See what's installed, used and changed.
RealmJoin merges agent, Intune, registry and Store inventory into one software report, adds real run counts from your Windows devices if you switch usage metering on, and writes every admin action to an audit log in your own Log Analytics workspace.
- Four inventory sources
- Optional usage metering
- 30 audit categories
- 730 days retention by default
One report, four sources
The software report combines what the RealmJoin Agent installed, the Windows uninstall registry, Appx and MSIX packages, and Intune's detected apps, which also covers devices without the agent and non-Windows devices. A pattern catalog maps raw entries to catalog packages, so "Adobe Acrobat (64-bit)" and its registry key end up in one row.
- Version spread with drill-down to devices and users
- Filter by source, mapped or unmapped, compliant, enabled
- Desired versus actual software per device
- Store app names resolved from Microsoft Store metadata
Real usage, not just installs
Usage metering is optional: you decide whether it runs in your tenant. When it does, RealmJoin reads Windows' record of which programs run and how often on every check-in and matches each executable to a package, first by process name, then by file hash, then by install path, leaving out installers and Windows' own files. Every app gets installed and used counts, total runs and a last-used date.
- Optional, switched on per tenant
- Find installs unused for 30, 90 or 180 days
- Reclaim licenses before the renewal, not after
- Package usage export with a summary sheet
Shadow IT, found
Software that nobody deployed still ends up on devices. RealmJoin lists every Windows title found in inventory that wasn't installed through RealmJoin, with device and user counts and a best-effort match to Intune apps, so you can package it, block it or ask why it's there.
Telemetry that answers audit questions
Every agent check-in carries more than an app list: hardware and serial, BIOS version and password status, TPM and BitLocker, Defender onboarding and antivirus products, Microsoft 365 Apps channel, printers, Windows Update safeguard holds, whether the user signed in with Windows Hello, and whether the new Secure Boot certificate is in place.
- Ready for the Windows UEFI CA 2023 certificate change
- Safeguard holds with ID and description per device
- Queryable per device through the Customer API
An audit log that lives with you
RealmJoin writes audit, operational and runbook logs into your Log Analytics workspace through the Logs Ingestion API. Query them with KQL, keep them as long as your policy says, feed them to Sentinel.
- Tables
RJAuditLogs_CL,RJOperationalLogs_CLandRJRunbookLogs_CL - Who did it, to what, the old and the new value, and the context
- Retention set to 730 days when you connect the workspace
- The same logs readable in the portal, with a configuration check
{ "Message": "Rotated BitLocker recovery keys", "AuditSubject": { "Id": "8a1f…", "Name": "jonas.keller@contoso.com" }, "AuditTarget": { "Id": "c42e…", "Name": "NB-MUC-0412" }, "AuditChange": { "Property": "RecoveryKey", "OldValue": "5F1A…", "NewValue": "9B07…" }, "AuditContext": { … }}
30 audit categories
Take the data with you, or just ask
Six predefined Excel exports cover devices, packages, restrictions, antivirus, shadow IT and package usage. The Customer API returns device state and lists for your own tooling. And the built-in MCP server lets an AI assistant answer questions about your fleet with six read-only tools, behind tokens you can revoke.
- Tools for device state, device search, software report, packages and tenant overview
- Named tokens with expiry, revocation and last-used date
- 60 requests per minute per tenant
Find the licenses nobody uses.
Connect a tenant and roll out the agent to a pilot group. The first usage numbers arrive with the next check-ins.