Overview
What RealmJoin is, which problems it solves next to Microsoft Intune, and what you need to run it.
What is RealmJoin?
RealmJoin is a cloud-native, multi-tenant SaaS and the Application Lifecycle and Management companion to Microsoft Intune. It is developed and operated by glueckkanja in Microsoft Azure, hosted in Europe, and requires no on-premise servers and no local infrastructure.
RealmJoin does not replace Intune - it builds on it. Intune stays your MDM: it enrolls devices, applies compliance and configuration policies, and delivers apps. RealmJoin adds what modern workplace teams need on top of it:
a maintained application catalogue and packaging service, so you stop building and updating packages yourself,
a single, correlated view of users, groups and devices across Intune, Entra ID, Microsoft Defender, Windows Autopilot and sign-in logs,
process automation through curated runbooks that run in your own Azure Automation account,
delegated administration and self service, so helpdesk staff and end users can act without broad Intune or Entra admin roles.
Administrators work in the RealmJoin Portal; on Windows clients, the optional RealmJoin Agent adds deployment and self-service capabilities directly on the device.
What RealmJoin covers
Application Management
The Package Store contains a continuously maintained catalogue of more than 3,000 ready-to-use Windows and macOS application packages. You subscribe to the packages you need, assign them to managed groups, and RealmJoin keeps versions and update channels (Preview / Main) flowing.
Generic packages are maintained for all customers; custom and organic packages cover applications specific to your environment - and if something is missing, you can raise a packaging request instead of packaging it yourself.
Each package can be delivered either as an Intune deployment (
intunewinpushed into your tenant) or as a RealmJoin deployment through the Agent. See Deployment Methods for the comparison; macOS packages are provisioned via Intune.With RealmJoin deployment you additionally get package dependencies and install order, auto-upgrades for Available apps, self-service reinstall/repair, user deferral options and reliable delivery of very large payloads.
User, Group and Device Management
RealmJoin merges data from several Microsoft services into one view per object. On a device you see its Intune state next to Autopilot registration, Defender risk and sign-in activity; on a user you see licenses, group memberships, devices and policies - without switching portals.
From there you can drill down across correlated objects, run Advanced Search queries, export data, and trigger context-specific actions directly on the object.
Process Automation
Runbooks automate the recurring tasks of a modern workplace: onboarding and offboarding, group and mailbox management, device outphasing and wiping, Autopilot cleanup, reporting, security responses such as isolating a device or reading out BitLocker and LAPS secrets.
The runbook library is kept in sync from a public GitHub repository and executed in your own Azure Automation account under a managed identity you control - you can add your own runbooks alongside it. Scheduled runbooks cover recurring reports and cleanups, and every job is logged and auditable.
RealmJoin Agent
The RealmJoin Agent is an optional Windows 10/11 component. It applies the software and configuration policy assigned to a device after a local security assessment, and adds features that Intune alone does not offer:
the RealmJoin ESP, which holds the desktop until mandatory apps are installed - honouring dependencies and order,
a Self Service Portal and tray menu for user-initiated installs,
LAPS with passwords stored in your own Azure Key Vault,
Delegation, self service and auditing
Roles and Permissions: delegate portal functionality to Entra users and groups with pre-defined or custom roles, optionally combined with Privileged Identity Management. Helpdesk teams get exactly the actions they need - nothing more.
Self service: every user has access to their own profile page, and Self Service Forms collect structured requests such as incident reports or equipment orders.
Audit Log: all actions performed in the portal are written to a Log Analytics workspace in your own Azure environment.
How it works
RealmJoin's backend runs in Microsoft Azure and connects to your tenant through least-privilege Entra ID applications that you consent to during onboarding. Sensitive workloads deliberately stay in your environment: runbooks execute in your Azure Automation account, LAPS passwords live in your Azure Key Vault, and audit logs go to your Log Analytics workspace.
What you need
A Microsoft 365 / Entra ID tenant with Microsoft Intune licenses. RealmJoin is licensed per user, based on the Intune user license seats in your tenant - see Licensing.
A Global Administrator to consent to the RealmJoin applications during onboarding. Quick Setup covers core portal functionality; Advanced Setup unlocks the full feature set, including Autopilot, the Agent, privileged device actions, LAPS, audit logs and security features.
An Azure subscription for the resources RealmJoin uses in your own environment: Azure Automation for runbooks, Key Vault for LAPS passwords and Log Analytics for audit and runbook logs. Expected Azure cost is minimal - see the FAQ.
Optional: the RealmJoin Agent on Windows 10/11 clients for RealmJoin-based app deployment and the Agent-exclusive features. Microsoft Defender for Endpoint features require the corresponding Microsoft license.
No on-premise servers, agents for the backend, or network appliances are required at any point.
Getting started
Pick the deployment guide that matches your scope and follow it end to end - from consenting to the RealmJoin applications to your first package assignment.
Last updated
Was this helpful?