SOLUTIONS

Security you can check, not just believe.

Where RealmJoin runs, where your data lives, which permissions it asks for, and how it's operated. Written for the people who have to sign off.

  • ISO 27001 certified operations
  • TLS 1.2 or later, outbound HTTPS on 443 only
  • Configuration signed with RSA-SHA512
  • Nine roles, 178 named permissions
West Europe
Primary Azure region, North Europe as backup
Your Azure
Runbooks, admin passwords and audit logs
24 hours
To ship a fix for a critical vulnerability
99.5%
Availability target, with service credits

Hosted in Microsoft Azure, in Europe

RealmJoin is a cloud-native, multi-tenant service built and operated by glueckkanja in Germany. Nothing runs on your servers.

  • Region

    Azure West Europe, with North Europe as backup. Customer data does not leave Europe.

  • Platform

    Containerized .NET services on Azure App Service, with Azure SQL, Cosmos DB, Blob Storage and Key Vault.

  • Transport

    TLS 1.2 or later for every connection, HSTS, and cookies that are always secure and HTTP-only.

  • Endpoints

    Devices talk to RealmJoin over outbound HTTPS on port 443 only, with FQDN-based allow lists.

The sensitive parts stay in your tenant

RealmJoin is SaaS, but the things you'd least like to hand over run in your own Microsoft 365 tenant and Azure subscription.

RealmJoin service

Microsoft Azure, West Europe, with North Europe as backup

  • Portal and APIs
  • Background automation
  • Package catalog and CDN

Your Microsoft 365 tenant

Where the decisions stay

  • Intune
  • Entra ID
  • Autopilot
  • Defender for Endpoint

Your Azure subscription

Where the sensitive work happens

  • Azure Automationruns the runbooks
  • Key Vaultholds local admin passwords
  • Log Analyticskeeps audit, operational and runbook logs
  • Storageserves wallpapers, signatures and favorites

Your devices

Optional RealmJoin Agent on Windows

  • Accepts only signed configuration
  • Outbound HTTPS on port 443
  • Peer-to-peer caching with BranchCache
  • Retention

    Device state history is kept for 90 days. Log retention in your workspace is yours to set; RealmJoin proposes 730 days.

  • Leaving

    Offboarding deletes a tenant's data in a structured, resumable sequence covering every data category, and keeps a record that it happened.

Every permission, and why it's there

Permissions are split across separate app registrations so you only consent to what you use. Quick Setup grants them with one consent; Advanced Setup lets you grant each one yourself, and every permission can be downgraded or revoked later.

Microsoft Graph permissions RealmJoin asks for and what each one is used for
Microsoft Graph permissionUsed for
Core, granted by default
User.Read.AllUsers on user and device pages
Device.Read.AllEntra devices, correlated with Intune and the agent
DeviceManagementManagedDevices.Read.AllIntune managed devices
DeviceManagementConfiguration.Read.AllCompliance and configuration policies
DeviceManagementApps.ReadWrite.AllCreating and updating Intune apps from the store
Group.ReadWrite.AllManaged app groups and group tools
GroupMember.ReadWrite.AllUpdate groups and membership changes
Optional, only if you switch the feature on
DeviceLocalCredential.Read.AllWindows LAPS in Intune
BitlockerKey.Read.AllBitLocker recovery keys
DeviceManagementManagedDevices.PrivilegedOperations.AllDevice actions such as sync, scan and key rotation
DeviceManagementScripts.ReadWrite.AllIntune remediation scripts
DeviceManagementServiceConfig.Read.AllAutopilot information
AuditLog.Read.AllSign-in details
WindowsUpdates.ReadWrite.AllWindows device updates enrollment
LicenseAssignment.Read.AllIntune license count
  • Read-only mode

    Connect the core with read-only permissions first and upgrade later.

  • Administrative Unit scoping

    Swap tenant-wide group write for one Administrative Unit, where RealmJoin acts as Groups Administrator only.

  • Separate apps

    Portal, core, core read-only, security features (Defender, needs an MDE subscription), the client app and Partner Center each have their own registration.

  • No secret in your tenant for Automation

    Azure Automation connects through a RealmJoin-managed multi-tenant app.

Nothing runs that wasn't signed

From the configuration a device receives to the installer it runs, every step can be verified.

  • Signed configuration

    Every device configuration is signed with RSA-SHA512 and verified by the agent before it acts.

  • Device identity

    Devices prove who they are with their Entra device certificate, checked against Entra ID. New devices can only be claimed shortly after enrollment.

  • Hash-checked packages

    Package content comes from RealmJoin's CDN and is SHA-256 verified before it runs.

  • Clean sources

    Maintained packages are built from official vendor sources in a private pipeline with malware scans.

Access control, down to the permission

Sign-in is Microsoft Entra ID. Every page and API call is authorized against roles you control.

  • Roles

    Nine built-in roles, assigned through Entra groups or directory roles.

  • Custom roles

    Compose roles from 178 named permissions.

  • Runbook permissions

    Who may run which runbook, down to the target group, in one JSON document per tenant.

  • Password access

    Restrictions per device owner group; every view logged with who, when and from where.

  • Tenant isolation

    Tenant filters are applied at the data layer to every tenant-scoped query.

  • Audit log

    30 categories with old and new values, in your own Log Analytics workspace. Roles, custom roles and local admin access

How the service is run

RealmJoin is developed and operated by glueckkanja, whose development and operations team is ISO 27001 certified.

  • Monitored

    The platform is watched with Microsoft Sentinel and Microsoft Defender, with a SOC behind it; admins sign in with passkeys.

  • Gated releases

    Changes pass a staging environment behind an approval gate; production releases need a separate, smaller approver group, and a hotfix path exists for urgent fixes.

  • Fast security fixes

    Fixes for critical vulnerabilities ship within 24 hours.

  • Recoverable

    Databases support point-in-time restore, and infrastructure is defined as code.

Sub-processors

The companies whose services RealmJoin relies on to process customer data. The current list is kept in the documentation.

Sub-processors, where they are and what they process
CompanyLocationPurpose
Microsoft Ireland Operations Ltd.Dublin, IrelandAzure hosting
GitHub B.V.Amsterdam, NetherlandsSource code and runbook library
GitLab Inc.United StatesPackaging pipeline

What we commit to

  • 99.5% availability target

    Around the clock, with a 10% service credit below 99.5% and 25% below 99.0%.

  • Support included

    Monday to Friday, 08:00 to 18:00 CET, in English and German.

  • Incident response

    Typically under four hours for incidents.

  • Security fixes

    Critical vulnerabilities fixed within 24 hours.

  • Packaging

    Requested packages typically delivered within five business days.

  • Transparency

    Live service status, public changelog and feedback board.

Bring your security questions.

Our engineers walk your security and compliance team through the architecture, the permissions and the data flows, with your questionnaire if you have one.