Skip to main content

Practical guide

Set up Intune backups you can verify

Use this checklist before relying on an automatic schedule. It covers authentication, storage, the first backup and a restore drill. Follow your organization's normal approval process for app registration and tenant access.

1. Install and prepare tenant access

Download the stable Windows or macOS installer for your architecture. Review operating-system and network requirements, then have an authorized administrator run the setup script to create the single-tenant public client app registration and grant the documented delegated permissions.

Sign in with the admin account that will run the backups. Its Intune roles determine what configuration it can read. For Azure storage, grant the required storage access separately.

2. Choose storage and save the recovery key

Choose encrypted local storage on Community, Pro or MSP. Pro and MSP can use your Azure storage account. Save the recovery key somewhere separate from the admin device before relying on encrypted backups.

Record the storage location, the person responsible for the key and the retention policy. A backup on a lost computer is not a complete recovery strategy unless you can retrieve the files and key from another location.

3. Run and review a manual backup

Run a backup with the scope you intend to protect. Inspect its result, log, item types and counts. Investigate access-denied types and exclusions, and confirm that the policies you intend to recover are present.

Make a small unassigned test policy if your organization permits it and practice restoring it as a copy. Record the result rather than assuming that a completed export proves every recovery path.

4. Configure and observe the schedule

Community supports a weekly schedule. Pro and MSP also support daily schedules and custom retention. Keep TenuVault running in the tray, arrange startup where appropriate and make sure the computer is awake at the scheduled time.

Observe an actual scheduled run and inspect its status. Test your operating procedure after a restart, sign-in expiry and a missed scheduled slot. Desktop backups require an active usable session; background launch does not guarantee an always-on service.

5. Keep an operational record

Record the app version, backup timestamp, scope, result, storage location and restore-drill outcome in your change system. Assign someone to check failures and key availability.

Repeat the drill after meaningful app, tenant, storage or authentication changes. Choose backup frequency and retention from your recovery requirements, then verify that your operating procedure meets them.

Read the technical guides

Product scope reviewed 3 October 2026. Check your installed release and the current plan table before using a workflow.