Security you can check, not just believe.
Where RealmJoin runs, where your data lives, which permissions it asks for, and how it's operated. Written for the people who have to sign off.
- ISO 27001 certified operations
- TLS 1.2 or later, outbound HTTPS on 443 only
- Configuration signed with RSA-SHA512
- Nine roles, 178 named permissions
- West Europe
- Primary Azure region, North Europe as backup
- Your Azure
- Runbooks, admin passwords and audit logs
- 24 hours
- To ship a fix for a critical vulnerability
- 99.5%
- Availability target, with service credits
Hosted in Microsoft Azure, in Europe
RealmJoin is a cloud-native, multi-tenant service built and operated by glueckkanja in Germany. Nothing runs on your servers.
Region
Azure West Europe, with North Europe as backup. Customer data does not leave Europe.
Platform
Containerized .NET services on Azure App Service, with Azure SQL, Cosmos DB, Blob Storage and Key Vault.
Transport
TLS 1.2 or later for every connection, HSTS, and cookies that are always secure and HTTP-only.
Endpoints
Devices talk to RealmJoin over outbound HTTPS on port 443 only, with FQDN-based allow lists.
The sensitive parts stay in your tenant
RealmJoin is SaaS, but the things you'd least like to hand over run in your own Microsoft 365 tenant and Azure subscription.
RealmJoin service
Microsoft Azure, West Europe, with North Europe as backup
- Portal and APIs
- Background automation
- Package catalog and CDN
Microsoft Graph, only with the permissions you consent to
Your Microsoft 365 tenant
Where the decisions stay
- Intune
- Entra ID
- Autopilot
- Defender for Endpoint
Your Azure subscription
Where the sensitive work happens
- Azure Automationruns the runbooks
- Key Vaultholds local admin passwords
- Log Analyticskeeps audit, operational and runbook logs
- Storageserves wallpapers, signatures and favorites
Your devices
Optional RealmJoin Agent on Windows
- Accepts only signed configuration
- Outbound HTTPS on port 443
- Peer-to-peer caching with BranchCache
Retention
Device state history is kept for 90 days. Log retention in your workspace is yours to set; RealmJoin proposes 730 days.
Leaving
Offboarding deletes a tenant's data in a structured, resumable sequence covering every data category, and keeps a record that it happened.
Every permission, and why it's there
Permissions are split across separate app registrations so you only consent to what you use. Quick Setup grants them with one consent; Advanced Setup lets you grant each one yourself, and every permission can be downgraded or revoked later.
| Microsoft Graph permission | Used for |
|---|---|
| Core, granted by default | |
| User.Read.All | Users on user and device pages |
| Device.Read.All | Entra devices, correlated with Intune and the agent |
| DeviceManagementManagedDevices.Read.All | Intune managed devices |
| DeviceManagementConfiguration.Read.All | Compliance and configuration policies |
| DeviceManagementApps.ReadWrite.All | Creating and updating Intune apps from the store |
| Group.ReadWrite.All | Managed app groups and group tools |
| GroupMember.ReadWrite.All | Update groups and membership changes |
| Optional, only if you switch the feature on | |
| DeviceLocalCredential.Read.All | Windows LAPS in Intune |
| BitlockerKey.Read.All | BitLocker recovery keys |
| DeviceManagementManagedDevices.PrivilegedOperations.All | Device actions such as sync, scan and key rotation |
| DeviceManagementScripts.ReadWrite.All | Intune remediation scripts |
| DeviceManagementServiceConfig.Read.All | Autopilot information |
| AuditLog.Read.All | Sign-in details |
| WindowsUpdates.ReadWrite.All | Windows device updates enrollment |
| LicenseAssignment.Read.All | Intune license count |
Read-only mode
Connect the core with read-only permissions first and upgrade later.
Administrative Unit scoping
Swap tenant-wide group write for one Administrative Unit, where RealmJoin acts as Groups Administrator only.
Separate apps
Portal, core, core read-only, security features (Defender, needs an MDE subscription), the client app and Partner Center each have their own registration.
No secret in your tenant for Automation
Azure Automation connects through a RealmJoin-managed multi-tenant app.
Nothing runs that wasn't signed
From the configuration a device receives to the installer it runs, every step can be verified.
Signed configuration
Every device configuration is signed with RSA-SHA512 and verified by the agent before it acts.
Device identity
Devices prove who they are with their Entra device certificate, checked against Entra ID. New devices can only be claimed shortly after enrollment.
Hash-checked packages
Package content comes from RealmJoin's CDN and is SHA-256 verified before it runs.
Clean sources
Maintained packages are built from official vendor sources in a private pipeline with malware scans.
Access control, down to the permission
Sign-in is Microsoft Entra ID. Every page and API call is authorized against roles you control.
Roles
Nine built-in roles, assigned through Entra groups or directory roles.
Custom roles
Compose roles from 178 named permissions.
Runbook permissions
Who may run which runbook, down to the target group, in one JSON document per tenant.
Password access
Restrictions per device owner group; every view logged with who, when and from where.
Tenant isolation
Tenant filters are applied at the data layer to every tenant-scoped query.
Audit log
30 categories with old and new values, in your own Log Analytics workspace. Roles, custom roles and local admin access
How the service is run
RealmJoin is developed and operated by glueckkanja, whose development and operations team is ISO 27001 certified.
Monitored
The platform is watched with Microsoft Sentinel and Microsoft Defender, with a SOC behind it; admins sign in with passkeys.
Gated releases
Changes pass a staging environment behind an approval gate; production releases need a separate, smaller approver group, and a hotfix path exists for urgent fixes.
Fast security fixes
Fixes for critical vulnerabilities ship within 24 hours.
Recoverable
Databases support point-in-time restore, and infrastructure is defined as code.
Observable
Every service reports health and telemetry; the public status page shows availability.
Sub-processors
The companies whose services RealmJoin relies on to process customer data. The current list is kept in the documentation.
| Company | Location | Purpose |
|---|---|---|
| Microsoft Ireland Operations Ltd. | Dublin, Ireland | Azure hosting |
| GitHub B.V. | Amsterdam, Netherlands | Source code and runbook library |
| GitLab Inc. | United States | Packaging pipeline |
What we commit to
99.5% availability target
Around the clock, with a 10% service credit below 99.5% and 25% below 99.0%.
Support included
Monday to Friday, 08:00 to 18:00 CET, in English and German.
Incident response
Typically under four hours for incidents.
Security fixes
Critical vulnerabilities fixed within 24 hours.
Packaging
Requested packages typically delivered within five business days.
Transparency
Live service status, public changelog and feedback board.
Bring your security questions.
Our engineers walk your security and compliance team through the architecture, the permissions and the data flows, with your questionnaire if you have one.