For the complete documentation index, see llms.txt. This page is also available as Markdown.

Overview

This document provides a comprehensive overview of all runbooks currently available in the RealmJoin portal. Each runbook is listed along with a brief description or synopsis to give a clear understanding of its purpose and functionality. The runbook name links to the detailed reference page of the respective runbook.

To ensure easy navigation, the runbooks are categorized into different sections based on their area of application. The following categories are currently available:

  • Device

  • Group

  • Organization

  • User

Each category contains multiple runbooks that are further divided into subcategories based on their functionality. The runbooks are listed in alphabetical order within each subcategory.

Device

AVD

Runbook Name
Synopsis

Restart Host

Reboots a specific AVD Session Host.

Toggle Drain Mode

Sets Drainmode on true or false for a specific AVD Session Host.

General

Runbook Name
Synopsis

Assign Groups By Template

Assign cloud-only groups to a device based on a template

Change Grouptag

Assign a new AutoPilot GroupTag to this device.

Check Device Compliance

Check the compliance status of a device

Check Updatable Assets

Check if a device is onboarded to Windows Update for Business

Enroll Updatable Assets

Enroll device into Windows Update for Business

Outphase Device

Remove/Outphase a windows device

Remove Primary User

Removes the primary user from a device.

Rename Device

Rename a device.

Set Primary User

Set a new primary user on a managed Intune device

Unenroll Updatable Assets

Unenroll device from Windows Update for Business.

Wipe Device

Wipe a Windows or MacOS device

Wipe Managed App Data

App selective wipe - remove company app data from this MAM device

Security

Runbook Name
Synopsis

Check Defender Status

Check a device's presence and risk status in Entra ID and Microsoft Defender for Endpoint

Enable Or Disable Device

Enable or disable a device in Entra ID

Isolate Or Release Device

Isolate this device.

Reset Mobile Device Pin

Reset a mobile device's password/PIN code.

Only allow Microsoft-signed code to run on a device, or remove an existing restriction.

Show all BitLocker recovery keys for a device

Display macOS FileVault recovery key

Show Laps Password

Show a local admin password for a device.

Group

Devices

Runbook Name
Synopsis

Check Updatable Assets

Check if devices in a group are onboarded to Windows Update for Business.

Unenroll devices from Windows Update for Business.

General

Runbook Name
Synopsis

Add/remove a nested group to/from a group

Add Or Remove Owner

Add or remove a Office 365 group owner

Add Or Remove User

Add or remove a group member

Change Visibility

Change a group's visibility

List All Members

List all members of a group, including members that are part of nested groups

List Owners

List all owners of an Office 365 group.

List User Devices

List devices owned by group members.

Remove Group

Remove a group. For Microsoft 365 groups, also the associated resources (Teams, SharePoint site) will be removed.

Rename Group

Rename a group.

Mail

Runbook Name
Synopsis

Enable or disable external parties to send emails to a Microsoft 365 group

Show or hide a group in the address book

Teams

Runbook Name
Synopsis

Archive Team

Archive a team

Organization

Applications

Runbook Name
Synopsis

Add an application registration to Azure AD

Add a GSA application registration to Azure AD

Delete an application registration from Azure AD

Delete a GSA application registration from Azure AD including associated objects

Export a report of all (enterprise) application owners and users

List enterprise applications with no recent sign-ins

Generate and email a comprehensive Application Registration report

List expiry date of all Application Registration credentials

Update an application registration in Azure AD

Devices

Runbook Name
Synopsis

Add Autopilot Device

Import a Windows device into Windows Autopilot

Import a device into Intune via corporate identifier

Auto-approve new driver updates in Intune driver update policies

Clean up orphaned and stale Windows Autopilot device registrations

Creates Endpoint Analytics baselines in Microsoft Intune with a specified naming schema.

Detect and rename duplicate Intune device display names using a prefix and random suffix

Scheduled deletion of stale devices based on last activity date and platform

Get the BitLocker recovery key

Notify primary users about their stale devices via email

Outphase Devices

Remove or outphase multiple devices

Reports all managed devices in Intune that do not have a primary user assigned.

Compare primary user assignments in Intune against RealmJoin for Windows managed devices

Scheduled report of stale devices based on last activity date and platform.

Report users with more than five registered devices

Reports all Windows Entra devices that have no associated Windows Autopilot object.

Sync Intune serial numbers to Entra ID extension attributes

General

Runbook Name
Synopsis

Sync devices of users in a specific group to another device group

Add Management Partner

List or add Management Partner Links (PAL)

Update logos of Microsoft Store Apps (new) in Intune

Add Office365 Group

Create an Office 365 group and SharePoint site, optionally create a (Teams) team.

Add or remove a SafeLinks URL exclusion from a policy

Add or remove a SmartScreen URL indicator in Microsoft Defender

Add or remove a URL entry in the Intune Trusted Sites policy

Sync primary users of Intune managed devices by platform into an Entra ID group

Add Security Group

Create a Microsoft Entra ID security group

Add User

Create a new user account

Create a Viva Engage (Yammer) community

Assign cloud-only groups to many users based on a predefined template

Bulk delete Autopilot objects by serial number

Bulk retire devices from Intune using serial numbers

Check last Azure AD Connect sync status

Check Intune assignments for one or more device names

Check Intune assignments for one or more group names

Check Intune assignments for one or more user principal names

Check if given serial numbers are present in Autopilot

Add unenrolled Autopilot devices to an exclusion group

Show recent first-time device enrollments

List or export all Windows Autopilot devices

Export All Intune Devices

Export a list of all Intune devices and where they are registered

Write daily Windows 365 utilization data to Azure Table Storage

Export non-compliant Intune devices and settings

Export Policy Report

Create a report of tenant policies from Intune and Entra ID.

Invite external guest users to the organization

List all Administrative Template policies and their assignments

Report groups that have license assignment errors

Alert by email on newly announced Microsoft 365 Service Health issues

Office365 License Report

Generate an Office 365 licensing report

Monitor/Report expiry of Apple device management certificates

Generate and email a license availability report based on thresholds

Scheduled report on PIM activations

Sync All Devices

Sync all Intune Windows devices

Sync Apple Tokens

Sync Apple Enrollment Program Tokens and VPP Tokens with Intune

Sync members between a Teams Shared Channel or a group and an Entra security group

Ensure a security group's members are owners of mapped Teams and their shared channels.

Mail

Runbook Name
Synopsis

Add Distribution List

Create a classic distribution group

Add Equipment Mailbox

Create an equipment mailbox

Add Mail Contact

Create a new Exchange Online mail contact with optional display name and address list settings

Add or remove a public folder

Create/Remove a contact, to allow pretty email addresses for Teams channels.

Add or remove entries from the Tenant Allow/Block List

Add Room Mailbox

Create a room mailbox resource

Add Shared Mailbox

Create a shared mailbox

Hide or unhide special mailboxes in the Global Address List

Set Booking Config

Configure Microsoft Bookings settings for the organization

Phone

Runbook Name
Synopsis

Check whether a phone number is assigned in Microsoft Teams

Security

Runbook Name
Synopsis

Add Defender Indicator

Create a new Microsoft Defender for Endpoint indicator

Export Conditional Access policies to an Azure Storage account

Find the user associated with a specific SMS-based authentication phone number

List Admin Users

List Entra ID role holders and optionally evaluate their MFA methods

List Azure AD role assignments expiring within a given number of days

List Inactive Devices

List or export inactive devices with no recent logon or Intune sync

List Inactive Users

List users with no recent interactive sign-ins

List Microsoft Information Protection labels

List role-assignable groups with eligible role assignments but without owners

Report users by the count of their registered MFA methods

List Vulnerable App Regs

List app registrations potentially vulnerable to CVE-2021-42306

Monitor and report pending Endpoint Privilege Management (EPM) elevation requests

Send notification email if Conditional Access policies have been created or modified in the last 24 hours.

Generate report for Endpoint Privilege Management (EPM) elevation requests

Sync users with secure MFA methods registered into an Entra ID group

User

AVD

Runbook Name
Synopsis

User Signout

Removes (Signs Out) a specific User from their AVD Session.

General

Runbook Name
Synopsis

Assign Groups By Template

Assign cloud-only groups to a user based on a template

Assign or remove a license for a user via group membership

Assign Windows365

Assign and provision a Windows 365 Cloud PC for a user

List Group Memberships

List group memberships for this user

List Group Ownerships

List group ownerships for this user.

List Manager

List manager information for this user

Offboard User Permanently

Permanently offboard a user

Offboard User Temporarily

Temporarily offboard a user

Reprovision Windows365

Reprovision a Windows 365 Cloud PC

Resize Windows365

Resize an existing Windows 365 Cloud PC for a user

Unassign Windows365

Remove and deprovision a Windows 365 Cloud PC for a user

Mail

Runbook Name
Synopsis

Add or remove an email address for a mailbox

Assign Owa Mailbox Policy

Assign an OWA mailbox policy to a user

Convert To Shared Mailbox

Convert a user mailbox to a shared mailbox and back

Delegate Full Access

Grant or revoke Exchange Online FullAccess mailbox permission for one or more users

Delegate Send As

Delegate SendAs permissions for other user on his/her mailbox or remove existing delegation

Delegate Send On Behalf

Delegate SendOnBehalf permissions for the user's mailbox

Hide or unhide a mailbox in the address book

List Mailbox Permissions

List mailbox permissions for a mailbox

List room mailbox configuration

Manage Archive Mailbox

Manage the Exchange Online archive mailbox for a user

Remove Mailbox

Hard delete a shared mailbox, room or bookings calendar

Set Out Of Office

Enable or disable mailbox out-of-office notifications

Set room mailbox resource policies

Phone

Runbook Name
Synopsis

Disable Teams Phone

Microsoft Teams telephony offboarding

Get Teams User Info

Get Microsoft Teams voice status for a user

Grant Teams User Policies

Grant Microsoft Teams policies to a Microsoft Teams enabled user

Set immediate call forwarding for a Teams user

Set Teams Phone

Assign a phone number to a Microsoft Teams enabled user, enable calling and Grant specific Microsoft Teams policies.

Security

Runbook Name
Synopsis

Confirm compromise or dismiss a risky user

Create a temporary access pass for a user

Enable or disable password expiration for a user

List MFA Methods

List all MFA / authentication methods of a user

Reset MFA

Remove all App- and Mobilephone auth methods for a user

Reset Password

Reset a user's password

Revoke Or Restore Access

Revoke or restore user access

Set or remove a user's mobile phone MFA method

Userinfo

Runbook Name
Synopsis

Rename User

Rename a user or mailbox

Set Photo

Set the profile photo for a user

Update User

Update user metadata and memberships

Last updated

Was this helpful?