PLATFORM

A first day that just works, and every day after.

The optional RealmJoin Agent is a Windows service that holds the desktop until mandatory apps are in place, installs them in the right order, keeps them current and gives people an app catalog of their own. It only accepts configuration that RealmJoin has signed.

  • Windows 10 and 11
  • Signed configuration
  • Checks in every 30 minutes
  • Canary, Beta and Stable

A small service with a clear job

The agent runs as a Windows service next to Intune. Every 30 minutes it fetches its configuration, verifies the signature, installs, updates or removes packages, and reports back what it found. Packages come from RealmJoin's CDN and are hash-checked before they run.

  • Dependencies, install order and deployment phases
  • Staggered auto-upgrades that skip weekends
  • A local security check: encryption, patch level, firewall, antivirus
  • Shared devices with per-user packages, Windows 365 and AVD aware
  • Extended logs on request from the device page
  • Receives

    • Signed configuration, RSA-SHA512
    • Packages and their assignments
    • Policies and user and group settings
    • Local admin account instructions
    • Desktop notifications
  • Reports

    • Installed software, registry and Store apps
    • Run counts per executable, if usage metering is on
    • Hardware, BIOS, TPM and BitLocker
    • Defender and antivirus state
    • Encrypted local admin passwords

Outbound HTTPS on port 443 only. The agent is optional: RealmJoin delivers apps through Intune without it.

The desktop opens when the apps are ready

RealmJoin's enrollment status page holds the desktop until every mandatory package is installed, in dependency order, even for very large installers such as CAD suites. People start with a working machine instead of a to-do list.

  • Respects "Depends on" and install order
  • Works with Windows Autopilot
  • Initial-phase packages install before the first sign-in completes

An app catalog people actually use

The web App Catalog lists the apps someone may install and lets them install, update or repair them without a ticket. It replaces the old tray menu, opens from the tray or the Start menu, and helpdesk sees the same catalog for any device on its user page.

  • Install, update and repair
  • Only apps assigned as Available
  • Also reachable from the profile page
Example data.

Tell people before it matters

Desktop notifications go to the groups you choose, skip the ones you exclude, and appear only between the start and end dates you set. Write them in several languages; people see their own, with a fallback. App installs can announce themselves with a custom hero image.

  • Info and alert categories
  • Drafts, scheduling and expiry
  • A dedicated Notification Agent role for your comms team
  • Remote support, one click away

    With the AnyDesk integration, every device carries its own AnyDesk ID. People start a remote session from the tray, supporters from the device page, and each session shows up in a log with time, origin and duration. It's audited like everything else.

    • Per-device AnyDesk IDs
    • Session log on the device page
    • Permission-controlled for supporters
  • Easy on the network

    Package content is shared between devices on the same network with BranchCache in distributed mode, switched on by default. Branch offices download a large installer once, not once per laptop. Delivery Optimization details come back with each check-in.

    • Peer-to-peer caching without extra servers
    • Large payloads delivered reliably
    • No proxy needed, outbound HTTPS only

Agent updates on your terms

The agent looks for its own updates every hour and follows the release channel you pick: Canary for the curious, Beta for your pilot, Stable for everyone else. Older agents keep working while you roll forward; the service adapts their configuration.

Canary
Earliest builds
Beta
Pilot group
Stable
Everyone else

A profile page for everyone

Every employee can sign in to RealmJoin and see themselves the way helpdesk does: account state, last sign-in with location and MFA method, compliant and non-compliant devices, groups, Teams and app roles. From there they sync their own device, open the App Catalog, send a corporate form or, if you allow it, see their device's local admin.

  • Fewer "is my laptop compliant?" tickets
  • Links to My Applications and My Account
  • Guest and external users supported
Example data.

Everything on the endpoint

  • Signed configuration

    The agent verifies every configuration before acting on it.

  • Enrollment status page

    Desktop held until mandatory apps are installed.

  • Dependency-aware installs

    Parents first, order within each level.

  • App Catalog

    Install, update and repair without a ticket.

  • Notifications

    Multilingual, targeted, scheduled.

  • Local admin accounts

    Emergency, support and privileged, escrowed per tenant.

  • AnyDesk

    Per-device IDs, tray shortcut, session log.

  • BranchCache

    Peer-to-peer package content, on by default.

  • Advanced telemetry

    Hardware, BIOS, Secure Boot, Office channel, sign-in method.

  • Usage data

    Optional run counts per executable for license decisions.

  • Release channels

    Canary, Beta and Stable.

  • Profile page

    Self-service view for every employee.

Make day one boring, in the best way.

Add the agent to your Autopilot profile, pick the mandatory apps and watch the next new laptop open with everything in place.