Skip to content

App registration and delegated permissions

The app registration TenuVault signs in with, every delegated permission it requests, and why.

TenuVault signs in through an app registration that you create in your own tenant. This page describes exactly what that app registration contains, which permissions it requests, and how you can restrict or revoke it.

For the step-by-step setup, see Create the app registration.

The setup script, New-TenuVaultDesktopApp.ps1, is available from the sign-in screen in TenuVault (Copy setup script) and in the public repository. It creates:

SettingValue
NameTenuVault Desktop by default. Change it with -DisplayName.
Supported account typesSingle tenant (accounts in your organization only).
Client typePublic client.
CredentialsNone. No client secret and no certificate.
Redirect URIshttp://localhost (sign-in through your system browser) and ms-appx-web://Microsoft.AAD.BrokerPlugin/<client ID> (sign-in through the Windows account broker).
PermissionsDelegated permissions only, listed below. No application permissions.
ConsentTenant-wide admin consent for the delegated permissions.
Enterprise appHidden from the My Apps portal.
Notes field“Used by the TenuVault desktop app. Delegated permissions only, no credentials.”

At the end, the script prints your tenant ID and the application (client) ID. You enter these in TenuVault when you sign in.

You need the Microsoft.Graph.Applications and Microsoft.Graph.Identity.SignIns PowerShell modules (the script installs them for the current user if they are missing) and one of these roles:

  • Global Administrator
  • Privileged Role Administrator
  • Cloud Application Administrator

The script connects to Microsoft Graph with the delegated scopes Application.ReadWrite.All, DelegatedPermissionGrant.ReadWrite.All and AppRoleAssignment.ReadWrite.All. It needs them only to create the app registration, grant consent and, if you use -AllowedGroupId, assign the group. TenuVault itself never uses these scopes.

Delegated permissions let an app act on behalf of a signed-in user. They never grant access on their own:

  • TenuVault can never do more than you can. The effective access is the overlap between the delegated permissions and the roles of the admin who signs in. An admin with a read-only Intune role cannot restore or change anything through TenuVault, even though the app registration requests write permissions.
  • There is no background identity. Without application permissions and without a secret, the app registration cannot get a token by itself. Every token belongs to a person who signed in.
  • Your sign-in controls apply. MFA, Conditional Access and sign-in frequency apply to every TenuVault session.
  • Changes are traceable. Writes appear under the signed-in admin’s name in the Intune and Entra audit logs.
PermissionWhy TenuVault needs it
User.ReadSigns you in and reads your own basic profile.
Organization.Read.AllReads your organization’s name and verified domains for the tenant overview.
Policy.Read.AllRequested by the setup script. See the note below the table.
DeviceManagementConfiguration.ReadWrite.AllBacks up and restores device configuration profiles, Settings Catalog and endpoint security policies, administrative templates, compliance policies, security baselines, Windows update profiles, assignment filters, policy sets, compliance notification templates and related configuration. Also used by Quick Start and Framework coverage to read and create Settings Catalog policies.
DeviceManagementApps.ReadWrite.AllBacks up and restores apps, app categories, app configuration policies and app protection policies.
DeviceManagementServiceConfig.ReadWrite.AllBacks up and restores enrollment configurations, Windows Autopilot deployment profiles, Apple enrollment profiles, terms and conditions and Company Portal branding.
DeviceManagementScripts.ReadWrite.AllBacks up and restores Windows PowerShell scripts, macOS shell scripts, macOS custom attributes, remediations and compliance scripts.
DeviceManagementRBAC.ReadWrite.AllBacks up and restores Intune roles, role assignments, scope tags and multi admin approval policies.
DeviceManagementManagedDevices.Read.AllReads device categories and device clean-up rules for backups, and the managed device count and compliance rate shown in the tenant overview. Read only: TenuVault cannot change or wipe devices.
PermissionWhy TenuVault needs it
user_impersonationLists the Azure subscriptions and storage accounts you can see, so you can pick a storage account for backups. Used only when you choose Your Azure storage account, encrypted as backup storage. TenuVault only reads these lists; it does not create or change subscriptions or storage accounts.
PermissionWhy TenuVault needs it
user_impersonationReads and writes backup files in your storage account. Used only when you store backups in Azure.

Delegated storage access also requires an Azure role on the storage account itself. The admin who signs in needs Storage Blob Data Contributor on the storage account.

The app registration only defines what TenuVault may request. What each admin can actually do depends on their own roles:

TaskRole
Back up, compare and restore Intune configurationAn Intune role such as Intune Administrator. A custom Intune role with fewer rights limits TenuVault in the same way.
Store backups in AzureStorage Blob Data Contributor on the storage account.

By default, tenant-wide admin consent lets any user in the tenant sign in to the app registration. Access is still limited by each user’s own Intune role, but you can narrow it further.

Run the setup script with -AllowedGroupId and the object ID of a security group:

./New-TenuVaultDesktopApp.ps1 -TenantId contoso.onmicrosoft.com -AllowedGroupId <group object ID>

The script sets Assignment required on the enterprise app and assigns the group. Only members of that group can then sign in to TenuVault. You can change the assigned users and groups later in the Microsoft Entra admin center, under Enterprise applications.

Because the app registration lives in your tenant, you can revoke TenuVault’s access at any time without contacting anyone:

  • Remove consent: in the Microsoft Entra admin center, open the enterprise app, go to Permissions and revoke the granted permissions. TenuVault can no longer obtain tokens with them.
  • Delete the app registration: TenuVault can no longer sign in to your tenant at all.
  • Disable sign-in: set Enabled for users to sign-in? to No on the enterprise app.

You can target the app registration with your own controls, for example:

  • A Conditional Access policy that requires a compliant device or phishing-resistant MFA for TenuVault sign-ins. On Windows, TenuVault signs in through the Windows account broker when it is available, which satisfies device-based Conditional Access. You can check which method is in use under Settings > About.
  • Sign-in frequency to control how long a TenuVault session lasts before you sign in again.