# RealmJoin Documentation

Application Lifecycle and Management Companion to Microsoft Intune

[RealmJoin](https://realmjoin.com) is the perfect companion to Microsoft Intune. Deploy and maintain software from a curated catalogue of more than 3,000 applications, manage your Entra ID users, groups and devices in one unified view, and automate everyday IT operations - all cloud-native, without any on-premise servers or other local requirements.\
Manage software lifecycle, devices and users & start with automation - no matter if work happens in corporate headquarters or at [Starbucks](https://www.starbucks.com).

<figure><img src="/files/K75n0tBaHhCScOvli6ms" alt=""><figcaption></figcaption></figure>

These docs cover the technical aspects of RealmJoin, from onboarding your tenant to the reference for every runbook. Everything else about the product can be found on the [RealmJoin website](https://www.realmjoin.com/).

## New to RealmJoin?

<table data-view="cards"><thead><tr><th></th><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Overview</strong></td><td>What RealmJoin is, which problems it solves and how it complements Microsoft Intune.</td><td><a href="/pages/Tfzv2aN8xtH3K3M5eCO6">/pages/Tfzv2aN8xtH3K3M5eCO6</a></td></tr><tr><td><strong>Architecture Overview</strong></td><td>The cloud backend, how devices and administrators connect, and which resources RealmJoin uses in your own tenant.</td><td><a href="/pages/riHEaBpn1xSQIZSgA7PH">/pages/riHEaBpn1xSQIZSgA7PH</a></td></tr><tr><td><strong>Portal Navigation</strong></td><td>A guided tour through the RealmJoin Portal and everything you can reach from it.</td><td><a href="/pages/9hhY3AJj09rM2W7ud9PQ">/pages/9hhY3AJj09rM2W7ud9PQ</a></td></tr></tbody></table>

## Set up your environment

<table data-view="cards"><thead><tr><th></th><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Getting Started</strong></td><td>Decide which deployment guide fits your scope - standard for a trial or Intune-only setup, extended for the full feature set.</td><td><a href="/pages/ewGnJx6vAdlx6nC8h3iO">/pages/ewGnJx6vAdlx6nC8h3iO</a></td></tr><tr><td><strong>Onboarding</strong></td><td>Onboard RealmJoin Portal to your Entra ID tenant using Quick or Advanced Setup.</td><td><a href="/pages/TH5ltCfKQq46OCm4Q6G2">/pages/TH5ltCfKQq46OCm4Q6G2</a></td></tr><tr><td><strong>Required Permissions</strong></td><td>Every permission RealmJoin requests, and what each of them is used for.</td><td><a href="/pages/XkZJS6HDIdur7AmmCz1t">/pages/XkZJS6HDIdur7AmmCz1t</a></td></tr><tr><td><strong>Deploying the Agent</strong></td><td>Roll out the optional RealmJoin Agent to your Windows clients.</td><td><a href="/pages/HMKELYXl8Ouf0RLabchl">/pages/HMKELYXl8Ouf0RLabchl</a></td></tr></tbody></table>

## Explore by area

<table data-view="cards"><thead><tr><th></th><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Application Management</strong></td><td>Package Store, subscriptions, assignments, update channels and packaging requests.</td><td><a href="/pages/kO2QTRSP1jcwKvFk9OxL">/pages/kO2QTRSP1jcwKvFk9OxL</a></td></tr><tr><td><strong>User, Group &#x26; Device Management</strong></td><td>Entra ID, Intune, Defender, Autopilot and sign-in data correlated in a single view.</td><td><a href="/pages/cV2auHYEl0Z9stziuych">/pages/cV2auHYEl0Z9stziuych</a></td></tr><tr><td><strong>Automation</strong></td><td>Runbooks that run in your own Azure Automation account, plus Intune remediation scripts.</td><td><a href="/pages/YOH1XjzLEJA9KAWCAQW4">/pages/YOH1XjzLEJA9KAWCAQW4</a></td></tr><tr><td><strong>RealmJoin Agent</strong></td><td>ESP, dependency-aware app deployment, LAPS, notifications and self service on the device.</td><td><a href="/pages/rTxvdhy59PjO00SYlqjR">/pages/rTxvdhy59PjO00SYlqjR</a></td></tr><tr><td><strong>Analyze &#x26; Export</strong></td><td>Advanced search, software reporting and data export.</td><td><a href="/pages/1a79RA3QBUnA8LyFZS9k">/pages/1a79RA3QBUnA8LyFZS9k</a></td></tr><tr><td><strong>Administration &#x26; Settings</strong></td><td>Roles and permissions, group namespaces, self service forms and third-party integrations.</td><td><a href="/pages/vMrUZBydTi0yDmoy95Ti">/pages/vMrUZBydTi0yDmoy95Ti</a></td></tr><tr><td><strong>Security &#x26; Privacy</strong></td><td>Data handling, tenant separation and hosting.</td><td><a href="/pages/RVCRGMbcGT80hRGdqSyl">/pages/RVCRGMbcGT80hRGdqSyl</a></td></tr><tr><td><strong>Developer Reference</strong></td><td>RealmJoin API, runbook development and report functions.</td><td><a href="/pages/vhVGKfdwT0YHvUxECS0L">/pages/vhVGKfdwT0YHvUxECS0L</a></td></tr></tbody></table>

## Stay up to date and get help

* **What's new:** the [RealmJoin Changelog](https://feedback.realmjoin.com/) lists new features and fixes - and takes your feature requests.
* **Questions:** browse the [FAQ](/troubleshooting-and-faq/faq) and [Troubleshooting](/troubleshooting-and-faq/troubleshooting) sections.
* **Support:** [Support & Service Level](/legal/support) explains how to reach us and which response times apply.
* **Watch and learn:** [RealmJoin Unlocked](/introduction/realmjoin-unlocked-vodcast), our video podcast series.
* **Bookmarks:** the most important RealmJoin addresses are collected under [Useful Links](/introduction/useful-links).

{% hint style="info" %}
Ready to jump in? [RealmJoin Portal](https://portal.realmjoin.com) is where all administration happens.
{% endhint %}


# Overview

What RealmJoin is, which problems it solves next to Microsoft Intune, and what you need to run it.

## What is RealmJoin?

RealmJoin is a **cloud-native, multi-tenant SaaS** and the **Application Lifecycle and Management companion to Microsoft Intune**. It is developed and operated by [glueckkanja](https://www.glueckkanja.com/) in Microsoft Azure, hosted in Europe, and requires **no on-premise servers and no local infrastructure**.

RealmJoin does not replace Intune - it builds on it. Intune stays your MDM: it enrolls devices, applies compliance and configuration policies, and delivers apps. RealmJoin adds what modern workplace teams need on top of it:

* a maintained **application catalogue and packaging service**, so you stop building and updating packages yourself,
* a **single, correlated view** of users, groups and devices across Intune, Entra ID, Microsoft Defender, Windows Autopilot and sign-in logs,
* **process automation** through curated runbooks that run in your own Azure Automation account,
* **delegated administration and self service**, so helpdesk staff and end users can act without broad Intune or Entra admin roles.

Administrators work in the [RealmJoin Portal](https://portal.realmjoin.com); on Windows clients, the optional [RealmJoin Agent](/realmjoin-agent/realmjoin-client) adds deployment and self-service capabilities directly on the device.

## What RealmJoin covers

### Application Management

The [Package Store](/application-management/packages/package-store) contains a continuously maintained catalogue of more than 3,000 ready-to-use Windows and macOS application packages. You subscribe to the packages you need, assign them to managed groups, and RealmJoin keeps versions and update channels (Preview / Main) flowing.

* **Generic packages** are maintained for all customers; **custom** and **organic packages** cover applications specific to your environment - and if something is missing, you can raise a [packaging request](/application-management/packages/packaging-requests) instead of packaging it yourself.
* Each package can be delivered either as an **Intune deployment** (`intunewin` pushed into your tenant) or as a **RealmJoin deployment** through the Agent. See [Deployment Methods](/application-management/deployment-methods) for the comparison; macOS packages are provisioned via Intune.
* With RealmJoin deployment you additionally get **package dependencies and install order**, auto-upgrades for *Available* apps, self-service reinstall/repair, user deferral options and reliable delivery of very large payloads.

{% content-ref url="/pages/kO2QTRSP1jcwKvFk9OxL" %}
[Packages](/application-management/packages)
{% endcontent-ref %}

### User, Group and Device Management

RealmJoin merges data from several Microsoft services into **one view per object**. On a device you see its Intune state next to Autopilot registration, Defender risk and sign-in activity; on a user you see licenses, group memberships, devices and policies - without switching portals.

From there you can drill down across correlated objects, run [Advanced Search](/analyze-and-export/advanced-search) queries, export data, and trigger context-specific actions directly on the object.

{% content-ref url="/pages/cV2auHYEl0Z9stziuych" %}
[Overview](/ugd-management/user-group-device-management)
{% endcontent-ref %}

### Process Automation

[Runbooks](/automation/runbooks) automate the recurring tasks of a modern workplace: onboarding and offboarding, group and mailbox management, device outphasing and wiping, Autopilot cleanup, reporting, security responses such as isolating a device or reading out BitLocker and LAPS secrets.

The runbook library is kept in sync from a [public GitHub repository](https://github.com/realmjoin/realmjoin-runbooks) and executed in **your own Azure Automation account** under a managed identity you control - you can add your own runbooks alongside it. Scheduled runbooks cover recurring reports and cleanups, and every job is logged and auditable.

{% content-ref url="/pages/YOH1XjzLEJA9KAWCAQW4" %}
[Runbooks](/automation/runbooks)
{% endcontent-ref %}

### RealmJoin Agent

The [RealmJoin Agent](/realmjoin-agent/realmjoin-client) is an optional Windows 10/11 component. It applies the software and configuration policy assigned to a device after a local security assessment, and adds features that Intune alone does not offer:

* the [RealmJoin ESP](/realmjoin-agent/realmjoin-client/realmjoin-esp), which holds the desktop until mandatory apps are installed - honouring dependencies and order,
* a [Self Service Portal](/realmjoin-agent/client-menu/self-service-portal) and [tray menu](/realmjoin-agent/client-menu/realmjoin-tray) for user-initiated installs,
* [LAPS](/realmjoin-agent/realmjoin-client/local-admin-password-solution-laps) with passwords stored in your own Azure Key Vault,
* [user notifications](/realmjoin-agent/realmjoin-client/showing-notifications), [multi-user shared devices](/realmjoin-agent/realmjoin-client/multi-user-devices) and [AnyDesk integration](/realmjoin-agent/realmjoin-client/anydesk-integration).

{% content-ref url="/pages/HMKELYXl8Ouf0RLabchl" %}
[Deploying the Agent](/realmjoin-agent/installation)
{% endcontent-ref %}

### Delegation, self service and auditing

* [**Roles and Permissions**](/administration-and-settings/permission)**:** delegate portal functionality to Entra users and groups with pre-defined or custom roles, optionally combined with [Privileged Identity Management](/administration-and-settings/permission/implementing-privileged-identity-management-pim-with-realmjoin-portal). Helpdesk teams get exactly the actions they need - nothing more.
* **Self service:** every user has access to their own [profile page](/ugd-management/user-profile), and [Self Service Forms](/administration-and-settings/self-service-forms) collect structured requests such as incident reports or equipment orders.
* [**Audit Log**](/monitoring-and-logs/audit-log)**:** all actions performed in the portal are written to a Log Analytics workspace in your own Azure environment.

## How it works

RealmJoin's backend runs in Microsoft Azure and connects to your tenant through **least-privilege Entra ID applications** that you consent to during onboarding. Sensitive workloads deliberately stay in your environment: runbooks execute in your Azure Automation account, LAPS passwords live in your Azure Key Vault, and audit logs go to your Log Analytics workspace.

{% content-ref url="/pages/riHEaBpn1xSQIZSgA7PH" %}
[Architecture Overview](/deployment/architecture-overview)
{% endcontent-ref %}

## What you need

* A **Microsoft 365 / Entra ID tenant** with **Microsoft Intune** licenses. RealmJoin is licensed per user, based on the Intune user license seats in your tenant - see [Licensing](/legal/licensing).
* A **Global Administrator** to consent to the RealmJoin applications during [onboarding](/deployment/onboarding-realmjoin-portal). Quick Setup covers core portal functionality; Advanced Setup unlocks the full feature set, including Autopilot, the Agent, privileged device actions, LAPS, audit logs and security features.
* An **Azure subscription** for the resources RealmJoin uses in your own environment: Azure Automation for runbooks, Key Vault for LAPS passwords and Log Analytics for audit and runbook logs. Expected Azure cost is minimal - see the [FAQ](/troubleshooting-and-faq/faq#what-cost-to-expect-from-azure-resources).
* Optional: the **RealmJoin Agent** on Windows 10/11 clients for RealmJoin-based app deployment and the Agent-exclusive features. Microsoft Defender for Endpoint features require the corresponding Microsoft license.

{% hint style="info" %}
No on-premise servers, agents for the backend, or network appliances are required at any point.
{% endhint %}

## Getting started

Pick the deployment guide that matches your scope and follow it end to end - from consenting to the RealmJoin applications to your first package assignment.

{% content-ref url="/pages/ewGnJx6vAdlx6nC8h3iO" %}
[Getting Started](/deployment/getting-started)
{% endcontent-ref %}


# Navigation

RealmJoin Portal navigation from the About me page, with areas that adapt to your permission level.

When you visit [RealmJoin Portal](https://portal.realmjoin.com), you will first be presented with an "About me" page.

!["About me" page](/files/MS2LGakZkOe6vy5aYi55)

Your permissions level will determine what is visible within the navigation bar. These allow you to navigate to different areas of interest.

The icon of the current location is highlighted in light blue.

## [User, Group and Device management](/ugd-management/user-group-device-management)

### ![](/files/D9bcIZYACIgLnNVx2dBj) [User Profile](/ugd-management/user-profile)

See information about the signed in user, including merged information from Entra and Intune.

### ![](/files/IThuGoTSkzcbxMrxVggZ) [Organization](/ugd-management/organization-details)

This will give you information and statistics about your Azure tenant, recent application updates and RealmJoin's integration into your environment (including a link to the dedicated feature activation page).

### ![](/files/mVRt9rdkJ6aWcERyDGhf) [Users](/ugd-management/user-list)

"Users" includes normal users, Entra ID guests as well as Exchange rooms and shared mailboxes.

### ![](/files/kS0uJxsox7pNjPpBedg1) [Groups](/ugd-management/user-list)

"Groups" includes regular Entra ID groups, Teams in Microsoft Teams, Offce365 groups as well as Exchange distribution groups. You can also switch to the groups settings to set advanced RealmJoin configurations.

### ![](/files/TUrkrpNJ1DgGy6eI0Ygq) [Devices](/ugd-management/user-list)

"Devices" includes all Entra ID joined clients as well as devices registered in Entra ID, like mobile phones.

## [Application Management](/application-management/packages)

### ![](/files/oLAbPvKrCzyg80RnbtLP) [Packages](/application-management/packages/package-management)

The list of subscribed packages includes your checked in applications from RealmJoin's application store and gives you an overview about current versions and automation for each package.

### ![](/files/yOuhvBOO3490GmhjGMv2) [Package Store](/application-management/packages/package-store)

In the store you can search for and import ready-to-use generic application packages for Windows and macOS and get access to your requested custom application packages.

### ![](/files/eAHbqcK2Q50eI5c9I82x) [Software Report](/analyze-and-export/software-reporting)

The Software Report gives you an overview of the different versions of each deployed and found application on your devices.

### ![](/files/au35L2rG7CplypDbArTU) [Request Package](/application-management/packages/packaging-requests)

Request packages as generic applications for the store or custom packages for your environment. Please refer to the guidelines.

## [Automation](/automation/connecting-azure-automation)

### ![](/files/XIhrQzyRPEubmVTO57Em) [Runbook Jobs](/automation/runbooks/runbook-logs)

See the results and logfiles/output of recent [Process Automation](/automation/runbooks) tasks

### ![](/files/o9fSH1WrgDbXq8Fvy7mk) [Remediation Scripts](/automation/remediation-scripts)

Review and manage Intune Remediation Scripts and assignments. You can leverage premade templates from our repository and stage them into your Intune environment.

## Tools

### ![](/files/JvFhwPyYvfaqppFAFkNA) [Notifications](/realmjoin-agent/realmjoin-client/showing-notifications)

Configure Notifications that can be displayed on devices based on groups and timeframes.

### ![](/files/j8wr98P5pHzomdj8E71d) Favorites

Use this tool to create JSON or XML files to configure browser favorites for Microsoft Edge and Google Chrome for Windows and macOS.

### ![](/files/H3vVZViDXducqqZgHTUE) [Self Service Form History](/administration-and-settings/self-service-forms#review-submissions)

See a list of recent form submissions and review senders and submission contents.

### ![](/files/5NIJGkPbQWvYCkmgzpvg) [Self Service Forms](/administration-and-settings/self-service-forms#using-forms)

Users can report incidents or request equipment using forms. See [Self Service Forms](/administration-and-settings/self-service-forms) for more information.

### ![](/files/mneMuKyjbJZBB4k2g5UB) [AVD Templates](/deployment/infrastructure/avd-templates)

Use RealmJoin to prepare templates for AVD deployment.

## Other

### ![](/files/itk4VBS45fAcySod5jXe) [Audit Logs](/monitoring-and-logs/audit-log)

Review and audit all actions done in RealmJoin Portal (synced to a Log Analytics Workspace in your Azure environment).

### ![](/files/Cd7EkZZ8gYCUU0DrxvBL) [RealmJoin Settings](/administration-and-settings/settings)

Configuration and customization of RealmJoin. This area is only available to RealmJoin Administrators.


# Useful Links

Key RealmJoin links to bookmark for quick access.

* RealmJoin Portal:

  <https://portal.realmjoin.com>
* Public Runbook Repository:

  <https://github.com/realmjoin/realmjoin-runbooks>
* General RealmJoin website:

  [https://realmjoin.com/](https://realmjoin.com)
* Documentation:

  [https://docs.realmjoin.com/](https://docs.realmjoin.com)


# RealmJoin Unlocked Vodcast

Welcome to RealmJoin Unlocked, our official video podcast series. This series is designed to bridge the gap between technical innovation and practical application for our customers and partners.

## The Idea Behind RealmJoin Unlocked

The goal of this cast is to ensure that every RealmJoin user – especially those without dedicated consulting – can unlock the full potential of our product. We want to:

* **Introduce New Features:** Stay up to date with the latest developments in the RealmJoin ecosystem.
* **Drive Value:** Explain how specific functions provide real-world benefits to your IT operations.
* **Share Field Experience:** We bring in "RealmJoin Champions" and Workplace experts from our team to discuss best practices.
* **Solve Problems:** We address frequently asked questions and common challenges directly in the episodes.

The vodcast is hosted by Dr. Moritz Pohl of our product team, featuring rotating guests from our RealmJoin and Microsoft Intune departments.

***

#### Episode Overview

<table><thead><tr><th width="105">Episode</th><th width="115">Title</th><th width="198">Key Topics</th><th width="202">Guest</th><th>Link</th></tr></thead><tbody><tr><td>1</td><td>RealmJoin: What's New</td><td>Product Wrap-up, vNext Portal, macOS Support, Managed App Subscriptions</td><td>Steffen Schwerdtfeger, Cloud Architect and RealmJoin Champion</td><td><a href="https://www.youtube.com/watch?v=pm-VfgOB1kc">Watch on YouTube</a></td></tr><tr><td>2</td><td>RealmJoin: Self-Service update</td><td>New self-service App Catalog, extended data export, ARM, FAQ</td><td>Jonas Heckmann, Cloud Engineer and RJ team member</td><td><a href="https://www.youtube.com/watch?v=y2NJ8AuRBkA">Watch on YouTube</a></td></tr></tbody></table>

***

#### Episode 1: Wrap-up & What's New ![Views](https://img.shields.io/youtube/views/pm-VfgOB1kc?style=flat-square\&label=Views\&color=red)

In this kick-off episode, we take a deep dive into the evolution of RealmJoin over the last 12 to 18 months. We discuss how the product has transitioned from a specialized patch management tool to a comprehensive "Companion to Intune."

**Highlights:**

* [**00:02:23**](https://www.youtube.com/watch?v=pm-VfgOB1kc\&t=143s) **The Evolution of RealmJoin:** How the tool grew from a patch management script to an "Operator Dashboard."
* [**00:06:27**](https://www.youtube.com/watch?v=pm-VfgOB1kc\&t=387s) **The vNext Portal:** Moving to a modern UI and a backend fully driven by Microsoft Graph API.
* [**00:10:47**](https://www.youtube.com/watch?v=pm-VfgOB1kc\&t=647s) **Parity with Intune:** Choosing between the RealmJoin Agent and native Intune deployment.
* [**00:13:58**](https://www.youtube.com/watch?v=pm-VfgOB1kc\&t=838s) **Advanced LAPS Features:** Managing local administrator passwords with self-service options.
* [**00:18:34**](https://www.youtube.com/watch?v=pm-VfgOB1kc\&t=1114s) **Runbooks & Remediation:** Leveraging a library of over 100 community-driven PowerShell scripts with Azure automation.
* [**00:24:36**](https://www.youtube.com/watch?v=pm-VfgOB1kc\&t=1476s) **Managed Subscriptions:** Automating the application lifecycle with "update rings."
* [**00:29:42**](https://www.youtube.com/watch?v=pm-VfgOB1kc\&t=1782s) **The Packaging Factory:** Accessing over 8.000 generic and private application packages.
* [**00:33:28**](https://www.youtube.com/watch?v=pm-VfgOB1kc\&t=2008s) **macOS as a First-Class Citizen:** Managing Apple devices agentlessly through the RealmJoin portal.
* [**00:36:56**](https://www.youtube.com/watch?v=pm-VfgOB1kc\&t=2216s) **LAPS for macOS:** Implementing self-service password management for Mac users.

**Watch the full Episode:** [RealmJoin What's New: V Next Portal, Managed Subscriptions, Runbooks and macOS Packages](https://www.youtube.com/watch?v=pm-VfgOB1kc)

***

#### Episode 2: RealmJoin Self-Service update ![Views](https://img.shields.io/youtube/views/y2NJ8AuRBkA?style=flat-square\&label=Views\&color=red)

In our second episode, Moritz is joined by **Jonas Heckmann (Cloud Engineer & RealmJoin Core Team)** to shift the focus to user empowerment, data accessibility, and platform compatibility. They dive into key updates including the brand-new user self-service app catalog, extended reporting downloads for better analytics, and a detailed look at native ARM support.

**Key Highlights & Timestamps:**

* [**00:00:00**](https://www.youtube.com/watch?v=y2NJ8AuRBkA\&t=0s) **Introduction:** Moritz welcomes Jonas to discuss the recent portal updates.
* [**00:01:40**](https://www.youtube.com/watch?v=y2NJ8AuRBkA\&t=100s) **User Self-Service App Catalog:** Showcase of the new user portal and "Reinstall" functionality.
* [**00:07:15**](https://www.youtube.com/watch?v=y2NJ8AuRBkA\&t=435s) **Extended Reporting Downloads:** Exporting detailed inventory and deployment data from the vNext portal.
* [**00:13:40**](https://www.youtube.com/watch?v=y2NJ8AuRBkA\&t=820s) **Native ARM Support:** Addressing current compatibility and native architecture support.

**Watch the Full Episode:** [RealmJoin Self-Service update: App Catalog, Reporting & ARM Support](https://www.youtube.com/watch?v=y2NJ8AuRBkA)

> **Get Involved:** For questions regarding the topics mentioned in our podcast, please reach out to our support team at <support@realmjoin.com> or visit our [feedback portal](https://feedback.realmjoin.com).


# Getting Started

A decision matrix to choose between the standard and extended RealmJoin deployment guides based on required features and scope.

## Decision Matrix

| Requirement/Scope                                   | Standard Guide | Extended Guide |
| --------------------------------------------------- | -------------- | -------------- |
| Basic Features/Permissions                          | ☑️             |                |
| Full or Selective Features/Permissions              |                | ☑️             |
| Trial or PoC                                        | ☑️             |                |
| Intune based App Deployment **only**                | ☑️             |                |
| Intune **AND** RealmJoin Agent based App Deployment |                | ☑️             |
| RealmJoin Agent exclusive features                  |                | ☑️             |
| Automate administrative tasks using Runbooks        |                | ☑️             |
| Microsoft Defender for Endpoint Integration         |                | ☑️             |


# Extended Guide

This will guide you through all steps to deploy RealmJoin for an enterprise-grade environment with advanced requirements e.g. Runbooks, Logging etc.

## Prerequisites

* [ ] Windows PowerShell
* [ ] Azure subscription (at least Contributor rights on that subscription)
* [ ] Azure owner rights (at least on Resource Group level)
* [ ] Microsoft Entra ID "Global administrator" (Consent to access Graph API)

## Azure Resource Overview

| Type                    | Description                                                                                                               |
| ----------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| Application Insights    | Optionally stores LAPS-related audit and access events.                                                                   |
| Automation Account      | Hosts RealmJoin runbooks and related automation tasks.                                                                    |
| Key Vault               | Stores LAPS passwords securely in your Azure environment.                                                                 |
| Log Analytics Workspace | Stores RealmJoin audit logs, archived runbook logs, and optional reporting data.                                          |
| Storage Account         | Provides storage for optional Workplace Cloud Storage features such as favorites, files, and Outlook signature templates. |

{% stepper %}
{% step %}

#### Onboard the RealmJoin Portal

Onboarding onto the RealmJoin Portal will establish the initial connection to RealmJoin. Administrators will be able to choose from the Quick or Advanced Setup once complete. This guide continues with the **Advanced Setup** path.

{% content-ref url="/pages/TH5ltCfKQq46OCm4Q6G2" %}
[Onboarding](/deployment/onboarding-realmjoin-portal)
{% endcontent-ref %}
{% endstep %}

{% step %}

#### Proceed with the Advanced Setup

Use **Advanced Setup** to deploy RealmJoin with granular permission control. You can add or remove permissions later with the RealmJoin PowerShell module.

{% content-ref url="/pages/aM3XHiiAsUIHKzD2Lled" %}
[Advanced Setup](/deployment/onboarding-realmjoin-portal/advanced-setup)
{% endcontent-ref %}
{% endstep %}

{% step %}

#### Establish Group Permissions

Assign RealmJoin access through Entra groups.

Use built-in roles for standard access or create custom roles for stricter control.

{% hint style="warning" %}
Assign permissions carefully. Some roles grant **elevated access** in RealmJoin Portal
{% endhint %}

{% content-ref url="/pages/O9C3aUU8SqYnRfq85BAs" %}
[Pre-defined Roles](/administration-and-settings/permission/pre-defined-roles)
{% endcontent-ref %}

{% content-ref url="/pages/IVfhCi6AQlLrInlb0rPI" %}
[Custom Roles](/administration-and-settings/permission/custom-roles)
{% endcontent-ref %}
{% endstep %}

{% step %}

#### Set up the RealmJoin Agent

Install the RealmJoin Agent on Windows devices to unlock agent-based features such as application lifecycle management, RealmJoin ESP, LAPS, notifications, AnyDesk integration, audit tasks, and compliance checks.

If you do not need the agent, continue to the next relevant step.

{% content-ref url="/pages/HMKELYXl8Ouf0RLabchl" %}
[Deploying the Agent](/realmjoin-agent/installation)
{% endcontent-ref %}
{% endstep %}

{% step %}

#### Set up optional RealmJoin Agent add-ons

Enable optional add-ons that require additional configuration after the agent is installed.

Use this step if you want to extend the agent with:

* **LAPS** for managed local admin accounts, password rotation, and secure password storage
* **AnyDesk Integration** for remote support workflows directly from RealmJoin Portal

If you do not need these add-ons, continue to the next step.

{% content-ref url="/pages/ZZEe7EpGe2H2R8R3cVVP" %}
[Local Admin Password Solution (LAPS)](/realmjoin-agent/realmjoin-client/local-admin-password-solution-laps)
{% endcontent-ref %}

{% content-ref url="/pages/7KKYiTUw8ofVTRNkDMqr" %}
[AnyDesk Integration](/realmjoin-agent/realmjoin-client/anydesk-integration)
{% endcontent-ref %}
{% endstep %}

{% step %}

#### Connect Azure Automation

Connect Azure Automation to enable runbooks and remediation scripts.

These features automate recurring administrative tasks, reduce manual effort, and improve traceability.

{% content-ref url="/pages/AR3xCOpDeW8R544P1CPT" %}
[Connecting Azure Automation](/automation/connecting-azure-automation)
{% endcontent-ref %}
{% endstep %}

{% step %}

#### Connect Azure Log Analytics Workspace

Connect a Log Analytics Workspace to store RealmJoin audit data and runbook execution logs.

This also enables integrations such as Windows Update for Business reporting.

{% content-ref url="/pages/6eNVb62uA6Ogi6yjhKRd" %}
[Connecting Azure Log Analytics Workspace](/monitoring-and-logs/log-analytics)
{% endcontent-ref %}
{% endstep %}

{% step %}

#### Deploy Packages

RealmJoin Portal provides and maintains a large library of ready-to-use packages for Windows and macOS.

When deploying packages, first decide whether the application should be delivered through **Microsoft Intune** or through the **RealmJoin Agent**. This depends on your deployment model and whether you want to use agent-based features.

For new applications, start with a **pilot group** before assigning packages broadly. If a newer package version is available, you can test it as a **Preview** before promoting it into production. Once validation is complete, you can enable **update automation** for ongoing lifecycle management.

If a required application is not available in the Package Store, use **Packaging Requests** to request a generic, custom, or organic package for your environment.

A typical rollout is: import package → configure assignments → test with pilot users or devices → enable automation.

{% content-ref url="/pages/qujii1DZUl1kXifaINjB" %}
[Package Store](/application-management/packages/package-store)
{% endcontent-ref %}

{% content-ref url="/pages/yQVOjSbUC2pGkJz3PC4l" %}
[Package Management Overview](/application-management/packages/package-management)
{% endcontent-ref %}

{% content-ref url="/pages/dybUrRL6OuX8Itod5RAQ" %}
[Package Configuration and Assignments](/application-management/packages/package-deployment)
{% endcontent-ref %}

{% content-ref url="/pages/FqMbSqsnYnENrt2DqzsH" %}
[Packaging Requests](/application-management/packages/packaging-requests)
{% endcontent-ref %}
{% endstep %}

{% step %}

#### Configure optional platform features

After the core setup is complete, you can enable additional features for daily operations.

**Workplace Cloud Storage** connects an Azure Storage Account to the RealmJoin Portal. Once connected, administrators can:

* Manage favorites for Edge and Google Chrome
* Store backgrounds and other files with a publicly accessible URL
* Store Outlook signature templates

{% content-ref url="/pages/heG4AaGnHYV68cFPuwJB" %}
[Workplace Cloud Storage](/administration-and-settings/workplace-cloud-storage)
{% endcontent-ref %}

**Self Service Forms** are a convenient way to collect structured data from users. This can be used to let users report incidents or indicate changes, like the need for a new workplace setup in an office.

{% content-ref url="/pages/jRclcF9bEknJAxZDT9Nb" %}
[Self Service Forms](/administration-and-settings/self-service-forms)
{% endcontent-ref %}

**Group namespaces** assist the RealmJoin Portal in sorting groups into different categories based off a specified prefix. The RealmJoin Portal includes default group namespaces, however additional namespaces may be added.

{% content-ref url="/pages/zCocP0Gjiy1FiibGx0q5" %}
[Group Namespaces](/administration-and-settings/groups)
{% endcontent-ref %}

The **Software Report** aggregates data from the RealmJoin Agent and Intune to provide a list of all applications, their versions and the method of deployment.

{% content-ref url="/pages/mCeyb7oglPHaMdF6as0y" %}
[Software Reporting](/analyze-and-export/software-reporting)
{% endcontent-ref %}
{% endstep %}
{% endstepper %}


# Onboarding

Step by step guide on deploying the RealmJoin Portal to a new tenant

## Self-onboard RealmJoin Portal

{% stepper %}
{% step %}

#### Sign in as a Global Admin

Visit <https://portal.realmjoin.com> and sign in as **Global Admin** of your Entra ID Tenant.

<figure><img src="/files/mUtQoG6h8ZvVnUBwQKRe" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Accept Permissions

Select "Consent on behalf of your organization" to approve the RealmJoin Portal on behalf of your organization.

<figure><img src="/files/LWyOWqn9TmR2A7QfNhzk" alt=""><figcaption><p>The App will request basic permissions needed to interact with the RealmJoin Portal. These permissions are required for any user interacting with RealmJoin Portal - e.g. to use self-services.</p></figcaption></figure>
{% endstep %}

{% step %}

#### Fill in the form

The nominated email will receive important updates and portal notifications.

<figure><img src="/files/ErO0njhpZUhGBZcJRd5T" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Select "Quick Setup" or "Advanced Setup"

* "Quick Setup" provides core RealmJoin Portal functionality
* "Advanced Setup" provides full RealmJoin functionality. Additionally, choose "Advanced Setup" if your organization has special compliance needs or requires maximum control over granted permissions.

| Features                                 | Quick Setup | Advanced Setup |
| ---------------------------------------- | :---------: | :------------: |
| Core Portal Functionality                |      ☑️     |       ☑️       |
| Autopilot                                |             |       ☑️       |
| RealmJoin Client                         |             |       ☑️       |
| Remediation Scripts                      |             |       ☑️       |
| Privileged Device Actions                |             |       ☑️       |
| Intune LAPS                              |             |       ☑️       |
| Security Features (MDE license required) |             |       ☑️       |
| Audit Logs                               |             |       ☑️       |

<figure><img src="/files/GxYNsF7LBSCVX2TTwudA" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

{% content-ref url="/pages/aM3XHiiAsUIHKzD2Lled" %}
[Advanced Setup](/deployment/onboarding-realmjoin-portal/advanced-setup)
{% endcontent-ref %}


# Advanced Setup

The Advanced Setup allows you to assign permissions in a more granular and customized way. This approach is more flexible but more complex and requires running the RealmJoin PowerShell module.

The RealmJoin PowerShell module automates the setup of your RealmJoin tenant. It:

* Creates the required Microsoft Entra ID service principals for the RealmJoin applications
* Assigns the appropriate Microsoft Graph permissions based on the features you select
* Configures RealmJoin features (Portal, Intune LAPS, Autopilot, device actions, remediation scripts, security features)
* Cleans up legacy applications from previous configurations

The module is published on the [PowerShell Gallery](https://www.powershellgallery.com/packages/RealmJoin).

## Prerequisites

{% hint style="info" %}
The required Microsoft Graph PowerShell modules are installed automatically the first time you run a command.
{% endhint %}

* **PowerShell 5.1** or later
* Sign in as a **Global Administrator** of your Entra ID tenant when prompted
* The following Microsoft Graph permissions are needed to create the service principals and assign permissions:
  * `Organization.Read.All`
  * `Application.ReadWrite.All`
  * `AppRoleAssignment.ReadWrite.All`

## Recommended Setup

The setup command displayed by the RealmJoin Portal will provide permissions for:

* Core features
* Intune LAPS
* Sign-in data
* Remediation scripts
* Autopilot
* Intune device actions

To add all features or individual features, see [Other Commands](#other-commands).

{% stepper %}
{% step %}

#### Open PowerShell on Windows/Mac

We recommend installing and running the RealmJoin PowerShell module on your device's PowerShell rather than Azure CloudShell.
{% endstep %}

{% step %}

#### Copy and Run the RealmJoin Onboarding Script

The script will prompt you to authenticate with Microsoft Graph. Sign in with your Global Administrator.

```powershell
Install-Module -Force -Name RealmJoin
Complete-RJTenantOnboarding -Token 1234ABCD 6>&1
```

{% hint style="info" %}
**About `6>&1`:** These commands write their progress updates to PowerShell's Information stream. The `6>&1` redirection displays that output in the console — without it you won't see the detailed progress messages during execution.
{% endhint %}

<figure><img src="/files/5CufG7jT37trS9oD9o5X" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/rhVnd5wO24K1JPAAdIWD" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Begin using RealmJoin

Once finished, the script will launch the RealmJoin Portal

<figure><img src="/files/mkUc5Jl6XMxylZfPWXxb" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

## Other Commands

### Interactive Setup

For a guided, menu-driven experience:

```powershell
Show-RJInteractiveSetup 6>&1
```

To review the available features before configuring anything:

```powershell
Show-RJFeatureInfo 6>&1
```

### Custom Configuration

#### Default Features

Enables the mandatory core portal functionality plus the default optional features (everything except the RealmJoin Client):

```powershell
New-RJTenant 6>&1
```

#### Minimal Features (only mandatory features)

```powershell
New-RJTenant -Features @() 6>&1
```

#### Full Feature Set

```powershell
New-RJTenant -All 6>&1
```

#### Read-Only Permissions

Assigns read-only permissions where available (for example, `Group.ReadWrite.All` becomes `Group.Read.All`):

```powershell
New-RJTenant -ReadOnly 6>&1
```

#### Custom Feature Selection

```powershell
New-RJTenant -Features @('RealmJoinPortal', 'IntuneLAPS', 'Autopilot') 6>&1
```

### Updating Existing Configuration

`Update-RJTenant` adjusts an already-configured tenant. The alias `Complete-RJTenantOnboarding` can be used interchangeably with `Update-RJTenant`.

#### Add New Features

```powershell
Update-RJTenant -AddFeatures @('SecurityFeatures') 6>&1
```

#### Remove Features

```powershell
Update-RJTenant -RemoveFeatures @('ShowSignin') 6>&1
```

#### Switch to Read-Only Permissions

```powershell
Update-RJTenant -ReadOnly 6>&1
```

#### Preview Changes

```powershell
Update-RJTenant -AddFeatures @('SecurityFeatures') -WhatIf 6>&1
```

## Available Features

Use these feature names with the `-Features`, `-AddFeatures`, and `-RemoveFeatures` parameters. Mandatory features are always enabled. The default configuration (`New-RJTenant` without parameters) enables every feature except **Client**.

| Feature               | Description                                                                       | Default |
| --------------------- | --------------------------------------------------------------------------------- | :-----: |
| `RealmJoinPortal`     | Core portal functionality for user self-service and admin interaction (mandatory) |    ☑️   |
| `IntuneLAPS`          | Retrieve and manage local admin passwords via Intune LAPS                         |    ☑️   |
| `ShowSignin`          | Display user sign-in history and audit logs                                       |    ☑️   |
| `Autopilot`           | View Windows Autopilot deployment profiles and status                             |    ☑️   |
| `DeviceIntuneActions` | Execute privileged device actions (sync, restart, wipe, etc.)                     |    ☑️   |
| `DeviceHealthScript`  | Manage and deploy PowerShell remediation scripts to devices                       |    ☑️   |
| `SecurityFeatures`    | Advanced threat protection and security analytics (requires MDE licenses)         |         |
| `Client`              | RealmJoin Agent — client application for device management                        |         |

## Troubleshooting

{% hint style="warning" %}
**"Insufficient permissions"** — Ensure the account you sign in with is a Global Administrator and can consent to the Microsoft Graph permissions listed under [Prerequisites](#prerequisites).
{% endhint %}

If the module cannot be found, confirm the PowerShell Gallery is available and reinstall:

```powershell
Get-PSRepository 6>&1
Install-Module -Name RealmJoin -Force 6>&1
```

### Getting Help

```powershell
Get-Help New-RJTenant -Full
Get-Help Update-RJTenant -Examples
Get-Help Show-RJInteractiveSetup -Detailed
```


# Required Permissions

Microsoft Graph and Azure permissions required by the RealmJoin Portal apps for self-service and administrative functionality.

RealmJoin Portal consists of multiple apps which are used for different use cases.

## RealmJoin Portal

Application ID: `b0130885-16be-4c6f-83de-5b1042b5d2e3`

Users interact with this app for self-service. Admins use this app to interact with all RealmJoin Portal features.

All the following permissions are of the permission type “**Delegated**” ( = can only operate when a user is interactively signed in). Also, this app can be **consented per User** ( = admin consent is optional).

These permissions are required for basic functionality of the app per user.

### API Permissions

The following permissions are from type "Delegated" and are mainly used for login to the Portal.

| Claim           | Permission                                          |
| --------------- | --------------------------------------------------- |
| User.Read       | Sign in and read user profile                       |
| profile         | View users' basic profile                           |
| email           | View users' email address                           |
| openid          | Sign users in                                       |
| offline\_access | Maintain access to data you have given it access to |

{% hint style="info" %}
Depending on the way you onboarded your tenant, you may find the "RealmJoin Portal - Core Features" permissions from below inside the "RealmJoin Portal" Application or in the separate one described below.
{% endhint %}

The following table reflects the permissions (type Application permissions) if Administrative Units (AU) **are not used**.

Some of the permissions are needed for optional features, please refer to your onboarding agent to adopt the consent to your needs.

| Claim                                                   | Permission                                                        |
| ------------------------------------------------------- | ----------------------------------------------------------------- |
| AuditLog.Read.All                                       | Read all audit log data                                           |
| BitlockerKey.Read.All                                   | Read all BitLocker keys                                           |
| Device.Read.All                                         | Read all devices                                                  |
| DeviceLocalCredential.Read.All                          | Read device local credential passwords                            |
| DeviceManagementApps.ReadWrite.All                      | Read and write Microsoft Intune apps                              |
| DeviceManagementConfiguration.Read.All                  | Read Microsoft Intune device configuration and policies           |
| DeviceManagementManagedDevices.PrivilegedOperations.All | Perform user-impacting remote actions on Microsoft Intune devices |
| DeviceManagementManagedDevices.Read.All                 | Read Microsoft Intune devices                                     |
| DeviceManagementScripts.ReadWrite.All                   | Read and write Microsoft Intune Scripts                           |
| DeviceManagementServiceConfig.Read.All                  | Read Microsoft Intune configuration                               |
| Group.ReadWrite.All                                     | Read and write all groups                                         |
| GroupMember.ReadWrite.All                               | Read and write all group memberships                              |
| User.Read.All                                           | Read all users' full profiles                                     |
| WindowsUpdates.ReadWrite.All                            | Read and write all Windows update deployment settings             |
| AdministrativeUnit.Read.All (optional)                  | Read all administrative units                                     |

## RealmJoin Portal - Core Features

Application ID: `61fcb903-2868-4c54-91cd-2716c62c5007`

Admins and Users do not directly interact with this app. It represents RealmJoin’s backend that interacts with Entra ID and Intune.

All actions triggered by this app are filtered through RealmJoin’s internal permission (RBAC) model which can evaluate Entra group and role memberships.

All the following permissions are of the permission type “**Application**” ( = can operate without a signed in user) and target [MS Graph API](https://docs.microsoft.com/en-us/graph/api/overview?view=graph-rest-1.0). You can read more about the individual permissions [here](https://docs.microsoft.com/en-us/graph/permissions-reference).

### API Permissions

The following table reflects the permissions (type Application permissions) if Administrative Units (AU) **are not used**.

Some of the permissions are needed for optional features, please refer to your onboarding agent to adopt the consent to your needs.

| Claim                                                   | Permission                                                        |
| ------------------------------------------------------- | ----------------------------------------------------------------- |
| AuditLog.Read.All                                       | Read all audit log data                                           |
| BitlockerKey.Read.All                                   | Read all BitLocker keys                                           |
| Device.Read.All                                         | Read all devices                                                  |
| DeviceLocalCredential.Read.All                          | Read device local credential passwords                            |
| DeviceManagementApps.ReadWrite.All                      | Read and write Microsoft Intune apps                              |
| DeviceManagementConfiguration.Read.All                  | Read Microsoft Intune device configuration and policies           |
| DeviceManagementManagedDevices.PrivilegedOperations.All | Perform user-impacting remote actions on Microsoft Intune devices |
| DeviceManagementManagedDevices.Read.All                 | Read Microsoft Intune devices                                     |
| DeviceManagementScripts.ReadWrite.All                   | Read and write Microsoft Intune Scripts                           |
| DeviceManagementServiceConfig.Read.All                  | Read Microsoft Intune configuration                               |
| Group.ReadWrite.All                                     | Read and write all groups                                         |
| GroupMember.ReadWrite.All                               | Read and write all group memberships                              |
| User.Read.All                                           | Read all users' full profiles                                     |
| WindowsUpdates.ReadWrite.All                            | Read and write all Windows update deployment settings             |
| AdministrativeUnit.Read.All (optional)                  | Read all administrative units                                     |

## RealmJoin Portal - Security Features

Application ID: `e5713826-15ee-4f6c-91ee-56cb1844e275`

This app is responsible for advanced security information in the ReamJoin Portal. Please refer to your onboarding agent to adopt the consent to your needs.

All of the following permissions use the `WindowsDefenderATP` API.

### API Permissions

| Claim                           | Permission                                                         |
| ------------------------------- | ------------------------------------------------------------------ |
| AdvancedQuery.Read.All          | Run advanced queries                                               |
| Alert.Read.All                  | Read all alerts                                                    |
| File.Read.All                   | Read file profiles                                                 |
| Ip.Read.All                     | Read IP address profiles                                           |
| Machine.Read.All                | Read all machine profiles                                          |
| Score.Read.All                  | Read Threat and Vulnerability Management score                     |
| SecurityConfiguration.Read.All  | Read all security configurations                                   |
| SecurityRecommendation.Read.All | Read Threat and Vulnerability Management security recommendations  |
| Software.Read.All               | Read Threat and Vulnerability Management software information      |
| Ti.Read.All                     | Read all IOCs                                                      |
| Url.Read.All                    | Read URL profiles                                                  |
| User.Read.All                   | Read user profiles                                                 |
| Vulnerability.Read.All          | Read Threat and Vulnerability Management vulnerability information |

## RealmJoin Agent

Application ID: `008c704d-20fe-4c15-bab0-c2e6f66a992c`

This app is responsible for the client application (RealmJoin Agent).

Please refer to your onboarding agent to adopt the consent to your needs.

### API Permissions

| Claim           | Permission                    |
| --------------- | ----------------------------- |
| Device.Read.All | Read all devices              |
| Group.Read.All  | Read all groups               |
| User.Read       | Sign in and read user profile |
| User.Read.All   | Read all users' full profiles |


# Infrastructure Considerations

RealmJoin infrastructure and network requirements, including proxy guidance and the Azure and Office 365 IP ranges that must be reachable.

## Network

### Avoid Proxies

Initial deployment needs direct internet access. No proxy would be ideal, but a transparent proxy should work fine (if truly transparent). If a proxy is unavoidable as a minimum requirement the following services/addresses need to be directly accessible:

For a list of the corresponding IP ranges click the following link:

[Azure IP Ranges and Service Tags – Public Cloud](https://www.microsoft.com/en-us/download/details.aspx?id=56519)

This file contains the compute IP address ranges (including SQL ranges) used by the Microsoft Azure Datacenters. A new xml file will be uploaded every Wednesday (Pacific Time) with the new planned IP address ranges. New IP address ranges will be effective on the following Monday (Pacific Time).\
Download the new xml file and perform the necessary changes on your site before Monday.

[Office 365 URLs and IP address ranges](https://support.office.com/en-us/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2)

This article links a file that contains the compute IP address ranges that you should include in your outbound allow lists to ensure your computers can successfully use Office 365.

{% hint style="info" %}
IP addresses filtering alone is not a complete solution due to dependencies on internet-based services such as Domain Name Services (DNS), Content Delivery Networks (CDNs), Certificate Revocation Lists and other third party or dynamic services. These dependencies include dependencies on other Microsoft services such as the Azure Content Delivery Network and will result in network traces or firewall logs indicating connections to IP addresses owned by third parties or Microsoft but not listed on this page. These unlisted IP addresses, whether from third party or Microsoft owned CDN and DNS services, are dynamically assigned and can change at any time.
{% endhint %}

### BranchCache and Device isolation

BranchCache is a Windows technology designed to **reduce WAN traffic** and **speed up content delivery** inside corporate networks. It does this by allowing Windows clients to share downloaded data with each other, instead of every device pulling the same content repeatedly from the cloud.

{% hint style="info" %}
For RealmJoin, BranchCache is **enabled by default** on CDN and client side.
{% endhint %}

Why not use Delivery Optimization? This mechanism does not support third‑party package sources. It works only with Microsoft‑controlled endpoints (e.g.: Windows Update, Store, M365 Apps or Intune).

So within RealmJoin, we rely on BranchCache because it is a **built‑in Windows peering mechanism** that works for third‑party content:

* **CDN side**: It is enabled by default. If requested, we can disable BranchCache entirely on the CDN side (per tenant), which makes the client‑side configuration irrelevant.
* On the **client side**, the feature is enabled by default as well. By setting `BranchCache.Mode = "Undefined"` (see [User and Group Settings](/ugd-management/user-and-group-settings)), this default behaviour can be changed. However, for existing clients, the feature will not be actively disabled once it has been activated before. To disable, run `Disable-BC` on the desired devices.

For BranchCache to be effective, the clients need to be able to communicate directly with each other. So, they should not be separated by different VLANs, subnets or communication blocked via device isolation. We use BranchCache in **Distributed Cache Mode**, where every client maintains a local cache and retrieves cached data from peers. The option **Hosted Cache Mode**, which requires a dedicated Windows Server and is configured on clients via the "Configure Hosted Cache Servers" policy, is **not supported** by RealmJoin.

When a client device downloads software packages for the first time, the files are divided into chunks that are significantly smaller than the original content and cached on the device. If the same package is afterwards requested from a different client device in the same network, it downloads content information instead of the complete content from the server. The content information is used to locate the desired content on other devices in the network. **Client peer discovery** in "Distributed Cache Mode" works as follows:

* A client sends a multicast query such as "Does anyone have content ID XYZ?"
* Any peer that holds the requested segment responds directly via uni-cast.

Instead of downloading packages from the server, the content in form of the chopped up chunks is transferred to the client device. If the requested software is available on several devices, the load is balanced between them.

For more details see Microsoft Learn: [BranchCache](https://learn.microsoft.com/en-us/windows-server/networking/branchcache/branchcache)

### RealmJoin Connection Endpoints

RealmJoin connects to the following hosts (using HTTPS) that might be considered in your firewall settings:

* `cdn.realmjoin.com`
* `x1.c.lencr.org`
* `client-api.realmjoin.com`
* `client-api-staging.realmjoin.com`
* `realmjoin-backend.azurewebsites.net`
* `realmjoin-backend-staging.azurewebsites.net`
* `nuget.realmjoin.com`
* `enterpriseregistration.windows.net`
* `gkrealmjoin.s3.amazonaws.com`
* `login.microsoftonline.com`
* `graph.microsoft.com`
* `realmjoinstaticcdn.azureedge.net` (Notifier)


# Limiting the Scope of RealmJoin Portal

Use of Administrative Units with RealmJoin

RealmJoin Portal supports [Microsoft Entra ID Administrative Units (AU)](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/administrative-units).

### Restricted Management Administrative Unit

To hide/protect some sensitive groups from RealmJoin, you can create a **restricted management Administrative Unit in Microsoft Entra ID**. After creating that restricted AU, you can assign **sensitive groups** to that AU and "hide" these groups from RealmJoin Portal (and everybody using the RealmJoin Portal).\
This is a good idea for **high-sensitive groups** that you want to protect, e.g. groups used for granting permissions/roles or to exclude users from certain Conditional Access Policies etc.\
Users and applications **must explicitly be granted/added** to the scope of the AU to be able to interact with groups that are "protected" by the restricted management AU.

To make use of restricted management administrative units, there are **no settings needed in RealmJoin**.

* You can read more about Restricted management administrative units in Microsoft Entra ID [here](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/admin-units-restricted-management).
* To create a restricted AU, you can follow Microsoft's guide [here](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/admin-units-manage?tabs=admin-center).
* To add groups you want to protect to the restricted AU as well as administrators that you want to allow to interact with these groups, please see this guide [here](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/admin-units-members-add?tabs=admin-center).

### Assigning a dedicated Administrative Unit to RealmJoin Portal

To fully "encapsulate" RealmJoin Portal, you can create a dedicated AU (default non-restricted) and assign the RealmJoin Portal app to that AU.\
As a result, RealmJoin Portal will create groups only in that specific AU - and is also only able to interact with groups that are specifically in scope of this AU.

* To create an AU, you can follow [Microsoft's guide](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/admin-units-manage?tabs=admin-center)
* To add groups to the AU scope so that RealmJoin is still able to interact with these groups, please see [this guide](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/admin-units-members-add?tabs=admin-center)
* To assign roles with administrative unit scope, please see [this guide](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/manage-roles-portal?tabs=admin-center#assign-roles-with-administrative-unit-scope)

#### Enable RealmJoin to use Administrative Units

1. Create AU in Entra (default, not restricted).
2. In the AU, permanently assign the role "Group Administrator" to the RealmJoin Portal app (Application ID: "b0130885-16be-4c6f-83de-5b1042b5d2e3").
3. Add the Microsoft Graph API permission `"AdministrativeUnit.Read.All"` (type "Application") to the RealmJoin Portal app (Application ID: "b0130885-16be-4c6f-83de-5b1042b5d2e3").
4. Especially if you already use the RealmJoin Portal, move all groups that RealmJoin should be able to interact with to the scope of the AU (e.g. existing app groups or permission groups).
5. Create a ticket with the [RealmJoin Support](https://www.realmjoin.com/help/) and provide the ObjectID of the AU you created.
6. Wait for verification from RealmJoin Support.
7. Now you can safely remove the following application permissions from the RealmJoin Portal app (Application ID: "b0130885-16be-4c6f-83de-5b1042b5d2e3") as these are not AU-aware:\
   \
   `"Group.ReadWrite.All"` & `"GroupMember.ReadWrite.All"`\
   \
   Instead the Entra Role "Group Administrator" is used. Make sure that you added the role beforehand (Step 2).

{% hint style="info" %}
Please keep in mind that you can only add/remove the Microsoft Graph API permissions via Graph!

You can use the Grant-Script from the [RealmJoin Portal features page](https://portal.realmjoin.com/organization/features) shown below to add the `"AdministrativeUnit.Read.All"` permission.

* Copy the script, add the permission in the marked $permissions section, execute the script, confirm execution in the Portal.
* RealmJoin will automatically check for the new permission and will display it in the granted section.
* For removal of `"Group.ReadWrite.All"` & `"GroupMember.ReadWrite.All"` you can use the "Revoke" option next to the permissions to generate a script only for that specific permission.
  {% endhint %}

<figure><img src="/files/Pe62HBmrEIhW5cZNLNwW" alt=""><figcaption></figcaption></figure>


# AVD Templates

RealmJoin AVD templates apply application sets unattended via RealmJoin Client to build golden images for Azure Virtual Desktop hosts.

## Overview

Using this feature you can define a set (aka template) of applications. This set of applications can then be applied to a computer in a headless / unattended fashion using RealmJoin Client.

This is intended for creating golden images for Azure Virtual Desktop multi-session pooled hosts.

{% hint style="info" %}
Creating and managing Azure Virtual Desktop (AVD) templates is a complex task that requires expert knowledge, thorough planning, and precise configuration. While we fully support all RealmJoin-related topics described on this page, our ability to assist with broader AVD templating topics is limited. This includes—but is not limited to—general guidance on creating, customizing, deploying, and troubleshooting AVD templates.
{% endhint %}

## Permissions

To enable the feature, you must define a [custom role](/administration-and-settings/permission/custom-roles) and assign the role to a group or user.

Copy the following definition and make sure to change the GroupID accordingly.

```json
{
  "Rules": [
    {
      "Name": "Allow admins to access the templating feature",
      "Groups": [
        "<Group ID of Admin Group>"
      ],
      "Permissions": [
        "CanReadTemplateTable",
        "CanReadTemplateDetails",
        "CanEditTemplate",
        "CanDeleteTemplate",
        "CanChangeTemplatePackages",
        "CanChangeTemplateTokens"
      ]
    }
  ]
}
```

## Managing templates

### Creating a template

1. Click on the "templates" icon or open the Templates section by entering the url: <https://portal.realmjoin.com/templates>

<figure><img src="/files/HB90R16TPcrfIlpFlIGn" alt=""><figcaption><p>Templates List</p></figcaption></figure>

2. Select the <img src="/files/iI4YdXrlnH2uqt5ZY2oF" alt="" data-size="line"> icon (1), enter a meaningful name (2) and Click "Save" (3).

<figure><img src="/files/QkrVww6jBxf4GV1KbCSs" alt=""><figcaption><p>Create a template</p></figcaption></figure>

### Add Applications to a Template

1. Open the template by clicking on its name.
2. To add packages to the template, click the <img src="/files/iI4YdXrlnH2uqt5ZY2oF" alt="" data-size="line"> icon.

<figure><img src="/files/Vhht3hq8i2iUbLr79FFQ" alt=""><figcaption><p>Add packages to a template - 1</p></figcaption></figure>

3. Search for a package and hit the ![](/files/zwEKBJ3O1m2CdPcFTkt6) icon to add it to your template. The list represents all RealmJoin packages you have subscribed to in your environment.
4. Once you are done, click the **Close** button.

<figure><img src="/files/bvFf0BRCmT66dWcCJPUl" alt=""><figcaption><p>Add packages to a template - 2</p></figcaption></figure>

{% hint style="info" %}
Intune Packages can not be assigned using AVD templates.
{% endhint %}

### Remove Applications from a Template

1. Open the template by clicking on its name.
2. If you want to remove applications, click on **Unassign**. If you want to define arguments overwriting those set on the package level, you can do so by clicking on **Settings**.

<figure><img src="/files/o5FGXidSfb2UHDukDYoD" alt=""><figcaption><p>Remote packages from a template</p></figcaption></figure>

### Create a Token

To use the template via RealmJoin Client, you also need a token.

{% hint style="warning" %}
Please handle the token with care. If you think the token might have been leaked, revoke it by hitting the **Revoke** button next to the token.
{% endhint %}

1. Create a token, click on the **Tokens** tab.
2. Click the <img src="/files/iI4YdXrlnH2uqt5ZY2oF" alt="" data-size="line"> icon (1), enter a meaningful name (2) and click **Save** (3).

<figure><img src="/files/jsxo6nr5gNeT2UVnjfor" alt=""><figcaption><p>Create a token</p></figcaption></figure>

## Using a Template

### AVD / Headless Provisioning

Collect the template ID and the token you want to use for deployment.

<figure><img src="/files/lsFF9S8RshoEmMiNlYRK" alt=""><figcaption><p>Find template ID and token</p></figcaption></figure>

Run the following command from inside your system/VM you want to prepare as golden image:

1. Download RealmJoin: `Invoke-WebRequest -Uri "https://gkrealmjoin.s3.amazonaws.com/win-release/RealmJoin.exe" -OutFile "C:\temp\RealmJoin.exe"`
2. Install RealmJoin: `Start-Process -FilePath "C:\temp\RealmJoin.exe" -ArgumentList "-install" -Wait`
3. Run headless deployment. Make sure to enter your individual template ID and token: `Start-Process -FilePath "C:\Program Files\RealmJoin\RealmJoinService.exe" -ArgumentList " -avdprovision <Template ID> <Template Token>"`

### Logging and Traces

For both, RealmJoin installation and headless deployment, you can add an additional argument `-trace` to extend logging. To check the status/logs during headless deployment, open and periodically refresh realmjoin.log which can be found under `C:\Windows\Logs\`


# Architecture Overview

A high-level overview of the RealmJoin architecture: the cloud backend, how managed devices and administrators connect, and which resources RealmJoin uses in your own Microsoft tenant.

RealmJoin is a cloud-native, multi-tenant SaaS and the **Application Lifecycle and Management companion to Microsoft Intune**. It manages application deployment, user/group/device management and process automation across your Entra ID tenant — **with no on-premise servers or local infrastructure**. All backend services are operated by glueckkanja in **Microsoft Azure, hosted in Europe**.

RealmJoin covers three areas:

* **Application Management** – packaging, deployment, a self-service catalog and software reporting.
* **User, Group and Device Management** – a single, unified view that combines data from Intune, Entra ID, Microsoft Defender, Windows Autopilot and sign-in logs.
* **Process Automation** – runbooks that run in *your own* Azure Automation account.

## The big picture

```mermaid
%%{init: {"flowchart": {"htmlLabels": false, "nodeSpacing": 55, "rankSpacing": 90}} }%%
flowchart LR
    Admin["Administrators"]
    Integr["Your integrations"]
    Device["Managed devices<br/>(RealmJoin Agent)"]

    subgraph RJ["RealmJoin Backend - Azure (Europe)"]
        direction TB
        Portal["RealmJoin Portal"]
        CustApi["Customer-API"]
        ClientApi["Client-API"]
        FD{{"Azure Front Door"}}
        CDN["CDN and Package Server"]
        Core[("Backend services<br/>and databases")]
    end

    subgraph Tenant["Your Microsoft tenant"]
        direction TB
        Graph["Entra ID / Intune / Defender<br/>(via Microsoft Graph)"]
        subgraph AzureRes["Your Azure resources"]
            direction TB
            KV["Key Vault<br/>(LAPS passwords)"]
            Autom["Azure Automation<br/>(Runbooks)"]
            LA["Log Analytics<br/>(Logs)"]
        end
    end

    Admin --> Portal
    Integr --> CustApi
    Device --> ClientApi
    Device --> FD
    FD --> CDN

    Portal --> Core
    ClientApi --> Core
    CustApi --> Core

    Core -->|least-privilege access| Graph
    Core --> KV
    Core --> Autom
    Core --> LA
```

RealmJoin connects to your tenant through **least-privilege Entra ID applications** that you consent to during onboarding. Every action the backend performs is filtered through RealmJoin's **internal role-based access control (RBAC)** model, which evaluates Entra group and role membership.

## Backend components

The backend is a set of independently deployed services running in Microsoft Azure:

| Component                  | Purpose                                                                                             | Who connects to it                                                                    |
| -------------------------- | --------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------- |
| **RealmJoin Portal**       | The web interface administrators use to manage applications, devices, users, groups and automation. | Administrators, via Entra ID sign-in (OAuth 2.0 / OpenID Connect).                    |
| **Client-API**             | The endpoint the optional RealmJoin Agent on each device talks to.                                  | Managed devices, authenticated by device identity (Entra token + device certificate). |
| **Customer-API**           | A programmatic API for your own integrations and automation.                                        | Your systems and tools, using a per-customer API key.                                 |
| **CDN and Package Server** | Delivers application packages and content to devices.                                               | Managed devices.                                                                      |

Behind these, RealmJoin runs background processing services and stores data in managed Azure databases and storage. Internal-facing services (such as billing and background jobs) are not reachable from the internet.

## The RealmJoin Agent

The RealmJoin Agent is an **optional** Windows component. When installed, it:

* reports device state to the Client-API on a regular schedule,
* retrieves a **signed** device configuration (software and policy assignments),
* runs a local **security assessment** (encryption, patch level, firewall, antivirus) before applying mandatory apps,
* delivers applications efficiently using an enhanced Chocolatey engine plus **BranchCache** peer-to-peer distribution,
* supports **LAPS** (local admin password) — passwords are generated on the device and stored in **your own Azure Key Vault**.

```mermaid
sequenceDiagram
    participant Device as RealmJoin Agent
    participant API as Client-API
    participant CDN as RealmJoin CDN

    Device->>API: Report state & request configuration
    API-->>Device: Signed configuration (apps & policies)
    Device->>Device: Security assessment
    Device->>CDN: Download assigned packages
    Note over Device: Peer-to-peer package sharing via BranchCache
```

For details on package delivery and BranchCache, see [Infrastructure Considerations](/deployment/infrastructure).

## Process automation (runbooks)

Runbooks run in **your own Azure Automation account** — not in RealmJoin's backend. RealmJoin keeps your runbook library in sync with a curated, open GitHub repository and manages and monitors job execution from the Portal. The runbooks act through the Automation account's **managed identity**, so the permissions they use stay entirely within your control.

See [Connecting Azure Automation](/automation/connecting-azure-automation) and [Runbooks](/automation/runbooks) for more.

## Application delivery

Packages are produced by RealmJoin's packaging pipeline and delivered to devices through the RealmJoin **CDN** and **Package Server**, with geo-replicated storage and BranchCache for efficient in-network distribution. Applications can be delivered either through **RealmJoin Deployment** (via the Agent) or as **Intune Deployment** (an intunewin package pushed to your tenant).

## Resources in your own environment

Several capabilities use resources in **your own Microsoft tenant and Azure subscription**, so sensitive data stays under your control:

* **Azure Key Vault** – stores the LAPS local-admin passwords generated on your devices.
* **Azure Automation** – runs your runbooks under a managed identity you control.
* **Log Analytics** – stores audit logs and archived runbook logs.

RealmJoin accesses these — and Entra ID, Intune and Defender via Microsoft Graph — using only the least-privilege permissions you grant during onboarding. See [Portal Required Permissions](/deployment/required-permissions) for the full list.

## Security, hosting and data residency

* **Hosting:** All backend services run in **Microsoft Azure**, primarily in the **West Europe** region with backup in **North Europe**. **Customer data does not leave Europe.**
* **Delivery:** The Portal and APIs are reached directly over HTTPS. Application packages and content are delivered through the RealmJoin **CDN**, fronted by **Azure Front Door** for globally load-balanced distribution.
* **Encryption in transit:** All connections use HTTPS/TLS.
* **Identity:** Administrator access uses Entra ID (OAuth 2.0 / OpenID Connect); devices authenticate with their Entra device identity and a device certificate; programmatic APIs use per-customer keys.
* **Tenant isolation:** Each customer's data is separated, and all backend code paths operate within a per-tenant context.
* **Least privilege:** RealmJoin's Entra applications request only the permissions needed for the features you enable, and all actions are governed by RealmJoin's internal RBAC model.
* **Resilience:** Redundant infrastructure with automated failover and point-in-time database recovery; infrastructure is fully defined as code (Terraform).

{% hint style="info" %}
Externally reachable endpoints are the **Portal, Client-API, Customer-API, CDN and Package Server**. For the full list of hosts to allow in your firewall, see [Infrastructure Considerations](/deployment/infrastructure). For more detail on data handling and tenant separation, see [Security & Privacy](/security-and-privacy/security-and-privacy).
{% endhint %}


# Overview

Manage Entra ID users, groups, and devices in one RealmJoin view combining Intune, Defender, Autopilot, and sign-in data.

RealmJoin allows you to review and interact with Entra ID objects like users, groups and devices.

It combines information from multiple sources such as Intune, Microsoft Defender, the Windows Autopilot service and sign-in security logs into one single view.

Use the [navigation](/introduction/navigation) to inspect your [tenant/organization](/ugd-management/organization-details), [users, groups or devices](/ugd-management/user-list) and search and drill down across correlated objects and trigger [operations](/automation/runbooks) directly in context.

Users, Groups and Devices all have a list interface to find the object of interest and a [details page](/ugd-management/user-list/user-details) for reviewing and interacting with each object individually.

The details pages share some common elements for all these areas:

### **Object Properties**

Every object's detail page will show an overview of the core properties such as

* Name
* Entra ID Object ID
* Object Account Status
* License usage location

The object properties are static and be visible in any tab.

![Core Object Properties](/files/DNRTNjvqd6pgFoNUm4n4)

The right side of the screen shows the current tab, which can be

* "Overview" with more information about the object
* "[Runbooks](#runbooks)" showing available runbooks - as the name implies
* Different [data sources](#data-sources), like Azure AD, Sign in logs etc.

### Runbooks

RealmJoin offers operators the ability to automate day to day tasks using [Runbooks](/automation/runbooks). RealmJoin Portal offers context specific runbooks on tenant, device, group and user level via a separate tab.

![Runbook Tab](/files/kma7XHMvUCrZ4soYtKEn)

### Data Sources

RealmJoin Portal collects information from multiple sources. You can review the full source information for every object in source-specific tabs and it is presented as JSON data.

Raw source data is only available to RealmJoin administrators.

![Raw JSON Source Data](/files/ytjtIZLu7MjQ8FZAyN6n)


# Organization Details

RealmJoin organization details show an Azure tenant overview: user and group counts, Intune and runbook stats, and recent app changes.

![Organization Details View](/files/SoSxhBTUW470iIKncygC)

This page gives you an overview about

* Your organization (Azure Tenant), including number of users and groups
* Intune and Runbook Statistics
* The status of RealmJoin's features and integration
* Recent application updates and changes

This page follows the same principles as the other details pages. You have core properties of your tenant visible on the left side of the UI. The right side is specific to your current tab, which can include [runbooks](/ugd-management/user-group-device-management#runbooks) and [Entra ID raw data](/ugd-management/user-group-device-management#data-sources).


# User Profile

The RealmJoin User Profile tab gives users quick access to their apps, account, devices, and groups, with directory roles for admins.

![About Me - User](/files/akm4GpxQteh4QC7fPSCl)

The User Profile ![](/files/4FE07ZCWYsgMEAkTEAk4) tab allows users to quickly access resources they may need in a modern workplace environment, e.g.

* Microsoft's "My Applications" page to manage apps and services you have access to
* Access to Microsoft's "My Account" page to manage authentication factors

It also allows a user to quickly see their devices and groups.

Administrators will also be able to view their directory roles:

![About me - Admin](/files/DfwBR1HJOLuXwVUyq7Jw)

Switching to the detailed view displays the [user object's details](/ugd-management/user-list/user-details) page (elevated permission required).


# User, Group and Device Lists

Search and browse users, groups, and devices, and open any object's details page from RealmJoin Portal.

{% embed url="<https://www.youtube.com/watch?v=IlIEnhoaaIA>" %}
Brand new video tutorial
{% endembed %}

Selecting the Users, Groups or Devices tab offers administrators a simple way to search or review users in their environment. Clicking the name of a user, group or device object will lead you to the respective object's details page.

<figure><img src="/files/YnFBMYJIZwjty25kWsD5" alt=""><figcaption><p>User List</p></figcaption></figure>

<figure><img src="/files/PmWw1rroR7sjindhXnbg" alt=""><figcaption><p>Group List</p></figcaption></figure>

<figure><img src="/files/48C6pqrygc5ukAywjKPY" alt=""><figcaption><p>Device List</p></figcaption></figure>

### Object Types

User, Group and Device object types are separated in the same manner as Entra ID:

{% tabs %}
{% tab title="Users" %}
Users include:

* Entra ID user objects
* Entra ID external users, a.k.a. Guests
* Shared mailboxes
* Room and Equipment mailboxes
* Administrative user accounts
  {% endtab %}

{% tab title="Groups" %}
Group objects include:

* Entra ID static and dynamic groups
* Exchange Online mail-enabled groups and distribution groups
* Microsoft Office365 groups and teams
  {% endtab %}

{% tab title="Devices" %}
Devices include:

* Entra ID joined clients, like modern workplace clients
* Entra ID registered devices, like user-owned phones and tablets
* Other devices, like printers used by MS Universal Printing or Surface Hubs
  {% endtab %}
  {% endtabs %}

### Filters

You can use the filters above the list to limit search results to specific User, Group or Device objects:

{% tabs %}
{% tab title="Users" %}

<figure><img src="/files/CndrvmewArz4aRJz6XpZ" alt=""><figcaption><p>User Filters</p></figcaption></figure>

**User Type**

* **Any** - Both Members and Guests are displayed
* **Members** - Users native to your tenant (default)
* **Guests** - Azure B2B Guests invited from other tenants

**ADM Accounts**

* **Any** - Displays all user accounts (default)
* **ADM** - Filter to only show users whose DisplayName starts with "ADM" (admin accounts)
* **Non-ADM** - Negation of the "ADM" Filter

**Data completeness**

* **Any** - Show users with both complete and missing data (default)
* **No Data** - Show only users with missing data in "job title", "city" or "country"
  {% endtab %}

{% tab title="Groups" %}

<figure><img src="/files/gCua9HhzSagVeglSG0HW" alt=""><figcaption><p>Group Filters</p></figcaption></figure>

**Only RealmJoin Groups**

Turn this toggle **off** to include groups that do not match any RealmJoin naming scheme. When **off** all Entra ID groups will be shown.

By default (**on**), RealmJoin only lists groups related to RealmJoin's operation, such as

* Licensing Groups ("lic -")
* Application-Assignment Groups ("app -")
* Configuration/Permission Groups ("cfg -")

**Membership Type**

Limit the groups shown to

* **Static** - Groups with static member assignment
* **Dynamic** - Groups with dynamic membership
* **Any** - All groups (default)

**Group Type**

Limit the search results to the type of Entra ID group

* **Security** - List Security Groups. This currently also includes Exchange-related groups like Distribution Lists and mail-enabled Security Groups.
* **Unified** - List Microsoft 365 groups/teams as well as RealmJoin internal groups like "RealmJoin - All Users"
  {% endtab %}

{% tab title="Devices" %}

<figure><img src="/files/QsyBIe3PbegxI6qg933o" alt=""><figcaption><p>Device Filters</p></figcaption></figure>

**Only Enabled**

If toggled **on** (default) devices that have been disabled in Entra ID will not be shown.

Switch to **off** to see all devices including ones that are not enabled.

**Operating System / Device Type**

Use this filter to select devices based on their operating system or deployment method.

* **Any** - Show all devices
* **Win** (Default) - Show only Windows based devices
* **Mac** - Show only MacOS based devices
* **CloudPC** - Show only Windows365 devices
* **Mobiles** - Show iOS and Android devices
* **S-Hub** - Show Surface Hub devices
* **Printer** - Show Printers (from Universal Printing)
* **Other** - Show devices not matched by any other filters

**Compliance State**

For managed devices, you can choose to limit the results according to their [compliance state](https://docs.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started) in Intune.

* **Any** - Show all devices
* **Compliant** - Show only devices reported as compliant by Intune
* **Non-Compliant** - Show only devices reported as not currently compliant by Intune
  {% endtab %}
  {% endtabs %}


# User Details

RealmJoin user details show a single user object's summary and glanceable status such as enabled and member state.

This page will show you detailed information about a single user object.

### User Summary

![](/files/Blu4nhe8pGA63szJnORt)

### Status information

The User Summary include some glanceable information about the status of a user object:

* **Enabled** - The user is not blocked from sign in
* **Member** - The user is a native user in this tenant/organization
* **Guest** - This is an external user from a different organization
* **DE/US**... - Two letter code designating the user's [usage location](https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/licensing-groups-resolve-problems#usage-location-isnt-allowed) which is relevant for licensing.
* ![](/files/BbxuneuEe7WzuSQAD0a0) - Object creation date
* ![](/files/30wDD0YJBfynZfVDUXwZ) - Last sign-in activity

### Overview Tab

Main tab, showing you a host on information about the user, including owned devices and group memberships.

### Runbooks Tab

If you have been given Supporter or Admin-Permissions, this gives you access to runbooks that can be executed on this user object. For example to change an email-address for a user.

See[ Process Automation](/automation/runbooks) for more information.

### Settings Tab

You can assign Key-Value pairs of data to specific users to control RealmJoin Clients behavior for this user.

Most of the time this is used to overwrite settings configure on a group or for all users.

<figure><img src="/files/uLiteeQPwTr81vLeGg0v" alt=""><figcaption><p>Settings overview on a user</p></figcaption></figure>

You can add a setting assigned to this user using <img src="/files/jEye95N47L9YmjxQI2d6" alt="" data-size="line">, alternatively open an existing setting by clicking on its name/key or search for a setting by name/key.

Clicking a name/key will open a UI allowing you to manipulate/create the setting.

<figure><img src="/files/GfFOBRaLTrUvCjglctjz" alt=""><figcaption><p>Setting editor</p></figcaption></figure>

Be aware: The value of the setting must be valid JSON, which includes singular values like `true` or strings (without brackets).

The switches in the lower half of the wizard allow scoping this setting to certain scenarios like VDI / Windows365 machines.

Please see [Available Settings](/ugd-management/user-and-group-settings/additional-settings) for more information on which settings can be used.

### Other Tabs

* Raw [data sources](/ugd-management/user-group-device-management#data-sources), like Entra ID, Sign in logs etc display in JSON. Only available for RealmJoin administrators.


# Group Details

RealmJoin group details for Entra static and dynamic groups, Exchange Online mail-enabled groups and distribution groups, and Microsoft 365 groups.

![Application management group](/files/IToDwIPkpfAojdnyWIAz)

This page shows you details regarding a single group.

### Object Types

The category "groups" includes:

* Microsoft Entra static and dynamic groups
* Exchange Online mail-enabled groups and distribution groups
* Microsoft Office365 groups and teams

### **Object Properties**

Every group details page will show an overview of the core properties like

* Name
* Entra Object ID
* Additional properties

on the left side of the screen in a glanceable way. This part will not scroll and be always visible in any tab.

### Status information

The core properties include some glanceable information about the status of a user object:

* **Unified** - A Office365 group or Team group
* **Security** - An Entra ID (non-Office365) group
* **Mail enabled** - This group can receive eMail
* **Teams** - This group represents a Team
* **Static** - Members are assigned statically (manually) to a group
* **Dynamic** - Members are chosen via a membership rule, typically to group devices

Be aware of the different types of groups accross Entra ID and Exchange Online. A group is either a "**Security**" or a "**Unified**" group. Also, some groups like "**Security**" groups that are "**Mail enabled**" (like Distribution groups) can only be managed via Exchange Online, not Entra ID.

### Members

RealmJoin Portal will show you the current members of a group. It will show internal and external ("Guest") users separately. You can search/filter the members of a group using the on-screen search fields.

On Entra ID groups ("Non-mail enabled security" and "Unified") you can use RealmJoin Portal to add or remove members - if you have the appropriate permissions.

Please use a [runbook ](/automation/runbooks)to change owners of a group or to change memberships to Exchange Online groups, like Distribution Groups.

![Members of a group](/files/3Gz4DNHVPFLXimtxyPEf)

#### Adding Members

Using the "**Add**" button will show a dialogue where you can search for users to add to the group. You can search for users via Name or User Principal Name / eMail address.

![Adding Members](/files/ISBgp2N031NTIXUSVNec)

Press "+" to add a member to the group. The resulting membership will take a short time and not be immedaitely visible.

#### Removing Members

Using the "**Remove**" button will not show a new dialogue but add a "x" icon in front of existing members. You can still search/filter for members via Name or User Principal Name / eMail address while this is active.

![Removing Members](/files/4aHyF4g0DDBYl9h0ixKe)

Press the "x" icon to remove a member. The resulting change will take a short time and not be immedaitely visible.

### Runbooks Tab

If you have been given Supporter or Admin-Permissions, this gives you access to runbooks that can be executed on this group object. For example to change an email-address of a distribution list.

See[ Process Automation](/automation/runbooks) for more information.

### Settings Tab

You can assign Key-Value pairs of data to specific groups of users to control RealmJoin Clients behavior for these users.

<figure><img src="/files/Sod1Gl8LpVDjAzLSZH0O" alt=""><figcaption><p>Settings for this group</p></figcaption></figure>

You can add a setting assigned to this group using <img src="/files/jEye95N47L9YmjxQI2d6" alt="" data-size="line">, alternatively open an existing setting by clicking on its name/key or search by name/key.

Clicking a name/key will open a UI allowing you to manipulate/create the setting.

<figure><img src="/files/aDOIwF1Hfowa8kFOnANj" alt=""><figcaption><p>Settings Editor</p></figcaption></figure>

Be aware: The value of the setting must be valid JSON, which includes singular values like `true` or strings (without brackets).

The switches in the lower half of the wizard allow scoping this setting to certain scenarios like VDI / Windows365 machines.

Please see [Available Settings](/ugd-management/user-and-group-settings/additional-settings) for more information on which settings can be used.

### Tabs

The right side of the screen shows the contents of the current tab, which can be

* "Overview" with more information about the object
* "[Runbooks](/automation/runbooks)" showing available runbooks - as the name implies
* Raw [data sources](/ugd-management/user-group-device-management#data-sources), like Entra ID, Sign in logs etc display in JSON. Only available for RealmJoin administrators.

### More Actions

At the lower end of the groups details, you can find a "More" Button. Pressing it will open a menu of more available actions.

<img src="/files/IpjRMttM6OoxCYsLjEOR" alt="" data-size="original">

Currently, only Delete is available.

#### Delete

If you are allowed to delete the group, a confirmation dialogue will pop up upon pressing the Delete button. (If you don't have enough permissions, nothing will happen.)

![](/files/CCd2jDuGxiD3Bya5WnY1)

Pressing "Yes" will delete the group from Entra ID. This is of course also able to delete Exchange based objects like Distribution lists, or Microsoft 365 groups and teams.


# Device Details

RealmJoin device details show a single device's logged-on user, installed apps, and security recommendations with status.

## Overview

This page provides information about the device you’ve selected from the [Device List](/ugd-management/user-list).

<figure><img src="/files/TgkQBbgyTHiqm58eCDbA" alt=""><figcaption><p>Device Details</p></figcaption></figure>

The right side will show one of multiple tabs. The default **Overview** tab view will include information (if available) like

* The currently logged on user
* Currently installed apps/software, either managed by RealmJoin or Intune
* Security recommendations and if these are met by the device

### **Object Properties**

The left section of the Device Details page will show an overview of the core properties like

* Display Name
* Entra ID Object ID
* Device Owner
* Operating System
* Serial Number
* Additional properties

on the left side of the screen in a glanceable way. This part will not scroll and be always visible in any tab.

### Status Information

The core properties include some glanceable information about the status of a device object. Some statuses these are presented via icons that are either blue (active / present) or red (inactive missing).

<img src="/files/OFsREntftHzKOa3kSW3i" alt="" data-size="original">Endpoint Management active

![](/files/lkZa15ktFCGjJjnAf3H8)Disk Encryption enabled

![](/files/2SE8UQ0SGADhEgCAIsht)Defender ATP enabled

![](/files/E4Ofs6Lfp9mJ8jrbGWFf)A/V up to date

![](/files/zLKtIGowOrv3ZZpgRc1a)Compliant device

![](/files/BbxuneuEe7WzuSQAD0a0) When the object was created

![](/files/30wDD0YJBfynZfVDUXwZ) Last seen activity / Last contact

Other bits of information are presented as tags:

* AzureAD - This device is Entra ID Joined
* TPM2 - TPM2 is present and enabled
* Autopilot - This device is managed via Autopilot
* Company - Company Owned (not Personal)
* Personal - Personal, not Company Owned

### Local Admin Management (LAPS)

RealmJoin Portal can surface a device's local administrator credentials in two independent ways, and both can appear on the same device details page:

* **RealmJoin LAPS (agent-based)** – RealmJoin's own Local Admin Password Solution, delivered by the [RealmJoin Client](/realmjoin-agent/realmjoin-client) and stored in your own Azure Key Vault.
* **Intune LAPS integration** – retrieval of credentials that Microsoft's native **LAPS** has backed up to Microsoft Entra ID, read directly from Microsoft Graph. No RealmJoin Client required.

The two solutions are complementary. The table below summarizes the differences:

|                               | RealmJoin LAPS (agent-based)                              | Intune LAPS integration                       |
| ----------------------------- | --------------------------------------------------------- | --------------------------------------------- |
| Credentials come from         | RealmJoin Client, stored in **your own** Azure Key Vault  | **LAPS**, backed up to Microsoft Entra ID     |
| Requires the RealmJoin Client | Yes                                                       | No                                            |
| Account types                 | **Emergency**, **Support** (on-demand) and **Privileged** | Single managed local admin account per device |
| Actions                       | Reveal password, request on-demand Support Account, renew | Reveal / copy password, rotate password       |
| Platforms                     | Windows (and macOS)                                       | Windows and macOS                             |

{% hint style="info" %}
RealmJoin LAPS is the more capable option — multiple account types, on-demand support accounts, forced rotations and your own Key Vault as the store. The **Intune LAPS integration** is aimed at tenants that already rely on Microsoft's native LAPS and simply want to retrieve those credentials without leaving the Portal.
{% endhint %}

#### RealmJoin LAPS (agent-based)

When combined with the [RealmJoin Client](/realmjoin-agent/realmjoin-client), RealmJoin Portal can help with support tasks on windows clients that need local admin permissions by offering on-demand support accounts on clients. In many cases this removes the need to grant local admin permissions to the primary user of the device just to solve a one-time need.

![LAPS management](/files/TFgARGArQ62MYKnCr4ow)

By default, a local admin emergency account is created on a windows client. This account is useable even if network connectivity to the client fails. This is kind of a last resort.

It is recommended to use a "Support Account". When clicking "**Request**", a job is created/queued and RealmJoin Client will create an on-demand local admin account next time it syncs to the backend. This can take up to 30 minutes or alternatively a "Sync this device" can be triggered on the client to speed up the process. RealmJoin Portal will show state of "Requested" until the account is created and automatically switches to a view similiar to the Emergency Account when ready:

![Support Account](/files/K1P72Tg9T1EiY3SJhBJ4)

Click the dots to reveal the password.

The Support Account will automatically be removed after 12 hours.

See the [LAPS documentation](/realmjoin-agent/realmjoin-client/local-admin-password-solution-laps) for more details.

#### Intune LAPS integration

If you manage local administrator passwords with Microsoft's native **LAPS** — deployed through an Intune [account protection policy](https://learn.microsoft.com/intune/device-security/laps/deploy-policy) that backs the credential up to Microsoft Entra ID — RealmJoin Portal can read those credentials for you, so support staff don't have to switch to the Intune or Entra admin center.

Unlike RealmJoin LAPS, this integration does **not** require the RealmJoin Client. The Portal simply reads whatever LAPS has already backed up, via Microsoft Graph.

When the prerequisites below are met, an **Intune Local Admin Management** section appears on the device details page. It lists:

* **Username** – the local admin account name backed up from the device (Windows only; macOS does not report an account name).
* **Last Updated** – when the password was last backed up or rotated.
* **Expires** – when Windows LAPS will next rotate the password (Windows only).
* **Password** – hidden by default. Select the eye icon to reveal it (it is shown briefly, then masked again automatically) or click the masked value to copy it straight to your clipboard.

If your role allows it, a **Rotate Password** action is available. This asks Intune to generate and back up a fresh password; it is a request that Intune applies the next time the device processes it, not an instant change.

{% hint style="info" %}
Retrieving or rotating an Intune LAPS password is audited — both within RealmJoin and in the Microsoft Entra / Intune audit logs.
{% endhint %}

{% hint style="warning" %}
Credentials can only be shown when LAPS backs the account up to **Microsoft Entra ID**. Passwords for accounts backed up to on-premises Active Directory cannot be displayed — the same limitation applies in the Intune admin center.
{% endhint %}

**Prerequisites**

* The device is **Entra ID joined** and **enrolled in Intune**.
* **LAPS is configured in Intune** and the credential is backed up to Microsoft Entra ID. See Microsoft's [Windows LAPS support in Intune](https://learn.microsoft.com/intune/device-security/laps/overview) for setup. macOS devices are supported when enrolled via Automated Device Enrollment (ADE) with a LAPS-managed local account.
* The **required Microsoft Graph permissions** are granted to the RealmJoin app registration. An administrator can grant these under **Organization ▸ Features**, in the **Optional: Intune LAPS** card:
  * `DeviceLocalCredential.Read.All` – read Windows LAPS credentials.
  * `DeviceManagementManagedDevices.PrivilegedOperations.All` – read macOS LAPS credentials **and** rotate passwords (this scope is also required to rotate a Windows password).

If a device isn't Entra/Intune managed, or the Graph permissions aren't consented, the Intune Local Admin Management section simply doesn't appear.

**Who can view and rotate**

* **View** the Intune LAPS password: Tenant Admin, Global Admin, Tenant Supporter, Tenant Advanced Supporter and Tenant Auditor roles (as well as Entra Global Administrators).
* **Rotate** the password: the same roles **except** Tenant Auditor — auditors can read credentials but not rotate them.

**Self-service for end users**

Users can be allowed to view (and optionally rotate) the Intune LAPS credential of a device they own — where they are the primary user or registered owner — using the `Allow.SelfLAPSIntune` user or group setting. This is the Intune counterpart to the agent-based [`Allow.SelfLAPS`](/realmjoin-agent/realmjoin-client/local-admin-password-solution-laps#enable-self-service) setting.

The value can be:

* a boolean `true` / `false` (an explicit `false` always wins),
* a platform string `"windows"` or `"macos"` to grant access for that platform only, or
* an object with `CanReadPassword` / `CanRotatePassword` (optionally platform-specific via `CanReadPasswordWindows`, `CanRotatePasswordWindows`, `CanReadPasswordMacOS`, `CanRotatePasswordMacOS`).

```json
{
  "CanReadPassword": true,
  "CanRotatePassword": false
}
```

### Recovery Keys

For encrypted devices, RealmJoin Portal can work with the disk-encryption recovery key — **BitLocker** on Windows and **FileVault** on macOS.

Starting with **Portal v2026.29**, you can **rotate** a device's recovery key directly from the RealmJoin Portal. Rotating replaces the existing recovery key with a new one, which takes effect after the device next syncs.

{% hint style="info" %}
Recovery keys can also be retrieved via the [Show BitLocker Recovery Key](/automation/runbooks/runbook-references/device/security/show-bitlocker-recovery-key) and [Show FileVault Recovery Key](/automation/runbooks/runbook-references/device/security/show-filevault-recovery-key) runbooks.
{% endhint %}

## Warranty

Use the **Warranty** tab to display information like remaining vendor warranty time for **supported vendors/devices.**

{% hint style="success" %}
Currently supported vendors: Apple, Dell, Fujitsu, HP, Huawei, Lenovo and Microsoft
{% endhint %}

<figure><img src="/files/gAuZnkBwJLyFiFMhGj9a" alt=""><figcaption><p>Warranty Information</p></figcaption></figure>

{% hint style="info" %}
We rely on the information provided by the vendors through their APIs. We do not guarantee the accuracy of this information.
{% endhint %}

Depending on the API used, a captcha might be displayed before requesting/displaying warranty information.

## Actions

You can use the button **Intune Sync** to trigger a remote sync of Intune Policies.

Use the **Defender Scan** button to trigger a (quick) scan of Windows Defender on a managed client.

## Runbooks

"[Runbooks](/automation/runbooks)" showing available runbooks for devices.

## RAW data sources

RAW [data sources](/ugd-management/user-group-device-management#data-sources) displayed as JSON (only available for RealmJoin administrators):

* Entra ID
* Intune
* Autopilot
* Defender
* RealmJoin

{% hint style="info" %}
The RealmJoin state is updated when the agent checks in. Retention is 90 days. If a device is offline for more than 90 days, the state will not be available any more (icon greyed out). If it checks in again, the state will be re-evaluated and displayed after some minutes.
{% endhint %}


# User and Group Settings

RealmJoin Client settings and features like LAPS applied at tenant, group, or user scope, with narrower scopes overriding broader ones.

## Overview

Settings can be used to control RealmJoin Client's behavior and configure features like [LAPS](/realmjoin-agent/realmjoin-client/local-admin-password-solution-laps).

If settings have been created/assigned to users, you can review them under ![](/files/rsQw7zextf8pYvMnBDJU) - User Settings

Accordingly, if settings have been applied to any group, including "**RealmJoin - All Users"**, these can be reviewed under ![](/files/elwdpdb5nicxvM09GpHW) - Group Settings.

## Tenant Default Values

Default setting values can be defined at different scopes. The broadest scope is the tenant-wide client configuration, found in the Settings section of the RealmJoin Portal and accessible to any administrator. Settings defined there apply to all users unless overridden at a narrower scope.

<figure><img src="/files/MN9JZjiBHaIog5sShb0S" alt=""><figcaption></figcaption></figure>

The built-in RealmJoin group "RealmJoin - All Users" can be used to override tenant-wide defaults across all users. Settings assigned to a real user or group scope will in turn override both of these, as individual group and user assignments carry the highest priority.

The resulting priority order is: tenant-wide client config < RealmJoin - All Users < any user or group scope.

Example:

To define a baseline channel for all users, set the RealmJoin Agent Channel to "release" in the tenant-wide client config. To override this for all users at once, set "beta" on the "RealmJoin - All Users" group. To target only a specific set of users, assign "beta" directly to a dedicated group. The more specific scope always takes precedence.

## Settings Editor

<figure><img src="/files/VjdhfIdiaXD4zozv2txE" alt=""><figcaption><p>Settings Editor</p></figcaption></figure>

Be aware: The value of the setting must be valid JSON, which includes singular values like `true` or strings (without brackets).

The switches in the lower half of the wizard allow scoping this setting to certain scenarios like VDI / Windows365 machines. A setting that is filtered out by these switches behaves as if it had never been assigned:

* **Only in VDI** / **Ignore in VDI** — apply the setting only on, or never on, VDI (W365/AVD) devices. The two switches are mutually exclusive.
* **Only on hybrid-joined devices** / **Ignore on hybrid-joined devices** — apply the setting only on, or never on, hybrid-joined devices. These two are mutually exclusive as well.
* **Ignore on private devices** — skip the setting on private devices (not Entra ID joined).

You can modify and delete settings from the Settings Editor. You cannot create new settings here - Please navigate to the user or group you want a setting applied to and create the setting there.

See [Available Settings](/ugd-management/user-and-group-settings/additional-settings) to review which settings can be used.


# Available RealmJoin Policies

Reference of available RealmJoin Client settings and policies configurable per user or group.

The following article shows you a list of possible RealmJoin Client settings/policies. These can be configured and assigned per [user or group](/ugd-management/user-group-device-management).

Each setting consists of a **key** and a **value**:

* The key is a dot-separated path (for example `Integration.Notification`). RealmJoin merges the value into the client configuration at that path, on top of the [tenant-wide defaults](/ugd-management/user-and-group-settings#tenant-default-values).
* The value must be valid JSON — including plain values such as `true` or `"release"` (quoted, without brackets).

{% hint style="info" %}
A value of `undefined` **removes** the key from the effective configuration. Use this to drop a value that a broader scope (tenant-wide client config or "RealmJoin - All Users") has set, instead of overwriting it with a different value.
{% endhint %}

{% hint style="info" %}
The keys `Allow.*`, `Restrict.*` and `SoftwarePackageOverrides.*` are evaluated by the RealmJoin backend and are stripped from the configuration before it is sent to a device — they never reach the client.
{% endhint %}

### Allow users to access RealmJoin LAPS for their devices

Users may access different LAPS types for devices owned by visiting the RealmJoin portal.

**Key**

Allow\.SelfLAPS

**Value**

```
true | false
```

or per account type

```
{
  "EmergencyAccount": true,
  "SupportAccount": true,
  "PrivilegedAccount": true
}
```

See [Local Admin Password Solution (LAPS)](/realmjoin-agent/realmjoin-client/local-admin-password-solution-laps#enable-self-service) for the full self-service description.

{% hint style="info" %}
`Allow.*` settings do not follow the usual "narrower scope wins" precedence. All values assigned to the user and to their groups are combined, and an explicit `false` always wins over any `true`.
{% endhint %}

{% hint style="warning" %}
`Allow.*` and `Restrict.*` are resolved against the user's **Entra ID group memberships**. Assigning them to the built-in "RealmJoin - All Users" group has no effect — use a real Entra ID group or assign them directly to the user.
{% endhint %}

### Allow users to access Intune LAPS for their devices

Users may access and rotate the LAPS password for their devices.

**Key**

Allow\.SelfLAPSIntune

**Value**

```
true | false
```

or specifically:

```
{
  "CanReadPassword": true,
  "CanRotatePassword": false
}
```

Starting with **Portal v2026.29**, access can be scoped **per platform** (Windows/macOS). A platform-specific property overrides the generic `CanReadPassword`/`CanRotatePassword` for the matching device platform:

```
{
  "CanReadPasswordWindows": true,
  "CanRotatePasswordWindows": true,
  "CanReadPasswordMacOS": true,
  "CanRotatePasswordMacOS": false
}
```

A plain string value acts like `true` for the matching platform only:

```
"windows"|"macos"
```

Access is only granted to the device's primary user or registered owner. As with `Allow.SelfLAPS`, all assigned values are combined and an explicit `false` wins over any `true`.

### Configure BranchCache for RJ packages

This setting changes BranchCache mode for **new** clients.

**Key**\
BranchCache.Mode

**Value**

```
"Distributed"|"Undefined"
```

### Configure DomainConnect for Legacy Domains

The following settings configure DomainConnect for legacy domains.

**Key**\
DomainConnect.CredentialName

**Value**

```
"RealmJoin (domain)"
```

**Key**\
DomainConnect.Domain

**Value**

```
"domain.contoso.net"
```

**Key**\
DomainConnect.NetBIOS

**Value**

```
"contoso"
```

### Configure RealmJoin release channel

This setting changes the user's / user group's channel with the next update of the RealmJoin Client.

**Key**\
Environment.Channel

**Value**

```
"release" | "beta" | "canary"
```

{% hint style="info" %}
This setting is ignored on shared VDI clients — they always stay on the channel of their image.
{% endhint %}

### Configure RealmJoin ESP

Change if the default reboot after initial RealmJoin agent installation.

**Key**

FirstRun.AfterSuccessAction

**Value**

```
"none" | "logoff" | "restart"
```

Change if the RJ ESP is displayed.

If the deployment screen needs to be disabled for secondary users, the system variable *$env:RjDisableSecondaryInitialDeployment = 1* has to be set before the first SU login.

**Key**

FirstRun.DisableDeploymentScreen

**Value**

```
"true" | "false"
```

Show deployment screen on restricted or secure desktop.

**Key**

FirstRun.EnableSecureDesktop

**Value**

```
"true" | "false"
```

### Allow downgrade of packages <a href="#softwarepackaging.autoupgradecandowngrade" id="softwarepackaging.autoupgradecandowngrade"></a>

Allows downgrade of already installed applications via auto upgrade, if the version number is changed. Applies to all packages assigned to users receiving the policy via group or user settings.

**Key**

SoftwarePackaging.AutoUpgradeCanDowngrade

**Value**

```
"true" | "false"
```

### Global override of software package behavior

These settings are primarily intended for Deployment/DEM users on shared devices. They are applied to **all** software packages assigned to the receiving user.

Forces the background installation flag on every package.

**Key**

SoftwarePackageOverrides.AllowBackgroundInstall

**Value**

```
true | false
```

Ignores the phase part of the [main app / user part restrictions](/application-management/packages/package-settings) (Logon, Manual, Initial, Normal) of every package.

**Key**

SoftwarePackageOverrides.IgnorePhaseRestrictions

**Value**

```
true
```

Ignores the primary/secondary user part of those restrictions of every package.

**Key**

SoftwarePackageOverrides.IgnoreUserRestrictions

**Value**

```
true
```

{% hint style="info" %}
`IgnorePhaseRestrictions` and `IgnoreUserRestrictions` only take effect when set to `true`; `false` is the same as not setting them at all. Restrictions can only be lifted this way, never added.

When the device's primary user is a deployment (DEM) user, these overrides also apply to the packages that secondary users inherit from that deployment user.
{% endhint %}

### AnyDesk Feature

This setting enables or disables the [AnyDesk feature](/realmjoin-agent/realmjoin-client/anydesk-integration).

**Key**\
Integration.AnyDesk

**Value**

```json
{
"Enabled": true | false,
"BootstrapperUrl": "https://.../.../AnyDesk.exe",
"CustomClientSuffix": "myorg",
"Ui": {
    "TrayMenuTextEnglish": "Start remote session"
  }
}
```

* **Enabled:** Turns the AnyDesk integration on or off.
* **BootstrapperUrl:** Download location of the AnyDesk client used by the integration.
* **CustomClientSuffix:** Suffix of your custom AnyDesk client. It is used to build the `anydesk:` link the RealmJoin Portal opens when starting a session. Leave it out when using the generic client.
* **Ui.TrayMenuTextEnglish:** Caption of the entry in the RealmJoin tray menu. Defaults to `"Start remote session"`.

### ExecutionMonitor Feature

This setting enables or disables the ExecutionMonitor Feature.

**Key**\
Integration.ExecutionMonitor

**Value**

```json
{
"Enabled": true | false,
"UpdateInterval": "08:00"
}
```

### Notifier Feature

This setting enables or disables the [Notifier feature](/realmjoin-agent/realmjoin-client/showing-notifications) and it also activates or deactivates the editor UI.

**Key**\
Integration.Notification

**Value**

```json
{
"Enabled": true | false,
"SourceUrl": "URL_PROVIDED_BY_GK",
"FallbackCulture": "en",
"CheckInterval": "00:01"
}
```

* **Enabled:** Turns the Notifier on or off.
* **SourceUrl:** Location of the notification definitions. This value is created by RealmJoin when the feature is enabled for your tenant — do not change it.
* **FallbackCulture:** Language used when a notification has no content for the user's language. Defaults to `"en"`.
* **CheckInterval:** How often the client checks for new notifications ([HH:mm](https://learn.microsoft.com/en-us/dotnet/standard/base-types/standard-timespan-format-strings)). Defaults to `"00:01"`.

### LocalAdminManagement Features

This section shows you all necessary settings for the LocalAdminManagement features. For more details about this feature read the [Local Admin Password Solution article](/realmjoin-agent/realmjoin-client/local-admin-password-solution-laps).

**Key**\
LocalAdminManagement.Inactive

**Value**

```
false
```

**Key**\
LocalAdminManagement.CheckInterval

**Value**

```
"00:05"
```

**Key**\
LocalAdminManagement.EmergencyAccount

**Value**

```json
{
    "MaxStaleness": "00:45",
    "NamePattern": "ADM-{HEX:4}",
    "DisplayName": "Local Emergency Account",
    "PasswordCharSet": "1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz",
    "PasswordLength": 14
}
```

**Key**\
LocalAdminManagement.SupportAccount

**Value**

```json
{
    "MaxStaleness": "00:45",
    "NamePattern": "ADM-{HEX:4}",
    "DisplayName": "Local Support Administrator",
    "PasswordCharSet": "1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz",
    "PasswordLength": 14,
    "OnDemand": true | false
}
```

**Key**\
LocalAdminManagement.PrivilegedAccount

**Value**

```json
{
    "NamePattern": "Privileged-User-{COUNT:1}",
    "DisplayName": "Privileged User",
    "PasswordRenewals": ["DayAfterCreate", "Monthly", "Thursday"],
    "PasswordPreset": 3,
    "PasswordLength": 3
}
```

{% hint style="info" %}
All three account types share the same common properties (`NamePattern`, `DisplayName`, `PasswordCharSet`, `PasswordLength`, `PasswordPreset`, `MaxStaleness`). `OnDemand` and `Expiration` are specific to the support account, `Expiration` and `PasswordRenewals` to the privileged account. An account type that is not configured at all stays inactive. The [LAPS article](/realmjoin-agent/realmjoin-client/local-admin-password-solution-laps) describes every property, the defaults and the password presets in detail.
{% endhint %}

### AppCatalog Feature

This setting controls native, one-click access to the [App Catalog](/realmjoin-agent/client-menu/self-service-portal#app-catalog-tab) from the RealmJoin tray menu and Windows Start Menu.

**Key**\
AppCatalog

**Value**

```json
{
  "Enabled": true | false,
  "HidePackages": true | false,
  "CreateStartMenuShortcut": true | false,
  "Ui": {
    "DisplayName": "App Catalog"
  }
}
```

* **Enabled:** Adds an **App Catalog** entry to the RealmJoin tray menu that opens the device's App Catalog page in Microsoft Edge app mode.
* **HidePackages:** Hides the individual software packages from the classic tray "Install"/"Update" submenu, useful once users are directed to the App Catalog instead.
* **CreateStartMenuShortcut:** Requires `Enabled: true`. Creates a per-user Start Menu shortcut ("App Catalog") that opens the same page, so it can be found via Start search or pinned to the taskbar.
* **Ui.DisplayName:** Caption of the App Catalog entry in the RealmJoin tray menu. The same text is also used for the Start Menu shortcut created by `CreateStartMenuShortcut`. Defaults to `"App Catalog"`.

### Weblinks for RealmJoin Tray

The following setting generates a weblink in the tray.

**Key**\
WebLinks

**Value**

```json
[
  {
    "Name": "My Azure Account",
    "Target": "https://account.activedirectory.windowsazure.com/r/#/profile",
    "Platform": "any"
  },
  {
    "Name": "Outlook Web Access",
    "Target": "https://outlook.office365.com/owa/?realm=contoso.onmicrosoft.com",
    "Platform": "any"
  }
]
```

### Access Restrictions

{% hint style="info" %}
Currently only LAPS is supported
{% endhint %}

Assign this setting to the groups of the **device owners** you want to protect. It then restricts which administrators may use LAPS on the devices of those users.

**Key**\
Restrict.LAPS

Value

```json
{
  "Admin": [
    "11-cf35-49dd-a862-123123",
    "11-2ec2-47ee-8cb8-123123"
  ],
  "Supporter": [
    "23-cf35-49dd-a862-231"
  ],
  "Deny": []
}
```

Each property holds the object IDs of Entra ID groups. One list exists per RealmJoin role:

```
"Admin" | "Auditor" | "Supporter" | "AdvancedSupporter" | "RunbookRunner" |
"SoftwareAgent" | "SoftwareRequester" | "OrganicRequester" | "NotificationAgent" | "Deny"
```

{% hint style="warning" %}
The lists are inclusive: as soon as at least one list is filled, only administrators who hold the matching RealmJoin role **and** are a member of one of the groups listed for that role may use LAPS on these devices. Everyone else is denied.

Membership in a group listed under `Deny` always denies access, regardless of the other lists. Global admins are never restricted.
{% endhint %}

### Various Toggles

This section shows you four policies for RealmJoin.

**Key**\
Policies.DisableNetworkLocationWizard

**Value**

```
true | false
```

**Key**\
Policies.RequireSecurityFeatures.BitlockerEnabled

**Value**

```
true | false
```

**Key**\
Policies.SetCurrentUserAdministrator

**Value**

```
true | false
```

**Key**\
Policies.SetTimeserver

**Value**

```
["time.windows.com", "time.apple.com", "pool.ntp.org"]
```


# Advanced Search

Experience nearly load-free access to your data

RealmJoin introduces a revamped search mechanism that enables real-time access to tenant data. This enhancement ensures efficient performance even for tenants with a large volume of user, device, and group objects.

{% hint style="success" %}
The Advanced Search experience is available for the Users-, Groups-, Devices- & Packages-Table.\
Check out the Use Cases subpage for examples that help you get more value from your tenant data.
{% endhint %}

Tables can be searched using the *basic* or the *advanced* search feature.

{% hint style="info" %} <mark style="background-color:yellow;">**All searches have to be confirmed by either using the**</mark><mark style="background-color:yellow;">**&#x20;**</mark>*<mark style="background-color:yellow;">**enter key**</mark>*<mark style="background-color:yellow;">**&#x20;**</mark><mark style="background-color:yellow;">**or the**</mark> <img src="/files/YS0lK6kEUTLtQbvDvuNl" alt="" data-size="line"> <mark style="background-color:yellow;">**symbol.**</mark>
{% endhint %}

### Basic Search

Basic Search uses the Graph API to directly query tenant data, providing real-time results.

Basic Search is always available as a fallback when Advanced Search is not. It also appears during the initial loading of the cached table, allowing users to search immediately—even before the cache is fully built.

### Advanced Search

RealmJoin's advanced search feature uses caching and tokenization, making searches fast and reliable, and supports Unicode characters like Ø. This tokenization enables partial name searches, so a query like "Ma Mu" can locate a user named "Maren Müller".

Additionally, information not displayed in the table is also searchable, like post-codes or UPN.

<figure><img src="/files/vKP2DUT1nKIQeJ95j5aI" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Please make sure to only use the "Reload-Button" in the top right corner if you are missing very recently added information from Entra / Intune.
{% endhint %}

### Advanced Search Syntax Overview

Advanced Search allows querying across available table values using a flexible and powerful syntax. Below are the key features and rules:

{% hint style="success" %}
Click [here](/analyze-and-export/advanced-search/advanced-search-syntax) for more examples and sample use cases
{% endhint %}

* **Tokenized Search**:\
  Search terms are automatically tokenized to improve matching accuracy. For example, typing `lu sk` will match names like **Luke Skywalker**. The search always uses a **starts-with** approach rather than a full-text or "contains" search. This means a search for `walk` would **not** return **Skywalker**.
* **Logical AND**:\
  All filters are combined using logical **AND**. Every condition must be met.\
  Example: `Luke Skywalker country:france` searches for Luke Skywalker where the **country** starts with "france".
* **Column-specific Search**:\
  Use `column:` to search within a specific column.\
  Example: `country:france` searches for entries where the **country** starts with "france".
* **Operators**:
  * `:` → **startsWith** search\
    Example: `name:jo` matches "John", "Joanna", etc.
  * `=` → **equals** search\
    Example: `city=Stuttgart` matches exactly "Stuttgart"
  * `!=` or `!:` → **negation**\
    Example: `city!=Stuttgart`or `city!:Stuttgart` excludes "Suttgart"
* **Special Behavior**:
  * **Umlaut substitution**:\
    Umlauts are normalized (e.g., **Björn** can be found by searching for **Bjorn**).
  * **Unicode support**:\
    Unicode characters are supported in search terms.
  * **Brackets () are ignored** in startsWith searches.
  * **Empty value search**:
    * `zip:""` searches for empty values
    * `zip:` searches for any value
* **Supported Columns**:
  * Aliases for column names may exist and are listed in brackets
  * User table:
    * `name, upn, language (lang), jobtitle (job), city, country, zip (plz), enabled, department (dept)`
      * `enabled:` → accepts `true` or `false` (`enabled:true`)
  * Groups table
    * `name`
  * Device table
    * `name, operatingsystem (os), manufacturer (manu), model`

### FAQ

#### How often is the data cached?

The table is cached on a schedule, currently set to 1 hour.

#### Can I refresh the data manually?

In the top right corner of each table, there's a button to refresh the cached data.

#### Can other users use my refreshed data?

The table is available for all users in the same RealmJoin portal instance. Thus, a triggered rebuild will do so for all those users.

#### What is a RealmJoin portal instance?

The RealmJoin portal has three different instances for load balancing and redundancy reasons.

#### How long will a rebuild/refresh of the advanced search take?

The rebuild time depends on the size of the tenant and the number of objects. It is not uncommon, that the rebuild might take several minutes. During the rebuild, only the basic search is available. All data is then queried directly via Graph, thus reducing the capabilities in filtering and speed.


# Advanced Search examples

This page lists some typical use cases when working with the Advanced Search. There are many more variables and search queries - please contact us if you have questions or miss something.

## Users

**Get all German users:**

[`country:DE`](https://portal.realmjoin.com/users/all?search=country%3ADE)

***

**Get all users of a specific department:**

[`department:"Sales Department"`](https://portal.realmjoin.com/users/all?search=department%3A%22Sales%20Department%22)

***

**Get all users with job title CEO:**

[`job:CEO`](https://portal.realmjoin.com/users/all?search=job%3ACEO)

***

**Get all users with job title CEO not in Germany:**

[`job:CEO country!:Germany`](https://portal.realmjoin.com/users/all?search=job%3ACEO%20country!%3AGermany)

***

**Get all users starting with ADM- with an empty department:**

[`name:ADM- department=""`](https://portal.realmjoin.com/users/all?search=name%3AADM-%20department%3D%22%22)

***

**Get all users with postal code 63065:**

[`zip:63065`](https://portal.realmjoin.com/users/all?search=zip%3A63065)

***

**List all users with specific domain:**

[`domain.com`](https://portal.realmjoin.com/users/all?search=domain.com)

***

## Groups

**Get all static groups:**

[`IsStatic:1`](https://portal.realmjoin.com/groups/all?search=IsStatic%3A1)

***

**Get all dynamic groups:**

[`IsStatic:0`](https://portal.realmjoin.com/groups/all?search=IsStatic%3A0)

***

## Devices

**Get all Windows 11 Version 22H2 devices:**

[`os:"Windows 11 (22H2)"`](https://portal.realmjoin.com/devices?search=OS%3D%22Windows%2011%20\(22H2\)%22)

***

**Get all Printers:**

[`OS:Printer`](https://portal.realmjoin.com/devices?compliance=0\&type=0\&search=OS%3APrinter)

***

**Get all Dell XPS devices:**

[`manu:dell model:xps`](https://portal.realmjoin.com/devices?search=manu%3Adell%20model%3Axps)

***

**Get all devices with RealmJoin Version 4.19 installed:**

[`rj:4.19`](https://portal.realmjoin.com/devices?search=rj%3A4.19)

***

**Get all Surface Hubs:**

[`Model:Surface Hub`](https://portal.realmjoin.com/devices?search=Model%3ASurface%20Hub)

***

## Packages

**Get all RealmJoin (basic) packages:**

[`Type:1`](https://portal.realmjoin.com/apps?search=Type%3A1)

***

**Get all Intune (basic) packages:**

[`Type:3`](https://portal.realmjoin.com/apps?search=Type%3A3)

***

**Get all Intune (managed) packages:**

[`Type:5`](https://portal.realmjoin.com/apps?search=Type%3A5)

***

**Get all RealmJoin (managed) packages:**

[`Type:7`](https://portal.realmjoin.com/apps?search=Type%3A7)

***

**Get all Packages with a running preview:**

[`StatusCurrentPreviewVersionParsed:`](https://portal.realmjoin.com/apps?search=StatusCurrentPreviewVersionParsed%3A)

***

**Get all "PreRelease"-Packages (deprecated):**

[`Preview:1`](https://portal.realmjoin.com/apps?search=Preview%3A1)


# Data Export

Export Data of queried tables to perform filtering and analysis with your tenant data

RealmJoin introduces an export functionality which enables you to work with your tenant data outside of the portal.

## General Exporting

You can query the User, Group, Device and Package tables for your requested data and generate an OpenXML file containing the queried data with all columns.

Simply go to a table, perform your search and press the download button in the top right corner:

<figure><img src="/files/NIzjCzCBMRp9JWZ7C9gA" alt=""><figcaption></figcaption></figure>

## Export Use Case: Software Report

You can query for specific software and packages in the [software report](https://portal.realmjoin.com/softwarereport/all) and get a resulting table of users or devices with the different installed versions.

Clicking on an entry in the "Devices" or "Users" column will result in a pre-filtered table-view which can be easily exported via the export button shown in the screenshot above.

This enables you to do evaluations on installed software and identify Devices and Users with outdated versions.

<figure><img src="/files/DIfgVuhdxbV10ltNayWg" alt=""><figcaption><p>Overview of installed versions of Git for Windows</p></figcaption></figure>

{% hint style="info" %}
Find more information about Software Reporting with RealmJoin in the [Software Reporting Section](/analyze-and-export/software-reporting).
{% endhint %}

## Predefined Dataset Exports

In addition to ad-hoc table exports, RealmJoin Portal offers one-click Excel (.xlsx) downloads of key datasets for reporting and auditing. You will find the **General Data Export** section in the portal navigation. Each export is available as a one-click download.

<figure><img src="/files/pCriI7SoqM3VOrHowacV" alt=""><figcaption><p>Export section in the RealmJoin portal</p></figcaption></figure>

### Available Exports

#### Device Export

Exports all devices in your environment with the following columns:

| Column                | Description                             |
| --------------------- | --------------------------------------- |
| Device Name           | Name of the device                      |
| Owner                 | Device owner                            |
| Owner UPN             | Owner's User Principal Name             |
| Primary User (RJ)     | Primary user as determined by RealmJoin |
| Operating System      | Installed operating system              |
| Manufacturer          | Hardware manufacturer                   |
| Model                 | Device model                            |
| CPU                   | Processor name                          |
| CPU Speed (GHz)       | Processor clock speed                   |
| RAM (GB)              | Installed memory                        |
| Disk (GB)             | Disk capacity                           |
| Last Seen             | Timestamp of last activity              |
| Compliant             | Compliance state                        |
| Enabled               | Whether the device is enabled           |
| RJ Version            | Installed RealmJoin client version      |
| Office Version        | Installed Microsoft Office version      |
| Office Update Channel | Configured Office update channel        |
| First Seen            | Timestamp of first appearance           |
| Serial Number         | Hardware serial number                  |
| Intune Last Sync      | Last sync timestamp with Intune         |

#### Package Export

Exports all subscribed packages with the following columns:

| Column              | Description                                 |
| ------------------- | ------------------------------------------- |
| Package Name        | Display name of the package                 |
| Package ID          | Unique package identifier                   |
| Coordinator         | Assigned coordinator                        |
| Platform            | Target platform                             |
| Version             | Currently deployed version                  |
| Auto Upgrade        | Whether automatic upgrades are enabled      |
| Allow Reinstall     | Whether reinstallation is allowed           |
| Group Name          | App category                                |
| Depends On          | Dependency on other packages, e.g. runtimes |
| Auto Deploy Main    | Auto-deployment state for the main ring     |
| Auto Deploy Preview | Auto-deployment state for the preview ring  |
| Latest Version      | Most recent available version               |
| Technical Owners    | Assigned technical owners                   |
| Maintained          | Whether the package is actively maintained  |

#### Package Restrictions

Exports all packages with their expert settings (restriction configuration) across deployment rings:

| Column          | Description                                           |
| --------------- | ----------------------------------------------------- |
| Package Name    | Display name of the package                           |
| Package ID      | Unique package identifier                             |
| Coordinator     | Assigned coordinator                                  |
| Platform        | Target platform                                       |
| Main: Normal    | Main script – normal restriction                      |
| Main: Initial   | Main script – initial restriction                     |
| Main: Manual    | Main script – manual restriction                      |
| Main: Logon     | Main script – logon restriction                       |
| Main: Primary   | Main script – primary restriction                     |
| Main: Secondary | Main script – secondary restriction                   |
| Has User Part   | Whether the package includes a user-context component |
| User: Normal    | User script – normal restriction                      |
| User: Initial   | User script – initial restriction                     |
| User: Manual    | User script – manual restriction                      |
| User: Logon     | User script – logon restriction                       |
| User: Primary   | User script – primary restriction                     |
| User: Secondary | User script – secondary restriction                   |

#### Antivirus Export

Exports antivirus status information across all devices:

| Column              | Description                                            |
| ------------------- | ------------------------------------------------------ |
| OS                  | Operating system                                       |
| OS Version          | Operating system version                               |
| Device Name         | Name of the device                                     |
| Client ID           | RealmJoin client identifier                            |
| AAD Device ID       | Entra ID (Azure AD) device identifier                  |
| Product Name        | Antivirus product name                                 |
| Is Defender         | Whether the product is Microsoft Defender              |
| Evaluated State     | RealmJoin's evaluated protection state                 |
| Raw State           | Raw antivirus state as reported                        |
| Last Signed-in User | Last user who signed in on the device                  |
| User ID             | User identifier                                        |
| User Is Local Admin | Whether the last signed-in user has local admin rights |
| Last Seen           | Timestamp of last activity                             |
| RJ Version          | Installed RealmJoin agent version                      |

#### Shadow IT

Exports Windows software found on devices that was **not** installed via RealmJoin, aggregated per product with device and user counts. It also includes a best-effort match against your assigned Intune apps, to help you spot software that could be brought under management:

| Column           | Description                                                                  |
| ---------------- | ---------------------------------------------------------------------------- |
| Type             | Software type / source (e.g. `Windows: Appx`)                                |
| Name             | Product name                                                                 |
| Publisher        | Publisher, taken from the software's signing certificate subject             |
| Known as         | Normalized / friendly product name, when RealmJoin can map one               |
| Versions         | Number of distinct versions found across all devices                         |
| Devices          | Number of devices the product was found on                                   |
| Users            | Number of users associated with those devices                                |
| Installations    | Total number of installations found                                          |
| Intune App Match | Whether the product could be matched to an assigned Intune app (best-effort) |

{% hint style="info" %}
The data in these exports is sourced from the RealmJoin agent and Intune and combined into the individual reports. Future iterations may include additional information; changes will be posted in the changelog and reflected in this documentation.
{% endhint %}


# Software Reporting

RealmJoin Software Reporting shows apps installed across all company devices, with versions and deployment methods from Microsoft Intune.

The software reporting feature in the portal provides comprehensive insights into the applications installed across all devices within the company. This feature aggregates data from both Microsoft Intune and RealmJoin, leveraging a small agent running on user devices to collect and report detailed information.

To access the software reporting feature, navigate to the portal and select the "Software Reporting" section. Here, you will find a comprehensive list of all applications installed on company devices, along with their deployment methods and versions. This information is crucial for maintaining an up-to-date inventory of software and ensuring compliance with company policies.

## Data Sources

1. **RealmJoin**: Utilizes a small agent on user devices to gather information on applications deployed through RealmJoin.
2. **Microsoft Intune**: Collects data on applications deployed via Intune.

## Details

The software reporting includes the following key details for each application found on company devices:

* **Application Name**: The name of the application installed.
* **Deployment Method**: The method used to deploy the application. This can include:
  * **Choco**: Applications deployed via RealmJoin using Chocolatey.
  * **Win32**: Applications deployed via Microsoft Intune.
  * **Appx**: Applications deployed via the Windows Store.
* **Version Installed**: The specific version of the application that is installed on the device.

<figure><img src="/files/GZx3etDpCcjgCZ7g9gdZ" alt=""><figcaption><p>Software Report filtered on "Adobe Reader"</p></figcaption></figure>

For each entry, all versions and all devices / users having the specific version installed can be displayed. The results are a filtered devices/user list, and can be exported for further usage (see [Data Export](https://docs.realmjoin.com/ugd-management/user-list/data-export)).

<figure><img src="/files/uVPg6nk7jrWack56YZj7" alt=""><figcaption><p>All installed version of "Adobe Reader" in the company inventory</p></figcaption></figure>

<figure><img src="/files/n8UMX8mhActqZdBMhD1L" alt=""><figcaption><p>All devices with the same version of "Adobe Reader" installed. May be exported to be further processed.</p></figcaption></figure>

{% hint style="info" %}
**Special Considerations:**

**Applications with Auto-Updaters**: For applications that have an auto-update feature, the version reported as RealmJoin (Choco) reflects only the initially installed version. To obtain the most current version, it is necessary to also check the Win32 entry.
{% endhint %}


# Deployment Methods: RealmJoin Agent vs. Intune

Comparison of native Intune deployment (intunewin + Intune Management Extension) and RealmJoin Agent deployment for Windows packages — and the additional capabilities the Agent adds.

Nearly every package in the [Package Store](/application-management/packages/package-store) can be deployed to your Windows devices in one of two ways. You choose the method per package when you [subscribe](/application-management/packages/package-store/package-store-details#subscription) to it, and you manage assignments the same way afterwards through [managed groups](/application-management/packages/package-deployment).

* **Intune deployment** – the package is pushed to your tenant as an `intunewin` app and delivered by Microsoft Intune and the Intune Management Extension, surfacing to users in the Company Portal.
* **RealmJoin deployment** – the package is installed by the [RealmJoin Agent](/realmjoin-agent/realmjoin-client) running on the device, surfacing to users in the [RealmJoin Tray](/realmjoin-agent/client-menu/realmjoin-tray) and [Self Service Portal](/realmjoin-agent/client-menu/self-service-portal).

{% hint style="info" %}
We recommend RealmJoin deployment. It supports everything the Intune method does and adds the capabilities described on this page. If you have decided to standardise on Intune-managed packages instead, see the [Migration Guide](/application-management/packages/migration-guide-realmjoin-to-intune-managed-packages).
{% endhint %}

## How each method delivers a package

{% tabs %}
{% tab title="Intune deployment" %}
The `intunewin` version of the package is pushed directly into your tenant. It contains all binaries plus a PowerShell-based deploy kit. From there it can be managed either from the RealmJoin Portal or in Intune directly.

* **Delivery:** Microsoft Intune + Intune Management Extension.
* **Self-service surface:** Company Portal → Apps.
* **Payload:** binaries bundled inside the `intunewin` package and staged to the tenant.
  {% endtab %}

{% tab title="RealmJoin deployment" %}
The RealmJoin Agent on the device executes all installation code and commands locally using its package engine ([classic Chocolatey or the Native Choco Runtime](/realmjoin-agent/realmjoin-client/native-choco-runtime)) together with PowerShell. Binaries are downloaded at installation time.

* **Delivery:** the RealmJoin Agent (`realmjoin.exe` / `realmjoinservice.exe`), syncing configuration roughly every 30 minutes.
* **Self-service surface:** RealmJoin Tray menu and Self Service Portal, organised into categories.
* **Payload:** binaries downloaded on demand during installation.
  {% endtab %}
  {% endtabs %}

## Feature comparison

Both methods support the fundamentals: **Required** (mandatory) and **Available** (user-initiated) assignments, managed group creation, staged **Preview / Main** channel automation with deferral and *Deploy at Night*, and version/update tracking in [Package Management](/application-management/packages/package-management). The table below focuses on where the two methods differ.

<table><thead><tr><th width="300">Capability</th><th width="180">Intune deployment</th><th>RealmJoin deployment</th></tr></thead><tbody><tr><td>Required &#x26; Available assignments</td><td>Yes</td><td>Yes</td></tr><tr><td>Managed groups &#x26; Preview/Main automation</td><td>Yes</td><td>Yes</td></tr><tr><td>Auto-upgrade to newer versions</td><td>Required packages; Available packages only via the Update group</td><td><strong>Required and Available packages</strong> directly</td></tr><tr><td>Package dependencies (<em>Depends on</em>) &#x26; install order</td><td>—</td><td><strong>Yes</strong> — prerequisites installed automatically, in a defined sequence</td></tr><tr><td>Self-service reinstall / repair (<em>Allow reinstallation</em>)</td><td>—</td><td><strong>Yes</strong></td></tr><tr><td>Background install on config change</td><td>—</td><td><strong>Yes</strong></td></tr><tr><td>User deferral control (<em>Deployment rate</em>: Slow/Fast/Tomorrow)</td><td>—</td><td><strong>Yes</strong></td></tr><tr><td>Install phase &#x26; audience control (<em>Main app / User part restrictions</em>)</td><td>—</td><td><strong>Yes</strong> — Logon/Manual/Initial/Normal, primary/secondary user</td></tr><tr><td>Onboard existing unmanaged installs (<em>Update group</em>)</td><td>Yes</td><td><strong>Yes</strong> — better integrated through RealmJoin's richer software inventory</td></tr><tr><td>Configuration / craft packages with multi-subscribe suffix</td><td>—</td><td><strong>Yes</strong></td></tr><tr><td>Own Enrollment Status Page, ordered with dependencies</td><td>Windows/Intune ESP</td><td><strong>Additional</strong> <a href="/pages/SJebyQIocNNdnjtpy4Zh">RealmJoin ESP</a>, honouring dependencies &#x26; order</td></tr><tr><td>Deploying very large payloads (e.g. large CAD suites)</td><td>Size and reliability limitations</td><td><strong>Handled reliably</strong></td></tr></tbody></table>

{% hint style="info" %}
The advanced per-package options above are the [**Expert Settings**](/application-management/packages/package-settings#expert-settings) of a package. RealmJoin App Deployment is required to use them, and the full feature set requires the RealmJoin Agent.
{% endhint %}

## What you gain with RealmJoin deployment

### Dependency resolution, ordering, and a matching ESP — a real highlight

RealmJoin can express relationships between packages. With **Depends on**, prerequisite packages (for example a Visual C++ or .NET runtime) are installed automatically before the app that needs them, and with **Order** you control the exact sequence of the rollout. This lets you model real application stacks instead of assigning every component independently and hoping the timing works out.

The real value shows during provisioning: the [RealmJoin ESP](/realmjoin-agent/realmjoin-client/realmjoin-esp) holds the Windows desktop until mandatory installs and configurations have completed, and it **respects those same dependencies and order numbers**. Prerequisites go on first, in the sequence you defined, before the desktop is released — so a device reaches the user fully and correctly provisioned rather than finishing its stack afterwards.

### Auto-upgrade for Available apps, not just mandatory ones

When a newer version enters the channel, the RealmJoin Agent upgrades both **Required** *and* **Available** packages already installed on a device, directly. Intune can also bring assigned **Available** apps up to date, but only indirectly via the [Update group](/application-management/packages/update-group). RealmJoin keeps self-service software patched to the same level as mandatory software out of the box, closing a common gap where optional apps drift out of date.

### Fine-grained control over *when* and *for whom*

Each package can define its **install phase** — after logon, only when the user starts it manually, only during initial provisioning, or during normal usage — and whether it runs for the primary user, secondary users, or both. Combined with the **Deployment rate** (letting users defer for a defined number of days before installation enforces itself), you get precise control over the end-user experience.

### Self-service repair and silent remediation

**Allow reinstallation** lets users re-run a package from the tray at any time to fix a broken installation — ideal for self-healing packages such as time-sync or configuration fixes. **Allow background installation** applies configuration changes automatically on the next sync, without interrupting the user.

### Onboarding of existing installations

The [**Update group**](/application-management/packages/update-group) dynamically discovers copies of a software title that were installed outside of management and pulls those devices into the managed deployment. Newer versions — including security patches — then reach those machines too, so unmanaged installs stop being blind spots. The Update group is available for Intune deployment as well, but it is more tightly integrated with RealmJoin thanks to RealmJoin's richer software inventory, which detects installations more completely.

### Configurations, not just applications

Beyond application installers, RealmJoin deployment handles **craft/configuration packages** — such as printer or network-drive mappings — and lets you subscribe the same craft package multiple times using a [suffix](/application-management/packages/package-store/package-store-details#craft-packages-suffix-configuration-or-notation), so a user can receive several distinct configurations of the same package.

### A polished end-user experience

The Agent surfaces available software in the RealmJoin Tray and Self Service Portal, grouped into the categories you define, and shows [app notifications](/realmjoin-agent/realmjoin-client/deploy-apps) with a customisable hero image and interactive snooze/defer options during installation.

### Reliable delivery — including very large payloads

RealmJoin deployment is more reliable in general, and it handles all kinds of payloads — including very large files such as big CAD suites — dependably, a scenario where Intune still runs into issues. Because the Agent downloads binaries at installation time and installs them locally, size-related delivery limits are far less of a concern.

### A modern engine and easier troubleshooting

The optional [Native Choco Runtime](/realmjoin-agent/realmjoin-client/native-choco-runtime) runs installations inside the RealmJoin service — no dependency on the ageing bundled Chocolatey 0.10.3 binary — while remaining a drop-in replacement for your existing packages. Installs run locally with detailed, isolated per-package logs on the device, and RealmJoin keeps adding more and more straightforward troubleshooting options, making it easier to see exactly what happened and why when an installation needs investigating.

## Choosing a method

<table data-view="cards"><thead><tr><th></th><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Subscribe &#x26; assign</strong></td><td>How to subscribe a package for either method and assign it to managed groups.</td><td><a href="/pages/MJDlSDsfzmSzoWLHlvgM">/pages/MJDlSDsfzmSzoWLHlvgM</a></td></tr><tr><td><strong>Expert Settings</strong></td><td>Full reference for the per-package options compared above.</td><td><a href="/pages/xo1IcZdqHYIf3AC3hsss">/pages/xo1IcZdqHYIf3AC3hsss</a></td></tr><tr><td><strong>Migrate to Intune</strong></td><td>If you have decided to standardise on Intune-managed packages.</td><td><a href="/pages/TcUfvw19ENQpneFQrm98">/pages/TcUfvw19ENQpneFQrm98</a></td></tr></tbody></table>


# Packages

RealmJoin's catalogue of ready-to-use Windows and macOS application packages deployable via RealmJoin Client or Microsoft Intune.

RealmJoin Packages are ready‑to‑use software packages provided through the RealmJoin Portal, offering a large, continuously maintained catalogue of Windows and macOS applications that can be easily deployed via the **RealmJoin Client** or **Microsoft Intune**. They include **generic packages** available to all customers, **custom and organic packages** tailored for specific environments, and **macOS‑specific packages**, all designed to simplify app deployment and lifecycle management for modern workplaces.

{% content-ref url="/pages/qujii1DZUl1kXifaINjB" %}
[Package Store](/application-management/packages/package-store)
{% endcontent-ref %}

{% content-ref url="/pages/yQVOjSbUC2pGkJz3PC4l" %}
[Package Management Overview](/application-management/packages/package-management)
{% endcontent-ref %}

{% content-ref url="/pages/dybUrRL6OuX8Itod5RAQ" %}
[Package Configuration and Assignments](/application-management/packages/package-deployment)
{% endcontent-ref %}

{% content-ref url="/pages/DnOffezbqf4ecJjdUi6s" %}
[Package Details](/application-management/packages/package-details)
{% endcontent-ref %}

{% content-ref url="/pages/xo1IcZdqHYIf3AC3hsss" %}
[Package Settings](/application-management/packages/package-settings)
{% endcontent-ref %}

{% content-ref url="/pages/FqMbSqsnYnENrt2DqzsH" %}
[Packaging Requests](/application-management/packages/packaging-requests)
{% endcontent-ref %}

{% content-ref url="/pages/TcUfvw19ENQpneFQrm98" %}
[Migration Guide: RealmJoin to Intune Managed Packages](/application-management/packages/migration-guide-realmjoin-to-intune-managed-packages)
{% endcontent-ref %}


# Package Store

The RealmJoin Package Store is a maintained library of ready-to-use packages deployable via RealmJoin Client or Intune.

{% embed url="<https://www.youtube.com/watch?v=QYBx9yto560>" %}

<figure><img src="/files/snk8ZzzVGCrT48wXlZUz" alt=""><figcaption><p>The RealmJoin application store</p></figcaption></figure>

RealmJoin Portal provides and maintains a large library of ready-to-use packages, easily deployable using either the RealmJoin Client or Intune.

### Categories

Packages are sorted into categories to simplify searching. The categories are displayed as tags on the package. Example categories are **Tools**, **Office**, **Driver**

### Search

You can use the search bar at the top to search for a package by:

* **Display name** - e.g. "7-Zip"
* **Category** - like "Tools" or "Office"
* **Description** - like "7-Zip is a free and open-source file archiver"
* **Package ID** - e.g. "generic-7zip" (visible via [Package Details](/application-management/packages/package-store/package-store-details))

The search updates results instantly as you type.

### Package Types

Every package falls in at least one of the following categories. The banner on the right side of a package is color-coded accordingly.

<figure><img src="/files/6j80zuIkQpgI5p1Sqcj0" alt=""><figcaption><p>Package type filter</p></figcaption></figure>

#### Generic Packages

If an application package is created without any customer-specific configuration hard-coded inside, it is created as generic package. Generic packages are available to all customers the same, and if possible, generic packages will be created as maintained packages.

This package is available for provisioning via RealmJoin Agent & Intune / [Package Management](/application-management/packages/package-management).

#### Custom Package

In contrast to the former types of packages, this kind of package is not globally available to all customers. In most cases this is a custom software package created specifically for your environment.

This package is available for provisioning via RealmJoin Agent & Intune / [Package Management](/application-management/packages/package-management).

#### Organic Package

In contrast to the former types of packages, this kind of package is not globally available to all customers. In most cases this is a custom software package created specifically for your environment.

This package is available for provisioning via RealmJoin Agent & Intune / [Package Management](/application-management/packages/package-management).

#### macOS Packages

Filter on OS type. Default filter is *Windows*, to access macOS packages, select *macOS*. This filter works in conjunction with the *generic/custom/organic/unlisted* filter.

macOS packages are only available for provisioning via Intune.

#### Unlisted Package

This section is only available for selected ADM accounts. If you can see it, you know what it is.

### Full vs. Limited Catalogue of Packages

If you recently self-onboarded into RealmJoin or do not have a subscription/licensing agreement yet, the list of software packages will be limited to a free-to-use subset of packages. Please [contact us](/legal/support) to enable the full catalogue of packages for your organization.


# Package Subscription Options

Subscribe to RealmJoin Package Store packages as managed or basic and deploy them via Intune or the RealmJoin agent.

{% embed url="<https://www.youtube.com/watch?v=QYBx9yto560>" %}
Video tutorial
{% endembed %}

<figure><img src="/files/AxIQNkl0jP4OWkPpamZ4" alt=""><figcaption><p>Package Store details page</p></figcaption></figure>

## Subscription

<figure><img src="/files/uWnupFCRXDs4CCL5pdua" alt=""><figcaption><p>Subscribe Buttons</p></figcaption></figure>

Packages will either be pushed directly to Intune as intunewin packages or deployed using the RealmJoin agent on the device (recommended).

## Subscription Type

Packages can be subscribed as *managed* or *basic*.

* *Basic* packages are available for assignment to groups or users and do not offer additional features.
* *Managed* packages allow RealmJoin to handle group creation and assignment.\
  The backend automatically creates a fixed set of groups, including preview and uninstall groups, and package assignments can only be made to these groups. Find more about managed groups [here](https://docs.realmjoin.com/app-management/packages/package-deployment#managed-deployment)

<figure><img src="/files/sEDgb5AT9JGX51NOS6z2" alt=""><figcaption><p>Application Groups</p></figcaption></figure>

The created Entra ID groups can be managed from both the RealmJoin Portal and Microsoft Entra ID.

## Package Types

Nearly all packages from the RealmJoin store can either be subscribed for RealmJoin Agent or Intune driven deployment.

### RealmJoin Deployment

RealmJoin driven deployment relies on the RealmJoin agent installed on the device. Using a modified Chocolatey engine and PowerShell, all code and installation commands are executed directly on the device. Binaries are downloaded during the installation.

### Intune Deployment

The Intune driven deployment pushes the intunewin version of the package directly into the tenant. It can be managed either from the RealmJoin portal or in Intune directly. The intunewin packages contain all binaries as well as a PowerShell based deploy kit.

{% hint style="info" %}
We recommend RealmJoin driven deployment, as it offers more options and manageability.
{% endhint %}

## App Categories

The name and group name/category can now be customized when subscribing to a new package. This feature allows for better organization and easier access to applications within both RealmJoin and Intune environments.

**RealmJoin Deployment**

* **Display**: The application will be displayed under the chosen Group Name in the RealmJoin Tray Menu.
* **Customization**: The appropriate Group name should be selected during the subscription process to ensure the application is categorized correctly.

**Intune Deployment**

* **Display**: The application will be displayed under the chosen category in Intune and in the Company Portal for assigned users.
* **Customization**:
  * Multiple categories can be selected for an application.
  * Categories can be edited afterwards in the "Expert Settings" of each package.
  * Categories can be managed under the settings of the portal to ensure they align with organizational needs.

<figure><img src="/files/hSEYuFphs4Tx7F1AcgOk" alt=""><figcaption><p>Configuration of Category/Group Name during the subscription process</p></figcaption></figure>

The total of categories can be managed from the *App Categories* tab in the general settings section in the RealmJoin portal.

<figure><img src="/files/wgvqBkvzPUFYx9oq4Coe" alt=""><figcaption><p>All categories available in the tenant</p></figcaption></figure>

## Multiple package subscriptions

### Craft Packages (Suffix Configuration or #-Notation)

Sometimes it is necessary to have multiple subscriptions of one craft package. Those craft packages are often used for configurations like printer or network drive mapping and need to be subscribed and assigned multiple times to users because there are multiple printer or network drives to be mapped. Therefore it is important to have a suffix, because RealmJoin only accepts every package ID once. The suffix is modifying the unique ID from "this-id" to "this-id#\[your-suffix]".

While subscribing to a craft package from the store, a suffix is automatically added to the ID of the package. If you want to edit the ID, you can simply click on "Set suffix" next to the orange dialog box showing the pre-defined ID.

<figure><img src="/files/QYKZtAOqcweCB3cLNc99" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
The suffix is only available for RealmJoin Deployment since it is not necessary for Intune Deployment!
{% endhint %}

### Choco Packages

If you need multiple configurations of an application, e.g. "Microsoft 365 Apps for Enterprise", you can subscribe it multiple times and change the name during the subscription process, i.e. "Microsoft 365 Apps for Enterprise - DE", which will be reflected in the managed package groups created by RealmJoin.

{% hint style="danger" %}
**Suffixes are not required—and therefore not available—for these types of packages, as each user can only be assigned and install a single instance of an application with a specific configuration at any given time. This limitation ensures that identical Chocolatey or IntuneWin applications, which share the same unique identifier, cannot be deployed to the same user more than once. Attempting to assign multiple copies of the same app with the same ID will result in conflicts and is not supported.**
{% endhint %}

You can change the name by choosing your package and subscription type and before hitting continue clicking next to the name in the top left corner to adjust it.

## Package Properties

### Core Properties

Every package's details page will show an overview of the core properties such as the package's **Display Name**, **Description** and **Package ID** ("Unique RJ ID") on the left side of the screen. This part will not scroll and be always visible in any tab.

### Status Fields

Also displayed on the left side of the screen are four status fields for a package, displayed as tags below the package name and publisher name.

![](/files/59moO5h2nqXXWfAoR0je)

These fields are binary - they are set to one of two possible values. The text of each field changes accordingly. Some of the fields are also color-coded for easier glanceability.

* **Maintained / Unmaintained:** RealmJoin will provide new versions / updates of maintained packages on a regular basis.\
  Automatic package management can be applied to keep the software delivered by these packages permanently up-to-date in your environment.
* **Generic / Custom:** Generic packages are available to all customers / environments. Custom packages are not globally available to all customers. In most cases this is a custom software package created specifically for your environment.
* **Billable / Non-Billable:** Provisioning of this package will count towards your package usage quota - if you have one. Currently all publicly available packages are billable.
* **Free to Use / Needs License:** Does this software need a commercial license to be used?

### MS Security Center Software Inventory (TVM) entry

If available, a link to this software title's [MS Security Center Software Inventory (TVM)](https://security.microsoft.com/software-inventory/applications)'s entry will be displayed. There you can check for known security issues and outdated versions of this software in your organization.

![An Application's TVM Entry](/files/6fj44d13EFQKUJ2jqeIR)

An appropriate license from Microsoft is needed to access TVM.

This page allows to examine your current security posture, incl. installed versions and distribution on devices as well as security recommendations regarding this software title.

### Version

![Available Version vs Provisioned Package](/files/EPSDM4SetteDsyL2EEGA)

Also displayed on the left side of the screen is the version of the software package.

If you already provisioned the package to your environment, a link to the provisioned package in [Package Management](/application-management/packages/package-management) will be displayed. The link will show the name and version of the provisioned package.

## Tabs

The right side of the screen shows the contents of the current tab.

The following tabs are available:

### Overview / Subscribe

<figure><img src="/files/XN2eC9TXekdq5FudUkLx" alt=""><figcaption><p>Overview and Provisioning</p></figcaption></figure>

#### Title, Description and other info

This tab will show the long description, license and technical help information of a package.

#### Subscribe / Provisioning

This tab also shows the Subscribe-Buttons for this package. See [Subscribe to Package](/application-management/packages/package-deployment).

### Versions

The package's changelog shows when the packages has been updated in RealmJoin's repository plus a short description of changes.

<figure><img src="/files/cgNWmgS5I1KUDP3sCBXv" alt=""><figcaption><p>App Package Changelog</p></figcaption></figure>


# Package Migration

Packages can be migrated to "Managed" if previously deployed as "Basic".

{% hint style="warning" %}
Package migration is only available for **RealmJoin** packages
{% endhint %}

## Identifying Packages

Currently only RealmJoin packages can be migrated from Basic to Managed deployment. This can be identified from the Packages table:<br>

<figure><img src="/files/OgOuZGX0pFoYEVCFCQ2K" alt=""><figcaption></figcaption></figure>

## Migration

1. Select a Basic RealmJoin package
2. Under Group Assignments, select More -> Convert to managed app (This process happens immediately).
   * Old groups are nested into the new Managed RealmJoin Groups. Settings made to the Basic groups will be adopted by the Managed groups.<br>

     <figure><img src="/files/FYXStYjbedDeQA9fiX6r" alt=""><figcaption><p>Before Migration</p></figcaption></figure>

     <figure><img src="/files/icihZOudp4SAFO527v6Y" alt=""><figcaption><p>After Migration</p></figcaption></figure>
   * Users are added to the most relevant group

     <figure><img src="/files/wgKxKCiE0HNsEg2ukE2n" alt=""><figcaption><p>Before Migration</p></figcaption></figure>

     <figure><img src="/files/Q0OBIeH6ReL0vLEustXz" alt=""><figcaption><p>After Migration</p></figcaption></figure>
3. (Optional) Pull members from nested groups directly into the RealmJoin managed groups. This setting migrates users directly to the RealmJoin managed group and optionally removes the nested group from the Managed group.
   1. Select relevant group -> More -> "Pull members up".
   2. Select the ![](/files/EtR6nf6jrDB8Sso6xGPr) on the desired nested group
   3. Choose "Remove Assignment" to remove the nested group or "Keep Assignment" to keep the nested group in the RealmJoin managed group
   4. Click Execute to begin the operation<br>

      <figure><img src="/files/WZ3HVL8sftDUquSS6QbK" alt=""><figcaption></figcaption></figure>


# Package Management Overview

RealmJoin Package Management lists all packages across RealmJoin and Microsoft Intune to filter, search, sort, and manage version updates.

Package Management shows all packages that currently exist in your environment across RealmJoin and Microsoft Intune.

<figure><img src="/files/8aFF0KADsrQsMR2o4wme" alt=""><figcaption><p>Package Management List</p></figcaption></figure>

Clicking on the name of a package will redirect you to the package's [details page](/application-management/packages/package-details).

## Filters

* **All** - Show all packages across RealmJoin and Intune, including mobile packages and Windows Store packages
* **Supported** - Show only packages handled by RealmJoin (RealmJoin Client + Intune)
* **RealmJoin** - Show only RealmJoin packages deployed via RealmJoin Client
* **Intune** - Show only RealmJoin packages deployed via Microsoft Intune
* **Updates only** - Limit the view to packages from the package store where there exists a newer version of the package in the store.
* **Automation only** - Limit the view to packages from the package store where automatic deployment of newer versions is configured.

## Search and Sort

The package list allows you to search for any package in your organization by any visible field, incl. name, version and platform.

The search supports real-time / as-you-type incremental search. The search results will update instantly as you type.

You can sort the current search result or the full list by any of the fields, by clicking on the fields name.

## Version and Preview

RealmJoin supports a staged update procedure for software packages.

If a newer version of a managed package exists, you can subscribe to the new version of a package as **Preview**. This will create a separate instance of the package with the new version and allows you to assign this package preview to a pilot user group for testing.

<figure><img src="/files/hZiVa78z1dymlZbhAHkC" alt=""><figcaption><p>List of Updates</p></figcaption></figure>

The package list shows you the version information of the main package, the preview package (if available) as well as the version number of the package currently available in the package store.

If *Update Automation* is activated, the desired update timeframe is displayed in the column **Automation**. A value of "ASAP" means, the package is due for updating.


# Package Configuration and Assignments

RealmJoin package subscriptions and assignment types such as Main (Required) and Available, for deploying software via RealmJoin or Intune.

{% embed url="<https://www.youtube.com/watch?v=BdF3rvMbjFs>" %}

## Managed Subscription

Packages subscribed as managed come with managed user groups. There are different types of groups available that can be chosen based on your scenario.

{% hint style="info" %}
Managed packages are the preferred way to deploy software to your users. You can combine it with automated package updates and lifecycle to ensure your users receive latest features and patches.
{% endhint %}

### **Main (Required)**

RealmJoin or Intune will automatically install the application. These applications are mandatory and both solutions will continuously attempt to install the application, if not found on the device.

### **Available**

{% tabs %}
{% tab title="RealmJoin" %}
The application will appear in the RealmJoin Agent tray and will require the user to initiate the download and installation manually.

<figure><img src="/files/KwCydSZintHuGdXiBaTI" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Intune" %}
The application will appear in Company Portal -> Apps and will require the user to initiate the download and installation manually.

<figure><img src="/files/iITRxYLDXl32gmErgaPm" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

### Preview

Users and devices in the Preview group will receive the latest version of the package before the other groups. Preview settings are configurable through the [Automation tab](/application-management/packages/package-details#automation).

### Uninstall

RealmJoin or Intune will uninstall the package from the assigned users and devices. Adding a user or device to the Uninstall group will remove them from all other groups.

### Update

The Update group is created on demand and automatically onboards loose installations of a software title into management, so that new versions — including security patches — also reach those devices. It is the mechanism that keeps Intune **Available** apps up to date, by temporarily assigning outdated devices as **Required**.

For details, see [Update Group](/application-management/packages/update-group).

### Exclude

Needs to be explicitly activated through "More" > "Exclude assignments" (like shown in the [picture below](#enable-additional-and-restore-default-groups)). Users in the specified group will be excluded from assignments all over the package and associated managed groups.

{% hint style="info" %}
This option should only be used in specific cases and is not intended to be used to manage assignment conflicts. You should always manage assignments with clear user to group assignments, without the need of using an exclude mechanic. We strongly advise against multi-layer assignment constructs.
{% endhint %}

#### Usage

The Exclude assignment of groups is used to ensure that users in the assigned exclude group are not managed within the package managed groups. It will not remove users from managed groups within the same package. Instead, it makes sure that certain packages are never assigned to the same user simultaneously.

For example, you can use the Exclude function to prevent a user, assigned to a 64-bit Adobe Reader package group, from also receiving the 32-bit version. Simply assign the used 64-bit package group as an exclude to the 32-bit package.

{% hint style="warning" %}
In managed packages, group management is handled by the RealmJoin Portal, which uses the GUID of each group after creation. This enables the portal to identify the provisioning type associated with each group. As a result, it is possible to establish a prioritization mechanism among groups. This ensures deterministic behavior in scenarios where a user is mistakenly assigned to multiple provisioning groups.

The prioritization order is (high to low):

Uninstall - \[Exclude] - \[Update] - Preview - Available - Required
{% endhint %}

### Enable additional and restore default groups

<figure><img src="/files/TODqYjMGtbzts2NqUnLg" alt=""><figcaption></figcaption></figure>

Via the "More"-Button you can activate the optional update group, manage exclude assignments and also restore the default managed groups in case they were deleted.

### Changing Assignments

{% hint style="warning" %}
Users and devices should only be in one RealmJoin managed group at any given time.
{% endhint %}

Users and devices can easily be moved across groups using the *Managed users* function.

<figure><img src="/files/J1mxD1Lu8XEHHFNEjbxr" alt=""><figcaption></figcaption></figure>

Selecting Main, Preview, Available and Uninstall will add the user to the chosen group and remove the user from all other groups relevant to the package.

Selecting Assign will add users to the Main group by default.

## Basic Subscription (Legacy)

Basic packages do not have any associated Microsoft Entra groups. You will have to manually assign groups, devices or users.

Groups, devices and users that are assigned to a Basic package will be assigned as Available by default and can be changed using the \[change settings] button.

<figure><img src="/files/LzPvB7HYmFQVd68HnrU8" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/0WHXNxd7zDW8KXYzCYm4" alt=""><figcaption></figcaption></figure>

#### Migrating from Basic to Managed subscriptions

To migrate a legacy basic package subscription to the standard managed format, the RealmJoin Portal provides a built-in conversion function. In the assigned groups section of the basic subscribed application package, the "Convert to Managed App" option is available behind the "More" button.

This feature creates the default managed subscription groups, in which the legacy users can be added vial bulk operation or nesting.

<figure><img src="/files/53XSUL8fgSTxthdjwFj5" alt=""><figcaption><p>Preparation to migrate a basic app to a managed app</p></figcaption></figure>

<figure><img src="/files/riFEtMUarHxuAOvbRZUI" alt=""><figcaption><p>Result of the migration process</p></figcaption></figure>


# Update Group

Keep Intune "Available" managed apps up to date with the optional per-package Update Group, which temporarily assigns outdated devices as Required.

Managed apps deployed via Intune as **Available** are installed on demand by users from the Company Portal. Intune does not push newer versions to devices that already have such an app installed — an **Available** assignment only ever offers the *current* version to devices that do not have the app yet. As a result, Available‑deployed apps are **not kept up to date natively**.

The optional **Update Group** closes this gap. When enabled per package, RealmJoin detects existing installations and temporarily brings them up to date by assigning the affected devices as **Required (Mandatory)** — without changing the package's normal **Available** assignment.

{% hint style="info" %}
The Update Group can be enabled for both Intune‑managed and RealmJoin Agent‑managed packages. It is most relevant for **Intune Available** apps, since the RealmJoin Agent already keeps Available packages up to date on its own (see [Auto upgrade](/application-management/packages/package-settings#expert-settings)).
{% endhint %}

## How it works

{% stepper %}
{% step %}

### Enable the Update Group per package

On the package's detail page, choose **More → Enable update group** (see [Enable additional and restore default groups](/application-management/packages/package-deployment#enable-additional-and-restore-default-groups)). RealmJoin creates a dedicated Entra ID group with the `(update)` suffix and assigns it to the app with the **Required** install intent. The group is managed entirely by the RealmJoin Portal and must not be edited manually.
{% endstep %}

{% step %}

### RealmJoin detects outdated installations

Using Intune reporting ("detected apps") data across the tenant, RealmJoin identifies every device that has the software installed at a version *older* than the latest subscribed and assigned version in the package.
{% endstep %}

{% step %}

### Outdated devices are temporarily assigned as Required

Detected outdated devices are added to the Update Group. Because the group carries the **Required** intent, Intune installs the new version on those devices as a mandatory deployment — overriding the "Available, on demand" behavior just for the update.
{% endstep %}

{% step %}

### Devices are removed once up to date

On a later run, devices that report the current version (or are no longer detected as outdated) are removed from the Update Group. They revert to the package's normal **Available** assignment. Membership is reconciled automatically.
{% endstep %}
{% endstepper %}

<figure><img src="/files/g4eeHc9S82LgLinMqhSn" alt=""><figcaption><p>Update Group Enabled</p></figcaption></figure>

## Requirements and scope

* The package must have a **newer version subscribed and assigned**. If no newer version exists, no device is considered outdated and nothing is assigned.
* Detection relies on Intune reporting data, so a device must have reported its installed apps to Intune to become eligible.
* By default the Update Group targets **all** reported devices in the tenant. To restrict this, assign the **"Eligible for Update Group"** permission to specific device groups in the portal settings. Once this permission is assigned to at least one group, the feature only processes devices within those groups.

{% hint style="warning" %}
The Update Group is a temporary, automated **Required** assignment used purely to carry updates. Devices move in and out of it automatically — do not add or remove members manually, and do not reuse the `(update)` group for other assignments.
{% endhint %}


# Package Details

The RealmJoin package details page shows a single package's properties and manages its user assignments and updates.

<figure><img src="/files/vz6zMKrBGn2bnTFZ1qXE" alt=""><figcaption><p>Package details page</p></figcaption></figure>

This page will show detailed information for a single package in your environment and allows you to manage its assignment to users and updates.

This page looks like the [Package Store Details](/application-management/packages/package-store/package-store-details) page but gives details about a package that is already imported into your environment. It does not reflect the generic package store entry.

## Package Types

This page can display any package that is understood by RealmJoin Portal, this includes

* **Managed** and **Basic** packages from the package store
* **Unmanaged** packages in Intune (not from the package store)
* **RealmJoin Classic** "Choco" and "Craft" packages

Different types of packages have different levels of support to be managed via RealmJoin Portal at this point. This guide will focus on **Managed** and **Basic** packages from the package store as these are best supported currently.

## Package Properties

### Name and Core properties

Every package detail page will show an overview of the core properties like the package's **Display Name**, **Description** and **Package ID** ("Unique RJ ID") on the left side of the screen. This part will not scroll and be always visible in any tab.

You can use the edit button next to the package's name to give a package a custom display name relevant to your users. For packages hosted in Intune, this will also rename the package's display name in Intune. This will not break the relationship with the [package store entry](/application-management/packages/package-store/package-store-details) for packages sourced from the [package store](/application-management/packages/package-store).

![Package Name and Status](/files/yYtC9iqymkxGb6O6blkK)

### Status Fields

Also displayed on the left side of the screen are four status fields for a package, displayed as tags below the package name and publisher name.

These fields are binary - they are set to one of two possible values. The text of each field changes accordingly. Some of the fields are also color-coded for easier glanceability.

* **Maintained / Unmaintained:** RealmJoin will provide new versions / updates of maintained packages on a regular basis.\
  Automatic package management can be applied to keep the software delivered by these packages permanently up-to-date in your environment.
* **Generic / Custom:** Generic packages are available to all customers / environments. Custom packages are not globally available to all customers. In most cases this is a custom software package created specifically for your environment.
* **Billable / Non-Billable:** Provisioning of this package will count towards your package usage quota - if you have one. Currently all publicly available packages are billable.
* **Free to Use / Needs License:** Does this software need a commercial license to be used?
* **Intunemanaged / Intuneunmanaged:** These tags denote packages, that are offered via Intune.
  * **Intunemanaged**: Managed and Basic packages from the package store, delivered via Intune
  * **Intuneunmanaged**: Unmanaged packages in Intune (not from the package store)

## Tabs

The right side of the screen shows the contents of the current tab.

The following tabs are available:

### Overview

<figure><img src="/files/WMkiEd20WXbSiUqkj032" alt=""><figcaption><p>Overview tab</p></figcaption></figure>

#### Title, Description and other Info

This tab will show the long description, license and technical help information of a package.

#### Assignments and Deployment Status

Use these tables to assign additional groups and check the deployment status of apps for devices and/or users.<br>

<figure><img src="/files/9iUu6L1WXDwjLanF6QHO" alt=""><figcaption></figcaption></figure>

#### Usage

{% hint style="warning" %}
The Usage function requires the RealmJoin Agent to properly populate data.
{% endhint %}

Use the usage table to determine the spread of versions deployed across your device fleet as well as your license count. Clicking on the numbers under Client Count or User Count will show the device/users using the respective version of the package.

<figure><img src="/files/MNqknSOFdsuYLNV44OzZ" alt=""><figcaption></figcaption></figure>

### History

The package's history shows when the package has been updated in RealmJoin's repository.

<figure><img src="/files/DEaYlRuKkbdIMLW1zD6x" alt=""><figcaption><p>History tab</p></figcaption></figure>

There are two types of changes tracked in Changelog.

![](/files/POOHvb6Vnsf2ACbo6mBk) Changes to the instance of the package in your environment, specifically in Intune. E.g. publishing a newer version of the package to your users.

![](/files/lUn3IoRMoGfHNxwJz2CC) Changes to package store entry.


# Package Settings

This page details the different settings available for deployed packages

## Automation

<figure><img src="/files/jeGGeUv84AnjaoiAG0tc" alt=""><figcaption><p>Package Automation</p></figcaption></figure>

For managed packages, the Automation tab lets you set up automatic deployment of the latest package versions from the package store to your environment.

* **Automate Main Channel** - Automatically deploy new versions of this package to your users. ("Main" subscription)
* **Automate Preview Channel** - Automatically deploy new versions of this package to your pilot users. ("Preview" subscription)

{% hint style="info" %}
The Preview Channel will only advance to a newer software version after deploying the current version in Preview to the Main Channel.

This is intended behavior to ensure that a testing / review process using the Preview Channel is not accidentally invalidated by a newer software version entering Preview.
{% endhint %}

The Preview Channel will take the newest version available from the App Store pushing its current version to the main channel.

{% hint style="success" %}
Recommendation:

* Automate only **Main Channel** for software that can upgrade without prior testing, such as web browsers from major vendors.
* Automate only **Preview Channel** for software you want to test before deploying. Push the validated version to Main Channel after testing and start testing the next version in Preview.

You can always manually push a newer version available in Package Store directly to **Preview** or **Main Channel** to skip a version you don't want published.
{% endhint %}

* **... defer X days** - Wait for this number of days to pass before publishing a new version to the channel. This is useful to avoid stress for users/clients if multiple package versions are published rapidly.
* **Deploy At Night** - Schedule automatic deployment during nighttime
* **Select target time zone** - If you use **Deploy At Night**, use this Time Zone to indicate when "at night" is.

These values can be globally preconfigured for newly imported packages in [Settings](/administration-and-settings/settings). Configuring them on a per package basis will overwrite the global defaults.

## Config

<figure><img src="/files/2BFpqzghtWqkaHhUuuMj" alt=""><figcaption><p>Package Config</p></figcaption></figure>

### Technical Application Owners

If wanted, you can assign multiple **Technical Application Owners** (TAO) to a package via storing their email-addresses.

For receiving **automated notification emails** for package updates, you can **enable** the switch below in addition.

### Arguments

**Arguments** allow you to pass command line switches to an application installation. This is commonly used to customize your package with language options, a license key etc. that need to be present at installation time.

{% hint style="info" %}
If a user already has the current subscribed version of a package installed and the package arguments are updated, the package will automatically re-run for that user using the new configuration.

If **Auto upgrade** is **OFF** and the user has an older version installed than the currently assigned one, the new configuration will **not** be applied.\
If **Auto upgrade** is **ON**, the user will receive both the new version and the updated configuration.
{% endhint %}

Some packages include a **Technical Help**, to explain possible **Arguments** and other Requirements.

![Technical Help for a Package](/files/Q7UfPB9OGKqTDhEuebre)

#### Special arguments for Intunewin packages

For Intunewin packages we offer a configurable package update UI notification which lets the user interact with the install / update of an application and gives control over the process.

<figure><img src="/files/GdB8QiebbUKjGWB4NLw0" alt=""><figcaption></figcaption></figure>

You can configure this dialog with the following settings in the arguments section:

```
--rjNotifyUser // Activate dialog
```

```
--rjNotifyAllowDefer[=n] // snooze option with x possible deferrals
```

```
--rjNotifyTimeout=n // when no user action is performed -> automatic snooze after x seconds (if deferral allowed), otherwise update
```

<figure><img src="/files/bhdncwlwnCFercy5C2xC" alt=""><figcaption></figcaption></figure>

### Expert Settings

{% hint style="info" %}
RealmJoin App Deployment required.\
For full feature set of "Expert settings": RealmJoin Agent required.
{% endhint %}

<table><thead><tr><th width="154">Setting</th><th width="478">Explanation</th><th>Agent only</th></tr></thead><tbody><tr><td>Allow reinstallation</td><td>This option allows the user to <strong>reinstall</strong> and therefore override their current installation of the <strong>package</strong> at any time.<br>E.g.: suitable for packages that help fixing client issues via self-service (time sync, ...).</td><td>Yes</td></tr><tr><td>Allow background installation</td><td>Executes <strong>package updates directly</strong> after configuration updates have been detected on the corresponding device (standard RJ sync interval: 30 minutes). Updates start without warning (no snooze option).<br>Do not use this option for regular packages as this might interrupt users when using the corresponding software.</td><td>Yes</td></tr><tr><td>Require compliance</td><td>The package is <strong>installed</strong> as soon as RealmJoin is able to verify that the device is <strong>considered "compliant"</strong>. This might stop the roll out for some time. The installation of the package and all other mandatory packages with higher order numbers are getting queued and only installed when the client is compliant.</td><td>Yes</td></tr><tr><td>Pre-Release</td><td>Legacy setting - see <a href="https://docs-classic.realmjoin.com/rj-portal/software-packages">RealmJoin Classic</a>.</td><td>Yes</td></tr><tr><td>Auto upgrade</td><td><p><strong>Automatically upgrades</strong> a package when a <strong>newer version</strong> becomes available. If the subscribed version is higher than the one on the device, RealmJoin re‑runs the package to update it.</p><p><br>Disable this option for packages with their own update mechanisms (e.g.: VPN client updated via gateway). When off, only new device installs receive the updated version.<br><br><strong>Behavior by platform:</strong></p><p><strong>RealmJoin Agent:</strong> Updates required <em>and</em> available packages.<br><strong>Intune:</strong> Updates required packages only. To keep <strong>Available</strong> apps up to date on Intune, enable the <a href="/pages/rQ3NxWM2LUAAoEbLQ0CU">Update Group</a>.</p></td><td>No</td></tr><tr><td>Only in VDI / Ignore in VDI</td><td>Execute this package on <strong>VDIs</strong> (W365 and Azure Virtual Desktop/WVD) devices only or exclude them from the installation.</td><td>Yes</td></tr><tr><td>Only on hybrid-joined devices / Ignore on hybrid-joined devices</td><td>Execute this package on <strong>hybrid-joined devices</strong> only or exclude them from the installation.</td><td>Yes</td></tr><tr><td>Ignore on private devices</td><td><strong>Exclude private</strong> devices (not Entra ID joined) from the installation.</td><td>Yes</td></tr><tr><td>Group name</td><td><strong>Category</strong> in which the package will show up in RealmJoin tray menu.</td><td>Yes</td></tr><tr><td>Depends on</td><td><p>Specifies prerequisite packages that must be installed before this package. RealmJoin installs all listed dependencies first. Ensure dependent packages are also assigned (e.g. marked as available).<br>Example: A runtime environment such as "Microsoft VC Redistributable Runtime" required for a software to run.</p><p><br>Enter the package ID (see RJ portal "Unique RJ ID" on the desired package) in the following format:<br><code>["package-id"]</code></p><p>For multiple packages:<br><code>["package-id1","package-id2"]</code></p><p>Example:<br><code>["generic-microsoft-vcredist-2019","generic-microsoft-net-core-desktop-runtime-6"]</code></p></td><td>Yes</td></tr><tr><td>Order</td><td>Defines the installation sequence using an integer value. Lower numbers run first (e.g., <strong>10</strong> installs before <strong>100</strong>).<br>A value of <strong>0</strong> means “no sequence” and runs only after all numbered packages.<br>Order numbers are applied <strong>only during the initial client rollout</strong>.</td><td>Yes</td></tr><tr><td></td><td><p><strong>Do not use </strong><em><strong>Dependency</strong></em><strong> and </strong><em><strong>Order</strong></em><strong> on the same package.</strong><br>During initial rollout (or any mandatory rollout after login), RealmJoin first installs all dependency packages, then installs the original packages. This two‑stage process overrides and can nullify any defined order numbers.</p><p><strong>For example:</strong></p><ul><li>Package A, order 1</li><li>Package B, order 101 and depending on Package C, order 100.</li><li>If all packages are assigned as mandatory, the installation sequence will be C, A, B</li></ul><p>User settings within application packages are treated as a set dependency.</p></td><td></td></tr><tr><td>Deployment rate</td><td>Select the deployment rate which <strong>allows or blocks</strong> users from <strong>deferring</strong> the package <strong>installation</strong> until the displayed date. You have the choice between "Slow" (+7), "Fast" (+3) and "Tomorrow" (+1).<br>Example: When choosing "Tomorrow", the current date + one day will be stored as fixed value. Users can defer until this date. Afterwards, the installation will just execute without further control. Note that the date is not dynamic (so, not depending on the client's last check in time).<br><strong>Note:</strong> The installation on devices includes a staged mechanism: installations will occur multiple times a day with a specific probability per trigger. This ensures a smoother rollout and utilizes BC/DO features effectively.</td><td>Yes</td></tr><tr><td>Main app restrictions</td><td><p>This option allows to define <strong>who</strong> can run a package installation and <strong>when</strong> it will happen (<strong>phase</strong>).</p><p>Define whether this package should run just for the primary user of a device (visible and changeable in RealmJoin portal), only secondary users or for both of them.</p><p>Choose between the following phases or combinations of them. Default is "Normal, Initial &#x26; Manual".<br></p><p><strong>Logon</strong>: The package runs after the user has logged on.</p><p><strong>Manual</strong>: The package will run when the user starts installation via tray menu manually.</p><p><strong>Initial</strong>: The package only runs during the initial client deployment.</p><p><strong>Normal</strong>: Neither Logon, nor Manual, nor Initial. Deployment during the normal usage of a client.</p></td><td>Yes</td></tr><tr><td>User part restrictions</td><td>Same options as before - but for the user part (if available for the corresponding package). E.g.: contains settings or scripts executed under the current user ("user" instead of "system scope").</td><td>Yes</td></tr></tbody></table>

<figure><img src="/files/tjZFL7wqMYYwnyJPGZzk" alt=""><figcaption><p>Expert Settings</p></figcaption></figure>


# Packaging Requests

RealmJoin provides Packaging‑as‑a‑Service (PACKaaS) for applications not available in the RJ Store or for outdated packages. For details, contact your RealmJoin consultant, partner, or support team.

## Architecture (Win11 & macOS)

The RealmJoin Packaging Factory is currently optimized for Windows 11 application requests, delivering robust and reliable packaging services across the Windows ecosystem. Full macOS support is in active development and will add hundreds of ready‑to‑use macOS applications to the RealmJoin Store, enabling a more complete cross‑platform experience.

macOS packages are currently in preview as we continue refining the macOS packaging pipeline. We accept macOS application requests on a best‑effort basis, though processing times and availability may vary during this development phase. Our team will handle these requests as effectively as possible within the current framework.

We appreciate your patience as we work toward delivering the same level of excellence for macOS that our Windows 11 users currently enjoy.

### Custom vs Generic Packaging

#### Generic Packages in RealmJoin

We aim to create packages as **generic** as possible. This allows all settings to be configured via the RealmJoin portal post-app subscription. Our **generic** packages feature unmodified installers provided by vendors, without any customer-specific alterations. These packages are accessible to all customers in the RealmJoin store.

#### Custom Packages in RealmJoin

**Custom** packages are exclusively available for customers in their **custom** section of the RealmJoin **Package Store**. The **custom** namespaces are used for modified installers, including those customized by the vendor for the customer, such as SAP, or for customer-developed apps and similar cases.

We invite customers to share their evaluation on whether an application can be packaged as *generic* or requires a *custom* package, however, the final decision is made by the RealmJoin Packaging Factory. Note that *custom* packages incur additional costs.

## Request Types

Three different PACKaaS requests are currently available: new package, update existing package and [organic packages](/application-management/packages/packaging-requests/organic-packages).

### New Packages

If an application is not available in the RealmJoin Store, it can be requested for packaging via the RealmJoin Packaging Factory. A valid PACKaaS request must include:

* **Application binaries**, which must always be uploaded for regular packaging requests (a download URL may be added for reference but is **not** sufficient). If there are multiple files, please use a zip container.
* **Documentation** describing all required configuration switches as command‑line parameters, registry keys, configuration files, or similar (screenshots are not accepted; PACKaaS does not include Scripting‑as‑a‑Service). Silent/unattended installation commands are always required.
* **Packaging type selection**, specifying whether the application should be created as a *generic* package (when no customer‑specific data is included) or as a *custom* package (additional fees may apply). The Packaging Factory may change a request from generic to custom if justified; for example, when customer‑specific details are identified during processing. Customers will be informed of such changes before the request is completed.
* **Contact email address**, which may differ from the currently authenticated user’s email.
* **Installation parameters**, which may be entered directly in the request instead of embedding them in the ZIP file.
* **Optional description**, a free‑text field for any additional context you want to pass to the Packaging Factory.
* **Use of “skip upload”**, which is allowed only when updating or adding parameters to an existing package—binaries must still be provided for all standard packaging requests.

{% hint style="info" %}
When you start a new package request, the form now highlights existing packages that match your input, helping you spot software that is already available in the RealmJoin Store and avoid duplicate requests.
{% endhint %}

<figure><img src="/files/WFIMQxIVCAR6srQVW2CO" alt=""><figcaption><p>RealmJoin packaging request form for new requests.</p></figcaption></figure>

### Package Updates

If an application is required in a newer version than the one available in the RealmJoin Store, the same processes and requirements apply as new package requests. When the updated binary behaves identically to the existing version, command‑line parameters may be omitted from the request. A dropdown list is available showing all packages currently subscribed to within the tenant, and update requests can only be submitted for those subscribed packages.

<figure><img src="/files/XYDIWaPSJnRJyLdwQXKr" alt=""><figcaption><p>RealmJoin package request form for package updates.</p></figcaption></figure>

{% hint style="info" %}
Note: Additional switches, new parameters or configuration files for an existing package are considered updates and shall be requested the identical way.
{% endhint %}

{% hint style="danger" icon="exclamation" %}
**Tickets, Files and Setup**

Please note that:

* all update and new package requests necessitate the provision of both binaries and documentation detailing the required command line parameters. Silent/unattended installation parameters are not optional and **must** be provided.
* if an update request does not entail changes from the previous version, the submission of new parameters is not required but need to be referred.
* the request creates a ticket. All communication will be handled in this ticket, and it will only be sent to the account that created it. **If this account does not have any active mailbox, the requester will not get any information.** The request form allows to set a new reply address in case an ADM account without mailbox is used to create the text. Once the ticket is created, the reply address can not and will not be changed.
* the software requester role can be assigned to any user group in the tenant, therefore, an ADM account may not be required.
* organic packages and PACKaaS might be not available right away, please get in touch with <support@realmjoin.com> if a feature is missing
* any incomplete request will be rejeceted.
  {% endhint %}


# Packaging Roles & Responsibilities

RealmJoin maintained versus unmaintained package types and update responsibilities split between the Packaging Factory and customers.

#### Package Maintenance Types

**Maintained Packages**

* **Regular Updates**: These packages are consistently monitored by the RealmJoin Packaging Factory.
* **Update Process**: After rigorous checks, updates are published in the store.
* **Support Options**: If updates are missing, customers can open a support ticket to address this.

**Unmaintained Packages**

* **Categorization**: Any package not marked as maintained falls into this category.
* **Update Requests**: Customers must submit a regular update request for non-maintained generic packages.
* **Cost**: Updates for generic packages are free of charge.

<figure><img src="/files/0cVHCwLcB5FEv1nGQj3B" alt=""><figcaption><p>generic maintained application package</p></figcaption></figure>

**Custom Packages**

* **Tailored Updates**: Custom package updates are created through specific requests from customers.
* **Pricing**: These updates incur charges, as they are personalized per customer needs.

<figure><img src="/files/3eY3QCa8PJBqhPHr8AzR" alt=""><figcaption><p>custom non-maintained application package</p></figcaption></figure>

**Responsibilities**

Maintained application packages will be updated once the vendor releases updates. The RealmJoin Packaging Factory does not monitor non-maintained applications. Customers are responsible for monitoring and request updates for all other applications themselves.

| Process Step                | RealmJoin                     | Customer                                   |
| --------------------------- | ----------------------------- | ------------------------------------------ |
| creation generic packages   | packaging                     | requesting                                 |
| custom package creation     | packaging                     | requesting                                 |
| application package testing | install, reinstall, uninstall | functional, share results with glueckkanja |
| update monitoring           | maintained packages           | non-maintained packages                    |


# Application Package Testing

RealmJoin's four-stage package testing cycle validates installation mechanics, exit codes, and deployment behavior for packaging requests.

### Overview

Most application packaging requests undergo a four-stage testing cycle to validate installation mechanics, exit codes, and deployment behavior. Functional testing of application features is the responsibility of the customer application owner.

### Testing Stages

#### 1. Manual Installation on Sandbox System

* Application binaries are manually installed following vendor documentation
* Dependencies and environmental requirements are identified and documented
* Reinstallation over existing installation is tested
* Uninstallation as provided by the vendor binaries is verified

#### 2. Command Line Installation

* Provided silent installation parameters and flags are tested and verified
* Exit codes are validated for success and failure scenarios
* Installation scripts are developed and executed
* Automated reinstallation and uninstallation procedures are validated
* All processes are confirmed to execute without user interaction

#### 3. Package Preparation

* Installation files are organized into RealmJoin package formats (NuGet, intunewin)
* Package metadata and scripts are defined, documentation added (if applicable)

#### 4. Automated Installation

* The package is installed on a fresh sandbox system
* Installation behaviour is verified against previous manual and CLI tests
* Package-based reinstallation and uninstallation are tested
* Exit codes are validated across all scenarios
* **Malware scanning** is performed on generic-packages during the automated build as a mandatory security gate


# Organic Packages

RealmJoin organic packages build from uploaded .zip files and publish automatically to the Package Store for binary file transport.

Organic packages are used for binary file transportation with a fixed configuration, which can not be changed. Uploaded .zip files are automatically added to the list of available packages in the tenant, and secured with a strong password. The content will be extracted to *`$env:SystemDrive\Install\packagename`* during package execution. This path can not be changed. An optional antivirus scan is available.

Because of this high standardization, organic packages are built automatically and within a couple of minutes. No ticket will be created and no charge added, the package will be made available in the Package Store under the Organic tab as soon as possible without the need of involvement of the packaging factory.

<figure><img src="/files/tD8TZGZ2LAaamoDgbAxn" alt=""><figcaption><p>Organic packaging request.</p></figcaption></figure>

##

{% hint style="warning" %}
Due to their automated creation process, organic packages cannot be updated. These packages are generated and published without user input, making them unchangeable. Additionally, since no installation routine is run, logical updates are not possible. To release a new version, create a new automatic organic package and remove the outdated one from your portal.
{% endhint %}

## Unlist Organic Packages

Organic packages can be unlisted after creation, if they should not be seen by other administrators in your tenant. Simply go to the package store, select the package and press the "Unlist now" button.

<figure><img src="/files/SGt6lCwhVPBEttnee7jh" alt=""><figcaption><p>Unlist now</p></figcaption></figure>


# Migration Guide: RealmJoin to Intune Managed Packages

This document outlines the best practices for transitioning package management from RealmJoin managed packages to Intune managed packages.

### Important Strategic Recommendation

**We currently recommend continuing to use RealmJoin managed packages instead of transitioning to Intune managed packages.** The RealmJoin agent provides significantly more features and greater flexibility for package management. Additionally, we highly recommend against running both RealmJoin and Intune managed packages in parallel for the same package or package family. Strategically, your organization should standardize on a single management mechanism across your environment to ensure consistency, reduce complexity, and avoid conflicts.

This migration guide is provided for organizations that have made the strategic decision to transition to Intune managed packages. Please thoroughly evaluate your requirements and consult with your RealmJoin solution architect before proceeding with this migration.

### Key Concept

Detection fingerprints remain consistent throughout the migration process. This means that Intune managed packages will recognize and properly handle devices that previously had RealmJoin managed package instances installed, ensuring continuity of deployment and inventory tracking.

### Migration Process

#### Step 1: Rename the RealmJoin Managed Package

Begin by renaming the existing RealmJoin managed package to free up the package name for reuse. This step is essential as Intune managed packages will use the same or similar naming convention.

**Actions:**

* Access the RealmJoin management portal
* Locate the package in the package management section
* Rename the package with a deprecation indicator (for example, append "\_legacy" or "\_deprecated" to the original name)
* Document the new name for reference

#### Step 2: Subscribe to the Intune Managed Package

After the RealmJoin package has been renamed, proceed with subscribing to the equivalent Intune managed package.

**Actions:**

* Navigate to the RealmJoin store
* Locate and select the package you wish to migrate to
* Complete the subscription process as Intune managed
* Verify that the package is properly registered in your Intune environment

**Note:** Use the original package name (now available after renaming the legacy package) to maintain consistency in your package naming schema.

#### Step 3: Transfer Users Using Bulk Operations (optional)

Transfer users from the RealmJoin managed package to the Intune managed package using the bulk operation function available in RealmJoin.

**Actions:**

* Access the managed groups of the Intune package
* Under the *More* section, select *Bulk Operations*
* Execute the bulk reassignment to the new Intune managed package
* Monitor the operation progress and verify successful transfers

<div><figure><img src="/files/GmIz2iZtdMbibTPQF3jt" alt="Selecting the bulk operation feature to copy all users from a existing group"><figcaption><p>Selecting the bulk operation feature to copy all users from a existing group</p></figcaption></figure> <figure><img src="/files/Mev2Fe0NlYwFFp3EiCSr" alt="Execution of the bulk operation. Users are added to the new group, a log is available for your reference."><figcaption><p>Execution of the bulk operation. Users are added to the new group, a log is available for your reference.</p></figcaption></figure></div>

### Detection Fingerprint Consistency

An important advantage of this migration approach is that detection fingerprints remain unchanged. The same fingerprint configuration used by the RealmJoin managed package will function seamlessly with the Intune managed package.

**Implications:**

* No need to reconfigure detection rules or fingerprints
* Existing inventory and deployment history remains valid
* Devices that previously received the RealmJoin package version will be correctly identified when transitioning to the Intune version
* Audit trails and compliance reporting remain accurate across the transition

### Post-Migration Verification

After completing the migration, perform the following verification steps:

* Verify all users have been successfully transferred to the Intune managed package
* Confirm that package detection is functioning correctly on client devices
* Check that no users remain assigned to the legacy RealmJoin package
* Review deployment status and ensure packages are installing correctly
* Validate that inventory and reporting data reflects the new Intune managed package

<figure><img src="/files/GjWmQ0ORhaVdv8Wn7abm" alt=""><figcaption><p>Available package is installed / updated via the company portal.</p></figcaption></figure>

<figure><img src="/files/vwAdT3YaVLCKlAjg33L9" alt=""><figcaption><p>Mandatory assigned Intune package is updated.</p></figcaption></figure>

### Rollback Considerations

Should issues arise during migration:

* Retain the renamed RealmJoin package for a minimum grace period to enable potential rollback
* Document all migration steps and timestamps for troubleshooting
* Have a clear rollback procedure in place before beginning the migration
* Test rollback procedures in a non-production environment first
* Provide all information including full log files in any support ticket


# Connecting Azure Automation

This guide outlines the onboarding process for both new and existing Automation Accounts.

## Overview

{% embed url="<https://www.youtube.com/watch?v=Ijp9XnE8UuA>" %}

To enable RealmJoin Portal to deliver [runbooks ](/automation/runbooks)for automating daily tasks, you must connect an [Azure Automation](https://learn.microsoft.com/en-us/azure/automation/overview) Account. This Automation Account will act as the host for your runbooks and provide the [permissions](/automation/connecting-azure-automation/azure-ad-roles-and-permissions) required for the runbooks to function within your environment.

## Considerations

The Automation Account's [Managed Identity](https://learn.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview) requires extensive [permissions ](/automation/connecting-azure-automation/azure-ad-roles-and-permissions)in your environment, such as the ability to modify group or user objects in Entra ID or manage mailboxes in Exchange Online. Limit administrative access to this account to prevent misuse of these privileges.

When using an existing Automation Account, note that RealmJoin Portal automatically creates, updates and removes runbooks coming from the [shared online repository of runbooks](https://github.com/realmjoin/realmjoin-runbooks). This functionality may not be supported in an existing Automation Account. If uncertain, we recommend creating a dedicated Azure Automation Account for RealmJoin Runbooks.

## Prerequisites

* Global Administrator privileges
* Access to PowerShell with the [Az](https://learn.microsoft.com/en-us/powershell/azure/?view=azps-15.3.0) module or [AZ CLI](https://learn.microsoft.com/en-us/cli/azure/?view=azure-cli-latest)
* Contributor permissions on an Azure subscription
* [Runbook requirements](/automation/connecting-azure-automation/azure-ad-roles-and-permissions)

## Instructions

{% stepper %}
{% step %}

#### Create an Azure Automation Account

1. Navigate to your [Azure Portal > Automation Accounts](https://portal.azure.com/#create/Microsoft.AutomationAccount)
2. Create a new Automation Account
3. In the Basics tab, choose your desired Subscription, Resource Group, Automation Account Name and Region<br>

   <figure><img src="/files/t1iKclOqIxrHP2KsZZMF" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
A separate Resource Group for your Automation Account is recommended
{% endhint %}

4. In the Advanced tab, ensure the System Assigned Managed Identity is enabled

   <figure><img src="/files/avxa9sp6RiMR6XJ5NYKW" alt=""><figcaption></figcaption></figure>
5. Select Review + Create and create your Automation Account
6. Navigate to the Resource Group containing your Azure Automation Account
7. In the IAM tab, assign the Azure Automation Account as a Contributor
   {% endstep %}

{% step %}

#### Assign Permissions to Azure Automation Account

The RealmJoin shared runbooks use the Azure Automation's system assigned managed identity to interact with Entra ID, MS Graph API etc.

Managed Identity permissions cannot currently be granted through the Azure Portal. Use Microsoft Graph or PowerShell to assign these permissions.

1. Download the following PowerShell scripts and JSON files to the same folder.\
   The script will assign the full permission set required by RealmJoin. Roles and permissions can be reviewed in the [Requirements](/automation/connecting-azure-automation/azure-ad-roles-and-permissions) section and adjusted as needed in the JSON files.

{% tabs %}
{% tab title="GrantAppPermToEntApp.ps1" %}
{% @github-files/github-code-block url="<https://github.com/Workplace-Foundation/approle-and-directoryrole-granter/blob/main/GrantAppPermToEntApp.ps1>" %}
{% endtab %}

{% tab title="AssignAzureADRoleToEntApp.ps1" %}
{% @github-files/github-code-block url="<https://github.com/Workplace-Foundation/approle-and-directoryrole-granter/blob/main/AssignAzureADRoleToEntApp.ps1>" %}
{% endtab %}

{% tab title="AllRealmJoinRunbooks\_collected\_permissions.json" %}
{% @github-files/github-code-block url="<https://github.com/realmjoin/realmjoin-runbooks/blob/production/docs/other/json/AllRealmJoinRunbooks_collected_permissions.json>" %}
{% endtab %}

{% tab title="AllRealmJoinRunbooks\_collected\_rbacroles.json" %}
{% @github-files/github-code-block url="<https://github.com/realmjoin/realmjoin-runbooks/blob/production/docs/other/json/AllRealmJoinRunbooks_collected_rbacroles.json>" %}
{% endtab %}
{% endtabs %}

2. Note down the Object ID of the Azure Automation Account's Managed Identity in Account Settings > Identity

   <figure><img src="/files/lsdHYqB5JuaEmnoLzoA1" alt=""><figcaption></figcaption></figure>
3. Open a PowerShell window.
4. Navigate to the folder containing the downloaded files

```
cd c:\temp\myfolder
```

5. Unblock scripts if necessary\
   ![](/files/7IrDTKFdREzdmr2uPahX)
6. Assign MS Graph Permissions to your Azure Automation Account using GrantAppPermToEntApp.ps1, replacing xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx with your Automation Account's Object ID

```
. .\GrantAppPermToEntApp.ps1 -enterpriseAppObjId "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" -permissionsTemplate .\AllRealmJoinRunbooks_collected_permissions.json
```

7. Assign Entra ID Admin Roles to your Azure Automation Account using AssignAzureADRoleToEntApp.ps1 replacing xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx with your Automation Account's Object ID

```
. .\AssignAzureADRoleToEntApp.ps1 -objectId "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" -rolesTemplate .\AllRealmJoinRunbooks_collected_rbacroles.json
```

8. The Azure Automation Account should now have the correct permissions to execute Runbooks<br>
   {% endstep %}

{% step %}

#### RealmJoin Runbook Configuration - Part 1

1. In RealmJoin Portal go to '[Settings -> Runbooks](https://portal.realmjoin.com/settings/runbooks-configuration)'.<br>

   <figure><img src="/files/Ar5PoXcrmVqZF4zwjjMP" alt=""><figcaption></figcaption></figure>
2. Fill in the Tenant ID, Subscription ID and Resource Group name belonging to the Azure Automation Account\
   The Tenant ID in the [Entra ID Overview page](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/Overview)

   <figure><img src="/files/nIhqPwD7Sq1Cp5ayU5Nu" alt=""><figcaption></figcaption></figure>
3. Copy the script in red underneath *ResourceGroup.*\
   This script creates a Service Principal in Entra ID with access to your Automation Account, allowing RealmJoin to manage, run and monitor runbooks.\
   The script is updated based on the inputs for Tenant ID, Subscription ID and Resource Group.<br>

   <figure><img src="/files/2HWJV1CQ1st2pFXxoIlY" alt=""><figcaption></figcaption></figure>
4. Leave the wizard open for now. We will return shortly in part 2.
   {% endstep %}

{% step %}

#### Granting Access for RealmJoin to Azure Automation

{% hint style="info" %}
You can use [Azure CloudShell](https://docs.microsoft.com/en-us/azure/cloud-shell/overview), so you don't need to install and authenticate a local copy of AZ CLI.
{% endhint %}

1. Run the script copied previously in PowerShell.

   <figure><img src="/files/oxnhA9CyBfVswPOkKHWJ" alt=""><figcaption></figcaption></figure>
2. Note down the values for `appId` and `password`.\
   The App Registration "RealmJoin Runbook Management" will be created.<br>

   ![App Registrations in Azure Portal](/files/IT1STktYqPLYSR2bw6rQ)
   {% endstep %}

{% step %}

#### RealmJoin Runbook Configuration - Part 2

1. In RealmJoin Portal return to the open window/wizard for '[Settings -> Runbooks](https://portal.realmjoin.com/settings/runbooks-configuration)'
2. Fill in the missing values for `appId` and `password` created in the last step
3. Fill in the name of the Automation Account created [previously](#create-an-azure-automation-account)
4. Choose the Branch of the shared runbook repository you want to follow.\
   If unsure, please choose `production`\
   All runbook branches may be viewed here: <https://github.com/realmjoin/realmjoin-runbooks>
5. Choose the same location as your Azure Automation Account to make sure your runbooks are executed in the correct [Azure region](https://docs.microsoft.com/en-us/azure/availability-zones/az-overview)

![Automation Account Connection in RealmJoin Portal](/files/dOGCfBtiYzwCtJnjpiwO)

6. Press "Save" to start the initial import of runbooks. Please leave this window open until you see the message "Sync completed".

![](/files/Qm6fC1BT1Zn1D2trdmSn)
{% endstep %}
{% endstepper %}


# Runbook Management App Permissions

Permissions and the RealmJoin Runbook Management app registration required for RealmJoin to interact with Azure Automation and runbooks.

This page describes the permissions needed for RealmJoin to interact with Azure Automation / Runbooks.

See [Runbook Execution Requirements](/automation/connecting-azure-automation/azure-ad-roles-and-permissions) to see which permissions need to be granted to Azure Automation for the runbooks to be useful in your environment.

## RealmJoin Runbook Management

RealmJoin will create an Application Registration called **RealmJoin Runbook Management** which is used to update the [Azure Automation Runbooks](/automation/runbooks) in your tenant based on [RealmJoin's shared runbook repository.](https://github.com/realmjoin/realmjoin-runbooks)

This app also will be used by RealmJoin Portal to trigger runbook execution after filtering requests through [RealmJoin's RBAC](/administration-and-settings/permission) and [Runbook Permissions](/automation/runbooks/runbook-permissions).

As this app is created individually for your tenant, there is no globally known Application ID as with [RealmJoin Portal's apps](/deployment/required-permissions).

This app will not have any API permissions.

### Azure Resource Permissions

The RealmJoin Runbook Management app will need to be at least Contributor on the Azure Resource Group hosting your Azure Automation Account. Using our [onboarding process](/automation/connecting-azure-automation) will make sure this permission is given.


# Runbook Execution Requirements

This wiki pages addresses what requirements and (system-level) permissions have to be given, so that runbooks can be executed.

## PowerShell Modules

{% hint style="info" %}
The PowerShell Modules section is automatically updated based on the [public repository](https://github.com/realmjoin/realmjoin-runbooks).
{% endhint %}

The shared runbooks available on [GitHub](https://github.com/realmjoin/realmjoin-runbooks) expect/use the following Windows PowerShell modules:

| Module                           | Minimum version in runbooks |
| -------------------------------- | --------------------------- |
| `Az.Accounts`                    | 5.5.0                       |
| `Az.Compute`                     | 5.1.1                       |
| `Az.DesktopVirtualization`       | 5.4.1                       |
| `Az.ManagementPartner`           | 0.7.5                       |
| `Az.Resources`                   | 9.0.1                       |
| `Az.Storage`                     | 9.6.0                       |
| `ExchangeOnlineManagement`       | 3.9.2                       |
| `Microsoft.Graph.Authentication` | 2.39.0                      |
| `MicrosoftTeams`                 | 7.6.0                       |
| `RealmJoin.RunbookHelper`        | 0.8.7                       |

RealmJoin Portal will automatically import and install these modules if referenced from inside a runbook. This import will also honor specified minimum versions for modules.

## Permissions

{% hint style="info" %}
The Permissions section is automatically updated based on the [public repository](https://github.com/realmjoin/realmjoin-runbooks).
{% endhint %}

The RealmJoin shared runbooks use the Azure Automation's [system assigned managed identity](https://learn.microsoft.com/en-us/azure/automation/enable-managed-identity-for-automation) to interact with Entra ID, MS Graph API etc.

The following list of roles and permissions will enable you to use all runbooks currently available in our shared repository.

It is not recommended to reduce these roles/permissions as the runbooks are tested only against this set of permissions. If you reduce the set of roles/permissions, some runbooks will cease to function.

### Entra ID Roles

Please assign the following Entra ID roles to the managed identity

* Application Developer
* Cloud Device Administrator
* Exchange Administrator
* Intune Administrator
* Teams Administrator
* User Administrator

### Graph API Permissions

Please grant the following Graph API-Permissions to the managed identity

* `Application.ReadWrite.All`
* `Application.ReadWrite.OwnedBy`
* `AppRoleAssignment.ReadWrite.All`
* `AuditLog.Read.All`
* `BitlockerKey.Read.All`
* `Channel.ReadBasic.All`
* `ChannelMember.ReadWrite.All`
* `CloudPC.ReadWrite.All`
* `Device.ReadWrite.All`
* `DeviceLocalCredential.Read.All`
* `DeviceManagementApps.ReadWrite.All`
* `DeviceManagementConfiguration.ReadWrite.All`
* `DeviceManagementManagedDevices.PrivilegedOperations.All`
* `DeviceManagementManagedDevices.ReadWrite.All`
* `DeviceManagementServiceConfig.ReadWrite.All`
* `Directory.ReadWrite.All`
* `Group.Create`
* `Group.ReadWrite.All`
* `GroupMember.ReadWrite.All`
* `IdentityRiskyUser.ReadWrite.All`
* `InformationProtectionPolicy.Read.All`
* `Mail.Send`
* `Organization.Read.All`
* `Place.Read.All`
* `Policy.Read.All`
* `Reports.Read.All`
* `ReportSettings.ReadWrite.All`
* `RoleAssignmentSchedule.Read.Directory`
* `RoleManagement.Read.All`
* `RoleManagement.Read.Directory`
* `ServiceHealth.Read.All`
* `Team.Create`
* `TeamMember.ReadWrite.All`
* `TeamSettings.ReadWrite.All`
* `User.ReadWrite.All`
* `UserAuthenticationMethod.ReadWrite.All`
* `WindowsUpdates.ReadWrite.All`

### Other App API Permissions

Please grant the following Office 365 Exchange Online API Permissions to the managed identity

* `Exchange.ManageAsApp`

Please grant the following WindowsDefenderATP API Permissions to the managed identity

* `Machine.Read.All`
* `Machine.Isolate`
* `Machine.RestrictExecution`
* `Ti.ReadWrite.All`

Please grant the following SharePoint API Permissions to the managed identity

* `User.Read.All`
* `Sites.Read.All`
* `Sites.FullControl.All`

### Granting Roles and Permissions

Granting permissions to Managed Identities can currently not be done using Azure Portal. We recommend using MS Graph / PowerShell scripting for this.

You can find an example for this process [here](https://github.com/Workplace-Foundation/approle-and-directoryrole-granter).

### Azure Resource Permissions

Please give at least "Contributor" access to the subscription or resource group hosting the Azure Automation Account for the runbooks

Some runbooks will use an Azure Storage Account to store reports or backups. Please give at least "Contributor" access to the corresponding subscription or resource group. Most runbooks can then create the resources inside the resource group on their own.

## Authentication Methods

### Managed Identities

Azure Automation supports [Managed Identities](https://docs.microsoft.com/en-us/azure/automation/enable-managed-identity-for-automation) (system assigned) as the primary to way to authenticate. This replaces the deprecated RunAs Accounts.

The RealmJoin Runbooks currently support RunAs Accounts if no managed identity is configured.

{% hint style="warning" %}
If a Managed Identity and a RunAs Account are configured at the same time, the runbooks from RealmJoin's shared repository will automatically prefer using the Managed Identity when using newer versions of our supporting `RealmJoin.RunbookHelper` Module starting with v0.8.0.

Older versions of the module could not fully utilize Managed Identities and preferred the RunAs Account.

Please make sure, that you grant the needed permissions to Managed Identity or disable it completely to only use the RunAs Account.
{% endhint %}

### Client Secret

Some private runbooks may need a ClientID/Secret-style authentication. There are currently no shared runbooks that require ClientID and Secret.

If needed, a ClientID and Secret can be stored in the managed credentials named "realmjoin-automation-cred" in the Azure Automation Account.

Currently the "realmjoin-automation-cred" in the automation account is created by the RJ-Wizard by default, but filled with random values - they would have to be filled with correct values.


# Runbooks

Automate day-to-day operations in your environment.

{% embed url="<https://www.youtube.com/watch?v=TfL7xRasVUg>" %}

RealmJoin provides administrators with the ability to automate tasks by using [Azure Automation](https://learn.microsoft.com/en-us/azure/automation/overview) to execute [PowerShell Runbooks](https://docs.microsoft.com/en-us/azure/automation/automation-runbook-types#powershell-runbooks).

Runbooks are scripts, automating tasks that normally must be executed by a support engineer / operator or administrator. Automating these tasks lowers the risk of manual error and allows better auditing of actions.

Some common tasks RealmJoin can help you automate include:

* User lifecycle operations (onboarding/offboarding users)
* Creating Temporary Access Passes (TAPs)
* Reporting M/O365 license usage
* Managing email aliases

You can offer RealmJoin Portal to your support and administration teams to simplify and improve the quality of your day-to-day operations.

![](/files/lN2fB6zXz8JmGsZllJy5)

### Migration to PowerShell Runtime Environments

RealmJoin is currently in the process of migrating from Windows PowerShell v5.1 to a PowerShell v7.4 [Runtime Environment](https://learn.microsoft.com/en-us/azure/automation/manage-runtime-environment).

{% hint style="info" %}
Make sure the "Runtime Environment" experience in your Automation Account is enabled.
{% endhint %}

<figure><img src="/files/kfZRNl31gT0WZLO7Gx68" alt=""><figcaption></figcaption></figure>

When running a [sync](#syncing-from-the-shared-repository), a custom PowerShell Runtime Environment "RJ-PowerShell-7.4" will be created, synced runbooks will be moved to this environment. If needed, required PowerShell modules will automatically be imported.

{% hint style="info" %}
Due to **varying process durations** that might cause errors like 404, please **sync again**. Additionally, wait a few minutes before starting the first runbook after the migration.
{% endhint %}

{% hint style="warning" %}
**Custom / non-synced runbooks will not be upgraded automatically.**

You can use Azure Portal and use "Edit in Portal" on these runbooks to manually migrate them. Make sure to "publish" the runbooks for the change to take effect.
{% endhint %}

<figure><img src="/files/fPdeFMz6IOeeij24Os3h" alt=""><figcaption></figcaption></figure>

## Common Runbooks

RealmJoin maintains a [shared online repository of runbooks](https://github.com/realmjoin/realmjoin-runbooks). They aim to cover many common operations found in most environments. The runbooks are continuously updated and improved. Of course, you can include your own custom runbooks, too.

RealmJoin Portal allows you to import these runbooks via [RealmJoin Runbook Management App](/automation/connecting-azure-automation/required-permissions#b31d828b-8bcb-45fc-8d72-5418777a5376) into your environment and offers your support and administration staff an easy, non-technical interface to the tasks the runbooks cover.

### Syncing from the Shared Repository

You can trigger a sync from the shared repository to your Azure Automation account by clicking "Sync runbooks with upstream" at

<https://portal.realmjoin.com/settings/general>

![Trigger a sync of your runbooks](/files/Bnkhj1qTrzN543GZorOX)

Wait for the "Sync completed" message. Please keep the browser window open while the sync process is running.

As described in the [naming convention](/automation/runbooks/naming-conventions) this will add, update and if needed remove runbooks from the connected Azure Automation Account to be in sync with RealmJoin's shared repository. This ensures that your runbooks are up to date, including improvements, fixes and new features.

## Customization

You can customize existing and new runbooks to your environment. For example, you can

* Use templates for common pieces of information, like office locations
* Prefill / preconfigure parameters, like to not allow deleting user object when offboarding
* Hide certain inputs/parameters

See [Runbook Customization ](/automation/runbooks/runbook-customization)for more details.

## Scopes

Runbooks in RealmJoin Portal are scoped to the different types of objects in your environment. Some runbooks operate on the tenant / organization level, like creating a license report. Some runbooks are scoped on a per user basis, like resetting a password. RealmJoin Portal uses this scoping to offer the right runbooks in the right context.

See [Naming Conventions](/automation/runbooks/naming-conventions) to learn about how runbooks are scoped to certain objects in your environment.

## Access Control

Access/Permissions to use certain runbooks can be granularly given on a runbook level. For example, Runbook Permissions could help you:

* Only allow access to this runbook to the 3rd level operators
* Only allow our VIP support crew to change the CEO's email address

See [Runbook Permissions](/automation/runbooks/runbook-permissions) for details on how to implement such rules in your environment.


# Runbook Customization

Adapt RealmJoin's generic runbooks to your environments' needs.

## Overview

The RealmJoin runbook implementation offers customizing capabilities to a runbook's author or an environments' administrator, so that they can:

* Host customer/tenant specific parameters and templates
* Offer UI elements like user-pickers or dropdown selections
* Present human readable explanations of parameters
* Hide unneeded UI elements

<figure><img src="/files/SLvSAWroXv0HjMLiq05J" alt=""><figcaption></figcaption></figure>

The customizations can be included in the runbook itself and/or stored in the customer's RealmJoin Portal instance. By default, we will try to offer sensible defaults in the runbooks offered on [GitHub](https://github.com/realmjoin/realmjoin-runbooks).

Some runbooks will come with examples of how to configure customer specific templates like specifying office locations for the user on-boarding.

### Format

The customizing can be defined (in descending order of priority)

* Block of JSON in [RealmJoin Portal settings](https://portal.realmjoin.com/settings/runbooks-customizations), overriding default runbook behavior
* Block of JSON in the header of a runbook

Additionally (with least priority)

* per parameter in the runbook header
* per parameter in the runbooks param block (using the RJRb Helper Module)

Some functionality (like templates) is only available in JSON format. Some functionality (like creating a user picker) is only available by specifying a data type in the param block. You can combine multiple types of customizations for best results.

## Runbook Param Block

The RealmJoin Portal parses a runbook's PowerShell param block to determine which input fields to render. Where possible, it will also validate the inputs according to the .NET type given for a variable.

The following data types are currently understood:

* `[bool]`, `[boolean]` - will present a binary toggle
* `[string]` - will present a textbox to type any alphanumeric input
* `[int]` - will present a textbox, only allowing numeric inputs
* `[DateTime]`, `[DateTimeOffset]` - Will present a date/time picker

You can apply standard PowerShell modifiers to parameters. RealmJoin Portal, in particullar, will understand if you specify `[Parameter(Mandatory = $true)]` to indicate a mandatory parameter and enforce these parameters being filled.

Where possible, RealmJoin Portal will also read and present given default values in the UI.

Be aware, default values from the runbook can be overridden by customizations. Additionally, parameters can be completely hidden by customizations.

### Customizing Parameters

To be able to customize parameters, please make sure to include RealmJoin's Runbook Helper PS Module in your runbook:

`#Requires -Modules @{ModuleName = "RealmJoin.RunbookHelper"; ModuleVersion = "0.6.0" }`

You can then include `[ValidateScript( { Use-RJInterface ... } )]` statements in the parameter definitions. For example the following will create a user picker, allowing to choose an Entra ID user and will pass its object id as string to the runbook.

```powershell
param(
    [ValidateScript( { Use-RJInterface -DisplayName "Assign device to this user (optional)" -Type Graph -Entity User } )]
    [string] $AssignedUserId = ""
)
```

Let's take this piece by piece. `[ValidateScript...]` is a modifier to the next parameter defined in the param-block. In this case the variable `$AssignedUserId`.

`Use-RJInterface` is part of our [RealmJoin Runbook Helper](https://github.com/realmjoin/RealmJoin.RunbookHelper) PowerShell Module. It allows you to specify what kind of input you expect using `-Type` and `-Entity`, if that is not already fully defined by the type of variable.

`-DisplayName` allows you to pass a human readable prompt / description for this parameter to RealmJoin Portal.

#### Graph Resources

In the example above, the source of information is MS Graph, as described by `-Type Graph`. For MS Graph, use `-Entity` to specify which kind of resource you're expecting. Available entities are `User`, `Group`, `Device`. This will produce a picker for either users, groups or devices in the given Entra ID.

The picker includes a quick search, to easily pin down the required resource.

![Picker Example](/files/c7VISjHnbx3trnccC2xe)

Currently, no multiselect is possible using a picker.

By default, a MS Graph picker will return the object's ID. If you require e.g. the user principal name instead, make sure to include "name" as suffix in your variable's name. So, basically, to get a user's id, name the parameter `$userid`. If you want a UPN, name it `$username`.

#### Graph Filtering

If you are using a MS Graph based picker, you can also specify `-Filter` and use an [ODATA-Filter](https://docs.microsoft.com/en-us/graph/query-parameters?context=graph%2Fapi%2F1.0\&view=graph-rest-1.0#filter-parameter) to limit the objects offered in the picker.

The following example will list only groups from Entra ID starting with "LIC\_".

```powershell
param(
    [Parameter(Mandatory = $true)]
    [ValidateScript( { Use-RJInterface -Type Graph -Entity Group -Filter "startswith(DisplayName, 'LIC_')" -DisplayName "License group" } )]
    [String] $GroupID_License
)
```

You can prepare filters and reuse them across multiple scripts using the [central datastore](#graph-filters). In this case just reference the filter by name using `-Filter "ref:LicenseGroup"`, where `ref:` indicates to look for a stored filter.

```powershell
param(
    [Parameter(Mandatory = $true)]
    [ValidateScript( { Use-RJInterface -Type Graph -Entity Group -Filter "ref:LicenseGroup" } )]
    [String] $GroupID_License
)
```

This specific example `ref:LicenseGroup` is available by default without further configuration.

![ODATA filter](/files/s7Ffj7GtF2wKYimdYfLk)

## Runbook Header

The Portal can parse a runbook's [comment based help](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_comment_based_help?view=powershell-5.1) section, if present.

Here is an example:

```powershell
<#
  .SYNOPSIS
  (Un-)Assign a license to a user via group membership.

  .DESCRIPTION
  (Un-)Assign a license to a user via group membership. More detailed description...

  .PARAMETER DefaultGroups
  Comma separated list of groups to assign. e.g. "DL Sales,LIC Internal Product"

  .NOTES
  Permissions:
  MS Graph (API):
  - User.Read.All
  - GroupMember.ReadWrite.All 
  - Group.ReadWrite.All

  .INPUTS
  RunbookCustomization: {
        "Parameters": {
            "UserName": {
                "Hide": true
            },
            "Remove": {
                "DisplayName": "Assign or Remove License",
                "SelectSimple": {
                    "Assign License to User": false,
                    "Remove License from User": true
                }
            }
        }
    }
#>
```

`.SYNOPSIS` - Give a very brief description of your runbook's function. This will be displayed in the list of available runbooks.

`.DESCRIPTION` - Give a description of your runbook's function. Can contain slightly more detail, as this will be displayed inside the runbooks execution / parameter dialogue.

`.PARAMETER` - Needs to be followed by a parameter's name. Allows you to give a detailed explanation of the expected input for the parameter in question.

`.INPUTS` - Can contain a block of JSON-based Runbook Customization.

`.NOTES` - Is not parsed / rendered. Please use this space to write down which permissions and requirements exist for your runbook.

`.EXAMPLE` - Is not parsed / rendered. Can contain an example of a JSON-based Customization to use in the RealmJoin Datastore in your tenant. These can be examples of how to create templates e.g. for different workflows or user classes.

## JSON Based Customizing

### Central Datastore

Each Azure tenant can host a "Runbook Customizations" datastore, found at <https://portal.realmjoin.com/settings/runbooks-customizations> .

The format is JSON with comments, allowing trailing commas. Currently, there are three relevant sections, `Settings`, `Templates`, `Runbooks`.

```json
{
    "Settings": {
    },
    "Templates": {
    },
    "Runbooks": {
    }
}
```

### Runbooks section

`Runbooks` is parsed by the portal when starting a runbook. If a section named like the current Azure Automation Runbook exists, its contents will be used to customize the frontend displayed to the user.

Assume the following simple demonstration runbook, called `rjgit-device_demo-runbook-customizing`.

```powershell
<#
  .SYNOPSIS
  Demonstrate Runbook Customizing

  .DESCRIPTION
  Demonstrate Runbook Customizing, like dropdown/select
#>

#Requires -Modules @{ModuleName = "RealmJoin.RunbookHelper"; ModuleVersion = "0.6.0" }

param(
    [string] $DeviceId,
    [bool] $ExtraWorkflow = $true,
    [int] $ExtraWorkflowTime = 15
)

"## Doing stuff to Device '$DeviceID'"

# Highly optional complicated workflow
if ($ExtraWorkflow) {
    "## Executing Meditation..."
    Start-Sleep -Seconds $ExtraWorkflowTime
}
```

If not customized, it will be presented like this in the frontend:

![Demo - before](/files/lar7zF8w8lxdLThDiqa9)

Thoughts:

* As this runbook is started from a device's context in portal, the `$DeviceId` is redundant information for a user. I already know which device I am working on.
* What happens if I enable or disable the "Extra Workflow"? Do I need to think about "Extra Workflow Time" if I disable "Extra Workflow"?

Let us improve on that. The following example JSON in the central datastore will modify the UI for the runbook.

```json
{
    "Runbooks": {
        "rjgit-device_demo-runbook-customizing": {
            "ParameterList": [
                {
                    "Name": "DeviceId",
                    "Hide": true
                }, 
                {
                    "Name": "ExtraWorkflow",
                    "Hide": true
                },
                {
                    "Name": "ExtraWorkflowTime",
                    "DisplayName": "How long to meditate?",
                },
                {
                    "DisplayName": "Execute Extra Workflow",
                    "DisplayBefore": "ExtraWorkflowTime",
                    "Select": {
                        "Options": [
                            {
                                "Display": "Execute Meditation (optional)",
                                "Customization": {
                                    "Default": {
                                        "ExtraWorkflow": true
                                    }
                                }
                            },
                            {
                                "Display": "Skip Device Mindfulness",
                                "Customization": {
                                    "Default": {
                                        "ExtraWorkflow": false
                                    },
                                    "Hide": [
                                        "ExtraWorkflowTime"
                                    ]
                                }
                            }
                        ],
                        
                    },
                    "Default": "Skip Device Mindfulness"
                }
            ]
        }
    }
}
```

You can use the same notation / features in your [runbook header](#runbook-header).

#### ParameterList

Each parameter has its own section in `ParameterList`. [Modifiers](#modifiers) allow to change the behaviour of that parameter.

The result will look like this:

![Demo - after hidden](/files/4ab6QeqqRjt4rZOwTsno)

Choosing the additional workflow will present (unhide) more parameters:

![Demo - after unhidden](/files/3pynzuCT0Yf9svBfG5wm)

This shows less clutter in comparison to before applying the customization. At the same time more information about the alternatives of "Extra Workflow" is available to the user. Also, a user now will only worry about "Extra Workflow Time" if it is relevant.

Changing the visibility of that field was done using a `"Customization"` block inside one of the `"Select"` options. You can currently have at most one such `"Customization"` block active at a time.

As you can see, the parameter `$DeviceId` is completely hidden. This is done by setting the `"Hide": true` for this parameter.

Parameters can have a `DisplayName`. We offered a human friendly `DisplayName` to replace `$ExtraWorkflowTime` in the UI. See other [modifiers](#modifiers) for more.

You can insert "unnamed" parameters (missing the `Name` statement) like the "Execute Extra Workflow" section, if you want to offer UI elements without directly returning a value. This is normally only used in conjunction with `Select`.

#### Select

We used `Select`, to display a list of `Options` in a dropdown. Each option can `Display` text, or trigger a `Customization`, like setting `Hide` or a `Default` value on other parameters. In our example, we used it to (un)hide `$ExtraWorkflowTime` and override `$ExtraWorkflow`'s value.

`$ExtraWorkflowTime` is thus only shown when relevant and the binary switch `$ExtraWorkflow` is now replaced with meaningful alternatives from a user's perspective.

In case of a `Select` for a named parameter, each option should have a `"ParameterValue": "..."` to pass to the runbook. You can place a `"ShowValue: false"` inside the `Select` block to only show the dropdown and not a field for the resulting parameters value.

Named parameter example:

```json
{
    "Name": "ExtraWorkflow",
    "DefaultValue": true,
    "DisplayName": "Execute Extra Workflow",
    "DisplayBefore": "ExtraWorkflowTime",
    "Select": {
        "Options": [
            {
                "Display": "Execute Meditation (optional)",
                "ParameterValue": true
            },
            {
                "Display": "Skip Device Mindfulness",
                "ParameterValue": false,
                "Customization": {
                    "Hide": [
                        "ExtraWorkflowTime"
                    ]
                }
            }
        ],
        "ShowValue": false
    }
}
```

The `Default` / `DefaultValue` statement in the parameter also specifies the initial state of the dropdown. In case of an unnamed parameter, use the `DisplayName` of the desired option, otherwise give a default return value, like "true" or "false" or some string.

#### Parameters

If you only have named parameters, you can use the slightly shorter `Parameters` format instead of `ParameterList`.

For an example see SelectSimple

#### SelectSimple

If the full power of a `Select` is not needed and you just want to offer a list of possible values in a dropdown (without applying additional customizing), you can use `SelectSimple`.

`SelectSimple` is only usable for named parameters.

Example:

```json
{
    "Runbooks": {
        "rjgit-device_demo-runbook-customizing": {
            "Parameters": {
                "DeviceId": {
                    "Hide": true
                }, 
                "ExtraWorkflow": {
                    "Name": "ExtraWorkflow",
                    "DisplayName": "Execute Extra Workflow",
                    "Default": false,
                    "SelectSimple": {
                        "Execute Meditation (optional)": true,
                        "Skip Device Mindfulness": false
                    }
                },
                "ExtraWorkflowTime": {
                    "DisplayName": "How long to meditate?"
                }
            }
        }
    }
}
```

The biggest difference (other than being much shorter) to our example before is that `$ExtraWorkflowTime` is always visible.

#### Modifiers

Each parameter can have one or more of the following modifiers:

* `"DisplayName": "text"` - Display "text" as name for the parameter in the UI
* `"Hide": true / false` - Hide this parameter
* `"Mandatory": true / false` - Require this parameter to be filled
* `"ReadOnly": true / false` - Protect this parameter from beeing changed from its default value
* `"DefaultValue": "..."` - Set a default value for this parameter. (You can also use `Default` instead.)
* `"GraphFilter": "startswith(DisplayName, 'LIC_')"` - see [Graph Filtering](#graph-filtering)
* `"AllowEdit": true / false` - Protect this parameter from manual editing. (combine this with templates)

### Settings

`Settings` allows you to store configuration data like Azure Storage Account names in a central place, while still keeping them separate from your runbooks.

You can access individual values from a runbooks param-Block using `Use-RJInterface`.

Let us take this example param-block of a runbook:

```powershell
param(
    [ValidateScript( { Use-RJInterface -Type Setting -Attribute "CaPoliciesExport.Container" } )]
    [string] $ContainerName,
    [ValidateScript( { Use-RJInterface -Type Setting -Attribute "CaPoliciesExport.ResourceGroup" } )]
    [string] $ResourceGroupName,
    [ValidateScript( { Use-RJInterface -Type Setting -Attribute "CaPoliciesExport.StorageAccount.Name" } )]
    [string] $StorageAccountName,
    [ValidateScript( { Use-RJInterface -Type Setting -Attribute "CaPoliciesExport.StorageAccount.Location" } )]
    [string] $StorageAccountLocation,
    [ValidateScript( { Use-RJInterface -Type Setting -Attribute "CaPoliciesExport.StorageAccount.Sku" } )]
    [string] $StorageAccountSku
)
```

Portal will try to prefill each parameter with values from the central datastore - if present. This also works if the parameter has been hidden in the UI.

A possible JSON in the datastore for this runbook would be:

```json
{
    "Settings": {
        "CaPoliciesExport": {
            "ResourceGroup": "rj-runbooks-01",
            "StorageAccount": {
                "Name": "rjrbexports01",
                "Location": "West Europe",
                "Sku": "Standard_LRS"
            }
        }
    }
}
```

The missing `Container` element will simply not be prefilled in the UI.

### Templates

`Templates` use JSON-references to pull in data - for example a lengthy list of office locations - when using a `Select` statement.

This allows to keep a customization neutral/reusable/separated from actual data.

Let us take the example of onboarding new users. You might have have multiple given options for departments or office locations, where assigning an office location also mandates a certain street address, country, state etc.

The following example of a runbook customization uses the `$ref` inside the `Runbooks` section to reference/import a subtree from the `Templates` section. Look out for the `$id`/`$values` keywords. Be aware that `$id`/`$values` have to defined before referencing them using `$ref`. That is why `Templates` is defined ahead of `Runbooks` in this example.

In this example we tell the portal to grab the subtree with the `$id` called `LocationOptions` and include its `$values`, replacing the `$ref` statement. So, the portal will render a `Select` as described in the `Runbooks` section but include the actual options from `Templates`.

A template can contain any statement that is supported in the referencing location. In this example, we use a `Customization` statement to modify other parameters like `StreetAddress`.

So, we can have a runbook specific customziation in `Runbooks` reusable accross multiple environments, while keeping actual data separate.

```json
{
    "Templates": {
        "Options": [
            {
                "$id": "LocationOptions",
                "$values": [
                    {
                        "Display": "DE-OF",
                        "Customization": {
                            "Default": {
                                "StreetAddress": "Kaiserstraße 39",
                                "PostalCode": "63065",
                                "City": "Offenbach",
                                "Country": "Germany"
                            }
                        }
                    },
                    {
                        "Display": "DE-DEG",
                        "Customization": {
                            "Default": {
                                "StreetAddress": "Lateinschulgassse 24-26",
                                "PostalCode": "94469",
                                "City": "Deggendorf",
                                "Country": "Germany"
                            }
                        }
                    },
                    {
                        "Display": "DE-HH",
                        "Customization": {
                            "Default": {
                                "StreetAddress": "Hans-Henny-Jahnn-Weg 53",
                                "PostalCode": "22085",
                                "City": "Hamburg",
                                "Country": "Germany"
                            }
                        }
                    },
                    {
                        "Display": "FI-HS",
                        "Customization": {
                            "Default": {
                                "StreetAddress": "Somewhere 42",
                                "PostalCode": "12345",
                                "City": "Helsinki",
                                "Country": "Finland"
                            }
                        }
                    }
                ]
            },
            {
                "$id": "CompanyOptions",
                "$values": [
                    {
                        "Id": "gkg",
                        "Display": "glueckkanja",
                        "Value": "glueckkanja AG"
                    },
                    {
                        "Id": "pp",
                        "Display": "PRIMEPULSE",
                        "Value": "PRIMEPULSE SE"
                    }
                ]
            }
        ]
    },
    "Runbooks": {
        "rjgit-org_general_add-user": {
            "ParameterList": [
                {
                    "DisplayName": "Office Location",
                    "DisplayAfter": "CompanyName",
                    "Select": {
                        "Options": {
                            "$ref": "LocationOptions"
                        }
                    }
                },
                {
                    "Name": "CompanyName",
                    "Select": {
                        "Options": {
                            "$ref": "CompanyOptions"
                        },
                        "AllowEdit": false
                    }
                }
            ],
            "ReadOnly": [
                "StreetAddress",
                "PostalCode",
                "City",
                "Country"
            ]
        }
    }
}
```

This will create the following UI:

![Demo - ref-location](/files/Qqlsc8SraAZQxyE7vM6i)

![Demo - ref-address](/files/IjcHOSlxR0AjYClSkNHF)

### Graph Filters

You can prepare [ODATA Graph-Filters](https://docs.microsoft.com/en-us/graph/query-parameters?context=graph%2Fapi%2F1.0\&view=graph-rest-1.0#filter-parameter) to be used in multiple runbooks. Store these in a section called `GraphFilters`.

The following example filters for a certain prefix in the `DisplayName` of a group, to only show licensing related groups in a group picker.

```json
"GraphFilters": {
    "LicenseGroup": "startswith(DisplayName, 'LIC_')" // also contained in RJ code as default
  }
```

See [Graph filtering](#graph-filtering) on how to use this from a runbook.


# Runbook Logs

Review recent and archived RealmJoin runbook executions, scoped by type and category, with search and sort.

## Overview

Runbook logs allows you to review recent and archived runbook executions (jobs).

<figure><img src="/files/2uwgcYBwzRy88f8NYDFV" alt=""><figcaption><p>Runbook Job List</p></figcaption></figure>

### Type and Category

Runbooks in RealmJoin Portal are scoped to either the organization (tenant), a device, a user or a group to align with [User, Group and Device management](/ugd-management/user-group-device-management).

Also, categories can be used to organize runbooks into specific topics. The default categories are "general", "mail" and "security".

Both type and category influence when/where a runbook will be offered in RealmJoin Portal and are reflected in Runbook logs to allow searching and sorting accordingly. See [Naming Conventions](/automation/runbooks/naming-conventions) to understand how type and category are assigned to a runbook.

### Search and Sort

You can search for jobs by job ID, name, type or category. The search will update as you type.

You can sort by most fields by clicking on the field's header (name).

### Job Details

Click on a job's ID to open the job's details page, which will show more metadata, the runbook's outputs and parameters. See [Runbook Job Details](/automation/runbooks/runbook-logs/runbook-job-details) for more information.

<figure><img src="/files/8z5CxMd8vABZbfPun0Ni" alt=""><figcaption><p>Runbook Job Details</p></figcaption></figure>

## Scheduled Jobs and Schedules

#### Scheduled Jobs

Click **Scheduled Jobs** to see all scheduled jobs in your Azure Automation Account, regardless of type/context.

<figure><img src="/files/5KwMa9aSOJaI3r0tWFJh" alt=""><figcaption><p>Scheduled Jobs</p></figcaption></figure>

You can **Delete** the scheduled job using the button to the right of the job. This will not delete the runbook, only the scheduled job.

See [Scheduling](/automation/runbooks/scheduling#assigning-schedules) if you wish to create new scheduled jobs.

#### Schedules

Click **Schedules** to view and manage available schedules for your runbooks.

See [Scheduling ](/automation/runbooks/scheduling#managing-schedules)to learn more.

## Archived Logs

Azure Automation will only keep runbook job logs for a limited time. RealmJoin offers to copy/archive runbook logs into a Log Analytics Workspace to preserve them for a longer time. This will only be available after you've correctly configured/onboarded [Log Analytics](/monitoring-and-logs/log-analytics).

Please be aware that you have to modify the Workspace's retention time to accommodate your needs as this will limit how long archived logs can be stored.

Click **Archived** to switch from the recent logs in Azure Automation to those stored in Log Analytics.

<figure><img src="/files/uashTEx50P217OuRQTxk" alt=""><figcaption><p>Archived Runbook Job Logs List</p></figcaption></figure>

You can search and inspect these the same as the regular logs under **Recent**.


# Runbook Job Details

View RealmJoin runbook job metadata, real-time console output, and details from Azure Automation jobs.

## Overview

RealmJoin Portal allows you to view runbooks jobs from Azure Automation.

<figure><img src="/files/2VxsEqiKYcohP4IIYsNJ" alt=""><figcaption><p>Runbook Job Details</p></figcaption></figure>

On the left side of the page you will find metadata about the runbook job, its type/context, job ID and its caller.

Be aware, "caller" is only present when runbooks are RealmJoin-aware and report this information, as Azure Automation has no concept for this.

On the right, you will find multiple tabs, representing:

### Console

This will show a live feed of the runbooks output. In contrast to Azure Automation, output of a runbook is readable in real time.

Using "Copy to Clipboard" you can copy the full output to use it e.g. in a service/ITIL ticket system.

### Input

Review the parameters used to start the runbook job.

<figure><img src="/files/E167nFxzCswPelqCNg92" alt=""><figcaption><p>Runbook Job Parameters</p></figcaption></figure>

### Errors and Warnings

If present, warnings and errors which are not part of regular output will be shown in these two tabs.

<figure><img src="/files/FJN2N4Y1kJF1C41u8cWX" alt=""><figcaption><p>Runbook Job Warnings</p></figcaption></figure>

### Exceptions

If the PowerShell script of the runbook threw an exception (and the runbook thus failed), you can review the Exception here.

Exceptions will also be shown above the regular output in **Console** if present to simplify identifying problems.

<figure><img src="/files/GQucuNWswdvEyF7VCXN2" alt=""><figcaption><p>Exception shown in Console</p></figcaption></figure>

### Source

This allows you to review the runbooks source code associated with this job.

<figure><img src="/files/hrYSCpeRQ86nJbyCXEOn" alt=""><figcaption><p>Runbook Source</p></figcaption></figure>


# Runbook Naming Conventions

RealmJoin runbook naming conventions: how context and category map shared repository runbook names into Azure Automation and the portal.

## Filenames in Github

We expect a certain file and naming structure in the [shared runbook repository](https://github.com/realmjoin/realmjoin-runbooks). RealmJoin will import these folders and files from GitHub into the customers Azure Automation Account.

Dashes ("-") will be converted into spaces. Folders are used to separate runbooks into "context" and "category", e.g. `user\general`. File names should be describing the purpose of the script.

All imported runbooks have a prefix of `rjgit-`, followed by the context, either `org`, `group`, `user` then category, for example `_general_`, `_security_`, `_mail_` and the name of the script itself like `add-additional-alias`.

### Example:

A runbook in Github in `user\general` named `add-additional-alias.ps1` will be shown as:

* `rjgit-user_general_add-additional-alias` in the Azure Automation Account
* "Add Additional Alias" in the RealmJoin Portal on a User object in the runbook category "General".

Common categories

* General
* Security
* Mail
* Userinfo

You can define additional categories, but not contexts.

### What is the purpose of this?

This allows to automagically fill and name the runbooks in the RealmJoin Portal. Also, the `rjgit-` prefix allows to avoid naming conflicts with local/customer runbooks. Runbooks not having this prefix will not be touched by RealmJoin's import logic.

## Private / Customer-specific Runbooks

You can host private (local) runbooks in your Azure Automation Account. These runbooks will appear in RealmJoin Portal just like the shared runbooks. Local runbooks will not be touched by our sync process and will not be visible to other customers.

To create a local runbook, remove the `rjgit-` prefix from the naming convention while keeping the rest of the naming structure intact.

Example: You want to offer a runbook "Private Runbook" in the context of Azure AD groups and the category "General". You would name it `group_general_private-runbook` in your Azure Automation Account.

This will look like this in Azure Automation:

![Runbook names in GitHub / Azure Automation](/files/uKO167D3Axnoda3cIjRS)

It will be presented in RealmJoin Portal as:

![Runbook names in RealmJoin Portal](/files/Y52kZfDQ1C2MiwlWlGaY)


# Runbook Parameters

RealmJoin runbook parameters such as TenantID and SubscriptionID that connect to Azure Automation and enable process automation.

## Overview

This page allows you to specify the components needed to interact with Azure Automation and enable the use of [Runbooks (Process Automation)](/automation/runbooks).

## Parameters

![Runbook Integration Parameters](/files/nip2u3UcAtRlaX6PuVOG)

### TenantID

Please provide the unique [id of your Entra ID tenant](https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/find-tenant-id-domain).

### SubscriptionID

Please provide the unique id of the Azure subscription hosting your Azure Automation Account.

### ResourceGroup

Please provide the name of the Azure ResourceGroup hosting your Azure Automation Account.

### ClientID and ClientSecret

RealmJoin will create an application in your Azure environment called "RealmJoin Runbook Management". This application will be used to interact with the Azure Automation Account. It will import runbooks from RealmJoin's central repository into your Automation Account and it will be used to start runbooks and to read runbook job logs.

Please provide the app's ClientID ("AppId") and ClientSecret, so that RealmJoin can authenticate against Azure Automation.

Make sure, that you securely store the ClientSecret. It will not be readable after saving this dialogue. If you click "Reset Setup", the field will be reset/emptied.

### Branch

RealmJoin maintains a public repository of shared runbooks at <https://github.com/realmjoin/realmjoin-runbooks>

These runbooks are imported when you sync runbooks on the [General Settings](/administration-and-settings/general) page.

Currently there are different git branches in this repository.

* **production** - The main branch for production use. These runbooks are thoroughly tested, and we recommend using this branch.
* **master** - Early / Insider versions runbooks. These should be usable at any given time but are less well tested.
* **feature-{...}** - Specific features can be tested ahead of time by using specific features branches as part of a private preview or beta testing. Not recommended for general use.

Specify the name of the branch you want to use. "production" is recommended.

### Location

Specify the Azure Location to use when importing runbooks. This is a drop-down field and needs no typed input.


# Runbook Permissions

How to grant/deny access to certain runbooks.

{% embed url="<https://www.youtube.com/watch?v=bLi_k_Yzhyw>" %}

## Scope

This addresses how to grant/deny access to certain runbooks in an Azure tenant. If you are looking for answers regarding which MS Graph API permissions are needed to run a certain action as a runbook, please have a look at our [requirements](/automation/connecting-azure-automation/azure-ad-roles-and-permissions).

## Overview

"Runbook Permissions" define the visibility of runbooks for certain users. Certain runbooks can also be blocked/hidden globally.

Like the [Runbook Customizations](/automation/runbooks/runbook-customization), defining these permissions is done by giving a JSON-formatted configuration as an RealmJoin admin in RealmJoin's web portal at <https://portal.realmjoin.com/settings/runbooks-permissions> .

### About this guide

We will give a short description of the syntax and then build a full example piece by piece. Feel free to directly go to the full sample and start from [there](#targetentitygroups).

## Configuration Syntax

### Runbook names

Runbooks are referenced by their names as seen in the Azure Automation Account, e.g. `rjgit-group_general_remove-group`.

Wildcards ('\*') can be used to match multiple runbooks. Multiple wildcards can be used in the same string, e.g. `rjgit-*_security_*`. This would all of the following examples:

* `rjgit-org_security_list-inactive-users`
* `rjgit-device_security_enable-or-disable-device`

The prefix `rjgit-` denotes runbooks that are imported from our piblic GitHub repository. Customer-specific runbooks have no prefix, e.g. `user_userinfo_custom-runbook`

### Entra ID Groups

Entra ID groups will be referenced using their Object ID, like `91688d11-9a34-42cd-8d1e-ce617d6c1234`. Currently, only security groups can be used.

## JSON Structure and Example

We will build a full configuration example piece by piece.

A JSON configuration consists of multiple sections, but all sections are optional and can be omitted.

It is allowed to add comments using the "//" prefix.

### EnabledRunbookPatterns

This section contains a list of runbooks allowed to be used. If this section is omitted, all runbooks are enabled/allowed by default.

If you define this section, then only runbooks mentioned in this section will be usable by any role / support and admin.

#### Example

* Allow only certain, individual runbooks by giving their full name

  `rjgit-group_general_remove-group`
* Allow all device related runbooks from our shared repository

  `rjgit-device_*`
* Allow all shared user runbooks

  `rjgit-user_*`
* Allow all customer specific (local), user related runbooks

  `user_*`

This implicitely leaves out many group- and all org- based runbooks. Be aware.

```
{
  "EnabledRunbookPatterns": [
    "rjgit-group_general_remove-group",
    "rjgit-device_*",
    "rjgit-user_*",
    "user_*"
  ]
}
```

### DisabledRunbookPatterns

A list of runbook that are globally disabled / forbidden. If this section is omitted or empty, all enabled runbooks (given via [EnabledRunbookPatterns](#enabledrunbookpatterns)) are usable.

Entries in this section take priority over entries in [EnabledRunbookPatterns ](#enabledrunbookpatterns)- the runbooks will be hidden/not be usable for anyone in this tenant.

#### Example

We will reuse the `EnabledRunbookPatterns` section from before.

* Disable all shared (`rjgit-`) runbooks in the `security` category.

```
{
  "EnabledRunbookPatterns": [
    "rjgit-group_general_remove-group",
    "rjgit-device_*",
    "rjgit-user_*",
    "user_*"
  ],
  "DisabledRunbookPatterns": [
    "rjgit-*_security_*"
  ]
}
```

### Roles

In this section you can assign a list of runbooks to an Entra ID group. This allows to define multiple support/operator roles in your tenant.

If this section is omitted, all RealmJoin support and administrators have access to all runbooks given in the previous sections.

{% hint style="warning" %}
If enabled, all users not belonging to a role will not see any runbooks.
{% endhint %}

#### Example

Continuing with what we have, let us create a device-support role `DeviceAdmin` and a user support role `UserAdmin`.

We will apply those roles to multiple Entra ID groups and for each role give a list of allowed runbooks. Be aware - this will restrict the user support role to only a small set of runbooks.

Let us add comments ("//") next to the group's object id that help the reader by giving the Entra ID group names.

```json
{
  "EnabledRunbookPatterns": [
    "rjgit-group_general_remove-group",
    "rjgit-device_*",
    "rjgit-user_*",
    "user_*"
  ],
  "DisabledRunbookPatterns": [
    "rjgit-*_security_*"
  ],
  "Roles": {
    "DeviceAdmin": {
      "Groups": [
        "9cbfc0af-c217-41e9-b790-3043788f1234", // 1st Device Support AAD Group
        "5555c0af-c217-41e9-b790-3043788f1234"  // 2nd Device Support AAD Group - other team
      ],
      "AllowedRunbookPatterns": [
        "rjgit-device_*"
      ]
    },
    "UserAdmin": {
      "Groups": [
        "1234c0af-c217-41e9-b790-3043788f1234" // User Support AAD Group
      ],
      "AllowedRunbookPatterns": [
        "rjgit-user_general_assign-or-unassign-license",
        "rjgit-user_mail_*",
        "user_*"
      ]
    }
  }
}
```

Now the `UserAdmin` role can:

* assign licenses to all users in your tenant
* modify email-addresses of all users in your tenant

The `DeviceAdmin` role can

* wipe any device in your tenant

### TargetEntityGroups

Perhaps you have some crucial VIP users. It should not be possible for just any support staff to erase a VIP's device or modify a VIP's email address. We can use "targeting" to restrict roles on critical users to dedicated teams.

"Devices" will be targeted by their primary/assigned user but not the device object in Entra ID. This allows to stick to a purely user-based group model.

We assume, Entra ID groups exist that contain critical VIP users. Using this section, we can carefully scope some more critical roles and runbooks for these specific Entra ID groups (targets).

Obviously, if you omit this section, all users/groups/devices in your tenant are treated as equals.

If you define TargetEntityGroups it should not have any impact on any other group not mentioned in the section.

#### Full Example

Assume group `0000c0af-c217-41e9-b790-3043788f0000` is our group of VIP users.

We introduce a new Entra ID group `4444c0af-c217-41e9-b790-3043788f4444` containing supporting staff that have been approved to administrate VIP users. These supporting staff should also have all other basic support permissions, so we will add them to the existing roles.

"Restricting" a role will not grant new roles to a supporter.

```json
{
  "EnabledRunbookPatterns": [
    "rjgit-group_general_remove-group",
    "rjgit-device_*",
    "rjgit-user_*",
    "user_*"
  ],
  "DisabledRunbookPatterns": [
    "rjgit-*_security_*"
  ],
  "Roles": {
    "DeviceAdmin": {
      "Groups": [
        "9cbfc0af-c217-41e9-b790-3043788f1234", // 1st Device Support AAD Group
        "5555c0af-c217-41e9-b790-3043788f1234", // 2nd Device Support AAD Group - other team
        "4444c0af-c217-41e9-b790-3043788f4444"  // VIP Support Crew
      ],
      "AllowedRunbookPatterns": [
        "rjgit-device_*"
      ]
    },
    "UserAdmin": {
      "Groups": [
        "1234c0af-c217-41e9-b790-3043788f1234", // User Support AAD Group
        "4444c0af-c217-41e9-b790-3043788f4444"  // VIP Support Crew
      ],
      "AllowedRunbookPatterns": [
        "rjgit-user_general_assign-or-unassign-license",
        "rjgit-user_mail_*",
        "user_*"
      ]
    }
  },
  "TargetEntityGroups": {
    "0000c0af-c217-41e9-b790-3043788f0000": {  // VIP Users - Treat with care!
      "RestrictRoles": {
        "UserAdmin": [
          "4444c0af-c217-41e9-b790-3043788f4444" // VIP Support
        ],
        "DeviceAdmin": [
          "4444c0af-c217-41e9-b790-3043788f4444" // VIP Support
        ]
      }
    }
  }
}
```

#### **Example: Restricting US Support Staff to Manage Only US Users**

In this scenario, we have US-based Support Staff who should only manage Users located in the US. To enforce this restriction:

* Create a permission rule that explicitly **denies** US Supporters the ability to execute Runbooks on **all Users**.
* Add an exception rule that specifically **allows** execution of Runbooks only for **US Users**.

This ensures US Supporters have permissions limited strictly to their intended target audience (US Users) and prevents accidental interactions with users outside this scope.

**Implementation**

1. A Runbook Runners Entra group must be assigned in Realm Join Portal
   1. Settings > Permissions > Runbook Runner Permissions
   2. US Supporters Entra group must be member of the Runbook Runners Group to allow general Runbook operation in the RealmJoin Portal.
2. Adding a new Role under Settings > Runbook Permissions
   1. In the Roles section add USSupporters Role with their Entra group (group object ID)
   2. Add AllowedRunbookPatterns for the USSupporters
3. Modify the TargetEntityGroups
   1. All-Users group must Restrict the Role USSupporters with an empty value (no Entra group object ID is added here). This is an implicit denial!
   2. US Users group must Restrict the Role USSupporters to the US Supporters Entra group object ID

<figure><img src="/files/NTJGkppcsljkIZEJ484f" alt=""><figcaption><p>Restricting US Support Staff to manage only US Users</p></figcaption></figure>

Below the complete example for this scenario:

```json
{
  // Portal Permission:
  // Runbook Runner Role: US Supporters

  // Group Memberships:
  // 3e1e7540-7f0c-483c-b9bf-500342e2467c: All-Users
  // c603278c-cc36-4661-bb7a-eecb7ab079f9: US Supporters
  // 0f76d01e-cc6b-4553-bf1d-e4ccedd9c824: US Users

  "EnabledRunbookPatterns": [ // General enablement of mail and security Runbooks
    "rjgit-*_mail_*",
    "rjgit-*security*"
  ],
  "DisabledRunbookPatterns": [
    "*password*"
  ],

  "Roles": {
    "USSupporters": {
      "Groups": [
        "c603278c-cc36-4661-bb7a-eecb7ab079f9" // US Supporters
      ],
      "AllowedRunbookPatterns": [ // allowed Runbooks for this Role - US Supporters
        "rjgit-user_*",
        "rjgit-device_*",
        "rjgit-group_*"
      ]
    }
  },
  
  "TargetEntityGroups": {
    "3e1e7540-7f0c-483c-b9bf-500342e2467c": { // All-Users
      "RestrictRoles": {
        "USSupporters": [
          // generally, do not allow Runbooks for any US Supporters
        ]
      }
    },
    "0f76d01e-cc6b-4553-bf1d-e4ccedd9c824": { // US Users
      "RestrictRoles": {
        "USSupporters": [
          "c603278c-cc36-4661-bb7a-eecb7ab079f9" // US Supporters
        ]
      }
    }
  }
}
```

### SchedulingEnabledRunbookPatterns

This section contains a list of runbooks that will be flagged as "schedulable". RealmJoin Port will allow to assign / manage schedules for these runbooks. See [Runbook Scheduling](/automation/runbooks/scheduling).

The following example describes the default behaviour if SchedulingEnabledRunbookPatterns are not defined:

```json
{
  "SchedulingEnabledRunbookPatterns": [
    "*_scheduled"
  ]
}
```

### SchedulingDisabledRunbookPatterns

This section contains a list of runbooks that will be blacklisted from being flagged as "schedulable". RealmJoin Port will not allow to assign / manage schedules for these runbooks. See [Runbook Scheduling](/automation/runbooks/scheduling).

A runbook present in both SchedulingEnabledRunbookPatterns and SchedulingDisabledRunbookPatterns will **not** be schedulable.

By default no runbooks are blacklisted. The following example just demonstrates the syntax:

```json
{
  "SchedulingDisabledRunbookPatterns": [
    "rjgit-user_*"
  ]
}
```


# Hybrid Runbook Worker

Run RealmJoin runbooks on a Hybrid Runbook Worker so they can reach on-premises and private-network resources that the Azure cloud cannot.

{% hint style="warning" %}
This feature is currently only available on [portal-staging.realmjoin.com](https://portal-staging.realmjoin.com).
{% endhint %}

By default, RealmJoin runbooks run in Microsoft's **Azure Automation cloud**. That is perfect for tasks against cloud services (Entra ID, Intune, Exchange Online, …), but the cloud has no line of sight into your **on-premises** or otherwise private network.

A **Hybrid Runbook Worker** solves this. It is a machine you run inside your own environment (for example on-premises, or in a private cloud network) and register with your Azure Automation Account. Runbooks that target that worker execute **on that machine, inside your network**, while still being started, tracked, and audited through RealmJoin just like any other runbook.

## Why you might use it

Use a Hybrid Runbook Worker whenever a runbook needs to reach something the Azure cloud can't:

* On-premises **Active Directory**, file servers, or print servers
* Line-of-business applications and databases hosted in your own datacenter
* Network devices, appliances, or internal APIs that are not exposed to the internet
* Any resource that must be accessed from inside your corporate network for security or connectivity reasons

You keep the convenience of RealmJoin's runbook experience (self-service, permissions, approvals, logging) while the actual work happens where your resources live.

## How it works

* **Where it runs.** A normal runbook runs in the Azure cloud sandbox. A hybrid runbook is handed to your Hybrid Runbook Worker instead, so it runs on your own machine and can talk to your internal resources.
* **Which runbooks are hybrid.** RealmJoin recognises a runbook as "hybrid" by its name: runbooks whose name ends with **`_hybrid`** are routed to your Hybrid Worker Group. All other runbooks continue to run in the cloud as before.
* **Where it runs, more precisely.** When a hybrid runbook starts, RealmJoin sends it to the **Hybrid Worker Group** you configured. A worker group can contain one or more machines; Azure Automation picks an available worker in that group to do the work.

{% hint style="info" %}
Enabling this feature does **not** move your existing runbooks off the cloud. Only runbooks named with the `_hybrid` suffix are directed to the Hybrid Runbook Worker.
{% endhint %}

## Prerequisites

Before you can enable the feature in RealmJoin, you need a working Hybrid Runbook Worker in your Azure Automation Account:

1. Deploy and register one or more machines as a **Hybrid Runbook Worker Group** in your Azure Automation Account. See Microsoft's guide on [Hybrid Runbook Workers](https://learn.microsoft.com/en-us/azure/automation/automation-hybrid-runbook-worker) for the setup steps.
2. Make sure those machines have network access to the on-premises or private resources your runbooks need.

{% hint style="warning" %}
If no Hybrid Runbook Worker Group exists in your Automation Account, RealmJoin cannot offer one to select and will ask you to register a worker first.
{% endhint %}

## Enabling it in RealmJoin

{% stepper %}
{% step %}

### Open your runbook settings

In the RealmJoin Portal, go to your runbook settings. The Hybrid Runbook Worker option becomes available once your initial runbook configuration has been saved.
{% endstep %}

{% step %}

### Turn on Hybrid Runbook Worker sync

Enable **Enable Hybrid Runbook Worker sync**. RealmJoin will read the Hybrid Worker Groups registered in your Azure Automation Account.
{% endstep %}

{% step %}

### Choose a Hybrid Worker Group

Select the **Hybrid Worker Group** that your hybrid runbooks should run on, then save. This becomes the default target for all `_hybrid` runbooks in your tenant.
{% endstep %}
{% endstepper %}

## Running a hybrid runbook

Running a hybrid runbook works exactly like any other runbook — your support and administration staff don't need to do anything special.

* When a runbook is directed to a Hybrid Runbook Worker, the run dialog shows a note such as *"Will run on hybrid runbook worker group: …"* so it is clear where the task will execute.
* If a runbook is configured with more than one worker group to choose from, the operator can **select which Hybrid Runbook Worker Group** to use when starting it.
* Runbooks that require [approval](/automation/runbooks/runbook-permissions) keep the selected worker group, so the task runs on the intended worker once approved.

{% hint style="info" %}
Runbook logs and job details are available in the RealmJoin Portal as usual — see [Runbook Logs](/automation/runbooks/runbook-logs) — regardless of whether a runbook ran in the cloud or on a Hybrid Runbook Worker.
{% endhint %}


# Runbook References

### Runbook References

This section contains detailed documentation for all available RealmJoin Runbooks. The runbooks are automatically generated from the [realmjoin-runbooks](https://github.com/realmjoin/realmjoin-runbooks) repository and updated daily.

All runbooks are organized into different folders based on their area of application.

The following categories are currently available:

* Device
* Group
* Organization
* User

Each category contains multiple runbooks that are further divided into subcategories based on their functionality. The runbooks are listed in alphabetical order within each subcategory.

### RealmJoin Runbook overview

A complete list of all runbooks - including synopsis and links to the detailed reference pages - is available on the [Runbook Overview](/automation/runbooks/runbook-references/overview) page.

The document for each runbook contains information about permissions, where to find, notes, and parameters and further information in general.


# Overview

This document provides a comprehensive overview of all runbooks currently available in the RealmJoin portal. Each runbook is listed along with a brief description or synopsis to give a clear understanding of its purpose and functionality. The runbook name links to the detailed reference page of the respective runbook.

To ensure easy navigation, the runbooks are categorized into different sections based on their area of application. The following categories are currently available:

* Device
* Group
* Organization
* User

Each category contains multiple runbooks that are further divided into subcategories based on their functionality. The runbooks are listed in alphabetical order within each subcategory.

### Device

#### AVD

| Runbook Name                                                                              | Synopsis                                                         |
| ----------------------------------------------------------------------------------------- | ---------------------------------------------------------------- |
| [Restart Host](/automation/runbooks/runbook-references/device/avd/restart-host)           | Reboots a specific AVD Session Host.                             |
| [Toggle Drain Mode](/automation/runbooks/runbook-references/device/avd/toggle-drain-mode) | Sets Drainmode on true or false for a specific AVD Session Host. |

#### General

| Runbook Name                                                                                                  | Synopsis                                                          |
| ------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------- |
| [Assign Groups By Template](/automation/runbooks/runbook-references/device/general/assign-groups-by-template) | Assign cloud-only groups to a device based on a template          |
| [Change Grouptag](/automation/runbooks/runbook-references/device/general/change-grouptag)                     | Assign a new AutoPilot GroupTag to this device.                   |
| [Check Device Compliance](/automation/runbooks/runbook-references/device/general/check-device-compliance)     | Check the compliance status of a device                           |
| [Check Updatable Assets](/automation/runbooks/runbook-references/device/general/check-updatable-assets)       | Check if a device is onboarded to Windows Update for Business     |
| [Enroll Updatable Assets](/automation/runbooks/runbook-references/device/general/enroll-updatable-assets)     | Enroll device into Windows Update for Business                    |
| [Outphase Device](/automation/runbooks/runbook-references/device/general/outphase-device)                     | Remove/Outphase a windows device                                  |
| [Remove Primary User](/automation/runbooks/runbook-references/device/general/remove-primary-user)             | Removes the primary user from a device.                           |
| [Rename Device](/automation/runbooks/runbook-references/device/general/rename-device)                         | Rename a device.                                                  |
| [Set Primary User](/automation/runbooks/runbook-references/device/general/set-primary-user)                   | Set a new primary user on a managed Intune device                 |
| [Unenroll Updatable Assets](/automation/runbooks/runbook-references/device/general/unenroll-updatable-assets) | Unenroll device from Windows Update for Business.                 |
| [Wipe Device](/automation/runbooks/runbook-references/device/general/wipe-device)                             | Wipe a Windows or MacOS device                                    |
| [Wipe Managed App Data](/automation/runbooks/runbook-references/device/general/wipe-managed-app-data)         | App selective wipe - remove company app data from this MAM device |

#### Security

| Runbook Name                                                                                                                     | Synopsis                                                                                  |
| -------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- |
| [Check Defender Status](/automation/runbooks/runbook-references/device/security/check-defender-status)                           | Check a device's presence and risk status in Entra ID and Microsoft Defender for Endpoint |
| [Enable Or Disable Device](/automation/runbooks/runbook-references/device/security/enable-or-disable-device)                     | Enable or disable a device in Entra ID                                                    |
| [Isolate Or Release Device](/automation/runbooks/runbook-references/device/security/isolate-or-release-device)                   | Isolate this device.                                                                      |
| [Reset Mobile Device Pin](/automation/runbooks/runbook-references/device/security/reset-mobile-device-pin)                       | Reset a mobile device's password/PIN code.                                                |
| [Restrict Or Release Code Execution](/automation/runbooks/runbook-references/device/security/restrict-or-release-code-execution) | Only allow Microsoft-signed code to run on a device, or remove an existing restriction.   |
| [Show Bitlocker Recovery Key](/automation/runbooks/runbook-references/device/security/show-bitlocker-recovery-key)               | Show all BitLocker recovery keys for a device                                             |
| [Show Filevault Recovery Key](/automation/runbooks/runbook-references/device/security/show-filevault-recovery-key)               | Display macOS FileVault recovery key                                                      |
| [Show Laps Password](/automation/runbooks/runbook-references/device/security/show-laps-password)                                 | Show a local admin password for a device.                                                 |

### Group

#### Devices

| Runbook Name                                                                                                                       | Synopsis                                                                  |
| ---------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------- |
| [Check Updatable Assets](/automation/runbooks/runbook-references/group/devices/check-updatable-assets)                             | Check if devices in a group are onboarded to Windows Update for Business. |
| [Unenroll Updatable Assets (Scheduled)](/automation/runbooks/runbook-references/group/devices/unenroll-updatable-assets_scheduled) | Unenroll devices from Windows Update for Business.                        |

#### General

| Runbook Name                                                                                                   | Synopsis                                                                                                          |
| -------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| [Add Or Remove Nested Group](/automation/runbooks/runbook-references/group/general/add-or-remove-nested-group) | Add/remove a nested group to/from a group                                                                         |
| [Add Or Remove Owner](/automation/runbooks/runbook-references/group/general/add-or-remove-owner)               | Add or remove a Office 365 group owner                                                                            |
| [Add Or Remove User](/automation/runbooks/runbook-references/group/general/add-or-remove-user)                 | Add or remove a group member                                                                                      |
| [Change Visibility](/automation/runbooks/runbook-references/group/general/change-visibility)                   | Change a group's visibility                                                                                       |
| [List All Members](/automation/runbooks/runbook-references/group/general/list-all-members)                     | List all members of a group, including members that are part of nested groups                                     |
| [List Owners](/automation/runbooks/runbook-references/group/general/list-owners)                               | List all owners of an Office 365 group.                                                                           |
| [List User Devices](/automation/runbooks/runbook-references/group/general/list-user-devices)                   | List devices owned by group members.                                                                              |
| [Remove Group](/automation/runbooks/runbook-references/group/general/remove-group)                             | Remove a group. For Microsoft 365 groups, also the associated resources (Teams, SharePoint site) will be removed. |
| [Rename Group](/automation/runbooks/runbook-references/group/general/rename-group)                             | Rename a group.                                                                                                   |

#### Mail

| Runbook Name                                                                                                          | Synopsis                                                                   |
| --------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------- |
| [Enable Or Disable External Mail](/automation/runbooks/runbook-references/group/mail/enable-or-disable-external-mail) | Enable or disable external parties to send emails to a Microsoft 365 group |
| [Show Or Hide In Address Book](/automation/runbooks/runbook-references/group/mail/show-or-hide-in-address-book)       | Show or hide a group in the address book                                   |

#### Teams

| Runbook Name                                                                     | Synopsis       |
| -------------------------------------------------------------------------------- | -------------- |
| [Archive Team](/automation/runbooks/runbook-references/group/teams/archive-team) | Archive a team |

### Organization

#### Applications

| Runbook Name                                                                                                                                                      | Synopsis                                                                         |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
| [Add Application Registration](/automation/runbooks/runbook-references/org/applications/add-application-registration)                                             | Add an application registration to Azure AD                                      |
| [Add GSA Application Registration](/automation/runbooks/runbook-references/org/applications/add-gsa-application-registration)                                     | Add a GSA application registration to Azure AD                                   |
| [Delete Application Registration](/automation/runbooks/runbook-references/org/applications/delete-application-registration)                                       | Delete an application registration from Azure AD                                 |
| [Delete GSA Application Registration](/automation/runbooks/runbook-references/org/applications/delete-gsa-application-registration)                               | Delete a GSA application registration from Azure AD including associated objects |
| [Export Enterprise Application Users](/automation/runbooks/runbook-references/org/applications/export-enterprise-application-users)                               | Export a report of all (enterprise) application owners and users                 |
| [List Inactive Enterprise Applications](/automation/runbooks/runbook-references/org/applications/list-inactive-enterprise-applications)                           | List enterprise applications with no recent sign-ins                             |
| [Report Application Registration](/automation/runbooks/runbook-references/org/applications/report-application-registration)                                       | Generate and email a comprehensive Application Registration report               |
| [Report Expiring Application Credentials (Scheduled)](/automation/runbooks/runbook-references/org/applications/report-expiring-application-credentials_scheduled) | List expiry date of all Application Registration credentials                     |
| [Update Application Registration](/automation/runbooks/runbook-references/org/applications/update-application-registration)                                       | Update an application registration in Azure AD                                   |

#### Devices

| Runbook Name                                                                                                                                                   | Synopsis                                                                                 |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- |
| [Add Autopilot Device](/automation/runbooks/runbook-references/org/devices/add-autopilot-device)                                                               | Import a Windows device into Windows Autopilot                                           |
| [Add Device Via Corporate Identifier](/automation/runbooks/runbook-references/org/devices/add-device-via-corporate-identifier)                                 | Import a device into Intune via corporate identifier                                     |
| [Auto Approve Driver Updates (Scheduled)](/automation/runbooks/runbook-references/org/devices/auto-approve-driver-updates_scheduled)                           | Auto-approve new driver updates in Intune driver update policies                         |
| [Cleanup Autopilot Devices (Scheduled)](/automation/runbooks/runbook-references/org/devices/cleanup-autopilot-devices_scheduled)                               | Clean up orphaned and stale Windows Autopilot device registrations                       |
| [Create Endpoint Analytics Baseline](/automation/runbooks/runbook-references/org/devices/create-endpoint-analytics-baseline)                                   | Creates Endpoint Analytics baselines in Microsoft Intune with a specified naming schema. |
| [Dedup Device Names (Scheduled)](/automation/runbooks/runbook-references/org/devices/dedup-device-names_scheduled)                                             | Detect and rename duplicate Intune device display names using a prefix and random suffix |
| [Delete Stale Devices (Scheduled)](/automation/runbooks/runbook-references/org/devices/delete-stale-devices_scheduled)                                         | Scheduled deletion of stale devices based on last activity date and platform             |
| [Get Bitlocker Recovery Key](/automation/runbooks/runbook-references/org/devices/get-bitlocker-recovery-key)                                                   | Get the BitLocker recovery key                                                           |
| [Notify Users About Stale Devices (Scheduled)](/automation/runbooks/runbook-references/org/devices/notify-users-about-stale-devices_scheduled)                 | Notify primary users about their stale devices via email                                 |
| [Outphase Devices](/automation/runbooks/runbook-references/org/devices/outphase-devices)                                                                       | Remove or outphase multiple devices                                                      |
| [Report Devices Without Primary User (Scheduled)](/automation/runbooks/runbook-references/org/devices/report-devices-without-primary-user_scheduled)           | Reports all managed devices in Intune that do not have a primary user assigned.          |
| [Report Primary User Mismatch (Scheduled)](/automation/runbooks/runbook-references/org/devices/report-primary-user-mismatch_scheduled)                         | Compare primary user assignments in Intune against RealmJoin for Windows managed devices |
| [Report Stale Devices (Scheduled)](/automation/runbooks/runbook-references/org/devices/report-stale-devices_scheduled)                                         | Scheduled report of stale devices based on last activity date and platform.              |
| [Report Users With More Than 5-Devices (Scheduled)](/automation/runbooks/runbook-references/org/devices/report-users-with-more-than-5-devices_scheduled)       | Report users with more than five registered devices                                      |
| [Report Windows Devices Without Autopilot (Scheduled)](/automation/runbooks/runbook-references/org/devices/report-windows-devices-without-autopilot_scheduled) | Reports all Windows Entra devices that have no associated Windows Autopilot object.      |
| [Sync Device Serialnumbers To Entraid (Scheduled)](/automation/runbooks/runbook-references/org/devices/sync-device-serialnumbers-to-entraid_scheduled)         | Sync Intune serial numbers to Entra ID extension attributes                              |

#### General

| Runbook Name                                                                                                                                             | Synopsis                                                                                |
| -------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- |
| [Add Devices Of Users To Group (Scheduled)](/automation/runbooks/runbook-references/org/general/add-devices-of-users-to-group_scheduled)                 | Sync devices of users in a specific group to another device group                       |
| [Add Management Partner](/automation/runbooks/runbook-references/org/general/add-management-partner)                                                     | List or add Management Partner Links (PAL)                                              |
| [Add Microsoft Store App Logos](/automation/runbooks/runbook-references/org/general/add-microsoft-store-app-logos)                                       | Update logos of Microsoft Store Apps (new) in Intune                                    |
| [Add Office365 Group](/automation/runbooks/runbook-references/org/general/add-office365-group)                                                           | Create an Office 365 group and SharePoint site, optionally create a (Teams) team.       |
| [Add Or Remove Safelinks Exclusion](/automation/runbooks/runbook-references/org/general/add-or-remove-safelinks-exclusion)                               | Add or remove a SafeLinks URL exclusion from a policy                                   |
| [Add Or Remove Smartscreen Exclusion](/automation/runbooks/runbook-references/org/general/add-or-remove-smartscreen-exclusion)                           | Add or remove a SmartScreen URL indicator in Microsoft Defender                         |
| [Add Or Remove Trusted Site](/automation/runbooks/runbook-references/org/general/add-or-remove-trusted-site)                                             | Add or remove a URL entry in the Intune Trusted Sites policy                            |
| [Add Primary Users Of Devices To Group (Scheduled)](/automation/runbooks/runbook-references/org/general/add-primary-users-of-devices-to-group_scheduled) | Sync primary users of Intune managed devices by platform into an Entra ID group         |
| [Add Security Group](/automation/runbooks/runbook-references/org/general/add-security-group)                                                             | Create a Microsoft Entra ID security group                                              |
| [Add User](/automation/runbooks/runbook-references/org/general/add-user)                                                                                 | Create a new user account                                                               |
| [Add Viva Engange Community](/automation/runbooks/runbook-references/org/general/add-viva-engange-community)                                             | Create a Viva Engage (Yammer) community                                                 |
| [Assign Groups By Template (Scheduled)](/automation/runbooks/runbook-references/org/general/assign-groups-by-template_scheduled)                         | Assign cloud-only groups to many users based on a predefined template                   |
| [Bulk Delete Devices From Autopilot](/automation/runbooks/runbook-references/org/general/bulk-delete-devices-from-autopilot)                             | Bulk delete Autopilot objects by serial number                                          |
| [Bulk Retire Devices From Intune](/automation/runbooks/runbook-references/org/general/bulk-retire-devices-from-intune)                                   | Bulk retire devices from Intune using serial numbers                                    |
| [Check Aad Sync Status (Scheduled)](/automation/runbooks/runbook-references/org/general/check-aad-sync-status_scheduled)                                 | Check last Azure AD Connect sync status                                                 |
| [Check Assignments Of Devices](/automation/runbooks/runbook-references/org/general/check-assignments-of-devices)                                         | Check Intune assignments for one or more device names                                   |
| [Check Assignments Of Groups](/automation/runbooks/runbook-references/org/general/check-assignments-of-groups)                                           | Check Intune assignments for one or more group names                                    |
| [Check Assignments Of Users](/automation/runbooks/runbook-references/org/general/check-assignments-of-users)                                             | Check Intune assignments for one or more user principal names                           |
| [Check Autopilot Serialnumbers](/automation/runbooks/runbook-references/org/general/check-autopilot-serialnumbers)                                       | Check if given serial numbers are present in Autopilot                                  |
| [Check Device Onboarding Exclusion (Scheduled)](/automation/runbooks/runbook-references/org/general/check-device-onboarding-exclusion_scheduled)         | Add unenrolled Autopilot devices to an exclusion group                                  |
| [Enrolled Devices Report (Scheduled)](/automation/runbooks/runbook-references/org/general/enrolled-devices-report_scheduled)                             | Show recent first-time device enrollments                                               |
| [Export All Autopilot Devices](/automation/runbooks/runbook-references/org/general/export-all-autopilot-devices)                                         | List or export all Windows Autopilot devices                                            |
| [Export All Intune Devices](/automation/runbooks/runbook-references/org/general/export-all-intune-devices)                                               | Export a list of all Intune devices and where they are registered                       |
| [Export Cloudpc Usage (Scheduled)](/automation/runbooks/runbook-references/org/general/export-cloudpc-usage_scheduled)                                   | Write daily Windows 365 utilization data to Azure Table Storage                         |
| [Export Non Compliant Devices](/automation/runbooks/runbook-references/org/general/export-non-compliant-devices)                                         | Export non-compliant Intune devices and settings                                        |
| [Export Policy Report](/automation/runbooks/runbook-references/org/general/export-policy-report)                                                         | Create a report of tenant policies from Intune and Entra ID.                            |
| [Invite External Guest Users](/automation/runbooks/runbook-references/org/general/invite-external-guest-users)                                           | Invite external guest users to the organization                                         |
| [List All Administrative Template Policies](/automation/runbooks/runbook-references/org/general/list-all-administrative-template-policies)               | List all Administrative Template policies and their assignments                         |
| [List Group License Assignment Errors](/automation/runbooks/runbook-references/org/general/list-group-license-assignment-errors)                         | Report groups that have license assignment errors                                       |
| [Monitor Service Health (Scheduled)](/automation/runbooks/runbook-references/org/general/monitor-service-health_scheduled)                               | Alert by email on newly announced Microsoft 365 Service Health issues                   |
| [Office365 License Report](/automation/runbooks/runbook-references/org/general/office365-license-report)                                                 | Generate an Office 365 licensing report                                                 |
| [Report Apple MDM Cert Expiry (Scheduled)](/automation/runbooks/runbook-references/org/general/report-apple-mdm-cert-expiry_scheduled)                   | Monitor/Report expiry of Apple device management certificates                           |
| [Report License Assignment (Scheduled)](/automation/runbooks/runbook-references/org/general/report-license-assignment_scheduled)                         | Generate and email a license availability report based on thresholds                    |
| [Report Pim Activations (Scheduled)](/automation/runbooks/runbook-references/org/general/report-pim-activations_scheduled)                               | Scheduled report on PIM activations                                                     |
| [Sync All Devices](/automation/runbooks/runbook-references/org/general/sync-all-devices)                                                                 | Sync all Intune Windows devices                                                         |
| [Sync Apple Tokens](/automation/runbooks/runbook-references/org/general/sync-apple-tokens)                                                               | Sync Apple Enrollment Program Tokens and VPP Tokens with Intune                         |
| [Sync Channel Or Group Members (Scheduled)](/automation/runbooks/runbook-references/org/general/sync-channel-or-group-members_scheduled)                 | Sync members between a Teams Shared Channel or a group and an Entra security group      |
| [Sync Shared Channel Owners (Scheduled)](/automation/runbooks/runbook-references/org/general/sync-shared-channel-owners_scheduled)                       | Ensure a security group's members are owners of mapped Teams and their shared channels. |

#### Mail

| Runbook Name                                                                                                                    | Synopsis                                                                                       |
| ------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- |
| [Add Distribution List](/automation/runbooks/runbook-references/org/mail/add-distribution-list)                                 | Create a classic distribution group                                                            |
| [Add Equipment Mailbox](/automation/runbooks/runbook-references/org/mail/add-equipment-mailbox)                                 | Create an equipment mailbox                                                                    |
| [Add Mail Contact](/automation/runbooks/runbook-references/org/mail/add-mail-contact)                                           | Create a new Exchange Online mail contact with optional display name and address list settings |
| [Add Or Remove Public Folder](/automation/runbooks/runbook-references/org/mail/add-or-remove-public-folder)                     | Add or remove a public folder                                                                  |
| [Add Or Remove Teams Mailcontact](/automation/runbooks/runbook-references/org/mail/add-or-remove-teams-mailcontact)             | Create/Remove a contact, to allow pretty email addresses for Teams channels.                   |
| [Add Or Remove Tenant Allow Block List](/automation/runbooks/runbook-references/org/mail/add-or-remove-tenant-allow-block-list) | Add or remove entries from the Tenant Allow/Block List                                         |
| [Add Room Mailbox](/automation/runbooks/runbook-references/org/mail/add-room-mailbox)                                           | Create a room mailbox resource                                                                 |
| [Add Shared Mailbox](/automation/runbooks/runbook-references/org/mail/add-shared-mailbox)                                       | Create a shared mailbox                                                                        |
| [Hide Mailboxes (Scheduled)](/automation/runbooks/runbook-references/org/mail/hide-mailboxes_scheduled)                         | Hide or unhide special mailboxes in the Global Address List                                    |
| [Set Booking Config](/automation/runbooks/runbook-references/org/mail/set-booking-config)                                       | Configure Microsoft Bookings settings for the organization                                     |

#### Phone

| Runbook Name                                                                                                             | Synopsis                                                    |
| ------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------- |
| [Get Teams Phone Number Assignment](/automation/runbooks/runbook-references/org/phone/get-teams-phone-number-assignment) | Check whether a phone number is assigned in Microsoft Teams |

#### Security

| Runbook Name                                                                                                                                        | Synopsis                                                                                                   |
| --------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- |
| [Add Defender Indicator](/automation/runbooks/runbook-references/org/security/add-defender-indicator)                                               | Create a new Microsoft Defender for Endpoint indicator                                                     |
| [Backup Conditional Access Policies](/automation/runbooks/runbook-references/org/security/backup-conditional-access-policies)                       | Export Conditional Access policies to an Azure Storage account                                             |
| [Find SMS Auth Phone Number](/automation/runbooks/runbook-references/org/security/find-sms-auth-phone-number)                                       | Find the user associated with a specific SMS-based authentication phone number                             |
| [List Admin Users](/automation/runbooks/runbook-references/org/security/list-admin-users)                                                           | List Entra ID role holders and optionally evaluate their MFA methods                                       |
| [List Expiring Role Assignments](/automation/runbooks/runbook-references/org/security/list-expiring-role-assignments)                               | List Azure AD role assignments expiring within a given number of days                                      |
| [List Inactive Devices](/automation/runbooks/runbook-references/org/security/list-inactive-devices)                                                 | List or export inactive devices with no recent logon or Intune sync                                        |
| [List Inactive Users](/automation/runbooks/runbook-references/org/security/list-inactive-users)                                                     | List users with no recent interactive sign-ins                                                             |
| [List Information Protection Labels](/automation/runbooks/runbook-references/org/security/list-information-protection-labels)                       | List Microsoft Information Protection labels                                                               |
| [List Pim Rolegroups Without Owners (Scheduled)](/automation/runbooks/runbook-references/org/security/list-pim-rolegroups-without-owners_scheduled) | List role-assignable groups with eligible role assignments but without owners                              |
| [List Users By MFA Methods Count](/automation/runbooks/runbook-references/org/security/list-users-by-mfa-methods-count)                             | Report users by the count of their registered MFA methods                                                  |
| [List Vulnerable App Regs](/automation/runbooks/runbook-references/org/security/list-vulnerable-app-regs)                                           | List app registrations potentially vulnerable to CVE-2021-42306                                            |
| [Monitor Pending EPM Requests (Scheduled)](/automation/runbooks/runbook-references/org/security/monitor-pending-epm-requests_scheduled)             | Monitor and report pending Endpoint Privilege Management (EPM) elevation requests                          |
| [Notify Changed CA Policies](/automation/runbooks/runbook-references/org/security/notify-changed-ca-policies)                                       | Send notification email if Conditional Access policies have been created or modified in the last 24 hours. |
| [Report EPM Elevation Requests (Scheduled)](/automation/runbooks/runbook-references/org/security/report-epm-elevation-requests_scheduled)           | Generate report for Endpoint Privilege Management (EPM) elevation requests                                 |
| [Sync MFA Secure Users To Group (Scheduled)](/automation/runbooks/runbook-references/org/security/sync-mfa-secure-users-to-group_scheduled)         | Sync users with secure MFA methods registered into an Entra ID group                                       |

### User

#### AVD

| Runbook Name                                                                  | Synopsis                                                    |
| ----------------------------------------------------------------------------- | ----------------------------------------------------------- |
| [User Signout](/automation/runbooks/runbook-references/user/avd/user-signout) | Removes (Signs Out) a specific User from their AVD Session. |

#### General

| Runbook Name                                                                                                  | Synopsis                                                   |
| ------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- |
| [Assign Groups By Template](/automation/runbooks/runbook-references/user/general/assign-groups-by-template)   | Assign cloud-only groups to a user based on a template     |
| [Assign Or Unassign License](/automation/runbooks/runbook-references/user/general/assign-or-unassign-license) | Assign or remove a license for a user via group membership |
| [Assign Windows365](/automation/runbooks/runbook-references/user/general/assign-windows365)                   | Assign and provision a Windows 365 Cloud PC for a user     |
| [List Group Memberships](/automation/runbooks/runbook-references/user/general/list-group-memberships)         | List group memberships for this user                       |
| [List Group Ownerships](/automation/runbooks/runbook-references/user/general/list-group-ownerships)           | List group ownerships for this user.                       |
| [List Manager](/automation/runbooks/runbook-references/user/general/list-manager)                             | List manager information for this user                     |
| [Offboard User Permanently](/automation/runbooks/runbook-references/user/general/offboard-user-permanently)   | Permanently offboard a user                                |
| [Offboard User Temporarily](/automation/runbooks/runbook-references/user/general/offboard-user-temporarily)   | Temporarily offboard a user                                |
| [Reprovision Windows365](/automation/runbooks/runbook-references/user/general/reprovision-windows365)         | Reprovision a Windows 365 Cloud PC                         |
| [Resize Windows365](/automation/runbooks/runbook-references/user/general/resize-windows365)                   | Resize an existing Windows 365 Cloud PC for a user         |
| [Unassign Windows365](/automation/runbooks/runbook-references/user/general/unassign-windows365)               | Remove and deprovision a Windows 365 Cloud PC for a user   |

#### Mail

| Runbook Name                                                                                                         | Synopsis                                                                                    |
| -------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- |
| [Add Or Remove Email Address](/automation/runbooks/runbook-references/user/mail/add-or-remove-email-address)         | Add or remove an email address for a mailbox                                                |
| [Assign Owa Mailbox Policy](/automation/runbooks/runbook-references/user/mail/assign-owa-mailbox-policy)             | Assign an OWA mailbox policy to a user                                                      |
| [Convert To Shared Mailbox](/automation/runbooks/runbook-references/user/mail/convert-to-shared-mailbox)             | Convert a user mailbox to a shared mailbox and back                                         |
| [Delegate Full Access](/automation/runbooks/runbook-references/user/mail/delegate-full-access)                       | Grant or revoke Exchange Online FullAccess mailbox permission for one or more users         |
| [Delegate Send As](/automation/runbooks/runbook-references/user/mail/delegate-send-as)                               | Delegate SendAs permissions for other user on his/her mailbox or remove existing delegation |
| [Delegate Send On Behalf](/automation/runbooks/runbook-references/user/mail/delegate-send-on-behalf)                 | Delegate SendOnBehalf permissions for the user's mailbox                                    |
| [Hide Or Unhide In Addressbook](/automation/runbooks/runbook-references/user/mail/hide-or-unhide-in-addressbook)     | Hide or unhide a mailbox in the address book                                                |
| [List Mailbox Permissions](/automation/runbooks/runbook-references/user/mail/list-mailbox-permissions)               | List mailbox permissions for a mailbox                                                      |
| [List Room Mailbox Configuration](/automation/runbooks/runbook-references/user/mail/list-room-mailbox-configuration) | List room mailbox configuration                                                             |
| [Manage Archive Mailbox](/automation/runbooks/runbook-references/user/mail/manage-archive-mailbox)                   | Manage the Exchange Online archive mailbox for a user                                       |
| [Remove Mailbox](/automation/runbooks/runbook-references/user/mail/remove-mailbox)                                   | Hard delete a shared mailbox, room or bookings calendar                                     |
| [Set Out Of Office](/automation/runbooks/runbook-references/user/mail/set-out-of-office)                             | Enable or disable mailbox out-of-office notifications                                       |
| [Set Room Mailbox Configuration](/automation/runbooks/runbook-references/user/mail/set-room-mailbox-configuration)   | Set room mailbox resource policies                                                          |

#### Phone

| Runbook Name                                                                                                                  | Synopsis                                                                                                             |
| ----------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- |
| [Disable Teams Phone](/automation/runbooks/runbook-references/user/phone/disable-teams-phone)                                 | Microsoft Teams telephony offboarding                                                                                |
| [Get Teams User Info](/automation/runbooks/runbook-references/user/phone/get-teams-user-info)                                 | Get Microsoft Teams voice status for a user                                                                          |
| [Grant Teams User Policies](/automation/runbooks/runbook-references/user/phone/grant-teams-user-policies)                     | Grant Microsoft Teams policies to a Microsoft Teams enabled user                                                     |
| [Set Teams Permanent Call Forwarding](/automation/runbooks/runbook-references/user/phone/set-teams-permanent-call-forwarding) | Set immediate call forwarding for a Teams user                                                                       |
| [Set Teams Phone](/automation/runbooks/runbook-references/user/phone/set-teams-phone)                                         | Assign a phone number to a Microsoft Teams enabled user, enable calling and Grant specific Microsoft Teams policies. |

#### Security

| Runbook Name                                                                                                                         | Synopsis                                                |
| ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------- |
| [Confirm Or Dismiss Risky User](/automation/runbooks/runbook-references/user/security/confirm-or-dismiss-risky-user)                 | Confirm compromise or dismiss a risky user              |
| [Create Temporary Access Pass](/automation/runbooks/runbook-references/user/security/create-temporary-access-pass)                   | Create a temporary access pass for a user               |
| [Enable Or Disable Password Expiration](/automation/runbooks/runbook-references/user/security/enable-or-disable-password-expiration) | Enable or disable password expiration for a user        |
| [List MFA Methods](/automation/runbooks/runbook-references/user/security/list-mfa-methods)                                           | List all MFA / authentication methods of a user         |
| [Reset MFA](/automation/runbooks/runbook-references/user/security/reset-mfa)                                                         | Remove all App- and Mobilephone auth methods for a user |
| [Reset Password](/automation/runbooks/runbook-references/user/security/reset-password)                                               | Reset a user's password                                 |
| [Revoke Or Restore Access](/automation/runbooks/runbook-references/user/security/revoke-or-restore-access)                           | Revoke or restore user access                           |
| [Set Or Remove Mobile Phone MFA](/automation/runbooks/runbook-references/user/security/set-or-remove-mobile-phone-mfa)               | Set or remove a user's mobile phone MFA method          |

#### Userinfo

| Runbook Name                                                                     | Synopsis                             |
| -------------------------------------------------------------------------------- | ------------------------------------ |
| [Rename User](/automation/runbooks/runbook-references/user/userinfo/rename-user) | Rename a user or mailbox             |
| [Set Photo](/automation/runbooks/runbook-references/user/userinfo/set-photo)     | Set the profile photo for a user     |
| [Update User](/automation/runbooks/runbook-references/user/userinfo/update-user) | Update user metadata and memberships |


# Device Runbooks

Here you can find all Device Runbooks along with the available subcategories.

## AVD

* [Restart Host](/automation/runbooks/runbook-references/device/avd/restart-host)
* [Toggle Drain Mode](/automation/runbooks/runbook-references/device/avd/toggle-drain-mode)

## General

* [Assign Groups By Template](/automation/runbooks/runbook-references/device/general/assign-groups-by-template)
* [Change Grouptag](/automation/runbooks/runbook-references/device/general/change-grouptag)
* [Check Device Compliance](/automation/runbooks/runbook-references/device/general/check-device-compliance)
* [Check Updatable Assets](/automation/runbooks/runbook-references/device/general/check-updatable-assets)
* [Enroll Updatable Assets](/automation/runbooks/runbook-references/device/general/enroll-updatable-assets)
* [Outphase Device](/automation/runbooks/runbook-references/device/general/outphase-device)
* [Remove Primary User](/automation/runbooks/runbook-references/device/general/remove-primary-user)
* [Rename Device](/automation/runbooks/runbook-references/device/general/rename-device)
* [Set Primary User](/automation/runbooks/runbook-references/device/general/set-primary-user)
* [Unenroll Updatable Assets](/automation/runbooks/runbook-references/device/general/unenroll-updatable-assets)
* [Wipe Device](/automation/runbooks/runbook-references/device/general/wipe-device)
* [Wipe Managed App Data](/automation/runbooks/runbook-references/device/general/wipe-managed-app-data)

## Security

* [Check Defender Status](/automation/runbooks/runbook-references/device/security/check-defender-status)
* [Enable Or Disable Device](/automation/runbooks/runbook-references/device/security/enable-or-disable-device)
* [Isolate Or Release Device](/automation/runbooks/runbook-references/device/security/isolate-or-release-device)
* [Reset Mobile Device Pin](/automation/runbooks/runbook-references/device/security/reset-mobile-device-pin)
* [Restrict Or Release Code Execution](/automation/runbooks/runbook-references/device/security/restrict-or-release-code-execution)
* [Show Bitlocker Recovery Key](/automation/runbooks/runbook-references/device/security/show-bitlocker-recovery-key)
* [Show Filevault Recovery Key](/automation/runbooks/runbook-references/device/security/show-filevault-recovery-key)
* [Show Laps Password](/automation/runbooks/runbook-references/device/security/show-laps-password)

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# AVD

On this overview page you can find all Device Runbooks in the AVD subcategory.

## Runbooks

* [Restart Host](/automation/runbooks/runbook-references/device/avd/restart-host)
* [Toggle Drain Mode](/automation/runbooks/runbook-references/device/avd/toggle-drain-mode)

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Restart Host

Reboots a specific AVD Session Host.

### Description

This Runbook reboots a specific AVD Session Host. If Users are signed in, they will be disconnected. In any case, Drain Mode will be enabled and the Session Host will be restarted. If the SessionHost is not running, it will be started. Once the Session Host is running, Drain Mode is disabled again.

### Location

Device → AVD → Restart Host

**Full Runbook name**

rjgit-device\_AVD\_restart-host

### Details

| Property         | Value                                                                                                                               |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| Version          | 1.0.1                                                                                                                               |
| Required modules | <p>RealmJoin.RunbookHelper (>= 0.8.7)<br>Az.DesktopVirtualization (>= 5.4.1)<br>Az.Accounts (>= 5.1.1)<br>Az.Compute (>= 5.1.1)</p> |
| Schedulable      | no                                                                                                                                  |

### Permissions

#### Permission notes

Azure: Desktop Virtualization Host Pool Contributor and Virtual Machine Contributor on Subscription which contains the Hostpool

### Parameters

#### DeviceName

The name of the AVD Session Host device to restart. Hidden in UI

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### SubscriptionIds

Array of Azure subscription IDs where the AVD Session Host resources are located. Retrieved from AVD.SubscriptionIds setting (Customization). Hidden in UI

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String\[]                              |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Toggle Drain Mode

Sets Drainmode on true or false for a specific AVD Session Host.

### Description

This Runbooks looks through all AVD Hostpools of a tenant and sets the DrainMode for a specific Session Host. The SubscriptionId value must be defined in the runbooks customization.

### Location

Device → AVD → Toggle Drain Mode

**Full Runbook name**

rjgit-device\_AVD\_toggle-drain-mode

### Details

| Property         | Value                                                                                                      |
| ---------------- | ---------------------------------------------------------------------------------------------------------- |
| Version          | 1.0.1                                                                                                      |
| Required modules | <p>RealmJoin.RunbookHelper (>= 0.8.7)<br>Az.DesktopVirtualization (>= 5.4.1)<br>Az.Accounts (>= 5.1.1)</p> |
| Schedulable      | no                                                                                                         |

### Permissions

#### Permission notes

Azure: Desktop Virtualization Host Pool Contributor on Subscription which contains the Hostpool

### Parameters

#### DeviceName

The name of the AVD Session Host device for which to toggle drain mode. Hidden in UI.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### DrainMode

Boolean value to enable or disable Drain Mode. Set to true to enable Drain Mode (prevent new sessions), false to disable it (allow new sessions). Default is false.

| Property            | Value      |
| ------------------- | ---------- |
| Required            | true       |
| Default Value       | False      |
| Type                | Boolean    |
| Portal display name | Drain Mode |

#### SubscriptionIds

Array of Azure subscription IDs where the AVD Session Host resources are located. Retrieved from AVD.SubscriptionIds setting (Customization). Hidden in UI.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String\[]                              |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# General

On this overview page you can find all Device Runbooks in the General subcategory.

## Runbooks

* [Assign Groups By Template](/automation/runbooks/runbook-references/device/general/assign-groups-by-template)
* [Change Grouptag](/automation/runbooks/runbook-references/device/general/change-grouptag)
* [Check Device Compliance](/automation/runbooks/runbook-references/device/general/check-device-compliance)
* [Check Updatable Assets](/automation/runbooks/runbook-references/device/general/check-updatable-assets)
* [Enroll Updatable Assets](/automation/runbooks/runbook-references/device/general/enroll-updatable-assets)
* [Outphase Device](/automation/runbooks/runbook-references/device/general/outphase-device)
* [Remove Primary User](/automation/runbooks/runbook-references/device/general/remove-primary-user)
* [Rename Device](/automation/runbooks/runbook-references/device/general/rename-device)
* [Set Primary User](/automation/runbooks/runbook-references/device/general/set-primary-user)
* [Unenroll Updatable Assets](/automation/runbooks/runbook-references/device/general/unenroll-updatable-assets)
* [Wipe Device](/automation/runbooks/runbook-references/device/general/wipe-device)
* [Wipe Managed App Data](/automation/runbooks/runbook-references/device/general/wipe-managed-app-data)

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Assign Groups By Template

Assign cloud-only groups to a device based on a template

### Description

Adds a device to one or more Entra ID groups using either group object IDs or display names. The list of groups is typically provided via runbook customization templates.

### Location

Device → General → Assign Groups By Template

**Full Runbook name**

rjgit-device\_general\_assign-groups-by-template

### Details

| Property         | Value                                                                                   |
| ---------------- | --------------------------------------------------------------------------------------- |
| Version          | 1.0.3                                                                                   |
| Required modules | <p>RealmJoin.RunbookHelper (>= 0.8.7)<br>Microsoft.Graph.Authentication (>= 2.39.0)</p> |
| Schedulable      | no                                                                                      |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Device.Read.All
  * Group.Read.All
  * GroupMember.ReadWrite.All

### Parameters

#### DeviceId

ID of the target device in Microsoft Graph.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### GroupsTemplate

Template selector used by portal customization to populate the group list.

| Property      | Value  |
| ------------- | ------ |
| Required      | false  |
| Default Value |        |
| Type          | String |

#### GroupsString

Comma-separated list of group object IDs or group display names.

| Property      | Value  |
| ------------- | ------ |
| Required      | true   |
| Default Value |        |
| Type          | String |

#### UseDisplaynames

If set to true, treats values in GroupsString as group display names instead of IDs.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | false                                  |
| Default Value    | True                                   |
| Type             | Boolean                                |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Change Grouptag

Assign a new AutoPilot GroupTag to this device.

### Description

This Runbook assigns a new AutoPilot GroupTag to the device. This can be used to trigger a new deployment with different policies and applications for the device.

### Location

Device → General → Change Grouptag

**Full Runbook name**

rjgit-device\_general\_change-groupTag

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Device.Read.All
  * DeviceManagementServiceConfig.ReadWrite.All

### Parameters

#### DeviceId

The device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### newGroupTag

The new AutoPilot GroupTag to assign to the device.

| Property      | Value  |
| ------------- | ------ |
| Required      | false  |
| Default Value |        |
| Type          | String |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Check Device Compliance

Check the compliance status of a device

### Description

This runbook retrieves the compliance status of a managed device from Microsoft Intune. In simple mode it shows the overall compliance state and lists any non-compliant policies. In detailed mode it additionally shows which specific settings are failing and the reason for each failure. Optionally, a report with the full compliance details can be sent via email.

### Location

Device → General → Check Device Compliance

**Full Runbook name**

rjgit-device\_general\_check-device-compliance

### Details

| Property         | Value                                                                                   |
| ---------------- | --------------------------------------------------------------------------------------- |
| Version          | 1.0.2                                                                                   |
| Required modules | <p>RealmJoin.RunbookHelper (>= 0.8.7)<br>Microsoft.Graph.Authentication (>= 2.39.0)</p> |
| Schedulable      | no                                                                                      |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Device.Read.All
  * DeviceManagementManagedDevices.Read.All
  * Organization.Read.All

### Parameters

#### DeviceId

The Entra ID device ID of the target device. Passed automatically by the RealmJoin platform.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### DetailedOutput

Select "Simple" (final value: $false) to show only the overall compliance state and non-compliant policy names. Select "Detailed" (final value: $true) to additionally show which specific settings are failing and the reason for each failure.

| Property            | Value       |
| ------------------- | ----------- |
| Required            | false       |
| Default Value       | False       |
| Type                | Boolean     |
| Portal display name | Output Mode |

**Portal options**

| Portal option                                                     | Value |
| ----------------------------------------------------------------- | ----- |
| Simple - show overall compliance state and non-compliant policies | false |
| Detailed - show failing settings and reasons per policy           | true  |

#### EmailTo

Optional - if specified, a compliance report will be sent to the provided email address(es). Can be a single address or multiple comma-separated addresses.

| Property            | Value                                  |
| ------------------- | -------------------------------------- |
| Required            | false                                  |
| Default Value       |                                        |
| Type                | String                                 |
| Portal display name | Recipient Email Address(es) (optional) |

#### EmailFrom

The sender email address. This needs to be configured in the runbook customization.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | false                                  |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Check Updatable Assets

Check if a device is onboarded to Windows Update for Business

### Description

This script checks if single device is onboarded to Windows Update for Business

### Location

Device → General → Check Updatable Assets

**Full Runbook name**

rjgit-device\_general\_check-updatable-assets

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.2                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * WindowsUpdates.ReadWrite.All

### Parameters

#### DeviceId

DeviceId of the device to check.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Enroll Updatable Assets

Enroll device into Windows Update for Business

### Description

This script enrolls a device into Windows Update for Business by registering it as an updatable asset for the specified update category.

### Location

Device → General → Enroll Updatable Assets

**Full Runbook name**

rjgit-device\_general\_enroll-updatable-assets

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.2                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * WindowsUpdates.ReadWrite.All

### Parameters

#### DeviceId

DeviceId of the device to enroll.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### UpdateCategory

Category of updates to enroll into. Possible values are: Driver, Feature, Quality or All. Selecting All will enroll the device into all three categories sequentially.

| Property      | Value   |
| ------------- | ------- |
| Required      | true    |
| Default Value | Feature |
| Type          | String  |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Outphase Device

Remove/Outphase a windows device

### Description

Remove/Outphase a windows device. You can choose if you want to wipe the device and/or delete it from Intune and AutoPilot. Optionally, the device can be tagged in Microsoft Defender for Endpoint to mark it as excluded from remediation. NOTE: The Exclusion Tag is applied to the device, but it only appears in the Defender portal's "Tags" filter once it has been created once via the portal (Device > Manage tags > "Create new tag").

### Microsoft Defender for Endpoint exclusion tag

Microsoft Defender for Endpoint has a native **Exclusion state** (shown in the Device Inventory filter as *Excluded* / *Not Excluded*). This state can only be set through the Defender portal — there is **no API** to set a device's native exclusion state programmatically.

Because the native exclusion state cannot be automated, this runbook instead applies a custom device tag (default `ExcludeFromRemediation`) when *Exclude device from Defender for Endpoint* is enabled. The device is looked up by its Entra ID device ID and tagged via `POST /api/machines/{id}/tags`, providing a marker that can be used to filter and target excluded devices.

#### One-time setup: make the tag filterable

The portal's **Tags** filter unfortunately only lists tags that were created through the portal. A tag set purely via the API is attached to the device and visible on the device page, but it does **not** appear in the Tags filter on its own.

To make the exclusion tag visible and usable for filtering in the [Defender Device Inventory](https://security.microsoft.com/machines), one client must be tagged manually once through the portal (select a device > **Manage tags** > "Create new tag", using the exact same tag value). After this one-time step the tag becomes a known, filterable tag, and this runbook can apply it to devices at scale.

> **Note:** This tag is only a label — it does not set the device's native Exclusion state and has no remediation effect on its own. It takes effect only if a Defender device group or automation rule is explicitly configured to match this tag value. Such rules match the tag value directly, independently of the portal **Tags** filter, so the one-time manual step only affects whether the tag is selectable for filtering in the portal UI.

See [Create and manage device tags](https://learn.microsoft.com/defender-endpoint/machine-tags#create-tags) for details.

### Location

Device → General → Outphase Device

**Full Runbook name**

rjgit-device\_general\_outphase-device

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * DeviceManagementManagedDevices.PrivilegedOperations.All
  * DeviceManagementManagedDevices.ReadWrite.All
  * DeviceManagementServiceConfig.ReadWrite.All
  * Device.Read.All
* **Type**: WindowsDefenderATP
  * Machine.Read.All
  * Machine.ReadWrite.All

#### RBAC roles

* Cloud device administrator

### Parameters

#### DeviceId

The device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### intuneAction

Determines the Intune action to perform (wipe, delete, or none).

| Property            | Value             |
| ------------------- | ----------------- |
| Required            | false             |
| Default Value       | 2                 |
| Type                | Int32             |
| Portal display name | Wipe this device? |

**Portal options**

| Portal option                                                            | Value |
| ------------------------------------------------------------------------ | ----- |
| Completely wipe device (not keeping user or enrollment data)             | 2     |
| Delete device from Intune (only if device is already wiped or destroyed) | 1     |
| Do not wipe or remove device from Intune                                 | 0     |

#### aadAction

Determines the Entra ID (Azure AD) action to perform (delete, disable, or none).

| Property            | Value                       |
| ------------------- | --------------------------- |
| Required            | false                       |
| Default Value       | 2                           |
| Type                | Int32                       |
| Portal display name | Delete device from EntraID? |

**Portal options**

| Portal option                              | Value |
| ------------------------------------------ | ----- |
| Delete device in EntraID                   | 2     |
| Disable device in EntraID                  | 1     |
| Do not delete EntraID device / do not care | 0     |

#### wipeDevice

If set to true, triggers a wipe action in Intune.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | false                                  |
| Default Value    | True                                   |
| Type             | Boolean                                |
| Hidden in portal | yes (preset via runbook customization) |

#### removeIntuneDevice

If set to true, deletes the Intune device object.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | false                                  |
| Default Value    | False                                  |
| Type             | Boolean                                |
| Hidden in portal | yes (preset via runbook customization) |

#### removeAutopilotDevice

"Delete device from AutoPilot database?" (final value: true) or "Keep device / do not care" (final value: false) can be selected as action to perform. If set to true, the runbook will delete the device from the AutoPilot database, which also allows the device to leave the tenant. If set to false, the device will remain in the AutoPilot database and can be re-assigned to another user/device in the tenant.

| Property            | Value                                  |
| ------------------- | -------------------------------------- |
| Required            | false                                  |
| Default Value       | True                                   |
| Type                | Boolean                                |
| Portal display name | Delete device from AutoPilot database? |

**Portal options**

| Portal option                                                      | Value |
| ------------------------------------------------------------------ | ----- |
| Remove the device from AutoPilot (the device can leave the tenant) | true  |
| Keep device / do not care                                          | false |

#### removeAADDevice

"Delete device from EntraID?" (final value: true) or "Keep device / do not care" (final value: false) can be selected as action to perform. If set to true, the runbook will delete the device object from Entra ID (Azure AD). If set to false, the device object will remain in Entra ID (Azure AD).

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | false                                  |
| Default Value    | True                                   |
| Type             | Boolean                                |
| Hidden in portal | yes (preset via runbook customization) |

#### disableAADDevice

"Disable device in EntraID?" (final value: true) or "Keep device / do not care" (final value: false) can be selected as action to perform. If set to true, the runbook will disable the device object in Entra ID (Azure AD). If set to false, the device object will remain enabled in Entra ID (Azure AD).

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | false                                  |
| Default Value    | False                                  |
| Type             | Boolean                                |
| Hidden in portal | yes (preset via runbook customization) |

#### excludeFromDefender

If set to true, the device will be tagged in Microsoft Defender for Endpoint with the specified exclusion tag. If set to false, the Defender step will be skipped entirely.

| Property            | Value                                      |
| ------------------- | ------------------------------------------ |
| Required            | false                                      |
| Default Value       | False                                      |
| Type                | Boolean                                    |
| Portal display name | Exclude device from Defender for Endpoint? |

**Portal options**

| Portal option                                   | Value |
| ----------------------------------------------- | ----- |
| Tag device as excluded in Defender for Endpoint | true  |
| Skip Defender operations                        | false |

#### defenderExclusionTag

The tag that will be added to the device in Microsoft Defender for Endpoint to mark it as excluded. Defaults to "ExcludeFromRemediation".

| Property            | Value                  |
| ------------------- | ---------------------- |
| Required            | false                  |
| Default Value       | ExcludeFromRemediation |
| Type                | String                 |
| Portal display name | Defender Exclusion Tag |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Remove Primary User

Removes the primary user from a device.

### Description

This script removes the assigned primary user from a specified Azure AD device. It requires the DeviceId of the target device and the name of the caller for auditing purposes.

### Location

Device → General → Remove Primary User

**Full Runbook name**

rjgit-device\_general\_remove-primary-user

### Details

| Property         | Value                                                                                   |
| ---------------- | --------------------------------------------------------------------------------------- |
| Version          | 1.0.2                                                                                   |
| Required modules | <p>RealmJoin.RunbookHelper (>= 0.8.7)<br>Microsoft.Graph.Authentication (>= 2.39.0)</p> |
| Schedulable      | no                                                                                      |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * DeviceManagementManagedDevices.ReadWrite.All

### Parameters

#### DeviceId

The unique identifier of the device from which the primary user will be removed. It will be prefilled from the RealmJoin Portal and is hidden in the UI.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Rename Device

Rename a device.

### Description

Rename a device (in Intune and Autopilot).

### Location

Device → General → Rename Device

**Full Runbook name**

rjgit-device\_general\_rename-device

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.2                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Device.Read.All
  * DeviceManagementManagedDevices.Read.All
  * DeviceManagementServiceConfig.ReadWrite.All
  * DeviceManagementManagedDevices.PrivilegedOperations.All

### Parameters

#### DeviceId

The device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### NewDeviceName

The new device name to set. This runbook validates the name against common Windows hostname constraints.

| Property      | Value  |
| ------------- | ------ |
| Required      | true   |
| Default Value |        |
| Type          | String |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Set Primary User

Set a new primary user on a managed Intune device

### Description

This runbook assigns a new primary user to an Intune managed device. It resolves the Intune managed device from the Entra Object ID provided by the portal, retrieves the current primary user and device details, removes the existing user assignment, and then sets the specified user as the new primary user. The output shows the previous and new assignment for audit purposes.

### Location

Device → General → Set Primary User

**Full Runbook name**

rjgit-device\_general\_set-primary-user

### Details

| Property         | Value                                                                                   |
| ---------------- | --------------------------------------------------------------------------------------- |
| Version          | 1.0.2                                                                                   |
| Required modules | <p>RealmJoin.RunbookHelper (>= 0.8.7)<br>Microsoft.Graph.Authentication (>= 2.39.0)</p> |
| Schedulable      | no                                                                                      |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * DeviceManagementManagedDevices.ReadWrite.All
  * User.Read.All

### Parameters

#### DeviceId

The Entra Object ID of the device. Pre-filled from the RealmJoin Portal and hidden in the UI.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### NewPrimaryUserId

The user to assign as the new primary user of the device.

| Property            | Value            |
| ------------------- | ---------------- |
| Required            | true             |
| Default Value       |                  |
| Type                | String           |
| Portal display name | New Primary User |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Unenroll Updatable Assets

Unenroll device from Windows Update for Business.

### Description

This script unenrolls devices from Windows Update for Business.

### Location

Device → General → Unenroll Updatable Assets

**Full Runbook name**

rjgit-device\_general\_unenroll-updatable-assets

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * WindowsUpdates.ReadWrite.All

### Parameters

#### DeviceId

DeviceId of the device to unenroll.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### UpdateCategory

Category of updates to unenroll from. Possible values are: driver, feature, quality or all (delete).

| Property      | Value  |
| ------------- | ------ |
| Required      | true   |
| Default Value | all    |
| Type          | String |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Wipe Device

Wipe a Windows or MacOS device

### Description

Wipe a Windows or MacOS device. For Windows devices, you can choose between a regular wipe and a protected wipe. For MacOS devices, you can provide a recovery code if needed and specify the obliteration behavior.

### Add the device to a compliance exclusion group

When *Add device to compliance exclusion group* (`addToExclusionGroup`) is enabled, the wiped Windows device is added to a compliance exclusion group. Devices in that group receive a longer compliance grace period after they are re-enrolled via Autopilot (this mirrors the **Check Device Onboarding Exclusion** runbook).

By default the group is identified by its **display name** (`exclusionGroupName`). Because display names are not guaranteed to be unique, you can instead pin the group by its **Object ID** (`exclusionGroupId`). When an Object ID is provided, it **always overrides** the display name, so name conflicts can never lead to the wrong group being used. `exclusionGroupId` is hidden by default and is meant to be set via runbook customization.

The group is resolved and validated in an upfront preflight check. If the configured group does not exist, the runbook aborts **before** any wipe/delete/disable action, so no half-applied state is left behind. Adding to the group is skipped for non-Windows devices and when the device is deleted from EntraID (`removeAADDevice`).

#### Pin the group by Object ID (recommended)

Preset the group's Object ID and enable the switch, keeping the fields hidden. This avoids any ambiguity from duplicate display names.

The json configuration for this is as follows:

```json
"rjgit-device_general_wipe-device": {
    "parameters": {
        "addToExclusionGroup": {
            "Default": true
        },
        "exclusionGroupId": {
            "Default": "00000000-0000-0000-0000-000000000000",
            "Hide": true
        },
        "exclusionGroupName": {
            "Hide": true
        }
    }
}
```

Replace `00000000-0000-0000-0000-000000000000` with the Object ID of your group (EntraID > Groups > *your group* > **Object Id**).

#### Pin the group by display name

If you prefer to work with the display name (and it is unique in your tenant), preset `exclusionGroupName` and leave `exclusionGroupId` empty so the name is used.

The json configuration for this is as follows:

```json
"rjgit-device_general_wipe-device": {
    "parameters": {
        "addToExclusionGroup": {
            "Default": true
        },
        "exclusionGroupName": {
            "Default": "cfg - Intune - Windows - Compliance for unenrolled Autopilot devices (devices)",
            "Hide": true
        }
    }
}
```

### Location

Device → General → Wipe Device

**Full Runbook name**

rjgit-device\_general\_wipe-device

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.1.0                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * DeviceManagementManagedDevices.PrivilegedOperations.All
  * DeviceManagementManagedDevices.ReadWrite.All
  * DeviceManagementServiceConfig.ReadWrite.All
  * Device.Read.All
  * GroupMember.ReadWrite.All
* **Type**: WindowsDefenderATP
  * Machine.Read.All

#### RBAC roles

* Cloud device administrator

### Parameters

#### DeviceId

The device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### wipeDevice

"Wipe this device?" (final value: true) or "Do not wipe device" (final value: false) can be selected as action to perform. If set to true, the runbook will trigger a wipe action for the device in Intune. If set to false, no wipe action will be triggered for the device in Intune.

| Property            | Value             |
| ------------------- | ----------------- |
| Required            | false             |
| Default Value       | True              |
| Type                | Boolean           |
| Portal display name | Wipe this device? |

**Portal options**

| Portal option                                                         | Value |
| --------------------------------------------------------------------- | ----- |
| Completely wipe device (Windows: not keeping user or enrollment data) | true  |
| Do not wipe device                                                    | false |

#### useProtectedWipe

Windows-only. If set to true, uses protected wipe.

| Property            | Value                        |
| ------------------- | ---------------------------- |
| Required            | false                        |
| Default Value       | False                        |
| Type                | Boolean                      |
| Portal display name | Windows: Use protected wipe? |

#### removeIntuneDevice

If set to true, deletes the Intune device object.

| Property            | Value                      |
| ------------------- | -------------------------- |
| Required            | false                      |
| Default Value       | False                      |
| Type                | Boolean                    |
| Portal display name | Delete device from Intune? |

**Portal options**

| Portal option                                                            | Value |
| ------------------------------------------------------------------------ | ----- |
| Delete device from Intune (only if device is already wiped or destroyed) | true  |
| Do not modify the Intune object / do not care                            | false |

#### removeAutopilotDevice

Windows-only. "Delete device from AutoPilot database?" (final value: true) or "Keep device / do not care" (final value: false) can be selected as action to perform. If set to true, the runbook will delete the device from the AutoPilot database, which also allows the device to leave the tenant. If set to false, the device will remain in the AutoPilot database and can be re-assigned to another user/device in the tenant.

| Property            | Value                                           |
| ------------------- | ----------------------------------------------- |
| Required            | false                                           |
| Default Value       | False                                           |
| Type                | Boolean                                         |
| Portal display name | Windows: Delete device from AutoPilot database? |

**Portal options**

| Portal option                                                      | Value |
| ------------------------------------------------------------------ | ----- |
| Remove the device from AutoPilot (the device can leave the tenant) | true  |
| Keep device / do not care                                          | false |

#### removeAADDevice

"Delete device from EntraID?" (final value: true) or "Keep device / do not care" (final value: false) can be selected as action to perform. If set to true, the runbook will delete the device object from Entra ID (Azure AD). If set to false, the device object will remain in Entra ID (Azure AD).

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | false                                  |
| Default Value    | False                                  |
| Type             | Boolean                                |
| Hidden in portal | yes (preset via runbook customization) |

#### disableAADDevice

"Disable device in EntraID?" (final value: true) or "Keep device / do not care" (final value: false) can be selected as action to perform. If set to true, the runbook will disable the device object in Entra ID (Azure AD). If set to false, the device object will remain enabled in Entra ID (Azure AD).

| Property            | Value                          |
| ------------------- | ------------------------------ |
| Required            | false                          |
| Default Value       | False                          |
| Type                | Boolean                        |
| Portal display name | Disable AzureAD device object? |

**Portal options**

| Portal option                              | Value |
| ------------------------------------------ | ----- |
| Disable device in AzureAD                  | true  |
| Do not modify AzureAD device / do not care | false |

#### skipWipeIfAtRisk

If set to true, the wipe is only performed when the device's Microsoft Defender for Endpoint risk score is not Medium or High. This protects forensic data (e.g. logs) of devices that may be involved in a security incident from being destroyed by the wipe.

| Property            | Value                                                      |
| ------------------- | ---------------------------------------------------------- |
| Required            | false                                                      |
| Default Value       | False                                                      |
| Type                | Boolean                                                    |
| Portal display name | Only wipe if device is not at risk (Defender Medium/High)? |

**Portal options**

| Portal option                                       | Value |
| --------------------------------------------------- | ----- |
| Only wipe if Defender risk score is not Medium/High | true  |
| Wipe regardless of Defender risk score              | false |

#### addToExclusionGroup

Windows-only. If set to true, the device is added to the compliance exclusion group referenced by 'exclusionGroupName'. This grants the device a longer compliance grace period after it is re-enrolled via Autopilot (see the 'Check Device Onboarding Exclusion' runbook).

| Property            | Value                                                                    |
| ------------------- | ------------------------------------------------------------------------ |
| Required            | false                                                                    |
| Default Value       | False                                                                    |
| Type                | Boolean                                                                  |
| Portal display name | Windows: Add device to compliance exclusion group (longer grace period)? |

**Portal options**

| Portal option                                | Value |
| -------------------------------------------- | ----- |
| Add device to the compliance exclusion group | true  |
| Do not add to exclusion group / do not care  | false |

#### exclusionGroupName

Display name of the compliance exclusion group the device should be added to when 'addToExclusionGroup' is enabled.

| Property            | Value                                                                          |
| ------------------- | ------------------------------------------------------------------------------ |
| Required            | false                                                                          |
| Default Value       | cfg - Intune - Windows - Compliance for unenrolled Autopilot devices (devices) |
| Type                | String                                                                         |
| Portal display name | Compliance exclusion group name                                                |

#### exclusionGroupId

Object ID of the compliance exclusion group. If provided, it always overrides 'exclusionGroupName' (avoids name conflicts). Hidden by default; intended to be set via Runbook Customization.

| Property            | Value                                                 |
| ------------------- | ----------------------------------------------------- |
| Required            | false                                                 |
| Default Value       |                                                       |
| Type                | String                                                |
| Portal display name | Compliance exclusion group Object ID (overrides name) |
| Hidden in portal    | yes (preset via runbook customization)                |

#### macOsRecoveryCode

MacOS-only. Recovery code for older devices; newer devices may not require this.

| Property            | Value                                               |
| ------------------- | --------------------------------------------------- |
| Required            | false                                               |
| Default Value       | 123456                                              |
| Type                | String                                              |
| Portal display name | MacOS: Recovery Code - not needed for newer devices |
| Hidden in portal    | yes (preset via runbook customization)              |

#### macOsObliterationBehavior

MacOS-only. Controls the OS obliteration behavior during wipe.

| Property            | Value                           |
| ------------------- | ------------------------------- |
| Required            | false                           |
| Default Value       | default                         |
| Type                | String                          |
| Portal display name | MacOS: OS Obliteration Behavior |

**Portal options**

| Portal option                                                       | Value                 |
| ------------------------------------------------------------------- | --------------------- |
| Default: Try to erase user date (EACS), obliterate OS if this fails | default               |
| Try to erase user data (EACS), do not obliterate the OS             | doNotObliterate       |
| Try to erase user data (EACS), else warn and obliterate the OS      | obliterateWithWarning |
| Always obliterate OS                                                | always                |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Wipe Managed App Data

App selective wipe - remove company app data from this MAM device

### Description

Performs an "App selective wipe" (Mobile Application Management) for this device, mirroring the Intune portal flow "Apps > App selective wipe > Create wipe request". It removes company data from apps protected by app protection policies without wiping the whole device - typically used for lost or stolen devices that are MAM-managed (not MDM-enrolled).

The runbook resolves the users registered on the device, collects their MAM app registrations that belong to this device and creates a wipe request for each affected user/device tag. The wipe is executed the next time each protected app checks in. Wipe requests can be monitored and cancelled in the Intune portal under "Apps > App selective wipe".

### Device matching

MAM app registrations belong to a user, not to a device object. The runbook therefore resolves the users registered on the device and matches their app registrations against the device's EntraID device id (`azureADDeviceId`). Registrations without an EntraID device id are matched by the device's display name as fallback; the runbook output indicates when this fallback was used.

### Wipe behavior

* The company app data is removed the next time each protected app checks in on the device; the wipe is not instantaneous.
* Pending wipe requests can be monitored and cancelled in the Intune portal under *Apps > App selective wipe*.
* Only app data protected by app protection policies (MAM) is affected. The device object itself is not touched: it remains in EntraID (and in Intune/Autopilot, if it is additionally MDM-enrolled). To disable or remove the device there as well, run the **Outphase Device** runbook (Device \ General) afterwards; for a full wipe of MDM-enrolled devices use **Wipe Device**.

### Location

Device → General → Wipe Managed App Data

**Full Runbook name**

rjgit-device\_general\_wipe-managed-app-data

### Details

| Property         | Value                                                                                   |
| ---------------- | --------------------------------------------------------------------------------------- |
| Version          | 1.0.0                                                                                   |
| Required modules | <p>RealmJoin.RunbookHelper (>= 0.8.7)<br>Microsoft.Graph.Authentication (>= 2.39.0)</p> |
| Schedulable      | no                                                                                      |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * DeviceManagementApps.ReadWrite.All
  * Device.Read.All
  * User.Read.All

#### RBAC roles

* Intune Administrator

### Parameters

#### DeviceId

The device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Security

On this overview page you can find all Device Runbooks in the Security subcategory.

## Runbooks

* [Check Defender Status](/automation/runbooks/runbook-references/device/security/check-defender-status)
* [Enable Or Disable Device](/automation/runbooks/runbook-references/device/security/enable-or-disable-device)
* [Isolate Or Release Device](/automation/runbooks/runbook-references/device/security/isolate-or-release-device)
* [Reset Mobile Device Pin](/automation/runbooks/runbook-references/device/security/reset-mobile-device-pin)
* [Restrict Or Release Code Execution](/automation/runbooks/runbook-references/device/security/restrict-or-release-code-execution)
* [Show Bitlocker Recovery Key](/automation/runbooks/runbook-references/device/security/show-bitlocker-recovery-key)
* [Show Filevault Recovery Key](/automation/runbooks/runbook-references/device/security/show-filevault-recovery-key)
* [Show Laps Password](/automation/runbooks/runbook-references/device/security/show-laps-password)

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Check Defender Status

Check a device's presence and risk status in Entra ID and Microsoft Defender for Endpoint

### Description

This runbook compares a device between Entra ID and Microsoft Defender for Endpoint based on its Entra device ID. It reports whether the device exists in each service, returns key properties like onboarding and health state, and evaluates the Defender risk score to flag elevated risk.

### Location

Device → Security → Check Defender Status

**Full Runbook name**

rjgit-device\_security\_check-defender-status

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.0                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Device.Read.All
* **Type**: WindowsDefenderATP
  * Machine.Read.All

### Parameters

#### DeviceId

The Entra device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Enable Or Disable Device

Enable or disable a device in Entra ID

### Description

This runbook enables or disables a Windows device object in Entra ID (Azure AD) based on the provided device ID. Use it to temporarily block sign-ins from a compromised or lost device, or to re-enable the device after remediation.

### Location

Device → Security → Enable Or Disable Device

**Full Runbook name**

rjgit-device\_security\_enable-or-disable-device

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Device.Read.All

#### RBAC roles

* Cloud device administrator

### Parameters

#### DeviceId

The device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### Enable

"Disable Device?" (final value: false) or "Enable Device again?" (final value: true) can be selected as action to perform. If set to false, the runbook will disable the device in Entra ID (Azure AD). If set to true, the runbook will enable the device in Entra ID (Azure AD) again.

| Property            | Value                    |
| ------------------- | ------------------------ |
| Required            | false                    |
| Default Value       | False                    |
| Type                | Boolean                  |
| Portal display name | Disable or Enable Device |

**Portal options**

| Portal option       | Value |
| ------------------- | ----- |
| Disable Device      | false |
| Enable Device again | true  |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Isolate Or Release Device

Isolate this device.

### Description

This runbook isolates a device in Microsoft Defender for Endpoint to reduce the risk of lateral movement and data exfiltration. Optionally, it can release a previously isolated device. Provide a short reason so the action is documented in the service.

### Location

Device → Security → Isolate Or Release Device

**Full Runbook name**

rjgit-device\_security\_isolate-or-release-device

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: WindowsDefenderATP
  * Machine.Read.All
  * Machine.Isolate

### Parameters

#### DeviceId

The device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### Release

"Isolate Device" (final value: false) or "Release Device from Isolation" (final value: true) can be selected as action to perform. If set to false, the runbook will isolate the device in Defender for Endpoint. If set to true, it will release a previously isolated device from isolation in Defender for Endpoint.

| Property            | Value   |
| ------------------- | ------- |
| Required            | true    |
| Default Value       | False   |
| Type                | Boolean |
| Portal display name | Action  |

**Portal options**

| Portal option                 | Value |
| ----------------------------- | ----- |
| Isolate Device                | false |
| Release Device from Isolation | true  |

#### IsolationType

The isolation type to use when isolating the device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | false                                  |
| Default Value    | Full                                   |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### Comment

A short reason for the (un)isolation action.

| Property            | Value                    |
| ------------------- | ------------------------ |
| Required            | true                     |
| Default Value       | Possible security risk.  |
| Type                | String                   |
| Portal display name | Reason for (Un)Isolation |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Reset Mobile Device Pin

Reset a mobile device's password/PIN code.

### Description

This runbook triggers an Intune reset passcode action for a managed mobile device. The action is only supported for certain, corporate-owned device types and will be rejected for personal or unsupported devices.

### Location

Device → Security → Reset Mobile Device Pin

**Full Runbook name**

rjgit-device\_security\_reset-mobile-device-pin

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * DeviceManagementManagedDevices.Read.All
  * DeviceManagementManagedDevices.PrivilegedOperations.All

### Parameters

#### DeviceId

The device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Restrict Or Release Code Execution

Only allow Microsoft-signed code to run on a device, or remove an existing restriction.

### Description

This runbook restricts code execution on a device via Microsoft Defender for Endpoint so that only Microsoft-signed code can run. Optionally, it can remove an existing restriction. Provide a short reason so the action is documented in the service.

### Location

Device → Security → Restrict Or Release Code Execution

**Full Runbook name**

rjgit-device\_security\_restrict-or-release-code-execution

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: WindowsDefenderATP
  * Machine.Read.All
  * Machine.RestrictExecution

### Parameters

#### DeviceId

The device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### Release

"Restrict Code Execution" (final value: false) or "Remove Code Restriction" (final value: true) can be selected as action to perform. If set to false, the runbook will restrict code execution on the device in Defender for Endpoint. If set to true, it will remove an existing code execution restriction on the device in Defender for Endpoint.

| Property            | Value   |
| ------------------- | ------- |
| Required            | true    |
| Default Value       | False   |
| Type                | Boolean |
| Portal display name | Action  |

**Portal options**

| Portal option           | Value |
| ----------------------- | ----- |
| Restrict Code Execution | false |
| Remove Code Restriction | true  |

#### Comment

A short reason for the (un)restriction action.

| Property            | Value                      |
| ------------------- | -------------------------- |
| Required            | true                       |
| Default Value       | Possible security risk.    |
| Type                | String                     |
| Portal display name | Reason for (Un)Restriction |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Show Bitlocker Recovery Key

Show all BitLocker recovery keys for a device

### Description

This runbook retrieves and displays all BitLocker recovery keys that are backed up for the specified device. Keys are sorted by creation date (newest first). Use it for disk recovery scenarios.

### Location

Device → Security → Show Bitlocker Recovery Key

**Full Runbook name**

rjgit-device\_security\_show-bitlocker-recovery-key

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * BitlockerKey.Read.All

### Parameters

#### DeviceId

The device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Show Filevault Recovery Key

Display macOS FileVault recovery key

### Description

Retrieves and displays the FileVault recovery key for a macOS device enrolled in Intune. This key is used to unlock the device if the user forgets their password or the device becomes locked.

### Location

Device → Security → Show Filevault Recovery Key

**Full Runbook name**

rjgit-device\_security\_show-filevault-recovery-key

### Details

| Property         | Value                                                                                   |
| ---------------- | --------------------------------------------------------------------------------------- |
| Version          | 1.0.2                                                                                   |
| Required modules | <p>RealmJoin.RunbookHelper (>= 0.8.7)<br>Microsoft.Graph.Authentication (>= 2.39.0)</p> |
| Schedulable      | no                                                                                      |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * DeviceManagementManagedDevices.PrivilegedOperations.All
  * DeviceManagementManagedDevices.Read.All

### Parameters

#### DeviceId

The Azure AD Device ID of the macOS device

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Show Laps Password

Show a local admin password for a device.

### Description

This runbook retrieves and displays the most recent Windows LAPS local administrator password that is backed up for the specified device. Use it for break-glass troubleshooting and rotate the password after use.

### Location

Device → Security → Show Laps Password

**Full Runbook name**

rjgit-device\_security\_show-laps-password

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.2                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * DeviceLocalCredential.Read.All

### Parameters

#### DeviceId

The device ID of the target device.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Group Runbooks

Here you can find all Group Runbooks along with the available subcategories.

## Devices

* [Check Updatable Assets](/automation/runbooks/runbook-references/group/devices/check-updatable-assets)
* [Unenroll Updatable Assets (Scheduled)](/automation/runbooks/runbook-references/group/devices/unenroll-updatable-assets_scheduled)

## General

* [Add Or Remove Nested Group](/automation/runbooks/runbook-references/group/general/add-or-remove-nested-group)
* [Add Or Remove Owner](/automation/runbooks/runbook-references/group/general/add-or-remove-owner)
* [Add Or Remove User](/automation/runbooks/runbook-references/group/general/add-or-remove-user)
* [Change Visibility](/automation/runbooks/runbook-references/group/general/change-visibility)
* [List All Members](/automation/runbooks/runbook-references/group/general/list-all-members)
* [List Owners](/automation/runbooks/runbook-references/group/general/list-owners)
* [List User Devices](/automation/runbooks/runbook-references/group/general/list-user-devices)
* [Remove Group](/automation/runbooks/runbook-references/group/general/remove-group)
* [Rename Group](/automation/runbooks/runbook-references/group/general/rename-group)

## Mail

* [Enable Or Disable External Mail](/automation/runbooks/runbook-references/group/mail/enable-or-disable-external-mail)
* [Show Or Hide In Address Book](/automation/runbooks/runbook-references/group/mail/show-or-hide-in-address-book)

## Teams

* [Archive Team](/automation/runbooks/runbook-references/group/teams/archive-team)

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Devices

On this overview page you can find all Group Runbooks in the Devices subcategory.

## Runbooks

* [Check Updatable Assets](/automation/runbooks/runbook-references/group/devices/check-updatable-assets)
* [Unenroll Updatable Assets (Scheduled)](/automation/runbooks/runbook-references/group/devices/unenroll-updatable-assets_scheduled)

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Check Updatable Assets

Check if devices in a group are onboarded to Windows Update for Business.

### Description

This runbook checks the Windows Update for Business onboarding status for all device members of a Microsoft Entra ID group. It queries each device and reports the enrollment state per update category and any returned error details. Use this to validate whether group members are correctly registered as updatable assets.

### Location

Group → Devices → Check Updatable Assets

**Full Runbook name**

rjgit-group\_devices\_check-updatable-assets

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Device.Read.All
  * Group.Read.All
  * WindowsUpdates.ReadWrite.All

#### Permission notes

Azure: Contributor on Storage Account

### Parameters

#### GroupId

Object ID of the group whose device members will be checked.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Unenroll Updatable Assets Scheduled

Unenroll devices from Windows Update for Business.

{% hint style="info" %}
This is a scheduled runbook. It is designed to run on a recurring schedule rather than being triggered for a single object. See [Scheduling](/automation/runbooks/scheduling) for details on how to configure runbook schedules.
{% endhint %}

### Description

This runbook unenrolls all device members of a Microsoft Entra ID group from Windows Update for Business updatable assets. You can remove a specific update category enrollment or delete the updatable asset registration entirely. Use this to offboard devices from WUfB reporting or to reset their enrollment state.

### Location

Group → Devices → Unenroll Updatable Assets (Scheduled)

**Full Runbook name**

rjgit-group\_devices\_unenroll-updatable-assets\_scheduled

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.1.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | yes                                |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Group.Read.All
  * WindowsUpdates.ReadWrite.All

### Parameters

#### GroupId

Object ID of the group whose device members will be unenrolled.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### UpdateCategory

The update category to unenroll from. Supported values are driver, feature, quality, or all.

| Property      | Value  |
| ------------- | ------ |
| Required      | true   |
| Default Value | all    |
| Type          | String |

#### IncludeUserOwnedDevices

When enabled, the runbook also resolves all user members of the group (including nested groups) and unenrolls every device the user is owner of.

| Property      | Value   |
| ------------- | ------- |
| Required      | false   |
| Default Value | False   |
| Type          | Boolean |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# General

On this overview page you can find all Group Runbooks in the General subcategory.

## Runbooks

* [Add Or Remove Nested Group](/automation/runbooks/runbook-references/group/general/add-or-remove-nested-group)
* [Add Or Remove Owner](/automation/runbooks/runbook-references/group/general/add-or-remove-owner)
* [Add Or Remove User](/automation/runbooks/runbook-references/group/general/add-or-remove-user)
* [Change Visibility](/automation/runbooks/runbook-references/group/general/change-visibility)
* [List All Members](/automation/runbooks/runbook-references/group/general/list-all-members)
* [List Owners](/automation/runbooks/runbook-references/group/general/list-owners)
* [List User Devices](/automation/runbooks/runbook-references/group/general/list-user-devices)
* [Remove Group](/automation/runbooks/runbook-references/group/general/remove-group)
* [Rename Group](/automation/runbooks/runbook-references/group/general/rename-group)

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Add Or Remove Nested Group

Add/remove a nested group to/from a group

### Description

This runbook adds a nested group to a target group or removes an existing nesting. It supports Microsoft Entra ID groups and Exchange Online distribution or mail-enabled security groups. Use the Remove switch to remove the nested group instead of adding it.

### Location

Group → General → Add Or Remove Nested Group

**Full Runbook name**

rjgit-group\_general\_add-or-remove-nested-group

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * User.Read.All
  * Group.ReadWrite.All
  * GroupMember.ReadWrite.All

### Parameters

#### GroupID

Object ID of the target group.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### NestedGroupID

Object ID of the group to add as a nested member.

| Property      | Value  |
| ------------- | ------ |
| Required      | true   |
| Default Value |        |
| Type          | String |

#### Remove

Set to true to remove the nested group membership, or false to add it.

| Property            | Value             |
| ------------------- | ----------------- |
| Required            | false             |
| Default Value       | False             |
| Type                | Boolean           |
| Portal display name | Remove this group |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Add Or Remove Owner

Add or remove a Office 365 group owner

### Description

This runbook adds a user as an owner of a group or removes an existing owner. For Microsoft 365 groups, it also ensures that newly added owners are members of the group. Use the Remove switch to remove ownership instead of adding it.

### Location

Group → General → Add Or Remove Owner

**Full Runbook name**

rjgit-group\_general\_add-or-remove-owner

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * User.Read.All
  * Group.ReadWrite.All
  * GroupMember.ReadWrite.All
* **Type**: Office 365 Exchange Online
  * Exchange.ManageAsApp

#### RBAC roles

* Exchange administrator

### Parameters

#### GroupID

Object ID of the target group.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### UserId

Object ID of the user to add or remove.

| Property      | Value  |
| ------------- | ------ |
| Required      | true   |
| Default Value |        |
| Type          | String |

#### Remove

"Add User as Owner" (final value: $false) or "Remove User as Owner" (final value: $true) can be selected as action to perform. If set to true, the runbook will remove the user from the group owners. If set to false, it will add the user as an owner of the group.

| Property            | Value               |
| ------------------- | ------------------- |
| Required            | false               |
| Default Value       | False               |
| Type                | Boolean             |
| Portal display name | Add or Remove Owner |

**Portal options**

| Portal option        | Value |
| -------------------- | ----- |
| Add User as Owner    | false |
| Remove User as Owner | true  |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Add Or Remove User

Add or remove a group member

### Description

This runbook adds a user to a group or removes a user from a group. It supports Microsoft Entra ID groups and Exchange Online distribution or mail-enabled security groups. Use the Remove switch to remove the user instead of adding the user.

### Location

Group → General → Add Or Remove User

**Full Runbook name**

rjgit-group\_general\_add-or-remove-user

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * User.Read.All
  * Group.ReadWrite.All
  * GroupMember.ReadWrite.All

### Parameters

#### GroupID

Object ID of the target group.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### UserId

Object ID of the user to add or remove.

| Property      | Value  |
| ------------- | ------ |
| Required      | true   |
| Default Value |        |
| Type          | String |

#### Remove

"Add User to Group" (final value: $false) or "Remove User from Group" (final value: $true) can be selected as action to perform. If set to true, the runbook will remove the user from the group. If set to false, it will add the user to the group.

| Property            | Value              |
| ------------------- | ------------------ |
| Required            | false              |
| Default Value       | False              |
| Type                | Boolean            |
| Portal display name | Add or Remove User |

**Portal options**

| Portal option         | Value |
| --------------------- | ----- |
| Add User as member    | false |
| Remove User as member | true  |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Change Visibility

Change a group's visibility

### Description

This runbook changes the visibility of a Microsoft 365 group between Private and Public. Set the Public switch to make the group public; otherwise it will be set to private. This does not change group membership, owners, or email addresses.

### Location

Group → General → Change Visibility

**Full Runbook name**

rjgit-group\_general\_change-visibility

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Group.ReadWrite.All

### Parameters

#### GroupID

Object ID of the target group.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### Public

"Make group private" (final value: $false) or "Make group public" (final value: $true) can be selected as action to perform.

| Property            | Value                |
| ------------------- | -------------------- |
| Required            | false                |
| Default Value       | False                |
| Type                | Boolean              |
| Portal display name | Set Group visibility |

**Portal options**

| Portal option      | Value |
| ------------------ | ----- |
| Make group private | false |
| Make group public  | true  |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# List All Members

List all members of a group, including members that are part of nested groups

### Description

This script retrieves the members of a specified EntraID group, including both direct members and those from nested groups. The output is a CSV file with columns for User Principal Name (UPN), direct membership status, and group path. The group path reflects the membership hierarchy—for example, “Primary, Secondary” if a user belongs to “Primary” via the nested group “Secondary.”

### Location

Group → General → List All Members

**Full Runbook name**

rjgit-group\_general\_list-all-members

### Details

| Property         | Value                                                                                   |
| ---------------- | --------------------------------------------------------------------------------------- |
| Version          | 1.0.3                                                                                   |
| Required modules | <p>RealmJoin.RunbookHelper (>= 0.8.7)<br>Microsoft.Graph.Authentication (>= 2.39.0)</p> |
| Schedulable      | no                                                                                      |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Group.Read.All
  * User.Read.All

### Parameters

#### GroupId

The Object ID of the Microsoft Entra ID group whose membership will be retrieved.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# List Owners

List all owners of an Office 365 group.

### Description

This runbook retrieves and lists the owners of the specified group. It uses Microsoft Graph to query the group and its owners and outputs the results as a table. Use this to quickly review ownership assignments.

### Location

Group → General → List Owners

**Full Runbook name**

rjgit-group\_general\_list-owners

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Group.Read.All

### Parameters

#### GroupID

Object ID of the target group.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# List User Devices

List devices owned by group members.

### Description

This runbook enumerates the users in a group and lists their registered devices. Optionally, it can add the discovered devices to a specified device group. Use this to create or maintain a device group based on group member ownership.

### Location

Group → General → List User Devices

**Full Runbook name**

rjgit-group\_general\_list-user-devices

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Group.Read.All

### Parameters

#### GroupID

Object ID of the group whose members will be evaluated.

| Property      | Value  |
| ------------- | ------ |
| Required      | true   |
| Default Value |        |
| Type          | String |

#### moveGroup

If set to true, the discovered devices are added to the target device group.

| Property      | Value   |
| ------------- | ------- |
| Required      | false   |
| Default Value | False   |
| Type          | Boolean |

#### targetgroup

Object ID of the target device group that receives the devices when moveGroup is enabled.

| Property      | Value  |
| ------------- | ------ |
| Required      | false  |
| Default Value |        |
| Type          | String |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Remove Group

Remove a group. For Microsoft 365 groups, also the associated resources (Teams, SharePoint site) will be removed.

### Description

This runbook deletes the specified group, which for Microsoft 365 groups means, that it also deletes the associated resources such as the Teams Team and the SharePoint Site.

### Location

Group → General → Remove Group

**Full Runbook name**

rjgit-group\_general\_remove-group

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Group.ReadWrite.All

### Parameters

#### GroupId

Object ID of the group to delete.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Rename Group

Rename a group.

### Description

This runbook updates a group's DisplayName, MailNickname, and Description. It does not change the group's email addresses. Provide only the fields you want to update; empty values are ignored.

### Location

Group → General → Rename Group

**Full Runbook name**

rjgit-group\_general\_rename-group

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * Group.ReadWrite.All

### Parameters

#### GroupId

Object ID of the group to update.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### DisplayName

New display name for the group.

| Property            | Value                       |
| ------------------- | --------------------------- |
| Required            | false                       |
| Default Value       |                             |
| Type                | String                      |
| Portal display name | New DisplayName / Team Name |

#### MailNickname

New mail nickname (alias) for the group.

| Property            | Value            |
| ------------------- | ---------------- |
| Required            | false            |
| Default Value       |                  |
| Type                | String           |
| Portal display name | New MailNickname |

#### Description

New description for the group.

| Property            | Value           |
| ------------------- | --------------- |
| Required            | false           |
| Default Value       |                 |
| Type                | String          |
| Portal display name | New Description |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Mail

On this overview page you can find all Group Runbooks in the Mail subcategory.

## Runbooks

* [Enable Or Disable External Mail](/automation/runbooks/runbook-references/group/mail/enable-or-disable-external-mail)
* [Show Or Hide In Address Book](/automation/runbooks/runbook-references/group/mail/show-or-hide-in-address-book)

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Enable Or Disable External Mail

Enable or disable external parties to send emails to a Microsoft 365 group

### Description

This runbook configures whether external senders are allowed to email a Microsoft 365 group. It uses Exchange Online to enable or disable the RequireSenderAuthenticationEnabled setting. You can also query the current state without making changes.

### Location

Group → Mail → Enable Or Disable External Mail

**Full Runbook name**

rjgit-group\_mail\_enable-or-disable-external-mail

### Details

| Property         | Value                                                                            |
| ---------------- | -------------------------------------------------------------------------------- |
| Version          | 1.0.1                                                                            |
| Required modules | <p>ExchangeOnlineManagement (>= 3.7.2)<br>RealmJoin.RunbookHelper (>= 0.8.7)</p> |
| Schedulable      | no                                                                               |

### Notes

Setting this via Microsoft Graph is broken as of 2021-06-28. Attribute: allowExternalSenders. See <https://docs.microsoft.com/en-us/graph/known-issues#setting-the-allowexternalsenders-property>.

### Permissions

#### Application permissions

* **Type**: Office 365 Exchange Online
  * Exchange.ManageAsApp

#### RBAC roles

* Exchange administrator

### Parameters

#### GroupId

Object ID of the Microsoft 365 group.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### Action

"Enable External Mail" (final value: 0), "Disable External Mail" (final value: 1) or "Query current state only" (final value: 2) can be selected as action to perform. If set to 0, the runbook will allow external senders to email the group. If set to 1, it will block external senders from emailing the group. If set to 2, it will return whether external mailing is currently enabled or disabled for the group without making any changes.

| Property            | Value         |
| ------------------- | ------------- |
| Required            | false         |
| Default Value       | 0             |
| Type                | Int32         |
| Portal display name | Choose action |

**Portal options**

| Portal option            | Value |
| ------------------------ | ----- |
| Enable External Mail     | 0     |
| Disable External Mail    | 1     |
| Query current state only | 2     |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Show Or Hide In Address Book

Show or hide a group in the address book

### Description

This runbook shows or hides a Microsoft 365 group or a distribution group from address lists. You can also query the current visibility state without making changes.

### Location

Group → Mail → Show Or Hide In Address Book

**Full Runbook name**

rjgit-group\_mail\_show-or-hide-in-address-book

### Details

| Property         | Value                                                                            |
| ---------------- | -------------------------------------------------------------------------------- |
| Version          | 1.0.1                                                                            |
| Required modules | <p>ExchangeOnlineManagement (>= 3.9.2)<br>RealmJoin.RunbookHelper (>= 0.8.7)</p> |
| Schedulable      | no                                                                               |

### Permissions

#### Application permissions

* **Type**: Office 365 Exchange Online
  * Exchange.ManageAsApp

#### RBAC roles

* Exchange administrator

### Parameters

#### GroupName

The identity of the target group (name, alias, or other Exchange identity value).

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

#### Action

"Show Group in Address Book" (final value: 0), "Hide Group from Address Book" (final value: 1) or "Query current state only" (final value: 2) can be selected as action to perform. If set to 0, the runbook will make the group visible in address lists. If set to 1, it will hide the group from address lists. If set to 2, it will return whether the group is currently hidden from address lists without making any changes.

| Property            | Value  |
| ------------------- | ------ |
| Required            | false  |
| Default Value       | 1      |
| Type                | Int32  |
| Portal display name | Action |

**Portal options**

| Portal option                | Value |
| ---------------------------- | ----- |
| Show Group in Address Book   | 0     |
| Hide Group from Address Book | 1     |
| Query current state only     | 2     |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Teams

On this overview page you can find all Group Runbooks in the Teams subcategory.

## Runbooks

* [Archive Team](/automation/runbooks/runbook-references/group/teams/archive-team)

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)


# Archive Team

Archive a team

### Description

This runbook archives a Microsoft Teams team backed by the specified Microsoft 365 group. It verifies that the group is provisioned as a team and then triggers the archive action via Microsoft Graph. Use this to decommission inactive teams while preserving their contents for review.

### Location

Group → Teams → Archive Team

**Full Runbook name**

rjgit-group\_teams\_archive-team

### Details

| Property         | Value                              |
| ---------------- | ---------------------------------- |
| Version          | 1.0.1                              |
| Required modules | RealmJoin.RunbookHelper (>= 0.8.7) |
| Schedulable      | no                                 |

### Permissions

#### Application permissions

* **Type**: Microsoft Graph
  * TeamSettings.ReadWrite.All

### Parameters

#### GroupID

Object ID of the Microsoft 365 group that backs the team.

| Property         | Value                                  |
| ---------------- | -------------------------------------- |
| Required         | true                                   |
| Default Value    |                                        |
| Type             | String                                 |
| Hidden in portal | yes (preset via runbook customization) |

[Back to Runbook Reference overview](/automation/runbooks/runbook-references)




---

[Next Page](/llms-full.txt/1)

