Practical guide
Does Microsoft Intune have a built-in backup?
Microsoft Intune has no built-in backup, recycle bin or version history for policies, so a deleted or overwritten policy cannot be brought back from the admin center. The native options are manual exports, Microsoft Graph sample scripts, audit logs and Tenant Configuration Management snapshots, which are kept for at most seven days and have no restore action. This guide explains what each one covers and which backup options fill the gap.
At a glance
- Microsoft Learn documents no recycle bin, soft delete or version history for Intune policies.
- A Windows settings catalog policy can be exported to a JSON file by hand; importing that file creates a new policy.
- Tenant Configuration Management snapshots cover 67 Intune resource types, are kept for a maximum of seven days and have no built-in restore or apply action.
- Intune audit logs record which properties changed, not the full policy, and Microsoft Graph returns up to two years of audit events.
- Windows settings backup and restore, formerly Windows Backup for Organizations, backs up Windows user settings, not Intune configuration.
The short answer: no native backup or undo
Microsoft Learn does not document a recycle bin, soft delete, undelete or per-policy version history for Intune configuration profiles, compliance policies or endpoint security policies. If an administrator deletes a policy or saves a bad change, the admin center has no button that returns the previous state.
Deleting a policy also affects devices. Microsoft states that when you delete a profile, its settings are removed from devices, with exceptions: on Windows some configuration service providers keep the setting (tattooing), and on Android, settings are not removed for the profile types Microsoft groups as all other profile types. The policy object itself is gone, and Microsoft documents no self-service or support path to recover it.
That does not mean Intune has no safety features. It has several useful pieces, but each solves a narrower problem than backup and restore. The rest of this guide goes through them one by one.
Native tools and what they cover
The table summarizes every native capability that is close to backup, with the limit that matters when you need to recover. Each item is covered in more detail below.
| Capability | What it does | Limit for recovery |
|---|---|---|
| Windows settings catalog JSON export | Exports one Windows settings catalog policy to a .json file; import creates a new policy | Manual, one policy at a time; Microsoft does not say whether assignments are included |
| Duplicate | Copies a settings catalog profile with the same settings and scope tags | The copy has no assignments and is another live policy in the same tenant, not a stored backup |
| Graph sample scripts | Export and import some policies with Microsoft Graph and PowerShell | Not every policy type; compliance assignments do not import; Win32 apps need the original .intunewin files |
| Multi Admin Approval | Requires a second administrator to approve changes such as Delete | Prevents mistakes; keeps no copy of the configuration |
| Intune audit logs | Record who changed which object and which properties changed | Not the full policy content; two years through Graph, one year in the admin center filter |
| Tenant Configuration Management | JSON snapshots and drift monitors for 67 Intune resource types | Snapshots kept up to seven days; monitors are monitor only; no apps, scripts or remediations |
| Microsoft Entra Backup and Recovery | One backup snapshot of supported Entra objects per day, with up to five days of history | Covers no Intune objects |
Settings catalog export and Graph sample scripts
Microsoft documents that you can export a Windows settings catalog policy to a .json file and import that file to create a new policy. It is a good habit before a risky edit, but it is manual, it works one policy at a time, and the import always creates a new object with a name you choose. Microsoft's page does not state whether assignments are part of the export, so do not rely on it for targeting.
For tenant migration, Microsoft says you can export and import some of your policies using Microsoft Graph and PowerShell sample scripts. The same page warns that the scripts do not export and import every policy, such as certificate profiles, and that you will have to recreate some policies. Compliance policy assignments can be exported but not imported, because a group ID is different in a new tenant, and Win32 apps need the original .intunewin source files.
Tenant Configuration Management snapshots
The Tenant Configuration Management (TCM) APIs in Microsoft Graph, also surfaced as configuration management in Microsoft Entra Tenant Governance, can take JSON snapshots of tenant settings and monitor them for drift across workloads including Intune. The Intune resource list names 67 resource types, including compliance policies, many device configuration templates, Windows settings catalog custom policies, enrollment restrictions and update rings. It lists no apps, no PowerShell or shell scripts and no remediations.
The limits matter for backup. A snapshot is retained for a maximum of seven days and then deleted automatically, so you have to download and store snapshots yourself. The base quota is 20,000 resources per tenant per month across all snapshots. Monitors run in monitorOnly mode, and Microsoft's FAQ says to fix drift with the admin center, PowerShell or Graph. There is no restore or apply action.
Basic capacity comes with Microsoft Entra ID P1 or P2, which are included in Microsoft 365 E3, E5 and Business Premium. Microsoft Entra ID Governance licenses add capacity, and Entra ID Free gets no configuration management. TCM is a useful drift signal and a short-lived export source, not a recovery system.
Audit logs and Multi Admin Approval
Intune audit logs show who changed which object, and the Target(s) section lists the properties that were changed. Microsoft documents that the Graph API returns two years of audit events, while the admin center date filter covers up to the previous year. You can send audit logs to Azure Monitor for longer retention. Audit logs help you reconstruct what happened, but they do not hold the full policy, so they cannot recreate one on their own.
Multi Admin Approval uses Intune access policies to require a second administrator to approve a change before it is applied. It can protect apps, compliance policies, settings catalog configuration policies and scripts, including the Delete action. It is prevention, not backup: a change that is approved by mistake is still applied, and nothing keeps the previous version.
Two other Microsoft features are sometimes mistaken for Intune backup. Microsoft Entra Backup and Recovery backs up Entra objects such as users, groups, applications and Conditional Access policies with five days of history, and lists no Intune objects. Windows settings backup and restore, formerly Windows Backup for Organizations, preserves Windows user settings and the list of installed Microsoft Store apps for device transitions.
What to use instead
Because Intune has no native backup, admins choose between manual exports, open source tools, commercial services and desktop tools such as TenuVault. Each can work; they differ in how much you build and operate yourself, where backups are stored and how restore behaves.
| Option | How it works | Restore behavior | Cost |
|---|---|---|---|
| Manual export and scripts | Windows settings catalog JSON exports and Microsoft Graph sample scripts you run and store yourself | Import creates new policies; not every type is covered | Free, plus staff time |
| IntuneBackupAndRestore | PowerShell module that writes JSON files to a folder | Creates new objects; assignments restored in a separate step | Free, MIT license |
| IntuneCD | Python CLI that writes JSON or YAML, designed for Git and pipelines | Updates by display name and creates missing items; assignments only when requested | Free, MIT license |
| IntuneManagement | PowerShell app with a WPF interface and a silent batch mode | Import modes include always import, skip if exists, and replace or update in preview | Free, MIT license |
| Microsoft365DSC | PowerShell Desired State Configuration for Microsoft 365, including Intune | Declarative apply; can clone configuration between tenants | Free, MIT license; requires DSC expertise |
| Commercial services | Hosted products such as Keepit, CoreView, Salto and Veeam, mostly storing data in the vendor's cloud | Varies by vendor; documented Intune scope differs widely | Mostly quote based |
| TenuVault | Desktop app for Windows and macOS; encrypted backups on your device, or in your own Azure storage on Pro and MSP | Unassigned copy on every plan; in place and with assignments on Pro and MSP | Community is free for one tenant |
How to choose an Intune backup approach
The open source tools are free, MIT licensed and capable, and they suit teams that are comfortable owning scripts, pipelines, storage and credentials. Commercial services reduce that work but usually keep your configuration in their cloud and price on request. Whichever you pick, judge it on recovery, not on the number of objects it exports.
- Does restore update the existing policy in place, or only create new copies that you then reassign?
- Are assignments saved, and can they be restored when the groups still exist?
- Where are backups stored, who can read them and who holds the encryption key?
- Does it run on a schedule you can verify, and does someone review failed runs?
- What is excluded? App installers, certificates with private keys and Apple enrollment tokens are not returned by Microsoft Graph, so backups of Graph data cannot contain them.
- Have you restored a test policy from it and compared the result?
Read the technical guides
Product scope reviewed . Check your installed release and the current plan table before using a workflow.
Frequently asked questions
Does Microsoft Intune have a recycle bin for deleted policies?+
No. Microsoft Learn documents no recycle bin, soft delete or undelete for Intune policies. Soft delete exists for some Microsoft Entra objects, such as groups and Conditional Access policies, but not for Intune configuration.
Does Intune keep a version history of policy changes?+
No. Intune has no per-policy version history or rollback. Audit logs record which properties changed and who changed them, but they do not store the full previous version of the policy.
Can Tenant Configuration Management restore Intune policies?+
No. Tenant Configuration Management monitors run in monitorOnly mode and Microsoft says to fix drift with the admin center, PowerShell or Graph. Snapshots are kept for a maximum of seven days, so download them if you want to keep them.
Is Windows Backup for Organizations a backup of Intune?+
No. Windows Backup for Organizations, now called Windows settings backup and restore, backs up Windows user settings and the list of installed Microsoft Store apps so they can be restored on a new device. It does not back up Intune policies, profiles, apps, scripts or assignments.
Can I export Intune policies without third-party tools?+
Yes, partly. Windows settings catalog policies can be exported to JSON in the admin center one at a time, and Microsoft publishes Graph sample scripts that export and import some policy types. Neither covers everything, and both create new policies on import.
Is there a free Intune backup tool?+
Yes. IntuneBackupAndRestore, IntuneCD, IntuneManagement and Microsoft365DSC are free open source projects under the MIT license. TenuVault Community is also free for one tenant, with weekly scheduled backups and single item restore as a copy.