PLATFORM

One screen per user, group and device.

RealmJoin correlates Entra ID, Intune, Autopilot, Defender for Endpoint and its own agent data. Helpdesk sees the whole picture and acts on it, without five portals and without Global Admin.

  • 18 views per device
  • Warranty for 7 vendors
  • 9 delegable roles
  • 6 Excel exports
Example data.

Everything about a device, on one page

Hardware, Office channel, logged-on users, installed software, Defender findings, compliance policies, local admin accounts, recovery keys and warranty sit side by side. When helpdesk needs the raw record, the Entra, Intune, Autopilot, Defender and RealmJoin JSON is one tab away.

  • Installed software with managed, mandatory and auto-upgrade badges
  • Defender onboarding, health, exposure, alerts, vulnerabilities and recommendations
  • Windows Update safeguard holds with ID and description

The 18 views of the device page.

OverviewWarrantySafeguard holdRunbooksRemediation scriptsRemediation auditCompliance policiesChangelogUser app catalogRecovery keysLAPS accessWindows Update enrollmentRealmJoin configEntra JSONIntune JSONAutopilot JSONDefender JSONRealmJoin JSON

People, not just accounts

The user page shows who someone is and why things behave the way they do: manager, last sign-in with Conditional Access result, MFA method and location, compliant and non-compliant devices, groups sorted into readable namespaces, and the RealmJoin roles and policies that apply, with where each one comes from.

  • Software status per app: available, installed, mandatory or not configured
  • Runbooks for this user, one click away
  • Self-service form responses and RealmJoin user settings
Example data.

Groups that explain themselves

Members, owners, nested groups and the dynamic query, plus the Intune and RealmJoin assignments that hang off a group. Bulk operations copy members between groups, and "pull members up" flattens nesting when you need it. Group namespaces turn name prefixes into titles people understand.

  • Filter by security or Microsoft 365, static or dynamic, Teams or not
  • Add, remove, rename and delete with the right permission
  • Namespaces sort groups on every user page

Example namespace mapping. The prefixes are the defaults for a new tenant; titles are yours to choose.

app - …
Applications
cfg - …
Configuration
lic - …
Licenses
sec - …
Security
sec - realmjoin - …
RealmJoin access
sec - support - …
Support

Warranty and lookups, built in

RealmJoin looks up warranty status from the serial number for seven manufacturers and shows start and end dates, time remaining, purchase and shipment dates. Network adapters get their vendor from the MAC address, mobile devices their IMEI details, and sign-ins a location with a country flag.

  • Apple, Dell, Fujitsu, HP, Huawei, Lenovo and Microsoft
  • MAC vendor lookup from an offline manufacturer database
  • IP location of the last sign-in on user and profile pages

Example data.

Act without switching portals

The actions helpdesk needs every day are on the device page, and each one sits behind its own permission. Supporters can sync and scan; rotating keys or changing the primary user can stay with second level.

Intune sync
Ask the device to check in now
Defender scan
Quick or full antivirus scan
Request device logs
Extended RealmJoin logs, optionally for one user
Rotate BitLocker or FileVault key
New recovery key, old one invalid
Rotate Windows LAPS password
For Intune-managed LAPS
Run a remediation script
On this device, on demand
Change primary user
Moves the device's RealmJoin packages along
Start AnyDesk session
With per-device ID and session log
Upgrade to Windows 11
Started as a runbook

Six exports people actually ask for

Predefined Excel exports, ready when someone from finance, audit or security asks. Any table in the portal exports on top of that.

  • Devices

    Owner and primary user, compliance, CPU, RAM, disk, Office version and channel, extra admin accounts, MAC addresses.

  • Packages

    Every package with coordinator, platform, version and expert settings.

  • Package restrictions

    Deployment phases and primary or secondary user rules, per package.

  • Antivirus

    Protection status per device. Microsoft Defender is evaluated strictly, other products optimistically.

  • Shadow IT

    Windows software found on devices that RealmJoin didn't install, with device and user counts.

  • Package usage

    With usage metering on: last use per device, with an "unused for N days" cutoff and a summary sheet.

Delegate without handing out Intune admin

Nine built-in roles cover the usual jobs. Map each to Entra groups or directory roles, and build custom roles from 178 fine-grained permissions when a job doesn't fit.

The nine built-in RealmJoin roles and what each one covers.
RoleWhat it's for
AdminFull tenant administration, settings, approving runbook runs.
AuditorRead almost everything, including logs; sees that passwords exist, never the passwords.
SupporterDevices, users and groups; sync, scan, logs, recovery keys, AnyDesk, support and emergency admin accounts.
Advanced SupporterSupporter plus JSON views, remediation scripts, primary user changes and all local admin accounts.
Runbook RunnerSee and run the runbooks their permissions allow, and edit schedules.
Software AgentSubscribe, upgrade and assign apps, and set update automation.
Software RequesterSend packaging requests.
Organic Software RequesterUpload installers for organic packages.
Notification AgentWrite and schedule desktop notifications.

Roles, permissions and scoping

  • Autopilot, including the awkward cases

    Import a device by serial number and hardware hash, check its Autopilot record and JSON on the device page, and move devices between tenants: RealmJoin wipes, removes the old identity, imports the hash into the new tenant and retries until it sticks.

    • Autopilot import from the portal
    • Cross-tenant moves for mergers and carve-outs
    • Scheduled cleanup of orphaned records by runbook
  • Wallpapers, signatures and favorites

    Workplace Cloud Storage keeps company wallpapers, Outlook signatures and other files in your own Azure Storage account. The favorites editor manages browser bookmarks with folders and drag and drop, then publishes them for Edge and Chrome on Windows and macOS.

    • Edge and Chrome JSON
    • Edge Legacy XML
    • Edge XML for macOS
    • Chrome XML for macOS

Everything in helpdesk and operations

  • Device page

    18 views across Entra, Intune, Autopilot, Defender and the agent.

  • User page

    Sign-ins, MFA, Conditional Access, devices, roles and software.

  • Group tools

    Bulk copy, pull members up, assignments, namespaces.

  • Advanced search

    Tokenized, umlaut-tolerant, with column filters.

  • Warranty

    Seven manufacturers, looked up from the serial number.

  • Lookups

    MAC vendor, IMEI and sign-in location.

  • Remote actions

    Sync, scan, logs, key rotation, primary user, AnyDesk.

  • Excel exports

    Six predefined exports plus export on every table.

  • Delegation

    Nine roles and custom roles, mapped to Entra groups.

  • Autopilot

    Import, inspect and move devices between tenants.

  • Workplace Cloud Storage

    Wallpapers, signatures, files and favorites in your storage.

  • Organization dashboard

    Intune and RealmJoin numbers, runbook results, app timeline.

Give helpdesk one screen, and fewer rights.

See your own devices and users in RealmJoin. Connecting a tenant takes one consent, and you can start read-only.