Skip to content

Network connections and data flows

Every outbound connection TenuVault makes, what it sends, and what happens if you block it.

TenuVault connects to three groups of services: Microsoft (for your tenant and storage), tenuvault.com (for license checks only) and GitHub (for updates and baseline content). This page lists every destination and exactly what is sent to it, so you can review the data flows and configure your firewall or proxy.

All connections use HTTPS on TCP port 443. TenuVault opens no inbound ports. During browser sign-in, Microsoft redirects your browser to http://localhost on your own machine, where TenuVault receives the sign-in result.

DestinationPurposeCarries tenant data?
login.microsoftonline.comMicrosoft sign-in and tokensYour sign-in only
graph.microsoft.comRead and write your Intune configurationYes, between your machine and Microsoft
management.azure.comList subscriptions and storage accounts for the storage pickerNo
<your account>.blob.core.windows.netYour own Azure storage account, when you store backups thereYes, encrypted backups in your account
tenuvault.comLicense checksNo
github.com, release-assets.githubusercontent.com, objects.githubusercontent.comApp updatesNo
api.github.com, raw.githubusercontent.comOpenIntuneBaseline packs for Quick Start and Framework coverageNo

TenuVault contains no telemetry, analytics or crash reporting, and sends nothing else.

TenuVault signs you in with the Microsoft Authentication Library (MSAL) as a public client, using your app registration’s client ID and your tenant. On Windows it uses the Windows account broker when available; otherwise, and on macOS, it opens your system browser.

  • Sent: your sign-in, the client ID of your app registration and the requested scopes. There is no client secret.
  • Received: an access token for the requested resource, a refresh token and an ID token for your account.
  • Stored: tokens are kept in an encrypted token cache on your machine, protected by Windows DPAPI or the macOS Keychain. On Windows with the account broker, Windows manages your account.

All Intune work goes directly from your machine to Microsoft Graph with your delegated token:

  • Backups read your Intune configuration, including assignments.
  • Restores, drift reverts, Quick Start and Framework coverage write the objects you choose to your tenant.
  • The tenant overview reads your organization’s name and verified domains, policy counts, and your managed device count and compliance rate.

Nothing from these calls is sent anywhere else. Results are written only to the backup storage you chose.

Azure Resource Manager: management.azure.com

Section titled “Azure Resource Manager: management.azure.com”

Used only when you choose Your Azure storage account, encrypted as backup storage. TenuVault lists the subscriptions and storage accounts you can access so you can pick one. It sends only your token and the list requests.

Azure Storage: <your account>.blob.core.windows.net

Section titled “Azure Storage: <your account>.blob.core.windows.net”

Used only when you store backups in your own Azure storage account. TenuVault uses these containers:

ContainerContentsEncrypted by TenuVault
intune-backupsYour backupsYes. Each file is encrypted with AES-256-GCM on your machine before upload.
audit-logsThe TenuVault audit log for the tenant, including which admin started each actionNo. Protected by your storage account’s own encryption and access control.
tenant-metadataTenant profile information TenuVault keeps for the tenantNo. Protected by your storage account’s own encryption and access control.

See Encryption and recovery key for how backup encryption works.

When backups are stored on This device, encrypted, TenuVault makes no storage connection at all. Backups, the audit log and tenant metadata are all written encrypted to the folder you choose.

The only TenuVault server the app talks to is the licensing service at https://tenuvault.com/api/desktop-license/. It is used to activate, refresh and release licenses. The app never contacts the payment provider directly.

  • The first time you use a tenant, to activate it.
  • Every 6 hours while the app runs, to refresh each activation.
  • When you enter a key, change license sharing, click Retry on the License page, remove a tenant or deactivate the machine.
  • For a tenant on Community, at most every 6 hours, to check whether a license has become available (for example one your organization shared).
RequestFields sent
Activate a license key for a tenantLicense key, installation ID, tenant ID, operating system, app version. When you are signed in to the tenant: the app registration’s client ID and, when one can be obtained without prompting you, a Microsoft ID token.
Refresh a license key activationLicense key, activation ID, installation ID, tenant ID. When sharing is on or not yet decided: the client ID and, when available, a Microsoft ID token. Your sharing choice, once one is set.
Organization license (a license shared with your tenant)Microsoft ID token, installation ID, operating system, app version, the action (activate, refresh or release) and, for refresh and release, the activation ID and the license’s ID. The license key is not sent and never reaches your machine.
Release (remove a tenant or deactivate the machine)License key and activation ID. For an organization license, the fields in the row above.

What each field is:

  • License key: the key from your purchase email. Community sends no key.
  • Installation ID: a random identifier generated on your machine and kept in its encrypted store. It identifies this installation, not you or your device.
  • Tenant ID: the ID of the tenant being licensed. Licenses are counted per tenant.
  • Client ID: the application (client) ID of your app registration. When you share a license with your tenant, only admins who sign in through this app registration are licensed by it.
  • Operating system and app version: win32 or darwin, and the TenuVault version number.
  • Microsoft ID token: proof of which tenant and app registration you signed in to. It contains identity claims, such as your name and user principal name. The app only sends a token issued within the last few minutes, and never sends access tokens or refresh tokens.
  • It checks the license key with the payment provider and records the activation there, with the installation ID, tenant ID, operating system and app version.
  • It verifies the Microsoft ID token against Microsoft’s public signing keys and uses only its tenant ID and audience (your client ID) to decide whether the license applies. The token is not stored.
  • When you share a license with a tenant, it stores the link between that tenant ID, the license and your app registration’s client ID, so other admins in the tenant can be licensed. The license key itself is not stored in this link.
  • It answers with an entitlement token signed by TenuVault, bound to the tenant and your installation. The app verifies it offline with a public key built into the app.

As with any web request, the service also sees your public IP address. It uses it only to limit the number of requests per address.

Tenant configuration, backups, policy names, device or user information, access tokens, refresh tokens and your backup recovery key are never sent to tenuvault.com.

Tenants that are already active keep working offline for up to 14 days after their last successful check. A new tenant cannot be activated on a paid plan until the service is reachable. On a machine without a license key, the Community tenant works without any connection to tenuvault.com.

DestinationWhat it is used for
github.comReads the public release feed of ugurkocde/tenuvault-desktop to find new versions.
release-assets.githubusercontent.com, objects.githubusercontent.comGitHub redirects release downloads to these hosts. Allow them as well as github.com.

The updater checks 15 seconds after the app starts and then every 6 hours. It downloads public files only and uploads nothing. You can turn updates off in Settings > Updates, or by policy on managed devices. See Install and update TenuVault.

If these hosts are blocked, update checks and downloads fail. The installed version keeps working.

DestinationWhat it is used for
api.github.comLists OpenIntuneBaseline releases and repository files when you load a pack in Quick Start or Framework coverage.
raw.githubusercontent.comDownloads the public policy files of the selected pack.

These requests download public files from the OpenIntuneBaseline repository. They send no tenant data and no tokens. Loading a pack and deploying it to your tenant are separate steps; the deployment itself goes to Microsoft Graph.

If these hosts are blocked, packs that are not already loaded in the current session cannot load. Backups and restores are not affected.

Some buttons open a web page in your default browser instead of making a request from the app, for example Try Pro or MSP free for 30 days, Start 30 day free trial, Manage subscription and Setup guide. These pages are visited by your browser only when you click them. TenuVault only opens https and mailto links, and never loads external pages inside the app window.

To use every feature, allow outbound HTTPS (TCP 443) to:

login.microsoftonline.com
graph.microsoft.com
management.azure.com
<your storage account>.blob.core.windows.net
tenuvault.com
github.com
release-assets.githubusercontent.com
objects.githubusercontent.com
api.github.com
raw.githubusercontent.com

management.azure.com and your storage account are needed only for backups in Azure. The GitHub hosts are needed only for updates and baseline packs.