Create the app registration
Create the app registration TenuVault signs in with.
TenuVault signs in through an app registration that lives in your own tenant. A PowerShell setup script creates it in one step and prints the two values you enter in the app: the tenant ID and the client ID.
You do this once per tenant. Every admin who uses TenuVault in that tenant signs in through the same app registration.
What the script creates
Section titled “What the script creates”| Setting | Value |
|---|---|
| Name | TenuVault Desktop (change it with -DisplayName) |
| Supported account types | Accounts in this organizational directory only (single tenant) |
| Client type | Public client: no client secret and no certificate |
| Redirect URIs | http://localhost (browser sign-in) and ms-appx-web://Microsoft.AAD.BrokerPlugin/<client id> (Windows account broker) |
| Permissions | Delegated permissions only, listed below |
| Admin consent | Granted tenant-wide for all of the permissions below |
| Enterprise application | Hidden from users’ My Apps portal |
| Sign-in restriction | Optional: only members of one group can sign in (-AllowedGroupId) |
Because the app is a public client with delegated permissions, every call runs as the signed-in admin. MFA, Conditional Access and your Intune role apply, and changes are attributed to that admin in the Entra and Intune audit logs.
Delegated permissions
Section titled “Delegated permissions”| API | Permission |
|---|---|
| Microsoft Graph | User.Read |
| Microsoft Graph | Organization.Read.All |
| Microsoft Graph | Policy.Read.All |
| Microsoft Graph | DeviceManagementConfiguration.ReadWrite.All |
| Microsoft Graph | DeviceManagementApps.ReadWrite.All |
| Microsoft Graph | DeviceManagementServiceConfig.ReadWrite.All |
| Microsoft Graph | DeviceManagementScripts.ReadWrite.All |
| Microsoft Graph | DeviceManagementRBAC.ReadWrite.All |
| Microsoft Graph | DeviceManagementManagedDevices.Read.All |
| Azure Service Management | user_impersonation |
| Azure Storage | user_impersonation |
The two Azure permissions are only used when backups go to your Azure storage account: Azure Service Management lists your subscriptions and storage accounts in the storage picker, and Azure Storage reads and writes the backup files. For what each permission is used for, see App registration and delegated permissions.
Before you start
Section titled “Before you start”- An account with Global Administrator, Privileged Role Administrator or Cloud Application Administrator, which can grant admin consent.
- PowerShell: Windows PowerShell 5.1 or PowerShell 7 on Windows, PowerShell 7 (
pwsh) on macOS. - The Microsoft Graph PowerShell modules
Microsoft.Graph.ApplicationsandMicrosoft.Graph.Identity.SignIns. If they are missing, the script installs them for the current user from the PowerShell Gallery. - Optional: the object ID of a security group, if only its members should be able to sign in.
Get the script
Section titled “Get the script”The setup script is built into TenuVault.
- Start TenuVault. If it shows Welcome to TenuVault, select a plan first; see Choose a plan on first launch. You can change your plan later.
- On the Prepare step of Set up TenuVault, select Copy setup script. You also find this button in Tenants > Connect tenant under First time? Create an app registration.
- Paste the script into a text editor and save it as
New-TenuVaultDesktopApp.ps1.
If someone else creates the app registration for you, send them the saved file.
Run the script
Section titled “Run the script”-
Open PowerShell in the folder where you saved the script.
-
Run the script with the parameters you need:
./New-TenuVaultDesktopApp.ps1 -TenantId contoso.onmicrosoft.comTo limit sign-in to the members of one security group:
./New-TenuVaultDesktopApp.ps1 -TenantId contoso.onmicrosoft.com -DisplayName "TenuVault Desktop" -AllowedGroupId 00000000-0000-0000-0000-000000000000 -
Sign in with your admin account when Microsoft Graph PowerShell asks you to. If you are prompted to consent to the permissions Graph PowerShell requests, accept. The script connects with
Application.ReadWrite.All,DelegatedPermissionGrant.ReadWrite.AllandAppRoleAssignment.ReadWrite.Allto create the app and grant consent. -
Wait for the script to finish. It prints:
Done. Enter these values in TenuVault > Tenants > Add tenant:Tenant id: <tenant id>Application (client) id: <client id> -
Copy the Application (client) id. You enter it when you sign in to your tenant. The tenant ID is always printed as a GUID, even if you passed a domain.
Parameters
Section titled “Parameters”| Parameter | Required | Description |
|---|---|---|
-TenantId | No | Tenant ID or domain to create the app registration in. Defaults to the tenant of the account you sign in with. |
-DisplayName | No | Name of the app registration. Default: TenuVault Desktop. |
-AllowedGroupId | No | Object ID of a security group. When set, user assignment is required on the enterprise application and only members of this group can sign in to TenuVault. |
Execution policy
Section titled “Execution policy”If PowerShell refuses to run the saved script because of the execution policy, allow scripts for the current session only and run it again:
Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass./New-TenuVaultDesktopApp.ps1 -TenantId contoso.onmicrosoft.comCreate the app registration manually
Section titled “Create the app registration manually”If you cannot run PowerShell, you can create the same app registration in the Microsoft Entra admin center. These steps reproduce every setting the script makes.
1. Register the app
Section titled “1. Register the app”- Go to Entra ID > App registrations > New registration.
- Name:
TenuVault Desktop. - Supported account types: Accounts in this organizational directory only (single tenant).
- Leave Redirect URI empty and select Register.
- On the Overview page, copy the Application (client) ID and the Directory (tenant) ID.
- Optional: under Branding & properties, set Internal notes to
Used by the TenuVault desktop app. Delegated permissions only, no credentials.The script adds this note; it has no effect on sign-in.
2. Add the redirect URIs
Section titled “2. Add the redirect URIs”- Open Authentication and select Add a platform > Mobile and desktop applications.
- Add these two custom redirect URIs, replacing
<client id>with the Application (client) ID from step 1:http://localhostms-appx-web://Microsoft.AAD.BrokerPlugin/<client id>
- Select Configure.
- Under Advanced settings, set Allow public client flows to Yes and save.
Do not add a client secret or a certificate.
3. Add the delegated permissions
Section titled “3. Add the delegated permissions”- Open API permissions > Add a permission.
- Select Microsoft Graph > Delegated permissions and add the nine Graph permissions listed in Delegated permissions.
User.Readis usually already present. - Select Add a permission again. Under Microsoft APIs (or APIs my organization uses), choose Azure Service Management > Delegated permissions >
user_impersonation. - Repeat for Azure Storage > Delegated permissions >
user_impersonation. - Select Grant admin consent for <your tenant> and confirm. Every permission should show Granted.
4. Hide the app from My Apps
Section titled “4. Hide the app from My Apps”- Go to Entra ID > Enterprise apps and open TenuVault Desktop.
- Open Properties, set Visible to users? to No and save.
5. Optional: limit sign-in to one group
Section titled “5. Optional: limit sign-in to one group”- In the same enterprise application, open Properties, set Assignment required? to Yes and save.
- Open Users and groups > Add user/group, select your security group and assign it.
Next step
Section titled “Next step”Choose a plan on first launch, then sign in to your tenant with the client ID.