Skip to content

Run your first backup

Take your first backup, read the progress log and confirm it worked.

The last setup step takes a first backup, so you know sign-in, permissions and storage all work before you rely on TenuVault.

On the First backup step, TenuVault shows Your tenant is connected.

  1. Select Run first backup.
  2. Watch the progress bar and the log. TenuVault first lists every Intune type (Reading Intune configuration…), then saves each object (Backing up <type>).
  3. When the backup ends, select Go to Backup & Restore to see it.

The first backup uses the default scope, Everything except apps: policies, scripts, updates, enrollment and tenant settings. To include apps, run a manual backup with Everything from Backup & Restore, described below. See What gets backed up.

To do it later, select Skip for now. TenuVault opens Tenants, and you can run the backup from Backup & Restore at any time.

  1. Open Backup & Restore and select the tenant.
  2. Select Run Backup.
  3. In Back up <tenant>, choose what to back up:
    • Everything except apps
    • Everything: also app details and assignments. Installer files are never included.
    • Custom: choose areas and individual types.
  4. Optional: select Also use this for automatic backups of <tenant> to save this choice for scheduled backups.
  5. Select Start backup.

For more on manual backups, see Run a backup.

ResultMeaning
Backup completed successfullyEvery object in scope was saved.
Backup completed with <n> warningsMost objects were saved, but some could not be read. The log lists each one with the reason. Older backups are kept because this backup is incomplete.
Backup failed: no policies could be savedNothing was saved. Check the log for the first error.

The log ends with a summary such as Backup completed: 214 policies in 1m 12s. Each type also gets a line such as Found 12 <type> and Backed up 12 <type>.

Log or error messageFix
Save your current backup recovery key in Settings before the first encrypted Azure backup.Open Settings > Storage and recovery and select Save recovery key, then run the backup again from Backup & Restore. See Save your recovery key.
Skipped <type>: the app registration lacks the permission. Run the setup script again to add it.Your app registration is missing a permission TenuVault now uses. Add the missing delegated permission and grant admin consent, as in Create the app registration manually.
Could not read <type>: …The log shows the error Microsoft Graph returned. If it is an access error, check that your Intune role includes this type.
A banner asks you to sign in againYour Microsoft session ended. Select Sign in in the banner, then run the backup again.
You do not have write access to storage account <name> …See Storage errors.

TenuVault is set up. Next: