Skip to content

Choose where backups are stored

Keep backups encrypted on this device or in your own Azure storage account, and save your recovery key.

On the Storage step you choose where this tenant’s backups go. Both options encrypt every backup with AES-256-GCM before it is written, and neither sends anything to TenuVault.

You can change the location later in Settings > Sign-in > Change storage.

This device, encryptedYour Azure storage account, encrypted
PlanAll plansPro and MSP
Where backups liveA folder on this computer or a network share, by default Documents/TenuVault BackupsThe intune-backups container in a storage account in your Azure subscription
Azure resources neededNoneAn existing storage account
Extra rolesNoneStorage Blob Data Contributor on the storage account, plus read access to the storage account (for example Reader) so it appears in the list
Other computers can read the backupsWith the recovery key and a copy of the folderWith the recovery key and access to the storage account
Before the first backupSaving the recovery key is strongly recommendedSaving the recovery key is required
  1. Select This device, encrypted. It is selected by default.
  2. TenuVault shows the backup folder under the option.
  3. Select Continue.

Backups are encrypted with a key protected by your Windows account or macOS Keychain. Nothing leaves this computer. Each backup file is encrypted on its own, and file names reveal nothing about your policies.

To use a different folder, such as a network share, change it in Settings > Storage and recovery > Change folder. See Backup storage and retention.

Option 2: Your Azure storage account, encrypted

Section titled “Option 2: Your Azure storage account, encrypted”

You need an existing storage account in a subscription of the tenant you signed in to. TenuVault does not create Azure resources.

  1. Select Your Azure storage account, encrypted. TenuVault shows Loading your storage accounts… while it lists the storage accounts your account can see across your subscriptions.
  2. In Storage account, choose the account. Each entry shows its name, resource group and region.
  3. Select Check access. TenuVault creates the intune-backups container if it does not exist, then writes and deletes a small test file to confirm you can store backups there.
  4. When the button shows Access confirmed, select Continue.
MessageWhat it means
No storage accounts found that your account can see. Ask an Azure administrator to create one and grant you access.Your account cannot read any storage account in Azure. Ask for a storage account and a role that can read it, such as Reader.
You do not have write access to storage account <name>. Ask an Azure administrator for the “Storage Blob Data Contributor” role on it. New role assignments can take a few minutes to apply.Assign Storage Blob Data Contributor on the storage account to your account, wait a few minutes, then select Check access again.
Storage account <name> rejected the request from this network. Allow this computer’s public IP address in the storage account’s networking settings, or connect through a network it allows.The storage account firewall blocks this computer. This is a network rule, not a missing role.
Storage account <name> could not be reached.Check your network, proxy and access to <name>.blob.core.windows.net.

TenuVault keeps one backup encryption key per computer, protected by your Windows account or macOS Keychain. The recovery key is an exported copy of it. You need it to read your backups on another computer, after reinstalling, or after a new Windows or macOS profile.

  1. Open Settings > Storage and recovery. You can do this during setup; TenuVault remembers your setup step.
  2. Under Encryption key, select Save recovery key.
  3. Choose where to save the file. By default it is Documents/TenuVault recovery key <fingerprint>.txt.
  4. Move the key into your password manager or another safe place, then delete the file.

Anyone with the recovery key and your backup files can read your Intune configuration. Store it like a password. For how the key works, see Encryption and recovery key.

When you select Continue, TenuVault checks the license for the tenant once more and saves it. Setup moves to First backup.

Run your first backup.