Skip to main content
Trust Center

Runs locally. Your app registration.
Your storage.

TenuVault Desktop backs up, compares and restores Intune configuration from the admin's computer. Your Intune data, backups and Microsoft access tokens never pass through a vendor server.

For your security review

Security and architecture overview (PDF)

Two pages for your security and governance team: the architecture, every connection the app makes, each delegated permission, how data is protected and the controls you keep. Share it internally as is.

Revision 1, 29 September 2026, describes version 0.1.0

Download PDF

Your own app registration

You create it in your tenant with the included script. No vendor app, no vendor client ID, no secret or certificate, no consent to a third party. Delete it and the app stops working.

Delegated access, admin in control

Every call runs as the signed-in admin and is limited by their Intune role. Changes to Intune happen only when an admin starts a restore, a drift revert, a baseline deployment or its undo.

Backups stay with you

Backups are encrypted on the computer with AES-256-GCM and kept on local disk or in your own Azure Storage account. No vendor server stores or processes Intune data. No telemetry or crash reporting.

No Intune data goes to the vendor

Everything that
leaves the computer

PurposeDestinationWhat is sent
Sign-inlogin.microsoftonline.comStandard OAuth request to your tenant with your app registration.
Intunegraph.microsoft.comRequests with the admin's delegated token. Reads for backups and drift; writes only for restores, drift reverts and baseline deployments an admin starts.
Storage pickermanagement.azure.comOptional. Lists the subscriptions and storage accounts the admin can see. Read only.
Azure backups<account>.blob.core.windows.netOptional. Your own storage account: backup content (encrypted before upload) and audit log entries. Not used when backups are stored locally.
License checktenuvault.comLicense key (if any), tenant ID, random install ID, OS, app version and, when signed in, your client ID and a short-lived Microsoft ID token. The service reads only the tenant and client ID from the token; name and UPN are not stored. Runs at start, every 6 hours, on first use of a tenant and on license changes. Entitlements stay valid offline for 14 days.
Updatesgithub.com*.githubusercontent.comVersion check and signed installer download. Can be turned off in Settings or by policy.
Baselinesapi.github.comraw.githubusercontent.comOptional. Downloads the public OpenIntuneBaseline repository for Quick Start and Frameworks. Nothing about your tenant is sent.

The licensing service also sees the requesting IP address. Sign-in through the browser or the Windows account broker contacts Microsoft services directly, outside TenuVault's control.

Delegated only, granted by your admin consent

Permissions

Plus openid, profile and offline_access. No application permissions, no client secret, no certificate. Consent is tenant-wide and tokens carry all consented scopes. Write scopes exist for restore; Microsoft enforces the admin's Intune role and scope tags on every call.

PermissionAccessUsed for
User.Read
Microsoft Graph
ReadSign in and read the signed-in admin's profile.
Organization.Read.All
Microsoft Graph
ReadTenant name and verified domains.
Policy.Read.All
Microsoft Graph
ReadRequested by the setup script, not used by the current version.
DeviceManagementConfiguration.ReadWrite.All
Microsoft Graph
Read, writeBack up and restore configuration, compliance, endpoint security and update policies.
DeviceManagementApps.ReadWrite.All
Microsoft Graph
Read, writeBack up and restore apps, app protection and app configuration policies.
DeviceManagementServiceConfig.ReadWrite.All
Microsoft Graph
Read, writeBack up and restore enrollment settings, branding and terms.
DeviceManagementScripts.ReadWrite.All
Microsoft Graph
Read, writeBack up and restore PowerShell and shell scripts and remediations.
DeviceManagementRBAC.ReadWrite.All
Microsoft Graph
Read, writeBack up and restore scope tags, Intune roles and role assignments.
DeviceManagementManagedDevices.Read.All
Microsoft Graph
ReadDevice counts and compliance rate on the tenant overview, and device clean-up rules. Device records are not stored.
user_impersonation
Azure Service Management
ReadList your subscriptions and storage accounts when you pick backup storage. Read only. Optional.
user_impersonation
Azure Storage
Read, writeBackups and the audit log in your own storage account. Optional.

The app registration script creates exactly this set. The app source is published in the desktop repository for review.

How your data is protected

Security
in detail

Data on the computer and at rest

  • Tokens, settings and backup keys are encrypted with Windows DPAPI or a macOS Keychain key, bound to the OS user. With the Windows account broker, Windows holds the tokens. The app will not start without OS encryption.
  • Local backups use AES-256-GCM per file, with keyed-hash file names so policy names are not visible on disk. Default folder: Documents/TenuVault Backups.
  • Azure backups are encrypted on the computer (AES-256-GCM) before upload. Blob names (policy display names), the audit log and tenant metadata rely on Azure's own encryption at rest.
  • Recovery key. Azure uploads are blocked until the admin saves it. Keep it in a password manager; without it, backups cannot be read on another computer or after a reinstall.
  • Exports (backup ZIP, reports) are unencrypted and saved where the admin chooses. Backups can hold secret values such as OMA-URI settings, so treat exports and the recovery key as sensitive.
  • Retention. Backups older than the retention setting (default 30 days) and audit entries older than 90 days are deleted.

Changes to your tenant

  • Admin-started only. Scheduled jobs read Intune and write to backup storage, never to Intune. Restores, reverts and deployments need an admin to start them.
  • Preview and confirm. The live tenant is compared with the backup, and overwriting requires an explicit confirmation. The default restore creates copies, with assignments off.
  • Cross-tenant copies are always created unassigned; referenced apps need reviewed mappings.
  • Write journal. Restore, revert and Quick Start writes are journaled locally; an unconfirmed write blocks retries until it is reconciled.
  • Audit trail under the admin's name, in your Azure storage or, for local backups, on the computer. Intune also logs every change.

Background backups

  • Runs as the signed-in admin. TenuVault runs backups itself while it runs in the tray. An optional per-user Task Scheduler task or LaunchAgent starts it at logon. No service account, no stored password, no app-only identity.
  • Never signs in on its own. If the session expires, the backup stops and asks the admin to sign in again.

Application hardening

  • Signed releases. Released Windows builds are signed with Azure Trusted Signing; macOS builds are signed and notarized.
  • Locked-down interface. Electron sandbox, context isolation, no Node.js in the interface, a Content Security Policy limiting scripts and connections to the app, and navigation to other sites blocked.
  • Electron fuses disable run-as-node, NODE_OPTIONS and inspector flags and enforce an integrity-checked app archive, verified in CI.
  • Licensing. The license service issues an Ed25519-signed entitlement, valid 14 days and verified offline.
You stay in control

Your
controls

  • Assignment required. The setup script can limit sign-in to one admin group. This also decides who can use a license shared with the tenant.
  • Conditional Access. Require MFA and a compliant device for this app. Sign-ins appear in your Entra logs.
  • Least privilege. Intune roles and scope tags limit what TenuVault sees and changes. With a read-only role, Microsoft rejects restores.
  • Storage access. Grant Storage Blob Data Contributor on the backup account only, or keep backups local.
  • Update control. Updates download automatically and install on quit. Turn this off in Settings or with the DisableAutoUpdate policy (HKLM or HKCU\SOFTWARE\Policies\TenuVault, or managed preference com.tenuvault.desktop).
  • Verify it yourself. Intune audit logs show every change. With Microsoft Graph activity logs enabled, filter by your client ID to see every call.
  • Revoke anytime. Disable or delete the app registration.

Vendor and contact

Vendor
Ugurlabs UG (haftungsbeschränkt), Düsseldorf, Germany
Security contact
security@ugurlabs.com
Service providers for licensing
Polar (license keys and payments), Supabase (license sharing records). Neither receives Intune data.
Data processing agreement
Available on request.