Skip to content

Create the app registration

Create the app registration TenuVault signs in with.

TenuVault signs in through an app registration that lives in your own tenant. A PowerShell setup script creates it in one step and prints the two values you enter in the app: the tenant ID and the client ID.

You do this once per tenant. Every admin who uses TenuVault in that tenant signs in through the same app registration.

SettingValue
NameTenuVault Desktop (change it with -DisplayName)
Supported account typesAccounts in this organizational directory only (single tenant)
Client typePublic client: no client secret and no certificate
Redirect URIshttp://localhost (browser sign-in) and ms-appx-web://Microsoft.AAD.BrokerPlugin/<client id> (Windows account broker)
PermissionsDelegated permissions only, listed below
Admin consentGranted tenant-wide for all of the permissions below
Enterprise applicationHidden from users’ My Apps portal
Sign-in restrictionOptional: only members of one group can sign in (-AllowedGroupId)

Because the app is a public client with delegated permissions, every call runs as the signed-in admin. MFA, Conditional Access and your Intune role apply, and changes are attributed to that admin in the Entra and Intune audit logs.

APIPermission
Microsoft GraphUser.Read
Microsoft GraphOrganization.Read.All
Microsoft GraphPolicy.Read.All
Microsoft GraphDeviceManagementConfiguration.ReadWrite.All
Microsoft GraphDeviceManagementApps.ReadWrite.All
Microsoft GraphDeviceManagementServiceConfig.ReadWrite.All
Microsoft GraphDeviceManagementScripts.ReadWrite.All
Microsoft GraphDeviceManagementRBAC.ReadWrite.All
Microsoft GraphDeviceManagementManagedDevices.Read.All
Azure Service Managementuser_impersonation
Azure Storageuser_impersonation

The two Azure permissions are only used when backups go to your Azure storage account: Azure Service Management lists your subscriptions and storage accounts in the storage picker, and Azure Storage reads and writes the backup files. For what each permission is used for, see App registration and delegated permissions.

  • An account with Global Administrator, Privileged Role Administrator or Cloud Application Administrator, which can grant admin consent.
  • PowerShell: Windows PowerShell 5.1 or PowerShell 7 on Windows, PowerShell 7 (pwsh) on macOS.
  • The Microsoft Graph PowerShell modules Microsoft.Graph.Applications and Microsoft.Graph.Identity.SignIns. If they are missing, the script installs them for the current user from the PowerShell Gallery.
  • Optional: the object ID of a security group, if only its members should be able to sign in.

The setup script is built into TenuVault.

  1. Start TenuVault. If it shows Welcome to TenuVault, select a plan first; see Choose a plan on first launch. You can change your plan later.
  2. On the Prepare step of Set up TenuVault, select Copy setup script. You also find this button in Tenants > Connect tenant under First time? Create an app registration.
  3. Paste the script into a text editor and save it as New-TenuVaultDesktopApp.ps1.

If someone else creates the app registration for you, send them the saved file.

  1. Open PowerShell in the folder where you saved the script.

  2. Run the script with the parameters you need:

    ./New-TenuVaultDesktopApp.ps1 -TenantId contoso.onmicrosoft.com

    To limit sign-in to the members of one security group:

    ./New-TenuVaultDesktopApp.ps1 -TenantId contoso.onmicrosoft.com -DisplayName "TenuVault Desktop" -AllowedGroupId 00000000-0000-0000-0000-000000000000
  3. Sign in with your admin account when Microsoft Graph PowerShell asks you to. If you are prompted to consent to the permissions Graph PowerShell requests, accept. The script connects with Application.ReadWrite.All, DelegatedPermissionGrant.ReadWrite.All and AppRoleAssignment.ReadWrite.All to create the app and grant consent.

  4. Wait for the script to finish. It prints:

    Done. Enter these values in TenuVault > Tenants > Add tenant:
    Tenant id: <tenant id>
    Application (client) id: <client id>
  5. Copy the Application (client) id. You enter it when you sign in to your tenant. The tenant ID is always printed as a GUID, even if you passed a domain.

ParameterRequiredDescription
-TenantIdNoTenant ID or domain to create the app registration in. Defaults to the tenant of the account you sign in with.
-DisplayNameNoName of the app registration. Default: TenuVault Desktop.
-AllowedGroupIdNoObject ID of a security group. When set, user assignment is required on the enterprise application and only members of this group can sign in to TenuVault.

If PowerShell refuses to run the saved script because of the execution policy, allow scripts for the current session only and run it again:

Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass
./New-TenuVaultDesktopApp.ps1 -TenantId contoso.onmicrosoft.com

If you cannot run PowerShell, you can create the same app registration in the Microsoft Entra admin center. These steps reproduce every setting the script makes.

  1. Go to Entra ID > App registrations > New registration.
  2. Name: TenuVault Desktop.
  3. Supported account types: Accounts in this organizational directory only (single tenant).
  4. Leave Redirect URI empty and select Register.
  5. On the Overview page, copy the Application (client) ID and the Directory (tenant) ID.
  6. Optional: under Branding & properties, set Internal notes to Used by the TenuVault desktop app. Delegated permissions only, no credentials. The script adds this note; it has no effect on sign-in.
  1. Open Authentication and select Add a platform > Mobile and desktop applications.
  2. Add these two custom redirect URIs, replacing <client id> with the Application (client) ID from step 1:
    • http://localhost
    • ms-appx-web://Microsoft.AAD.BrokerPlugin/<client id>
  3. Select Configure.
  4. Under Advanced settings, set Allow public client flows to Yes and save.

Do not add a client secret or a certificate.

  1. Open API permissions > Add a permission.
  2. Select Microsoft Graph > Delegated permissions and add the nine Graph permissions listed in Delegated permissions. User.Read is usually already present.
  3. Select Add a permission again. Under Microsoft APIs (or APIs my organization uses), choose Azure Service Management > Delegated permissions > user_impersonation.
  4. Repeat for Azure Storage > Delegated permissions > user_impersonation.
  5. Select Grant admin consent for <your tenant> and confirm. Every permission should show Granted.
  1. Go to Entra ID > Enterprise apps and open TenuVault Desktop.
  2. Open Properties, set Visible to users? to No and save.
  1. In the same enterprise application, open Properties, set Assignment required? to Yes and save.
  2. Open Users and groups > Add user/group, select your security group and assign it.

Choose a plan on first launch, then sign in to your tenant with the client ID.