Skip to content

Requirements

Operating systems, admin roles and network access TenuVault needs.

Check these before you install. TenuVault runs on your own computer and signs in as you, so most requirements are about your computer, your admin roles and your network.

WindowsmacOS
Architecturex64 or Arm64Apple silicon (arm64) or Intel (x64)
InstallerSetup program (.exe) or MSI for managed deploymentDMG or ZIP
Credential storeWindows data protection (DPAPI) for your user accountmacOS Keychain

TenuVault encrypts its saved data (sign-ins, license and backup key) with the operating system’s credential store. If the credential store is not available, TenuVault does not start and shows OS encryption is not available. Enable the operating system credential store before opening TenuVault.

Someone must create the app registration TenuVault signs in with. The setup script does this in one step. The person who runs it needs one of these Microsoft Entra roles:

  • Global Administrator
  • Privileged Role Administrator
  • Cloud Application Administrator

The script grants tenant-wide admin consent, so the account must be allowed to consent. See Create the app registration.

TenuVault uses delegated permissions only. Every request runs as the signed-in admin, so the app can never do more than that admin can do in Intune.

You want toYou need
Back up, compare and restore Intune configurationAn Intune role, for example Intune Administrator. Read access is enough for backups; restores write to Intune and need write access to the objects you restore.
Store backups in your own Azure storage accountStorage Blob Data Contributor on the storage account, and a role that can read the storage account in Azure (for example Reader) so it appears in the storage picker.
Store backups on your computerNothing extra.

MFA and Conditional Access apply to TenuVault the same way they apply to the Intune admin center.

  • Windows: TenuVault signs in through the Windows account broker (Web Account Manager), so device-based Conditional Access policies are satisfied on compliant or Entra-joined devices. If the broker is not available, TenuVault falls back to the browser. Settings > About shows which method is in use.
  • macOS: TenuVault signs in through your default browser. Device-based Conditional Access on macOS needs the Microsoft Enterprise SSO extension on the device.

TenuVault connects to the global Microsoft cloud endpoints below over HTTPS (TCP 443). Allow them through your proxy or firewall.

DestinationUsed forRequired
login.microsoftonline.comMicrosoft sign-in and tokensYes
graph.microsoft.comReading and writing Intune configurationYes
tenuvault.comLicense checksYes
management.azure.comListing your subscriptions and storage accounts in the storage pickerOnly for Azure storage
<account>.blob.core.windows.netReading and writing backups in your storage accountOnly for Azure storage
github.com, release-assets.githubusercontent.com, objects.githubusercontent.comAutomatic updatesFor updates
api.github.com, raw.githubusercontent.comOpenIntuneBaseline packs for Quick Start and FrameworksFor baselines

If GitHub is blocked, updates and baseline packs fail, but backup and restore keep working. For what is sent to each destination, see Network connections and data flows.

If your storage account uses firewall rules, the computer running TenuVault must be allowed through them. Otherwise TenuVault reports that the storage account rejected the request from this network.

Install TenuVault.