Plan the rollout
Section titled “Plan the rollout”- One app registration per tenant. Create it once with the setup script. Every admin signs in through the same app registration with their own account, so you share the client ID, not a secret.
- Decide who can sign in. Restrict sign-in to one group if TenuVault should only be used by a defined set of admins. See Restrict who can sign in.
- Give admins the right roles. Each admin needs an Intune role, and Storage Blob Data Contributor on the storage account if backups go to Azure. See Requirements.
- Decide how updates reach devices. Either let TenuVault update itself, or turn automatic updates off by policy and deploy new versions yourself. See Control automatic updates.
- Share licenses. The admin who holds the license key can share it with the tenant’s other admins, so they do not need the key. See Activate and manage your license.
Deploy with Intune
Section titled “Deploy with Intune”Use the MSI (TenuVault-<version>-win-x64.msi) from the releases page. It installs per machine, without prompts, and creates a desktop shortcut.
- In the Intune admin center, go to Apps > Windows > Create.
- For App type, choose Line-of-business app and upload the MSI.
- Complete the app information, then assign the app to a group of admin devices as Required or Available for enrolled devices.
Intune reads the product code and version from the MSI and installs it silently.
To install the MSI manually or with Configuration Manager:
msiexec /i "TenuVault-<version>-win-x64.msi" /qnThe MSI is x64 only. For Arm64 devices, use the setup program TenuVault-<version>-win-arm64.exe.
Use the DMG for each architecture: TenuVault-<version>-mac-arm64.dmg for Apple silicon and TenuVault-<version>-mac-x64.dmg for Intel.
- In the Intune admin center, go to Apps > macOS > Create.
- For App type, choose macOS app (DMG) and upload the DMG.
- Complete the app information and assign it to a group of admin Macs.
Create one app per architecture and assign each to the Macs it matches. The apps are signed and notarized.
Each admin still signs in and chooses storage on first launch; see Getting started. TenuVault stores sign-ins, settings and the backup key per user account on the device.
Control automatic updates
Section titled “Control automatic updates”By default, TenuVault checks GitHub for updates 15 seconds after it starts and every 6 hours, downloads them in the background and installs them on restart. When you deploy TenuVault centrally, you can turn this off with a policy and ship new versions through Intune instead, so every device runs the version you approved.
When the policy is set:
- Automatic update checks and downloads stop.
- Settings > Updates shows Your organization manages updates for TenuVault. and the Download and install updates automatically checkbox is locked.
TenuVault reads the policy when it starts. Restart TenuVault after the policy reaches the device.
Set a DWORD value DisableAutoUpdate = 1 under either of these keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\TenuVault(all users on the device)HKEY_CURRENT_USER\SOFTWARE\Policies\TenuVault(one user)
To deploy it with Intune, create a platform script (Devices > Scripts and remediations > Platform scripts) with this content:
$key = "HKLM:\SOFTWARE\Policies\TenuVault"New-Item -Path $key -Force | Out-NullNew-ItemProperty -Path $key -Name "DisableAutoUpdate" -PropertyType DWord -Value 1 -Force | Out-NullSet Run this script using the logged on credentials to No and Run script in 64 bit PowerShell Host to Yes. In a 32 bit host, the value lands under WOW6432Node and TenuVault does not see it.
To turn updates back on, delete the value or set it to 0.
Set the managed preference DisableAutoUpdate to true (boolean) for the preference domain com.tenuvault.desktop.
To deploy it with Intune:
-
Save this as
com.tenuvault.desktop.plist:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>DisableAutoUpdate</key><true/></dict></plist> -
Go to Devices > macOS > Configuration > Create > New policy, choose Templates > Preference file.
-
Enter
com.tenuvault.desktopas the Preference domain name and upload the file. -
Assign the profile to your admin Macs.
Restrict who can sign in
Section titled “Restrict who can sign in”By default, any user in the tenant can sign in through the TenuVault app registration. What they can do is still limited by their own Intune and Azure roles, because every permission is delegated.
To allow only one group:
- New app registration: run the setup script with
-AllowedGroupId <group object id>. The script sets Assignment required on the enterprise application and assigns the group. - Existing app registration: in the Microsoft Entra admin center, open Enterprise apps > TenuVault Desktop > Properties, set Assignment required? to Yes, then add the group under Users and groups.
Users outside the group get a Microsoft sign-in error when they try to connect the tenant.
You can also target the app with Conditional Access like any other cloud app. On Windows, TenuVault signs in through the Windows account broker, so device-based conditions such as compliant or Entra-joined devices work as they do for the Intune admin center. On macOS, device-based conditions need the Microsoft Enterprise SSO extension.
Scheduled backups on admin devices
Section titled “Scheduled backups on admin devices”Scheduled backups run on the admin’s computer, as that admin, while TenuVault is running. For reliable schedules, ask admins to:
- Keep Keep running in the tray when I close the window turned on.
- Turn on Start TenuVault in the tray when I sign in to this computer.
- Optionally select Install background launch, which reopens TenuVault within five minutes if it was closed.
Backups do not run while the admin is signed out or the computer is asleep or off. See Schedule backups and Settings reference.