Skip to content

Settings reference

Every control on the Settings page, what it does and when to use it.

Settings holds sign-in, backup storage, encryption, background backups and updates for this computer. Open it from the bottom of the sidebar.

The buttons at the top of the page jump to each section: Sign-in, Storage and recovery, Background and retention, Updates and About.

Settings apply to this computer only. Other admins who use TenuVault have their own settings.

The Appearance list at the top right sets the color theme.

OptionEffect
Use system settingFollows the light or dark mode of Windows or macOS, and switches when it changes. Default.
LightAlways light.
DarkAlways dark.

The Tenants card shows, for each connected tenant, who you are signed in as and where its backups are stored, for example Signed in as admin@contoso.com · Backups: This device (encrypted) or the name of the Azure storage account. Not signed in means TenuVault has no valid sign-in for the tenant.

If no tenant is connected, the card shows No tenants yet. with a link to Set up your first tenant.

ControlWhat it does
Sign in / Sign in againOpens a Microsoft sign-in for the tenant, pre-filled with the account last used. You must sign in to the same tenant; otherwise TenuVault shows You signed in to a different tenant. Sign in with an account from this tenant. Signing in again also rechecks the tenant’s license.
Change storageOpens Backup storage for <tenant>, where you choose between This device, encrypted and Your Azure storage account, encrypted.
  1. Select Change storage for the tenant.
  2. Choose the new location. For Azure, choose the Storage account and select Check access until it shows Access confirmed.
  3. Select Save. TenuVault confirms with Backups for <tenant> now go to <location>.

New backups go to the location you choose. Existing backups stay where they are and are only listed while that location is selected. Azure storage needs the Pro or MSP plan. For the options and errors, see Choose where backups are stored.

To add or remove tenants, use Tenants. See Manage tenants.

This card applies to tenants that keep backups on this device. Every backup file is encrypted with AES-256-GCM; file names reveal nothing about your policies.

ControlWhat it does
Import backup ZIPImports a backup exported as a ZIP file. TenuVault shows the source tenant, backup ID and SHA-256 hash, and asks you to confirm with Import locally. The snapshots are encrypted on this device. Import never changes Intune. See Backup storage and retention.
FolderShows the current backup folder. Default: Documents/TenuVault Backups.
Change folderChooses another folder, including a network share. Changing the folder does not move existing backups; move the folder’s contents yourself to keep them visible.
Open folderOpens the backup folder in Explorer or Finder, creating it if needed.

After an import, TenuVault shows Imported <backup>. Select this device as storage for tenant <tenant id> to preview and restore it. The archive must be smaller than 32 MiB, and your license must cover the source tenant.

The backup encryption key is protected by your Windows account or macOS Keychain. The same key encrypts backups on this device and backups uploaded to Azure storage.

ControlWhat it does
Key fingerprintIdentifies the current key. The recovery key file name includes it.
Save recovery keySaves the recovery key to a text file, by default Documents/TenuVault recovery key <fingerprint>.txt. The saved bundle includes all previous keys on this device. Required before the first Azure backup.
Import a recovery keyOpens a field where you paste a recovery key (TVK2. bundle, or a legacy TVK1. key) and select Import.

After you import a key, the imported key encrypts new backups, and backups made with the previous key stay readable. Save a new bundle after importing keys, so your saved recovery key covers every key on this device.

When a restore write to Intune ends without a clear answer (for example a timeout or a dropped connection), TenuVault records it and blocks an identical write until you confirm what happened. This history is where you do that.

ControlWhat it does
Restore history tenantChooses the tenant whose history is shown. Viewing it needs a current sign-in to that tenant, a license that covers it and Intune management access.
Refresh historyReloads the list.

Each entry shows the object name, time, state, tenant and the request (method and path). Request payloads and tokens are not stored. Interrupted writes stay blocked across restarts.

StateButtonsUse them when
uncertainConfirm appliedYou checked the target tenant in Intune and the change was made. Enter the object ID; a retry reuses it instead of repeating the write.
uncertainConfirm not appliedYou checked in Intune and the change was not made. The next attempt sends the write again.
reconciledCorrect applied IDYou entered the wrong object ID earlier. The next retry reads and verifies the object before any follow-up writes.
reconciledAllow a new operationYou deliberately want to send the same request again, which may create another object. Do not use it while resuming a repair.

Always check the target tenant in Intune before you resolve an entry. See What cannot be restored and restore write history.

Automatic backups run while TenuVault is running, in the window or in the system tray (the menu bar on macOS).

ControlWhat it does
Install background launchRegisters an operating system task that reopens TenuVault in the tray within five minutes while you are signed in to the computer. On Windows this is a Task Scheduler task for your user account; on macOS a LaunchAgent.
Remove background launchRemoves that task. Your backup schedules stay unchanged.

Background launch only helps while you are signed in to the computer. It does not run while you are signed out, or while the computer is asleep or off, and it does not wake the computer. Backups still need a valid Microsoft sign-in, plan access and available storage. The button is disabled with Available in installed Windows and macOS builds. when TenuVault is not an installed build.

To stop automatic restarts completely, remove background launch and turn off start at login before you quit TenuVault. If you move the app, install background launch again.

OptionDefaultEffect
Start TenuVault in the tray when I sign in to this computerOffStarts TenuVault hidden in the tray when you sign in to Windows or macOS.
Keep running in the tray when I close the windowOnClosing the window hides TenuVault instead of quitting, so schedules keep running. The first time, a notification says TenuVault is still running. When off, closing the window quits TenuVault on Windows; on macOS, TenuVault keeps running until you quit it.

The tray icon menu has Open TenuVault, Back up all tenants now, the next scheduled backup (or No scheduled backups) and Quit TenuVault.

Sets how long backups are kept: 7 days, 14 days, 30 days, 60 days, 90 days, 180 days, 365 days or Forever. Default: 30 days. The setting applies to every tenant on this computer.

  • Older backups are deleted after each successful backup. The newest backup is always kept.
  • If a backup is incomplete, no older backups are deleted.
  • A backup that is the newest copy of a type that later backups left out is kept.
  • Community tenants keep 30 days at most, even if you choose a longer period or Forever. Pro and MSP tenants keep what you choose.

See Backup storage and retention and Schedule backups.

ControlWhat it does
Download and install updates automaticallyOn by default. TenuVault checks 15 seconds after start and every 6 hours, downloads updates in the background and installs them when it restarts. Turning it off also stops a pending download.
Check nowChecks immediately. Disabled while automatic updates are off.
Restart and updateAppears when an update has downloaded. Restarts TenuVault and installs it.

The status line shows the current state:

StatusMeaning
Checking for updates…A check is running.
TenuVault is up to date.No newer version on your channel.
Downloading version <version> (<n>%)…An update is downloading.
Version <version> is ready to install.Select Restart and update, or it installs when you next quit.
Could not check for updates: <reason>The check failed, for example because GitHub is blocked. TenuVault keeps working.
Automatic updates are off.You turned automatic updates off.
Your organization manages updates for TenuVault.An administrator turned updates off by policy. The checkbox is locked. See Deploy TenuVault in your organization.

Nightly installs follow the nightly channel and stable installs follow stable. See Install and update TenuVault.

ItemShows
VersionTenuVault Desktop <version>
Sign-in method (Windows only)Signing in through the Windows account broker, so device-based Conditional Access applies. or The Windows account broker is unavailable; sign-in uses the browser.
Network summaryWhich services TenuVault talks to: Microsoft for sign-in, Graph and Azure; GitHub for the Open Intune Baseline catalog and updates; tenuvault.com for license checks. No tenant configuration or backup is ever sent to TenuVault.
LicenseOpens the License page. See Activate and manage your license.
Website and supportOpens tenuvault.com/desktop in your browser.