Overview
This document provides a comprehensive overview of all runbooks currently available in the RealmJoin portal. Each runbook is listed along with a brief description or synopsis to give a clear understanding of its purpose and functionality. The runbook name links to the detailed reference page of the respective runbook.
To ensure easy navigation, the runbooks are categorized into different sections based on their area of application. The following categories are currently available:
Device
Group
Organization
User
Each category contains multiple runbooks that are further divided into subcategories based on their functionality. The runbooks are listed in alphabetical order within each subcategory.
Device
AVD
Reboots a specific AVD Session Host.
Sets Drainmode on true or false for a specific AVD Session Host.
General
Assign cloud-only groups to a device based on a template
Assign a new AutoPilot GroupTag to this device.
Check the compliance status of a device
Check if a device is onboarded to Windows Update for Business
Enroll device into Windows Update for Business
Remove/Outphase a windows device
Removes the primary user from a device.
Rename a device.
Set a new primary user on a managed Intune device
Unenroll device from Windows Update for Business.
Wipe a Windows or MacOS device
App selective wipe - remove company app data from this MAM device
Security
Check a device's presence and risk status in Entra ID and Microsoft Defender for Endpoint
Enable or disable a device in Entra ID
Isolate this device.
Reset a mobile device's password/PIN code.
Only allow Microsoft-signed code to run on a device, or remove an existing restriction.
Show all BitLocker recovery keys for a device
Display macOS FileVault recovery key
Show a local admin password for a device.
Group
Devices
Check if devices in a group are onboarded to Windows Update for Business.
Unenroll devices from Windows Update for Business.
General
Add/remove a nested group to/from a group
Add or remove a Office 365 group owner
Add or remove a group member
Change a group's visibility
List all members of a group, including members that are part of nested groups
List all owners of an Office 365 group.
List devices owned by group members.
Remove a group. For Microsoft 365 groups, also the associated resources (Teams, SharePoint site) will be removed.
Rename a group.
Enable or disable external parties to send emails to a Microsoft 365 group
Show or hide a group in the address book
Teams
Archive a team
Organization
Applications
Add an application registration to Azure AD
Add a GSA application registration to Azure AD
Delete an application registration from Azure AD
Delete a GSA application registration from Azure AD including associated objects
Export a report of all (enterprise) application owners and users
List enterprise applications with no recent sign-ins
Generate and email a comprehensive Application Registration report
List expiry date of all Application Registration credentials
Update an application registration in Azure AD
Devices
Import a Windows device into Windows Autopilot
Import a device into Intune via corporate identifier
Auto-approve new driver updates in Intune driver update policies
Clean up orphaned and stale Windows Autopilot device registrations
Creates Endpoint Analytics baselines in Microsoft Intune with a specified naming schema.
Detect and rename duplicate Intune device display names using a prefix and random suffix
Scheduled deletion of stale devices based on last activity date and platform
Get the BitLocker recovery key
Notify primary users about their stale devices via email
Remove or outphase multiple devices
Reports all managed devices in Intune that do not have a primary user assigned.
Compare primary user assignments in Intune against RealmJoin for Windows managed devices
Scheduled report of stale devices based on last activity date and platform.
Report users with more than five registered devices
Reports all Windows Entra devices that have no associated Windows Autopilot object.
Sync Intune serial numbers to Entra ID extension attributes
General
Sync devices of users in a specific group to another device group
List or add Management Partner Links (PAL)
Update logos of Microsoft Store Apps (new) in Intune
Create an Office 365 group and SharePoint site, optionally create a (Teams) team.
Add or remove a SafeLinks URL exclusion from a policy
Add or remove a SmartScreen URL indicator in Microsoft Defender
Add or remove a URL entry in the Intune Trusted Sites policy
Sync primary users of Intune managed devices by platform into an Entra ID group
Create a Microsoft Entra ID security group
Create a new user account
Create a Viva Engage (Yammer) community
Assign cloud-only groups to many users based on a predefined template
Bulk delete Autopilot objects by serial number
Bulk retire devices from Intune using serial numbers
Check last Azure AD Connect sync status
Check Intune assignments for one or more device names
Check Intune assignments for one or more group names
Check Intune assignments for one or more user principal names
Check if given serial numbers are present in Autopilot
Add unenrolled Autopilot devices to an exclusion group
Show recent first-time device enrollments
List or export all Windows Autopilot devices
Export a list of all Intune devices and where they are registered
Write daily Windows 365 utilization data to Azure Table Storage
Export non-compliant Intune devices and settings
Create a report of tenant policies from Intune and Entra ID.
Invite external guest users to the organization
List all Administrative Template policies and their assignments
Report groups that have license assignment errors
Alert by email on newly announced Microsoft 365 Service Health issues
Generate an Office 365 licensing report
Monitor/Report expiry of Apple device management certificates
Generate and email a license availability report based on thresholds
Scheduled report on PIM activations
Sync all Intune Windows devices
Sync Apple Enrollment Program Tokens and VPP Tokens with Intune
Sync members between a Teams Shared Channel or a group and an Entra security group
Ensure a security group's members are owners of mapped Teams and their shared channels.
Create a classic distribution group
Create an equipment mailbox
Create a new Exchange Online mail contact with optional display name and address list settings
Add or remove a public folder
Create/Remove a contact, to allow pretty email addresses for Teams channels.
Add or remove entries from the Tenant Allow/Block List
Create a room mailbox resource
Create a shared mailbox
Hide or unhide special mailboxes in the Global Address List
Configure Microsoft Bookings settings for the organization
Phone
Check whether a phone number is assigned in Microsoft Teams
Security
Create a new Microsoft Defender for Endpoint indicator
Export Conditional Access policies to an Azure Storage account
Find the user associated with a specific SMS-based authentication phone number
List Entra ID role holders and optionally evaluate their MFA methods
List Azure AD role assignments expiring within a given number of days
List or export inactive devices with no recent logon or Intune sync
List users with no recent interactive sign-ins
List Microsoft Information Protection labels
List role-assignable groups with eligible role assignments but without owners
Report users by the count of their registered MFA methods
List app registrations potentially vulnerable to CVE-2021-42306
Monitor and report pending Endpoint Privilege Management (EPM) elevation requests
Send notification email if Conditional Access policies have been created or modified in the last 24 hours.
Generate report for Endpoint Privilege Management (EPM) elevation requests
Sync users with secure MFA methods registered into an Entra ID group
User
AVD
Removes (Signs Out) a specific User from their AVD Session.
General
Assign cloud-only groups to a user based on a template
Assign or remove a license for a user via group membership
Assign and provision a Windows 365 Cloud PC for a user
List group memberships for this user
List group ownerships for this user.
List manager information for this user
Permanently offboard a user
Temporarily offboard a user
Reprovision a Windows 365 Cloud PC
Resize an existing Windows 365 Cloud PC for a user
Remove and deprovision a Windows 365 Cloud PC for a user
Add or remove an email address for a mailbox
Assign an OWA mailbox policy to a user
Convert a user mailbox to a shared mailbox and back
Grant or revoke Exchange Online FullAccess mailbox permission for one or more users
Delegate SendAs permissions for other user on his/her mailbox or remove existing delegation
Delegate SendOnBehalf permissions for the user's mailbox
Hide or unhide a mailbox in the address book
List mailbox permissions for a mailbox
List room mailbox configuration
Manage the Exchange Online archive mailbox for a user
Hard delete a shared mailbox, room or bookings calendar
Enable or disable mailbox out-of-office notifications
Set room mailbox resource policies
Phone
Microsoft Teams telephony offboarding
Get Microsoft Teams voice status for a user
Grant Microsoft Teams policies to a Microsoft Teams enabled user
Set immediate call forwarding for a Teams user
Assign a phone number to a Microsoft Teams enabled user, enable calling and Grant specific Microsoft Teams policies.
Security
Confirm compromise or dismiss a risky user
Create a temporary access pass for a user
Enable or disable password expiration for a user
List all MFA / authentication methods of a user
Remove all App- and Mobilephone auth methods for a user
Reset a user's password
Revoke or restore user access
Set or remove a user's mobile phone MFA method
Userinfo
Rename a user or mailbox
Set the profile photo for a user
Update user metadata and memberships
Last updated
Was this helpful?