The other half of Microsoft Intune.
RealmJoin packages, patches and retires your apps, gives helpdesk one screen per user and device, and turns your PowerShell into guarded self-service. Cloud-native, hosted in Europe, nothing to run on your side.
Each shard is a group of devices. Illustrative rollout; hover to inspect.
Built on the Microsoft stack you already run
- Microsoft Intune
- Entra ID
- Windows Autopilot
- Defender for Endpoint
- Windows 365
- Azure Virtual Desktop
- Azure Automation
- Log Analytics and Sentinel
- Partner Center
What Intune leaves on your desk
Intune decides what should happen on a device. Packaging every update, delegating helpdesk and scripting the routine still land on your team. That's the work RealmJoin takes over.
Every app update is a small packaging project.
Subscribe once from 3,000+ maintained packages. New versions are picked up within 15 minutes and roll out through Preview and Main on the schedule you set.
How the app lifecycle worksApps assigned as Available fall behind.
The update group spots devices with an outdated install and makes the update required until they're current. No new assignments for you to build.
About the update groupHelpdesk needs five portals and broad admin roles.
One screen per user, group and device across Entra ID, Intune, Autopilot and Defender. Nine roles and 178 permissions hand out exactly what a job needs.
Helpdesk and operationsAutomation lives in someone's scripts folder.
175 open-source runbooks run in your own Azure Automation account, as forms with pickers, schedules and a full job log.
Runbook automationThe local admin password is a shared secret.
Emergency, support and privileged accounts per device, escrowed in a Key Vault dedicated to your tenant. Support access expires on its own and every view is audited.
Privileged accessNobody knows what's installed, let alone used.
Inventory from the agent and Intune, matched to real run counts when you switch usage metering on, shows unused licenses and shadow IT in one report.
Software insights
One console for the work around Intune
Six areas, one sign-in, one set of roles. Pick one to see what your team would work with every day.
Apps & patching
Subscribe from the store, choose delivery through Intune or the RealmJoin Agent, and let automation take care of new versions. Missing an app? Request it and the packaging team builds it.
- 3,000+ packages for Windows and macOS
- Preview and Main channels, 0 to 90 day delay, night window
- Upload your own installer and get a package within minutes
Automation
A curated runbook library runs in your own Azure Automation account. RealmJoin turns each script into a form, checks who may run it and keeps the job log.
- 175 runbooks for users, groups, devices and the organization
- Graph-backed pickers, permissions and schedules
- Curated Intune remediation scripts, staged and measured
Helpdesk
Entra ID, Intune, Autopilot, Defender and the agent, correlated per device and user. Sync, scan, rotate keys or start a remote session without switching portals.
- 18 views per device, from warranty to Defender findings
- Search that finds Maren Müller when you type "ma mu"
- Six Excel exports, including shadow IT and package usage
Privileged access
Three local admin accounts per device, passwords escrowed per tenant, and support access that expires on its own. Every look at a password lands in the audit log.
- Emergency, support and privileged accounts
- SelfLAPS, and Windows LAPS in Intune including macOS
- BitLocker and FileVault key rotation from the device page
Insights
The software report merges agent, Intune, registry and Store inventory, then, if you switch it on, adds run counts from every device. Unused installs and shadow IT stop hiding.
- Optional usage metering per app
- Shadow IT and desired-versus-actual views
- Audit log with old and new values, in your own workspace
Endpoint
The optional RealmJoin Agent holds the desktop until mandatory apps are in place, keeps them current and gives people an app catalog of their own.
- Enrollment status page that respects install order
- Web App Catalog to install, update and repair apps
- Notifications, BranchCache and AnyDesk built in
One version, from vendor to the last laptop
What happens when 7-Zip ships 25.01 and RealmJoin does the work. Click through the steps; the log fills in as you go.
- Vendor25.01 published
- CatalogListed, verified
- Preview48 devices
- Main3,912 devices
- Update group61 caught up
- Usage412 unused
09-08 09:12 vendor 7-Zip 25.01 published09-08 09:25 catalog generic-7zip 25.01 listed, hash verified09-10 23:04 preview app - win - 7-Zip (preview): 48 devices09-15 23:02 main promoted to Main: 3,912 devices09-16 02:10 update 61 outdated installs added to update group12-01 08:00 usage 412 devices without a run in 90 days
Run a runbook. Right here.
RealmJoin reads each script's parameters and builds the form: Graph-backed pickers, dropdowns, sensible defaults. Permissions decide who sees which runbook.
user/general/offboard-user-permanently.ps1
Offboard user permanently
Revokes access, blocks or deletes the account, adjusts groups and licenses, and hands over ownerships and direct reports.
Run a runbook to see its job output here.Simulated in your browser. The runbooks and parameters are real, from the open-source library on GitHub, where 175 of them are waiting.
Helpdesk gets one screen. You keep the keys.
Supporters see what they need to fix a device, and nothing their role doesn't cover. Try it: choose who is asking for this device's local admin password.
NB-MUC-0412 belongs to Maren Müller
Owner's groups: sec - finance, sec - executives
- Emergency accountAlways escrowed•••••••••••••• Show password
- Support accountOn request, expires after 12 h Request, then show
- Privileged accountRotated on renewal No access
The Supporter role covers the emergency and support accounts. The privileged account is out of scope. Every password view is written to the audit log.
- One page per device. Entra ID, Intune, Autopilot, Defender and agent data side by side, in 18 views from warranty to raw JSON.
- Actions without admin sprawl. Intune sync, Defender scans, BitLocker and FileVault key rotation, log requests and AnyDesk sessions, each behind its own permission.
- Warranty for seven vendors. Apple, Dell, Fujitsu, HP, Huawei, Lenovo and Microsoft, looked up from the serial number.
- Audited by default. Every password view and key rotation is written to the audit log in your Log Analytics workspace.
Installed isn't used.
Usage metering is optional: you decide whether it runs in your tenant. With it, RealmJoin matches Windows execution data to packages, so every install comes with run counts and a last-used date. The gap is where licenses go back.
- 2,020installs without a run in 90 days
- 214titles nobody deployed, found on devices
Example data for a 4,000-device tenant.
- Adobe Acrobat Pro610 of 1,240
- Microsoft Visio212 of 880
- SAP GUI for Windows1,960 of 2,100
- Zoom Workplace2,980 of 3,400
- Autodesk AutoCAD LT61 of 145
- Tableau Desktop18 of 96
Your tenant, your data
RealmJoin is SaaS, but the sensitive parts run where you already hold the keys: your Microsoft 365 tenant and your own Azure subscription.
RealmJoin service
Microsoft Azure, West Europe, with North Europe as backup
- Portal and APIs
- Background automation
- Package catalog and CDN
Microsoft Graph, only with the permissions you consent to
Your Microsoft 365 tenant
Where the decisions stay
- Intune
- Entra ID
- Autopilot
- Defender for Endpoint
Your Azure subscription
Where the sensitive work happens
- Azure Automationruns the runbooks
- Key Vaultholds local admin passwords
- Log Analyticskeeps audit, operational and runbook logs
- Storageserves wallpapers, signatures and favorites
Your devices
Optional RealmJoin Agent on Windows
- Accepts only signed configuration
- Outbound HTTPS on port 443
- Peer-to-peer caching with BranchCache
Who does the work
Intune is the right foundation. This is what changes for your team when RealmJoin sits on top of it.
| When this happens | Intune on its own | Intune with RealmJoin |
|---|---|---|
| A vendor ships a new version | You notice, repackage, test and update assignments. | The maintained package updates itself. You set the delay. |
| You want a pilot before everyone | You build and maintain ring groups per app. | Preview and Main channels with managed groups per app. |
| People installed an app as Available | They stay on whatever version they installed. | Outdated installs are updated through the update group. |
| An app isn't packaged yet | Your team builds and tests the Win32 package. | Request it from the packaging team, or upload the installer and get a package in minutes. |
| Offboarding, access passes, mailbox changes | Scripts on an admin's laptop, or many manual clicks. | Runbooks as forms, with permissions and a job log. |
| Helpdesk needs a local admin | Windows LAPS manages one account per device. | A support account that expires on its own, plus emergency and privileged accounts. |
| Is this software actually used? | Discovered apps show what is installed. | Optional usage metering: run counts and last use per app. |
| Is the laptop still under warranty? | Look it up on the vendor's site by serial number. | Warranty from seven vendors on the device page. |
The details admins ask about first
Before the first test tenant is connected, this is usually what comes up.
Service
- Service
- SaaS on Microsoft Azure, hosted in West Europe with North Europe as backup. Nothing to install on servers.
- Onboarding
- Quick Setup with one Entra admin consent, or Advanced Setup that grants each permission through PowerShell.
- Availability
- 99.5% target with service credits. Live status at status.realmjoin.com.
Endpoints
- Endpoints
- Windows 10 and 11 with the optional RealmJoin Agent. macOS apps through Intune as DMG or PKG. Windows 365 and Azure Virtual Desktop aware.
- App delivery
- Intune Win32, macOS DMG and PKG, or the RealmJoin Agent with dependencies, install phases and background installs.
- Network
- Outbound HTTPS on port 443 only, with FQDN-based allow lists.
Automation
- Update automation
- Preview and Main channels, 0 to 90 day delay, night window in your time zone, owner notifications.
- Automation
- Your Azure Automation account, PowerShell 7.4, 175 library runbooks plus your own, schedules and permissions.
Access and logging
- Access control
- Nine built-in roles, custom roles from 178 permissions, Entra groups or directory roles, Administrative Unit scoping.
- Logging
- Audit, operational and runbook logs in your Log Analytics workspace through the Logs Ingestion API, 730 days retention by default.
Integration
- Integration
- REST Customer API with OpenAPI docs, an MCP server for AI assistants, and a PowerShell module.
- Support
- Included. Monday to Friday, 08:00 to 18:00 CET, in English and German.
Scale
- Organizations
- 250 to 100,000+ users
- Managed seats
- 500,000+
- Availability
- High availability and geo-redundancy
Customer isolation
- Enrollment
- Single- or multi-tenant
- MSP
- MSP licensing available
For MSPs, security teams and developers
Three doors into the same platform.
For MSPs: every customer tenant, one console.
Switch between customer tenants, share package templates and run Microsoft CSP from the same portal.
Least privilege, by design.
Separate app registrations per feature, a read-only mode and Administrative Unit scoping. Grant, downgrade or revoke any permission later.
An API for your tools, and one for your AI.
A REST API with OpenAPI docs, plus an MCP server so assistants can answer questions about your fleet.
Three steps to your first automated update
- Connect your tenantConnect your tenantSign in at portal.realmjoin.com as a Global Administrator and grant one consent. Prefer to grant permissions one by one? Use the PowerShell module.
Install-Module RealmJoinComplete-RJTenantOnboarding -Token <token> - Subscribe your first appsSubscribe your first appsPick packages from the store, choose Intune or Agent delivery and decide when Preview and Main should follow a new release.
- Delegate and automateDelegate and automateMap roles to Entra groups, connect Azure Automation for runbooks and point audit logs at your Log Analytics workspace.
Questions that come up early
More in the documentation, or ask an engineer directly.
01Does RealmJoin replace Intune?
No. RealmJoin builds on Intune and uses it for enrollment, compliance, configuration and app delivery. It adds the application lifecycle, delegation and automation around it.
02Do we have to install the RealmJoin Agent?
No. Apps can be delivered through Intune alone. The optional Windows agent adds dependency-aware installs, its own enrollment status page, three local admin accounts, desktop notifications, optional usage data and peer-to-peer caching.
03Where is our data stored?
The RealmJoin service runs in Microsoft Azure in West Europe, with North Europe as backup. Runbooks, local admin passwords and audit logs live in your own Azure subscription.
04Which permissions does RealmJoin ask for?
Only those for the features you use, split across separate app registrations. You can connect read-only, limit RealmJoin to one Administrative Unit, and revoke or downgrade any permission later.
05What about macOS?
macOS apps are delivered through Intune as DMG or PKG. FileVault keys, Intune-managed LAPS and wipe work from the device page. The RealmJoin Agent itself is for Windows.
06What if an app isn't in the store?
Request it and the packaging team builds and tests it, typically within five business days. Or upload your installer as a ZIP and get an organic package within minutes.
07How is RealmJoin licensed?
Per user, in two editions, Apps and Enterprise, starting at 1,000 users. Monthly or annual terms, also available through Microsoft Marketplace. See pricing
08Can we try it first?
Yes. Connect your tenant yourself with one consent at portal.realmjoin.com, or book a demo with an engineer first.
Meet Us in Person
RealmJoin is on the road this autumn. Come by, bring your Intune questions, and see RealmJoin in action.
Workplace Ninja Summit
Community conference in Baden on Microsoft Endpoint Management and Security
it-sa
Meet us again this year at Europe's leading trade fair for IT security



