Admin rights, handled properly.
Three local admin accounts per device, escrowed in a Key Vault dedicated to your tenant. Support access that expires on its own. Recovery keys shown and rotated from the device page. And roles that give each person exactly what their job needs, with every step in your audit log.
- 3 admin accounts per device
- Escrow checked every hour
- 178 fine-grained permissions
- Every view audited
Example data. Last check of escrow: 23 minutes ago.
Three accounts, three jobs
One shared local admin is how passwords end up on sticky notes. The RealmJoin Agent keeps three accounts per device, each with its own audience and lifetime.
| Account | Who can use it | Lifetime | Made for |
|---|---|---|---|
| Emergency | Supporters and Advanced Supporters | Always present; a missing password is flagged | The moment nothing else works |
| Support | Helpdesk on request, ticket tokens, owners with SelfLAPS | Expires on its own, 12 hours by default | Remote sessions, installs, troubleshooting |
| Privileged | Advanced Supporters | Renewed on demand | Planned admin work |
Restrict who sees what, per device owner group. With Restrict.LAPS, passwords of executive devices can be limited to a VIP support group, whatever role someone else holds. The portal explains every decision: open a device and it tells you who may see its passwords, and why. Try the check
How escrow works
- The agent sets the password on the deviceThe agent sets the password on the devicePassword presets decide the format, including word-list passphrases that people can actually type over a phone line.
- It's encrypted before it leavesIt's encrypted before it leavesThe device encrypts the password with your tenant's RealmJoin certificate.
- It lands in your tenant's Key VaultIt lands in your tenant's Key VaultRealmJoin stores it as a secret in the Key Vault dedicated to your tenant and refuses keys from any other vault.
- Every view is checked and loggedEvery view is checked and loggedRoles, restrictions and SelfLAPS rules decide who may see which account. Each view is written to the audit log with who, when and for which device.
- Escrow is verified every hourEscrow is verified every hourRealmJoin checks every active device and flags missing passwords and orphaned secrets before anyone needs them.
SelfLAPS and tickets
POST /laps/request # support account, expiry per tenantPOST /laps/retrieve # password once it's escrowed
Windows LAPS in Intune, on the same page
Already running Windows LAPS through Intune? RealmJoin shows and rotates Intune-managed passwords for Windows and for Macs enrolled through Apple Business Manager. No agent needed, and it's an optional permission you grant only if you want it.
- Username, password, last update and expiry
- Rotation from the device page
- Audited as its own category
Recovery keys without a ticket to the Entra admin
A locked laptop at 07:30 is a helpdesk job, not an escalation. Supporters see BitLocker and FileVault recovery keys on the device page, and rotate them afterwards so the key they read out loses its value. Every look and every rotation is audited.
- BitLocker keys per drive, FileVault keys for Macs
- Rotation for both, right from the device
- Optional permission, granted only if you use it
Nine roles, mapped to groups you already have
Assign each role to Entra security groups or directory roles. A Global Administrator is recognized as such, and the app roles Admin and Auditor work too.
Example mapping in Settings, Permissions.
- sec - realmjoin - admins
- Admin
- sec - it - internal audit
- Auditor
- sec - support - first level
- Supporter
- sec - support - second level
- Advanced Supporter
- sec - automation - operators
- Runbook Runner
- sec - apps - packaging
- Software Agent
- sec - apps - requesters
- Software Requester
- sec - apps - organic upload
- Organic Requester
- sec - comms - it announcements
- Notification Agent
Custom roles from 178 permissions
When a job doesn't fit a built-in role, compose one. Custom roles grant named permissions to users or groups in a JSON editor in settings, from reading the device table to approving runbook runs. Partner-only permissions only apply in partner tenants.
A few of the 178 permission names. Highlighted: a "night shift" role that can read devices and rotate recovery keys, nothing more.
Limit the reach of RealmJoin itself
Least privilege applies to the tool too. Decide how much of your tenant RealmJoin may touch, and change your mind later.
Administrative Unit scoping
Limit RealmJoin to one Entra Administrative Unit; group writes happen only there.
Read-only core
Connect with read-only permissions and upgrade when you're ready.
Grant, downgrade, revoke
Every permission of every app registration, individually, from the features page.
Separate app registrations
Core, read-only, security and client permissions live in different apps.
Optional capabilities
Intune LAPS, sign-ins, BitLocker keys and more are opt-in.
Audited access
Password views and support account requests are recorded with who, when and from where.
Stop sharing the admin password.
See the three-account model on your own devices, with passwords in your own Key Vault.