The other half of Microsoft Intune.

RealmJoin packages, patches and retires your apps, gives helpdesk one screen per user and device, and turns your PowerShell into guarded self-service. Cloud-native, hosted in Europe, nothing to run on your side.

Microsoft Partner of the Year Award winner or finalist, Security MSSP of the Year finalist
Google Chrome140.0.7339.128via Intune (Win32)
Preview channel, pilot group0 / 0 devices updated

Each shard is a group of devices. Illustrative rollout; hover to inspect.

Built on the Microsoft stack you already run

  • Microsoft Intune
  • Entra ID
  • Windows Autopilot
  • Defender for Endpoint
  • Windows 365
  • Azure Virtual Desktop
  • Azure Automation
  • Log Analytics and Sentinel
  • Partner Center

What Intune leaves on your desk

Intune decides what should happen on a device. Packaging every update, delegating helpdesk and scripting the routine still land on your team. That's the work RealmJoin takes over.

  1. Every app update is a small packaging project.

    Subscribe once from 3,000+ maintained packages. New versions are picked up within 15 minutes and roll out through Preview and Main on the schedule you set.

    How the app lifecycle works
  2. Apps assigned as Available fall behind.

    The update group spots devices with an outdated install and makes the update required until they're current. No new assignments for you to build.

    About the update group
  3. Helpdesk needs five portals and broad admin roles.

    One screen per user, group and device across Entra ID, Intune, Autopilot and Defender. Nine roles and 178 permissions hand out exactly what a job needs.

    Helpdesk and operations
  4. Automation lives in someone's scripts folder.

    175 open-source runbooks run in your own Azure Automation account, as forms with pickers, schedules and a full job log.

    Runbook automation
  5. The local admin password is a shared secret.

    Emergency, support and privileged accounts per device, escrowed in a Key Vault dedicated to your tenant. Support access expires on its own and every view is audited.

    Privileged access
  6. Nobody knows what's installed, let alone used.

    Inventory from the agent and Intune, matched to real run counts when you switch usage metering on, shows unused licenses and shadow IT in one report.

    Software insights
PLATFORM

One console for the work around Intune

Six areas, one sign-in, one set of roles. Pick one to see what your team would work with every day.

One version, from vendor to the last laptop

7-Zipgeneric-7zip24.09
  1. Vendor25.01 published
  2. CatalogListed, verified
  3. Preview48 devices
  4. Main3,912 devices
  5. Update group61 caught up
  6. Usage412 unused
generic-7zip
09-08 09:12  vendor   7-Zip 25.01 published09-08 09:25  catalog  generic-7zip 25.01 listed, hash verified09-10 23:04  preview  app - win - 7-Zip (preview): 48 devices09-15 23:02  main     promoted to Main: 3,912 devices09-16 02:10  update   61 outdated installs added to update group12-01 08:00  usage    412 devices without a run in 90 days

Run a runbook. Right here.

RealmJoin reads each script's parameters and builds the form: Graph-backed pickers, dropdowns, sensible defaults. Permissions decide who sees which runbook.

Runbooks you may run

5 of 175 runbooks. Browse the library

user/general/offboard-user-permanently.ps1

Offboard user permanently

Revokes access, blocks or deletes the account, adjusts groups and licenses, and hands over ownerships and direct reports.

Ready
No job yet
Run a runbook to see its job output here.

Simulated in your browser. The runbooks and parameters are real, from the open-source library on GitHub, where 175 of them are waiting.

Helpdesk gets one screen. You keep the keys.

Supporters see what they need to fix a device, and nothing their role doesn't cover. Try it: choose who is asking for this device's local admin password.

NB-MUC-0412 belongs to Maren Müller

Owner's groups: sec - finance, sec - executives

Who is asking?
Why

The Supporter role covers the emergency and support accounts. The privileged account is out of scope. Every password view is written to the audit log.

  • One page per device. Entra ID, Intune, Autopilot, Defender and agent data side by side, in 18 views from warranty to raw JSON.
  • Actions without admin sprawl. Intune sync, Defender scans, BitLocker and FileVault key rotation, log requests and AnyDesk sessions, each behind its own permission.
  • Warranty for seven vendors. Apple, Dell, Fujitsu, HP, Huawei, Lenovo and Microsoft, looked up from the serial number.
  • Audited by default. Every password view and key rotation is written to the audit log in your Log Analytics workspace.

Installed isn't used.

Usage metering is optional: you decide whether it runs in your tenant. With it, RealmJoin matches Windows execution data to packages, so every install comes with run counts and a last-used date. The gap is where licenses go back.

  • 2,020installs without a run in 90 days
  • 214titles nobody deployed, found on devices

Example data for a 4,000-device tenant.

InstalledUsed in the last 90 days
  • Adobe Acrobat Pro610 of 1,240
  • Microsoft Visio212 of 880
  • SAP GUI for Windows1,960 of 2,100
  • Zoom Workplace2,980 of 3,400
  • Autodesk AutoCAD LT61 of 145
  • Tableau Desktop18 of 96
Bars are scaled to the largest install base. Usage comes from Prefetch and process data matched by process name, file hash or install path.

Your tenant, your data

RealmJoin is SaaS, but the sensitive parts run where you already hold the keys: your Microsoft 365 tenant and your own Azure subscription.

RealmJoin service

Microsoft Azure, West Europe, with North Europe as backup

  • Portal and APIs
  • Background automation
  • Package catalog and CDN

Your Microsoft 365 tenant

Where the decisions stay

  • Intune
  • Entra ID
  • Autopilot
  • Defender for Endpoint

Your Azure subscription

Where the sensitive work happens

  • Azure Automationruns the runbooks
  • Key Vaultholds local admin passwords
  • Log Analyticskeeps audit, operational and runbook logs
  • Storageserves wallpapers, signatures and favorites

Your devices

Optional RealmJoin Agent on Windows

  • Accepts only signed configuration
  • Outbound HTTPS on port 443
  • Peer-to-peer caching with BranchCache

Read the security overview

COMPARISON

Who does the work

Intune is the right foundation. This is what changes for your team when RealmJoin sits on top of it.

When this happensIntune on its ownIntune with RealmJoin
A vendor ships a new versionYou notice, repackage, test and update assignments.The maintained package updates itself. You set the delay.
You want a pilot before everyoneYou build and maintain ring groups per app.Preview and Main channels with managed groups per app.
People installed an app as AvailableThey stay on whatever version they installed.Outdated installs are updated through the update group.
An app isn't packaged yetYour team builds and tests the Win32 package.Request it from the packaging team, or upload the installer and get a package in minutes.
Offboarding, access passes, mailbox changesScripts on an admin's laptop, or many manual clicks.Runbooks as forms, with permissions and a job log.
Helpdesk needs a local adminWindows LAPS manages one account per device.A support account that expires on its own, plus emergency and privileged accounts.
Is this software actually used?Discovered apps show what is installed.Optional usage metering: run counts and last use per app.
Is the laptop still under warranty?Look it up on the vendor's site by serial number.Warranty from seven vendors on the device page.
AT A GLANCE

The details admins ask about first

Before the first test tenant is connected, this is usually what comes up.

Service

Service
SaaS on Microsoft Azure, hosted in West Europe with North Europe as backup. Nothing to install on servers.
Onboarding
Quick Setup with one Entra admin consent, or Advanced Setup that grants each permission through PowerShell.
Availability
99.5% target with service credits. Live status at status.realmjoin.com.

Endpoints

Endpoints
Windows 10 and 11 with the optional RealmJoin Agent. macOS apps through Intune as DMG or PKG. Windows 365 and Azure Virtual Desktop aware.
App delivery
Intune Win32, macOS DMG and PKG, or the RealmJoin Agent with dependencies, install phases and background installs.
Network
Outbound HTTPS on port 443 only, with FQDN-based allow lists.

Automation

Update automation
Preview and Main channels, 0 to 90 day delay, night window in your time zone, owner notifications.
Automation
Your Azure Automation account, PowerShell 7.4, 175 library runbooks plus your own, schedules and permissions.

Access and logging

Access control
Nine built-in roles, custom roles from 178 permissions, Entra groups or directory roles, Administrative Unit scoping.
Logging
Audit, operational and runbook logs in your Log Analytics workspace through the Logs Ingestion API, 730 days retention by default.

Integration

Integration
REST Customer API with OpenAPI docs, an MCP server for AI assistants, and a PowerShell module.
Support
Included. Monday to Friday, 08:00 to 18:00 CET, in English and German.

Scale

Organizations
250 to 100,000+ users
Managed seats
500,000+
Availability
High availability and geo-redundancy

Customer isolation

Enrollment
Single- or multi-tenant
MSP
MSP licensing available
BUILT FOR YOUR ROLE

For MSPs, security teams and developers

Three doors into the same platform.

Three steps to your first automated update

No servers, no agents on infrastructure, no project plan. Most of it is a consent screen and a few decisions.
  • Connect your tenant
    Connect your tenant
    Sign in at portal.realmjoin.com as a Global Administrator and grant one consent. Prefer to grant permissions one by one? Use the PowerShell module.
    Install-Module RealmJoin
    Complete-RJTenantOnboarding -Token <token>
  • Subscribe your first apps
    Subscribe your first apps
    Pick packages from the store, choose Intune or Agent delivery and decide when Preview and Main should follow a new release.
  • Delegate and automate
    Delegate and automate
    Map roles to Entra groups, connect Azure Automation for runbooks and point audit logs at your Log Analytics workspace.
GOOD TO KNOW

Questions that come up early

More in the documentation, or ask an engineer directly.

01Does RealmJoin replace Intune?

No. RealmJoin builds on Intune and uses it for enrollment, compliance, configuration and app delivery. It adds the application lifecycle, delegation and automation around it.

02Do we have to install the RealmJoin Agent?

No. Apps can be delivered through Intune alone. The optional Windows agent adds dependency-aware installs, its own enrollment status page, three local admin accounts, desktop notifications, optional usage data and peer-to-peer caching.

03Where is our data stored?

The RealmJoin service runs in Microsoft Azure in West Europe, with North Europe as backup. Runbooks, local admin passwords and audit logs live in your own Azure subscription.

04Which permissions does RealmJoin ask for?

Only those for the features you use, split across separate app registrations. You can connect read-only, limit RealmJoin to one Administrative Unit, and revoke or downgrade any permission later.

05What about macOS?

macOS apps are delivered through Intune as DMG or PKG. FileVault keys, Intune-managed LAPS and wipe work from the device page. The RealmJoin Agent itself is for Windows.

06What if an app isn't in the store?

Request it and the packaging team builds and tests it, typically within five business days. Or upload your installer as a ZIP and get an organic package within minutes.

07How is RealmJoin licensed?

Per user, in two editions, Apps and Enterprise, starting at 1,000 users. Monthly or annual terms, also available through Microsoft Marketplace. See pricing

08Can we try it first?

Yes. Connect your tenant yourself with one consent at portal.realmjoin.com, or book a demo with an engineer first.

RealmJoin Unlocked

The RealmJoin video podcast. Moritz Pohl and guests on releases, features and the realities of modern endpoint management.

Meet Us in Person

RealmJoin is on the road this autumn. Come by, bring your Intune questions, and see RealmJoin in action.

Mo
14
Sep

Workplace Ninja Summit

Community conference in Baden on Microsoft Endpoint Management and Security

Location Baden
Tu
27
Oct

it-sa

Meet us again this year at Europe's leading trade fair for IT security

Location Nuremberg