Run your first backup
Take your first backup, read the progress log and confirm it worked.
The last setup step takes a first backup, so you know sign-in, permissions and storage all work before you rely on TenuVault.
Run it from the guided setup
Section titled “Run it from the guided setup”On the First backup step, TenuVault shows Your tenant is connected.
- Select Run first backup.
- Watch the progress bar and the log. TenuVault first lists every Intune type (Reading Intune configuration…), then saves each object (Backing up <type>).
- When the backup ends, select Go to Backup & Restore to see it.
The first backup uses the default scope, Everything except apps: policies, scripts, updates, enrollment and tenant settings. To include apps, run a manual backup with Everything from Backup & Restore, described below. See What gets backed up.
To do it later, select Skip for now. TenuVault opens Tenants, and you can run the backup from Backup & Restore at any time.
Run it from Backup & Restore
Section titled “Run it from Backup & Restore”- Open Backup & Restore and select the tenant.
- Select Run Backup.
- In Back up <tenant>, choose what to back up:
- Everything except apps
- Everything: also app details and assignments. Installer files are never included.
- Custom: choose areas and individual types.
- Optional: select Also use this for automatic backups of <tenant> to save this choice for scheduled backups.
- Select Start backup.
For more on manual backups, see Run a backup.
Read the result
Section titled “Read the result”| Result | Meaning |
|---|---|
| Backup completed successfully | Every object in scope was saved. |
| Backup completed with <n> warnings | Most objects were saved, but some could not be read. The log lists each one with the reason. Older backups are kept because this backup is incomplete. |
| Backup failed: no policies could be saved | Nothing was saved. Check the log for the first error. |
The log ends with a summary such as Backup completed: 214 policies in 1m 12s. Each type also gets a line such as Found 12 <type> and Backed up 12 <type>.
Common problems on the first backup
Section titled “Common problems on the first backup”| Log or error message | Fix |
|---|---|
| Save your current backup recovery key in Settings before the first encrypted Azure backup. | Open Settings > Storage and recovery and select Save recovery key, then run the backup again from Backup & Restore. See Save your recovery key. |
| Skipped <type>: the app registration lacks the permission. Run the setup script again to add it. | Your app registration is missing a permission TenuVault now uses. Add the missing delegated permission and grant admin consent, as in Create the app registration manually. |
| Could not read <type>: … | The log shows the error Microsoft Graph returned. If it is an access error, check that your Intune role includes this type. |
| A banner asks you to sign in again | Your Microsoft session ended. Select Sign in in the banner, then run the backup again. |
| You do not have write access to storage account <name> … | See Storage errors. |
You are done
Section titled “You are done”TenuVault is set up. Next:
- Schedule backups. Community tenants can back up weekly; Pro and MSP can also back up daily.
- Keep TenuVault running in the tray so schedules run. See Settings reference.
- Learn how to restore items and detect drift.