Runs locally. Your app registration.
Your storage.
TenuVault Desktop backs up, compares and restores Intune configuration from the admin's computer. Your Intune data, backups and Microsoft access tokens never pass through a vendor server.
For your security review
Security and architecture overview (PDF)
Two pages for your security and governance team: the architecture, every connection the app makes, each delegated permission, how data is protected and the controls you keep. Share it internally as is.
Revision 1, 29 September 2026, describes version 0.1.0
Your own app registration
You create it in your tenant with the included script. No vendor app, no vendor client ID, no secret or certificate, no consent to a third party. Delete it and the app stops working.
Delegated access, admin in control
Every call runs as the signed-in admin and is limited by their Intune role. Changes to Intune happen only when an admin starts a restore, a drift revert, a baseline deployment or its undo.
Backups stay with you
Backups are encrypted on the computer with AES-256-GCM and kept on local disk or in your own Azure Storage account. No vendor server stores or processes Intune data. No telemetry or crash reporting.
Everything that
leaves the computer
| Purpose | Destination | What is sent |
|---|---|---|
| Sign-in | login.microsoftonline.com | Standard OAuth request to your tenant with your app registration. |
| Intune | graph.microsoft.com | Requests with the admin's delegated token. Reads for backups and drift; writes only for restores, drift reverts and baseline deployments an admin starts. |
| Storage picker | management.azure.com | Optional. Lists the subscriptions and storage accounts the admin can see. Read only. |
| Azure backups | <account>.blob.core.windows.net | Optional. Your own storage account: backup content (encrypted before upload) and audit log entries. Not used when backups are stored locally. |
| License check | tenuvault.com | License key (if any), tenant ID, random install ID, OS, app version and, when signed in, your client ID and a short-lived Microsoft ID token. The service reads only the tenant and client ID from the token; name and UPN are not stored. Runs at start, every 6 hours, on first use of a tenant and on license changes. Entitlements stay valid offline for 14 days. |
| Updates | github.com*.githubusercontent.com | Version check and signed installer download. Can be turned off in Settings or by policy. |
| Baselines | api.github.comraw.githubusercontent.com | Optional. Downloads the public OpenIntuneBaseline repository for Quick Start and Frameworks. Nothing about your tenant is sent. |
The licensing service also sees the requesting IP address. Sign-in through the browser or the Windows account broker contacts Microsoft services directly, outside TenuVault's control.
Permissions
Plus openid, profile and offline_access. No application permissions, no client secret, no certificate. Consent is tenant-wide and tokens carry all consented scopes. Write scopes exist for restore; Microsoft enforces the admin's Intune role and scope tags on every call.
| Permission | Access | Used for |
|---|---|---|
User.ReadMicrosoft Graph | Read | Sign in and read the signed-in admin's profile. |
Organization.Read.AllMicrosoft Graph | Read | Tenant name and verified domains. |
Policy.Read.AllMicrosoft Graph | Read | Requested by the setup script, not used by the current version. |
DeviceManagementConfiguration.ReadWrite.AllMicrosoft Graph | Read, write | Back up and restore configuration, compliance, endpoint security and update policies. |
DeviceManagementApps.ReadWrite.AllMicrosoft Graph | Read, write | Back up and restore apps, app protection and app configuration policies. |
DeviceManagementServiceConfig.ReadWrite.AllMicrosoft Graph | Read, write | Back up and restore enrollment settings, branding and terms. |
DeviceManagementScripts.ReadWrite.AllMicrosoft Graph | Read, write | Back up and restore PowerShell and shell scripts and remediations. |
DeviceManagementRBAC.ReadWrite.AllMicrosoft Graph | Read, write | Back up and restore scope tags, Intune roles and role assignments. |
DeviceManagementManagedDevices.Read.AllMicrosoft Graph | Read | Device counts and compliance rate on the tenant overview, and device clean-up rules. Device records are not stored. |
user_impersonationAzure Service Management | Read | List your subscriptions and storage accounts when you pick backup storage. Read only. Optional. |
user_impersonationAzure Storage | Read, write | Backups and the audit log in your own storage account. Optional. |
The app registration script creates exactly this set. The app source is published in the desktop repository for review.
Security
in detail
Data on the computer and at rest
- Tokens, settings and backup keys are encrypted with Windows DPAPI or a macOS Keychain key, bound to the OS user. With the Windows account broker, Windows holds the tokens. The app will not start without OS encryption.
- Local backups use AES-256-GCM per file, with keyed-hash file names so policy names are not visible on disk. Default folder: Documents/TenuVault Backups.
- Azure backups are encrypted on the computer (AES-256-GCM) before upload. Blob names (policy display names), the audit log and tenant metadata rely on Azure's own encryption at rest.
- Recovery key. Azure uploads are blocked until the admin saves it. Keep it in a password manager; without it, backups cannot be read on another computer or after a reinstall.
- Exports (backup ZIP, reports) are unencrypted and saved where the admin chooses. Backups can hold secret values such as OMA-URI settings, so treat exports and the recovery key as sensitive.
- Retention. Backups older than the retention setting (default 30 days) and audit entries older than 90 days are deleted.
Changes to your tenant
- Admin-started only. Scheduled jobs read Intune and write to backup storage, never to Intune. Restores, reverts and deployments need an admin to start them.
- Preview and confirm. The live tenant is compared with the backup, and overwriting requires an explicit confirmation. The default restore creates copies, with assignments off.
- Cross-tenant copies are always created unassigned; referenced apps need reviewed mappings.
- Write journal. Restore, revert and Quick Start writes are journaled locally; an unconfirmed write blocks retries until it is reconciled.
- Audit trail under the admin's name, in your Azure storage or, for local backups, on the computer. Intune also logs every change.
Background backups
- Runs as the signed-in admin. TenuVault runs backups itself while it runs in the tray. An optional per-user Task Scheduler task or LaunchAgent starts it at logon. No service account, no stored password, no app-only identity.
- Never signs in on its own. If the session expires, the backup stops and asks the admin to sign in again.
Application hardening
- Signed releases. Released Windows builds are signed with Azure Trusted Signing; macOS builds are signed and notarized.
- Locked-down interface. Electron sandbox, context isolation, no Node.js in the interface, a Content Security Policy limiting scripts and connections to the app, and navigation to other sites blocked.
- Electron fuses disable run-as-node, NODE_OPTIONS and inspector flags and enforce an integrity-checked app archive, verified in CI.
- Licensing. The license service issues an Ed25519-signed entitlement, valid 14 days and verified offline.
Your
controls
- Assignment required. The setup script can limit sign-in to one admin group. This also decides who can use a license shared with the tenant.
- Conditional Access. Require MFA and a compliant device for this app. Sign-ins appear in your Entra logs.
- Least privilege. Intune roles and scope tags limit what TenuVault sees and changes. With a read-only role, Microsoft rejects restores.
- Storage access. Grant Storage Blob Data Contributor on the backup account only, or keep backups local.
- Update control. Updates download automatically and install on quit. Turn this off in Settings or with the DisableAutoUpdate policy (HKLM or HKCU\SOFTWARE\Policies\TenuVault, or managed preference com.tenuvault.desktop).
- Verify it yourself. Intune audit logs show every change. With Microsoft Graph activity logs enabled, filter by your client ID to see every call.
- Revoke anytime. Disable or delete the app registration.
Vendor and contact
- Vendor
- Ugurlabs UG (haftungsbeschränkt), Düsseldorf, Germany
- Security contact
- security@ugurlabs.com
- Service providers for licensing
- Polar (license keys and payments), Supabase (license sharing records). Neither receives Intune data.
- Data processing agreement
- Available on request.