Skip to main content

TenuVault Desktop

Intune backup: back up and restore Microsoft Intune policies

TenuVault is a desktop app for Windows and macOS that backs up and restores Microsoft Intune configuration through Microsoft Graph, using your own delegated admin sign-in. It saves policies, scripts, apps and their assignments as encrypted snapshots on your computer or in your own Azure storage, and restores them as reviewed copies or in place. Scheduled backups use Everything except apps until you save a different choice for the tenant.

At a glance

  • TenuVault runs on Windows and macOS and reads Intune through Microsoft Graph with the signed-in administrator's delegated permissions.
  • A TenuVault backup covers 39 Intune object types in nine areas, with assignments where Intune has them.
  • Every TenuVault backup is encrypted with AES-256-GCM on the admin's computer before it is written to disk or uploaded.
  • TenuVault Community stores backups on the device; Pro and MSP can also store them in your own Azure storage account.
  • TenuVault Community is free for one tenant with manual and weekly backups and 30 days of history; Pro adds daily schedules, custom retention, replace in place and assignment restore for two tenants.
  • Tenant data and your Microsoft access token never reach a TenuVault server; the app talks to Microsoft for sign-in, Microsoft Graph and Azure, to GitHub for updates and OpenIntuneBaseline files, and to tenuvault.com for license checks.
TenuVault Desktop schedule settings for automatic Intune configuration backups
Product screenshot with fictional demo data. Scheduling requires an awake computer and an active user session.

Does Intune have built-in backup?

No. Microsoft documents no recycle bin, soft delete or version history for Intune policies, and no restore path for a deleted policy; the documented recovery approach is to recreate it from a prior export or backup.

The closest native tool is the settings catalog export: you export one policy to a .json file and import it to create a new policy. Microsoft does not say whether assignments are included.

For tenant migration, Microsoft points to Graph and PowerShell sample scripts and warns: "The scripts don't export and import every policy, such as certificate profiles."

Tenant Configuration Management (TCM), part of Microsoft Entra Tenant Governance, snapshots 67 Intune resource types, but not apps, scripts or remediations. Microsoft states: "A snapshot is retained for a maximum of seven days, after which it is automatically deleted." The base quota is stated as: "You can extract a maximum of 20000 resources per tenant per month." Monitors run in monitorOnly mode, so TCM detects drift but does not restore.

TCM base capacity comes with Microsoft Entra ID P1 or P2, included in Microsoft 365 E3, E5 and Business Premium. Entra ID Governance licenses add capacity; Entra ID Free gets none.

Windows settings backup and restore, formerly Windows Backup for Organizations, supports "backup and restore of Windows settings and the list of installed Microsoft Store apps only". Microsoft Entra Backup and Recovery covers no Intune objects.

Intune audit logs show who changed what, and you can "use Graph API to get two years of audit events". They record changed properties, not full policy content, so they cannot rebuild a deleted policy.

What TenuVault backs up

TenuVault backs up 39 Intune object types in nine areas. Each object is saved as Microsoft Graph (beta) returns it, with its settings and, where Intune has them, its assignments. Choose Everything, Everything except apps, or a custom selection. Scheduled backups use Everything except apps until you save a different choice for the tenant, so include apps explicitly if you need them.

Not part of the backup:

  • App installer files; apps are saved as their Intune details.
  • The Entra groups that assignments reference.
  • Apple and Android Enterprise enrollment tokens, and built-in objects Intune recreates itself.
  • Enrolled devices, and types your permissions cannot read; the log reports them.
Intune object types in a TenuVault backup, by area
AreaObject typesAssignments saved
Device configurationDevice configuration profiles, including custom OMA-URI profiles and Windows update rings; settings catalog and endpoint security policies; administrative templates; reusable settings; BIOS configurationsYes, except reusable settings
ComplianceCompliance policies with their noncompliance actions; settings catalog compliance policies; compliance scriptsYes
Endpoint securitySecurity baselines and template profilesYes
Scripts and remediationsWindows PowerShell scripts; macOS shell scripts; macOS custom attributes; remediationsYes
Windows updatesFeature update, expedited quality update, hotpatch quality update and driver update profilesYes
AppsApps with their categories, dependency and supersedence links; app categories; policy setsYes, except app categories
App protection and configurationApp configuration policies for managed devices and for managed apps; iOS, Android and Windows app protection policiesYes
EnrollmentEnrollment configurations; Windows Autopilot deployment profiles; Apple user enrollment profiles; Apple automated device enrollment profiles, and token details for reference only (the token itself must be uploaded again); Android Enterprise enrollment profiles; device categories; terms and conditionsYes, except Apple automated enrollment, Android Enterprise profiles and device categories
Tenant administrationAssignment filters; scope tags; custom Intune roles with their role assignments; compliance notification templates; Company Portal branding; device clean-up rules; multi admin approval policiesScope tags, Intune roles and Company Portal branding

What a configuration backup cannot recover

Microsoft Graph does not return app installer payloads, Apple enrollment and content tokens, or private keys, so no Intune backup can contain them.

Plan a separate source for each, and check Recovery readiness in the restore wizard before an incident.

  • Win32, line-of-business and MSI apps need their original installer. Store, web and Microsoft 365 apps restore without one.
  • Apple automated device enrollment needs its token uploaded again; profiles are kept for reference.
  • Restoring configuration does not enroll or migrate devices.

Where backups are stored

Each tenant keeps its backups in one location: encrypted on the device, or encrypted in your own Azure storage account. TenuVault never sends backups to a TenuVault server.

Save the recovery key in a password manager. Without it, backups can only be read on the computer and user account that created them. In Azure, blob names, which include display names, are not encrypted.

Scroll sideways to see all columns.

Backup storage, encryption, schedule and history by plan
PlanStorageEncryptionScheduleBackup history
CommunityThis device or a network shareAES-256-GCM, key protected by Windows DPAPI or the macOS KeychainManual and weeklyCleanup after 30 days
ProThis device or a network share, or your own Azure storage accountAES-256-GCM on your computer before writing or uploadManual, weekly or daily7 to 365 days, or forever
MSPPer tenant: this device or a network share, or a customer-controlled Azure storage accountAES-256-GCM on your computer before writing or uploadManual, weekly or daily, per tenant7 to 365 days, or forever

How restore works

Every restore starts from a backup snapshot and ends with a review step before TenuVault writes to Intune. The plan decides which methods are available.

Replace in place does not keep the version it overwrites, so back up first. If a write's outcome is uncertain, TenuVault blocks an identical write until you check Intune, which prevents duplicates.

TenuVault restore methods and the plans that include them
MethodWhat it doesPlans
Create copiesCreates each item next to the current one with a [Restored] name prefix. Existing items never change. Copies are unassigned unless you restore assignments.All plans. Community restores one item at a time as an unassigned copy.
Replace in placeReads each item from the tenant first. Changed items go back to the backed-up version, deleted items are recreated under their original name with a new ID, and matching items are skipped.Pro and MSP
Restore assignmentsApplies the groups and filters recorded in the backup. When replacing, assignments added since the backup are removed.Pro and MSP
Copy to other tenantsCreates unassigned copies in other connected tenants, with their original names and the Default scope tag.MSP, on every tenant involved

Schedules and retention

Community schedules a weekly backup; Pro and MSP add daily schedules. Schedules run from the desktop app, so the computer must be awake with TenuVault running in a usable session. It is not an unattended server service.

Retention runs only after a backup that finished without warnings, and the newest backup is always kept. Community removes backups older than 30 days; Pro and MSP keep 7 to 365 days, or forever. The setting applies to every tenant on the computer.

Two complete backups also enable drift detection.

TenuVault compared with Microsoft's built-in options

Two of Microsoft's options save some Intune configuration: a settings catalog JSON export and a Tenant Configuration Management snapshot. Neither runs scheduled backups that you can restore with assignments. The table shows how they differ from TenuVault.

Scroll sideways to see all columns.

Microsoft's built-in options and TenuVault
ApproachRestoreScheduleAssignmentsStorage
Settings catalog JSON exportImport creates a new policyNone; manual, one policy at a timeNot documented by MicrosoftA JSON file you download
Tenant Configuration Management snapshotsNone; monitors are monitorOnly and Microsoft says to fix drift in the admin center, PowerShell or GraphSnapshots run on demand; drift monitors run every six hoursResources include an Assignments parameterKept by Microsoft for a maximum of seven days
TenuVaultCopies on all plans; replace in place on Pro and MSP; copies to other tenants on MSPWeekly on Community; daily on Pro and MSPSaved where Intune has them; restored on Pro and MSPEncrypted on your computer or, on Pro and MSP, in your Azure storage

Set up your first backup

Install TenuVault, have an authorized administrator run the setup script for the app registration, sign in, choose storage and save the recovery key. Run a manual backup and review its log before scheduling.

Then restore one unassigned test policy as a copy and compare its settings. An export count does not prove recovery.

Read the technical guides

Product scope reviewed . Check your installed release and the current plan table before using a workflow.

Frequently asked questions

Does Microsoft Intune have a built-in backup?

No. Microsoft documents no recycle bin, version history or restore path for deleted Intune policies, and Tenant Configuration Management snapshots are kept for a maximum of seven days with no restore. TenuVault adds scheduled, encrypted Intune backups with a reviewed restore.

How do I back up Intune policies?

Install TenuVault on Windows or macOS, create the app registration with the setup script, sign in with an Intune admin account and choose storage. Run a manual backup, review it, then schedule weekly or, on Pro and MSP, daily backups.

Are Intune assignments included in a TenuVault backup?

Yes, where Intune has them. TenuVault saves group and filter references, not the Entra groups themselves. Restoring assignments requires TenuVault Pro or MSP.

Where are TenuVault Intune backups stored?

TenuVault stores Intune backups encrypted on your computer or a network share; Pro and MSP can also use your own Azure storage account. Backups never go to a TenuVault server.

Is TenuVault free for Intune backup?

TenuVault Community is free for one Intune tenant with weekly backups and 30 days of history. Pro costs €49 per month for two tenants and MSP starts at €99 per month for five tenant slots, excluding VAT, each with a 30-day trial.

Can I restore a deleted Intune policy?

Yes, if the policy is in a TenuVault backup. On Pro and MSP, replace in place recreates the deleted Intune policy under its original name with a new ID. On Community, TenuVault restores it as an unassigned copy.

Can I restore Intune configuration to another tenant?

Yes, on TenuVault MSP. It copies selected items from one connected Intune tenant's backup into others. Copies are never assigned, so you recreate groups and filters in the target tenant.

Does TenuVault back up Intune apps and installer files?

TenuVault backs up Intune app details and assignments when apps are included; scheduled backups use Everything except apps until you save a different choice for the tenant. Installer files are never downloaded. Store, web and Microsoft 365 apps can be recreated; Win32 and line-of-business apps need their original installer.

How does TenuVault encrypt Intune backups?

TenuVault encrypts each Intune backup file with AES-256-GCM on the admin's computer before writing or upload, with the key protected by Windows DPAPI or the macOS Keychain. Save the recovery key separately.

Does Intune data leave my tenant when I use TenuVault?

Intune tenant data and your Microsoft access token never reach a TenuVault server. TenuVault talks to Microsoft for sign-in, Graph and Azure, and to GitHub for updates and OpenIntuneBaseline files. License checks go to tenuvault.com and can include a Microsoft ID token as proof of the tenant; it is verified and never stored.