Network connections and data flows
Every outbound connection TenuVault makes, what it sends, and what happens if you block it.
TenuVault connects to three groups of services: Microsoft (for your tenant and storage), tenuvault.com (for license checks only) and GitHub (for updates and baseline content). This page lists every destination and exactly what is sent to it, so you can review the data flows and configure your firewall or proxy.
All connections use HTTPS on TCP port 443. TenuVault opens no inbound ports. During browser sign-in, Microsoft redirects your browser to http://localhost on your own machine, where TenuVault receives the sign-in result.
Summary
Section titled “Summary”| Destination | Purpose | Carries tenant data? |
|---|---|---|
login.microsoftonline.com | Microsoft sign-in and tokens | Your sign-in only |
graph.microsoft.com | Read and write your Intune configuration | Yes, between your machine and Microsoft |
management.azure.com | List subscriptions and storage accounts for the storage picker | No |
<your account>.blob.core.windows.net | Your own Azure storage account, when you store backups there | Yes, encrypted backups in your account |
tenuvault.com | License checks | No |
github.com, release-assets.githubusercontent.com, objects.githubusercontent.com | App updates | No |
api.github.com, raw.githubusercontent.com | OpenIntuneBaseline packs for Quick Start and Framework coverage | No |
TenuVault contains no telemetry, analytics or crash reporting, and sends nothing else.
Microsoft
Section titled “Microsoft”Sign-in: login.microsoftonline.com
Section titled “Sign-in: login.microsoftonline.com”TenuVault signs you in with the Microsoft Authentication Library (MSAL) as a public client, using your app registration’s client ID and your tenant. On Windows it uses the Windows account broker when available; otherwise, and on macOS, it opens your system browser.
- Sent: your sign-in, the client ID of your app registration and the requested scopes. There is no client secret.
- Received: an access token for the requested resource, a refresh token and an ID token for your account.
- Stored: tokens are kept in an encrypted token cache on your machine, protected by Windows DPAPI or the macOS Keychain. On Windows with the account broker, Windows manages your account.
Intune: graph.microsoft.com
Section titled “Intune: graph.microsoft.com”All Intune work goes directly from your machine to Microsoft Graph with your delegated token:
- Backups read your Intune configuration, including assignments.
- Restores, drift reverts, Quick Start and Framework coverage write the objects you choose to your tenant.
- The tenant overview reads your organization’s name and verified domains, policy counts, and your managed device count and compliance rate.
Nothing from these calls is sent anywhere else. Results are written only to the backup storage you chose.
Azure Resource Manager: management.azure.com
Section titled “Azure Resource Manager: management.azure.com”Used only when you choose Your Azure storage account, encrypted as backup storage. TenuVault lists the subscriptions and storage accounts you can access so you can pick one. It sends only your token and the list requests.
Azure Storage: <your account>.blob.core.windows.net
Section titled “Azure Storage: <your account>.blob.core.windows.net”Used only when you store backups in your own Azure storage account. TenuVault uses these containers:
| Container | Contents | Encrypted by TenuVault |
|---|---|---|
intune-backups | Your backups | Yes. Each file is encrypted with AES-256-GCM on your machine before upload. |
audit-logs | The TenuVault audit log for the tenant, including which admin started each action | No. Protected by your storage account’s own encryption and access control. |
tenant-metadata | Tenant profile information TenuVault keeps for the tenant | No. Protected by your storage account’s own encryption and access control. |
See Encryption and recovery key for how backup encryption works.
When backups are stored on This device, encrypted, TenuVault makes no storage connection at all. Backups, the audit log and tenant metadata are all written encrypted to the folder you choose.
tenuvault.com: license checks
Section titled “tenuvault.com: license checks”The only TenuVault server the app talks to is the licensing service at https://tenuvault.com/api/desktop-license/. It is used to activate, refresh and release licenses. The app never contacts the payment provider directly.
When the app connects
Section titled “When the app connects”- The first time you use a tenant, to activate it.
- Every 6 hours while the app runs, to refresh each activation.
- When you enter a key, change license sharing, click Retry on the License page, remove a tenant or deactivate the machine.
- For a tenant on Community, at most every 6 hours, to check whether a license has become available (for example one your organization shared).
Exactly what is sent
Section titled “Exactly what is sent”| Request | Fields sent |
|---|---|
| Activate a license key for a tenant | License key, installation ID, tenant ID, operating system, app version. When you are signed in to the tenant: the app registration’s client ID and, when one can be obtained without prompting you, a Microsoft ID token. |
| Refresh a license key activation | License key, activation ID, installation ID, tenant ID. When sharing is on or not yet decided: the client ID and, when available, a Microsoft ID token. Your sharing choice, once one is set. |
| Organization license (a license shared with your tenant) | Microsoft ID token, installation ID, operating system, app version, the action (activate, refresh or release) and, for refresh and release, the activation ID and the license’s ID. The license key is not sent and never reaches your machine. |
| Release (remove a tenant or deactivate the machine) | License key and activation ID. For an organization license, the fields in the row above. |
What each field is:
- License key: the key from your purchase email. Community sends no key.
- Installation ID: a random identifier generated on your machine and kept in its encrypted store. It identifies this installation, not you or your device.
- Tenant ID: the ID of the tenant being licensed. Licenses are counted per tenant.
- Client ID: the application (client) ID of your app registration. When you share a license with your tenant, only admins who sign in through this app registration are licensed by it.
- Operating system and app version:
win32ordarwin, and the TenuVault version number. - Microsoft ID token: proof of which tenant and app registration you signed in to. It contains identity claims, such as your name and user principal name. The app only sends a token issued within the last few minutes, and never sends access tokens or refresh tokens.
What the licensing service does with it
Section titled “What the licensing service does with it”- It checks the license key with the payment provider and records the activation there, with the installation ID, tenant ID, operating system and app version.
- It verifies the Microsoft ID token against Microsoft’s public signing keys and uses only its tenant ID and audience (your client ID) to decide whether the license applies. The token is not stored.
- When you share a license with a tenant, it stores the link between that tenant ID, the license and your app registration’s client ID, so other admins in the tenant can be licensed. The license key itself is not stored in this link.
- It answers with an entitlement token signed by TenuVault, bound to the tenant and your installation. The app verifies it offline with a public key built into the app.
As with any web request, the service also sees your public IP address. It uses it only to limit the number of requests per address.
What is never sent
Section titled “What is never sent”Tenant configuration, backups, policy names, device or user information, access tokens, refresh tokens and your backup recovery key are never sent to tenuvault.com.
If tenuvault.com is blocked
Section titled “If tenuvault.com is blocked”Tenants that are already active keep working offline for up to 14 days after their last successful check. A new tenant cannot be activated on a paid plan until the service is reachable. On a machine without a license key, the Community tenant works without any connection to tenuvault.com.
GitHub
Section titled “GitHub”App updates
Section titled “App updates”| Destination | What it is used for |
|---|---|
github.com | Reads the public release feed of ugurkocde/tenuvault-desktop to find new versions. |
release-assets.githubusercontent.com, objects.githubusercontent.com | GitHub redirects release downloads to these hosts. Allow them as well as github.com. |
The updater checks 15 seconds after the app starts and then every 6 hours. It downloads public files only and uploads nothing. You can turn updates off in Settings > Updates, or by policy on managed devices. See Install and update TenuVault.
If these hosts are blocked, update checks and downloads fail. The installed version keeps working.
OpenIntuneBaseline packs
Section titled “OpenIntuneBaseline packs”| Destination | What it is used for |
|---|---|
api.github.com | Lists OpenIntuneBaseline releases and repository files when you load a pack in Quick Start or Framework coverage. |
raw.githubusercontent.com | Downloads the public policy files of the selected pack. |
These requests download public files from the OpenIntuneBaseline repository. They send no tenant data and no tokens. Loading a pack and deploying it to your tenant are separate steps; the deployment itself goes to Microsoft Graph.
If these hosts are blocked, packs that are not already loaded in the current session cannot load. Backups and restores are not affected.
Links that open in your browser
Section titled “Links that open in your browser”Some buttons open a web page in your default browser instead of making a request from the app, for example Try Pro or MSP free for 30 days, Start 30 day free trial, Manage subscription and Setup guide. These pages are visited by your browser only when you click them. TenuVault only opens https and mailto links, and never loads external pages inside the app window.
Firewall allow list
Section titled “Firewall allow list”To use every feature, allow outbound HTTPS (TCP 443) to:
login.microsoftonline.comgraph.microsoft.commanagement.azure.com<your storage account>.blob.core.windows.nettenuvault.comgithub.comrelease-assets.githubusercontent.comobjects.githubusercontent.comapi.github.comraw.githubusercontent.commanagement.azure.com and your storage account are needed only for backups in Azure. The GitHub hosts are needed only for updates and baseline packs.