Start from OpenIntuneBaseline

Deploy, compare and validate the community baseline on every platform.
Deploy, compare and validate the OpenIntuneBaseline, then back up, restore and watch for drift from a desktop app that signs in as you. Your configuration never passes through a third-party server.
Free for one tenant, OpenIntuneBaseline included. Pro free for 30 days. New MSP offer coming soon.

Sign in with your own admin account , keep backups encrypted on this device or in your own Azure storage , and every change carries your name.
OpenIntuneBaseline, built in
OpenIntuneBaseline is the open Intune baseline by SkipToTheEndpoint and contributors. It stays independent and works with any tool. TenuVault loads the latest version from GitHub and helps you deploy it, keep it current and check it for drift.

New policies reach no device until you assign them, or go to one pilot group.
On by default once backup storage is set up: a full backup runs before anything changes, and if it fails, nothing is changed.
Undo deletes what a run created and puts back what it updated.
Customize a platform into your own versioned baseline and compare it with newer OIB versions.
OpenIntuneBaseline content: SkipToTheEndpoint and contributors, GPL-3.0. View on GitHub · Read the docs
Compare your Intune settings with independent, versioned framework mappings. Read-only, with PDF, CSV and JSON reports, included in Community.
A technical configuration comparison, not an audit or certification. No publisher endorsement is implied.

Deploy the baseline, protect it with backups, see what drifted and put back exactly what you need.

Deploy, compare and validate the community baseline on every platform.

Every policy type that matters, with assignments, encrypted on this device.

Restore any item as a copy, or in place with its assignments on Pro.

See what changed between backups, down to the setting.
When Conditional Access or policy rules out third party portals, TenuVault Desktop still fits. It is a public client in your own tenant, with no secret.
Only license checks go to tenuvault.com. Tenant configuration, backups and your Microsoft access token never do.
A calm, native feeling app for the tool you open when something went wrong.

Community is free for one tenant and includes OpenIntuneBaseline for every platform. Pro includes two tenants, daily backups and your own Azure storage, with a 30 day free trial. The new MSP offer includes five tenants and is coming soon. Prices in EUR, excluding VAT.
For admins who want a real safety net for one tenant.
Forever. No paid license or TenuVault web account.
DownloadFor organizations that must recover fast and control change.
2 tenants, billed monthly.
Start 30 day free trialFor service providers and organizations with 5 or more tenants.
Includes 5 tenants. Add more with graduated pricing.
Checkout opens when the new pricing and five-tenant license are ready.
An open Intune baseline for Windows, macOS, Windows 365 and BYOD, maintained by SkipToTheEndpoint and contributors under GPL-3.0. It is independent and works with any tool. TenuVault loads the latest version straight from GitHub.
Not until you assign the policies. New policies are created unassigned, or assigned only to a pilot group you enter, and policies already in the tenant are left out. A backup runs first unless you turn it off, and every run can be undone: undo deletes what the run created and puts back the previous version of what it updated.
No. Tenant data and your Microsoft access token never reach a TenuVault server. The app talks to Microsoft for sign in, Microsoft Graph and Azure, and to GitHub for updates and OpenIntuneBaseline files. License checks go to tenuvault.com and can include a Microsoft ID token as proof of the tenant; it is verified and never stored.
Delegated Microsoft Graph permissions for Intune configuration, apps, scripts and RBAC, plus Azure Storage only if backups go to your own storage account. The setup script lists and grants them. See the full list in the Trust Center.
One tenant with manual and weekly backups, 30 days of history, restoring single items as copies, drift detection, OpenIntuneBaseline for every platform and every framework except CIS, with PDF, CSV and JSON reports. No license key and no account needed.
Yes, with MSP. Cross tenant copies are created unassigned and require reviewed target dependencies, so nothing is pushed to devices by surprise.
Windows (EXE or MSI) or macOS, Apple silicon or Intel.
An admin runs New-TenuVaultDesktopApp.ps1 once to create it and grant consent.
Admins who use the app need an Intune role, for example Intune Administrator.
Community works without a key. Paste a Pro or MSP key on the License page.
Choose OpenIntuneBaseline in the sidebar and start a New Deployment.
Install, run the setup script, sign in. Your first backup is a few minutes away.
