PLATFORM

Admin rights, handled properly.

Three local admin accounts per device, escrowed in a Key Vault dedicated to your tenant. Support access that expires on its own. Recovery keys shown and rotated from the device page. And roles that give each person exactly what their job needs, with every step in your audit log.

  • 3 admin accounts per device
  • Escrow checked every hour
  • 178 fine-grained permissions
  • Every view audited

Example data. Last check of escrow: 23 minutes ago.

Three accounts, three jobs

One shared local admin is how passwords end up on sticky notes. The RealmJoin Agent keeps three accounts per device, each with its own audience and lifetime.

The three local admin accounts RealmJoin keeps per device
AccountWho can use itLifetimeMade for
EmergencySupporters and Advanced SupportersAlways present; a missing password is flaggedThe moment nothing else works
SupportHelpdesk on request, ticket tokens, owners with SelfLAPSExpires on its own, 12 hours by defaultRemote sessions, installs, troubleshooting
PrivilegedAdvanced SupportersRenewed on demandPlanned admin work

Restrict who sees what, per device owner group. With Restrict.LAPS, passwords of executive devices can be limited to a VIP support group, whatever role someone else holds. The portal explains every decision: open a device and it tells you who may see its passwords, and why. Try the check

How escrow works

From the device to your Key Vault and back to the one person allowed to see it.
  • The agent sets the password on the device
    The agent sets the password on the device
    Password presets decide the format, including word-list passphrases that people can actually type over a phone line.
  • It's encrypted before it leaves
    It's encrypted before it leaves
    The device encrypts the password with your tenant's RealmJoin certificate.
  • It lands in your tenant's Key Vault
    It lands in your tenant's Key Vault
    RealmJoin stores it as a secret in the Key Vault dedicated to your tenant and refuses keys from any other vault.
  • Every view is checked and logged
    Every view is checked and logged
    Roles, restrictions and SelfLAPS rules decide who may see which account. Each view is written to the audit log with who, when and for which device.
  • Escrow is verified every hour
    Escrow is verified every hour
    RealmJoin checks every active device and flags missing passwords and orphaned secrets before anyone needs them.

SelfLAPS and tickets

  • SelfLAPS for the people who need it

    Developers and power users sometimes need admin rights, and a ticket for each time helps nobody. The group settings Allow.SelfLAPS and Allow.SelfLAPSIntune let owners request the admin account of their own device. Only their own, and every request is logged.

    • Enabled per owner group, off by default
    • Works with RealmJoin LAPS and with Windows LAPS in Intune
  • Tickets and helpdesk tools

    People signed in with a ticket token, for example from ServiceNow, get the support account only for the devices named in their ticket. And your helpdesk tool can request a support account and fetch its password over the Customer API.

Customer API
POST /laps/request   # support account, expiry per tenantPOST /laps/retrieve  # password once it's escrowed

Windows LAPS in Intune, on the same page

Already running Windows LAPS through Intune? RealmJoin shows and rotates Intune-managed passwords for Windows and for Macs enrolled through Apple Business Manager. No agent needed, and it's an optional permission you grant only if you want it.

  • Username, password, last update and expiry
  • Rotation from the device page
  • Audited as its own category
Example data.

Recovery keys without a ticket to the Entra admin

A locked laptop at 07:30 is a helpdesk job, not an escalation. Supporters see BitLocker and FileVault recovery keys on the device page, and rotate them afterwards so the key they read out loses its value. Every look and every rotation is audited.

  • BitLocker keys per drive, FileVault keys for Macs
  • Rotation for both, right from the device
  • Optional permission, granted only if you use it
Example data. New keys are backed up at the next check-in.

Nine roles, mapped to groups you already have

Assign each role to Entra security groups or directory roles. A Global Administrator is recognized as such, and the app roles Admin and Auditor work too.

Example mapping in Settings, Permissions.

sec - realmjoin - admins
Admin
sec - it - internal audit
Auditor
sec - support - first level
Supporter
sec - support - second level
Advanced Supporter
sec - automation - operators
Runbook Runner
sec - apps - packaging
Software Agent
sec - apps - requesters
Software Requester
sec - apps - organic upload
Organic Requester
sec - comms - it announcements
Notification Agent

Custom roles from 178 permissions

When a job doesn't fit a built-in role, compose one. Custom roles grant named permissions to users or groups in a JSON editor in settings, from reading the device table to approving runbook runs. Partner-only permissions only apply in partner tenants.

A few of the 178 permission names. Highlighted: a "night shift" role that can read devices and rotate recovery keys, nothing more.

CanReadDeviceTableCanReadDeviceDetailsCanChangeRealmJoinPrimaryUserCanRotateRecoveryKeysCanApproveRunbookExecutionCanEditRunbookSchedulesCanReadRunbookTableCanEditAppAutomationCanEnableAppUpdateGroupCanEditAppExpertSettingsCanEditAppTechnicalApplicationOwnersCanChangeGroupMembersCanDeleteGroupCanReadLogsTableCanReadExportsTableCanAddSelfServiceFormsCanAssignDeviceHealthScriptsCanReadNotificationTableCanEditAppCategoriesCanReadChangelogTable

Limit the reach of RealmJoin itself

Least privilege applies to the tool too. Decide how much of your tenant RealmJoin may touch, and change your mind later.

  • Administrative Unit scoping

    Limit RealmJoin to one Entra Administrative Unit; group writes happen only there.

  • Read-only core

    Connect with read-only permissions and upgrade when you're ready.

  • Grant, downgrade, revoke

    Every permission of every app registration, individually, from the features page.

  • Separate app registrations

    Core, read-only, security and client permissions live in different apps.

  • Optional capabilities

    Intune LAPS, sign-ins, BitLocker keys and more are opt-in.

  • Audited access

    Password views and support account requests are recorded with who, when and from where.

Stop sharing the admin password.

See the three-account model on your own devices, with passwords in your own Key Vault.