PLATFORM

Every app packaged, patched and accounted for.

Subscribe from a catalog of 3,000+ maintained packages, deliver each one through Intune or the RealmJoin Agent, and let automation carry every new version through Preview and Main. When an app is missing, the packaging team builds it.

  • 3,000+ packages
  • New versions found within 15 minutes
  • Windows and macOS
  • Intune or Agent delivery
Example data.

A catalog someone else keeps current

The Package Store holds 3,000+ ready-to-deploy packages for Windows and macOS. Maintained packages are rebuilt from the official vendor source when the vendor ships, so subscribing is the last packaging decision you make for them.

  • Generic packages for everyone, custom packages private to your tenant, organic packages built from your own installer
  • Search by name, package ID, category or Defender inventory ID
  • Badges for maintained, free to use and needs a license
  • Defender vulnerability findings next to each app
Example data. 6 of 3,000+ packages. Defender TVM: 0 open vulnerabilities on subscribed versions.

Missing an app? Ask for it, or upload it.

Send a packaging request from the portal: a new generic package, a custom one only for you, or an update. The packaging team builds and tests it, typically within five business days. In a hurry? Upload your installer as a ZIP and RealmJoin builds an organic package within minutes, no ticket involved.

  • Four-stage test cycle and a malware scan for generic packages
  • Updates of generic packages are free; custom packaging runs on credits
  • Duplicate check before a request goes in
Example data.

Intune or the Agent, decided per package

Every package can go out through Intune or through the RealmJoin Agent. Mix them freely: the Agent where you need dependencies and install phases, Intune where you want nothing extra on the device. Either way, managed subscriptions create and maintain the assignment groups for you.

Groups created by a managed subscription, with the default naming template app - $platform - $appName ($modifier). You can change the template in settings.

app - win - 7-Zip
Main, required
app - win - 7-Zip (preview)
Preview
app - win - 7-Zip (available)
Available
app - win - 7-Zip (update)
Update group
app - win - 7-Zip (uninstall)
Uninstall
app - win - 7-Zip (excluded)
Excluded
  • Through Intune

    Win32, macOS DMG and PKG

    • Delivered and reported in Intune
    • Company Portal for Available apps
    • Kept current by update automation and the update group
  • Through the RealmJoin Agent

    Windows, recommended by RealmJoin

    • Dependencies and install order
    • Install phases and user deferral
    • Self-service reinstall and repair
    • Reliable with very large installers

New versions move on the schedule you set

RealmJoin checks every subscribed app against the catalog every 15 minutes. When a new version shows up, it plans the Preview step, emails the app's technical owners, and later promotes the version to Main. Nobody has to remember any of it.

  • Delay Preview and Main independently, from 0 to 90 days each
  • Night window from 23:00 to 06:00 in your time zone
  • Pin a version whenever you need to; downgrades are refused
  • Long Intune uploads run in the background with progress and timeouts
  1. Vendor release7-Zip 25.01 published
  2. DetectedTechnical owners emailed
  3. PreviewPilot group gets 25.01
  4. MainEveryone else

Everyone runs 7-Zip 25.01 8 days after the vendor shipped it, and nobody on your team had to touch it.

Available apps don't get left behind

Apps people install themselves from the Company Portal stay on whatever version they picked. RealmJoin fixes that: every night it looks at Intune's detected apps, finds devices with an outdated install and puts exactly those devices into the app's update group, where the update is required until the device is current.

  • Built from Intune detected apps and RealmJoin's own detection rules
  • Only devices that already have the app; nobody gets new software
  • Can be limited to chosen device groups

Example: update group for 7-Zip

  1. 2,140devices report 7-Zip in Intune's detected apps
  2. 61of them run a version older than 25.01
  3. 61added to app - win - 7-Zip (update) at 02:10
  4. 0outdated installs the next morning

Example numbers.

Rules for the awkward apps

Some apps need a runtime first, some must never land on a Cloud PC, some can wait until the user is ready. Expert settings handle that per package when it's delivered by the RealmJoin Agent, and deployment phases decide whether it installs during setup, at logon, in the background or on demand. Setting names as they appear in the portal.

  • Depends on

    Parent packages that install first, one or several.

  • Order

    Fine-tune the install order within each dependency level.

  • Deployment rate

    Give users the option to defer the installation.

  • Allow background installation

    Install while the user is working.

  • Require compliance

    Only install on Intune-compliant devices.

  • Only in VDI, ignore in VDI

    Target or skip Windows 365 and Azure Virtual Desktop.

  • Hybrid-joined rules

    Only on, or never on, hybrid-joined devices.

  • Ignore on private devices

    Keep company software off personal machines.

  • Auto upgrade

    Upgrade automatically when a newer version is available.

  • Priority cascade

    Decide which assignment wins when a user is in several groups.

Beyond the classic desktop

Cloud PCs, multi-session hosts and Macs follow the same catalog and the same automation, each through the path that fits it.

  • Windows 365 and Azure Virtual Desktop

    RealmJoin recognizes multi-session hosts and personal desktops, so packages can target or skip them. Package templates bundle apps and variables for images, and a provisioning endpoint hands the right configuration to an AVD golden image with a token you can revoke.

    • Only-in-VDI and ignore-in-VDI rules per package
    • Templates with tokens for images and provisioning
    • Runbooks to assign Cloud PCs and drain session hosts
  • macOS, through Intune

    macOS packages from the store are delivered by Intune as DMG or PKG, with the same Preview and Main automation. FileVault keys, Intune-managed LAPS for Macs enrolled through Apple Business Manager, and wipe are available from the device page.

    • The RealmJoin Agent runs on Windows. On macOS, RealmJoin works entirely through Intune.

Everything in apps and patching

  • Package Store

    3,000+ maintained packages for Windows and macOS.

  • Private catalog

    Custom packages that only your organization sees.

  • Packaging requests

    New packages and updates, built and tested for you.

  • Organic packages

    Upload an installer, get a package within minutes.

  • Intune or Agent delivery

    Chosen per package, mixed freely.

  • Managed groups

    Main, Preview, Available, Update, Uninstall and Excluded, created for you.

  • Update automation

    Preview and Main, delays from 0 to 90 days, night window.

  • Owner notifications

    Emails before automated rollouts and when versions arrive.

  • Update group

    Outdated Available installs brought current.

  • Version pinning

    Hold a version; downgrades are refused.

  • Expert settings

    Dependencies, order, deferral, VDI and hybrid rules.

  • App timeline

    Recent app actions on the organization dashboard.

Hand your patching backlog to RealmJoin.

Connect a tenant, subscribe ten apps, set the delays. The next vendor release is the first one you don't have to handle.