TenuVault Desktop
Deploy OpenIntuneBaseline, then keep it current
TenuVault helps you deploy the independent community baseline, compare an existing deployment and investigate setting drift. OpenIntuneBaseline is maintained by SkipToTheEndpoint and contributors and is licensed under GPL-3.0.

New Deployment
Select the baseline platform and review the policies your tenant can use. Supported platform packs include Windows, macOS, Windows 365 and BYOD app protection. Licensing-aware selection helps you identify appropriate content.
New policies are unassigned by default, or can target a reviewed pilot group. Policies already in the tenant are left out of a new deployment. A backup runs first by default once storage is configured; if that backup fails, the deployment does not proceed.
Existing Deployment and Policy Validation
Compare an existing deployment with an upstream version to see what matches, what has changed and what is new. Policy Validation examines setting differences against the baseline.
Pro and MSP add supported updates and drift fixes in place. Review each change before applying it: configuration that fits one tenant may need exceptions in another. These checks do not prove that every device has applied the policy.
Version provenance and undo
The workflow records the baseline version used for a run. Review that provenance when investigating results or deciding whether to upgrade a deployment.
Undo is scoped to a deployment run: it removes what the run created and restores what it updated. Treat this as an operational safeguard, not a substitute for a verified backup, reviewed permissions and a pilot.
Your baseline and upstream attribution
Pro and MSP support versioned custom baselines and reviewed upgrades. Keep intentional tenant changes documented so a baseline update does not accidentally erase a local decision.
The upstream baseline remains independent and can be used without TenuVault. Preserve its attribution and license when sharing policy content. Framework configuration comparisons are separate read-only assessments and do not constitute certification.
Read the technical guides
Product scope reviewed 3 October 2026. Check your installed release and the current plan table before using a workflow.