Skip to main content

Practical guide

Prepare an Intune configuration recovery plan

Plan for lost policies, an unavailable admin computer and rebuilding configuration in another tenant. A usable recovery plan combines configuration backups with keys, access, dependencies and an exercised procedure.

Define the scope and recovery requirements

Inventory the Intune configuration you need to recover and the time and data-loss limits your organization expects. Map those requirements to backup frequency, retention and the people who can run recovery.

A configuration backup does not recover enrolled devices, endpoint files or every application artifact. Keep the coverage and limitations attached to the plan so the incident team knows what needs a separate procedure.

Keep files, keys and access recoverable

Document where backups are stored and how an authorized administrator can retrieve them if the usual computer is lost. Store the recovery key separately and verify the documented import procedure on an approved device.

Keep a usable app registration, admin roles and storage permissions available. Licensing checks, Microsoft authentication and network availability have their own requirements; offline verification does not make live tenant operations offline.

Review dependencies and external artifacts

Use recovery readiness to identify items that can be restored automatically, missing mappings and manual actions. Record installers, certificates and tokens that Microsoft Graph cannot export and define their separate recovery source.

For another tenant, review group and filter mappings, licensing, scope tags and application dependencies. Cross-tenant copies remain unassigned until reviewed; restoring configuration does not enroll or migrate devices.

Exercise the plan and retain evidence

Start with a small unassigned policy-copy drill. If production recovery relies on replacement or assignment restoration, exercise those modes separately in an approved test scope.

Retain timestamps, app version, backup status, original and created IDs, setting comparisons and manual steps. Use the measured outcome to revise the plan; do not treat an export count as proof of full recovery.

Recover, reconcile and validate

During an incident, select a verified backup, review the recovery plan and restore only the approved scope. Reconcile partial writes before repeating an operation.

Validate recovered settings and assignments, account for new object IDs and complete the external-artifact procedures. Observe intended endpoint behavior separately, then document remaining gaps and the next recovery test.

Read the technical guides

Product scope reviewed 3 October 2026. Check your installed release and the current plan table before using a workflow.