For the complete documentation index, see llms.txt. This page is also available as Markdown.

Advanced Telemetry

What the RealmJoin Agent reports about a device by default, what the RealmJoin Telemetry Package adds on top, and where that information appears in the RealmJoin Portal.

The RealmJoin Agent regularly reports a device state to RealmJoin — a snapshot of what the device looks like right now. That state is what feeds "Last Seen", the hardware and software information on a device, the compliance signals and the device exports in the Portal.

Advanced Telemetry extends that baseline with additional information that Windows does not expose to Intune, or only exposes with considerable effort: real hardware details, Microsoft 365 Apps configuration, Windows Update safeguard holds, logon method, BIOS management status and more. It is delivered through the RealmJoin Telemetry Package from the Package Store.

Advanced Custom Telemetry is part of RealmJoin Enterprise. See Licensing for the full feature comparison.

What is collected by default

As soon as the RealmJoin Agent is installed, it reports the following without any additional package:

Area
Examples

Identity & operating system

Machine and host name, joined domain, Windows version and display version, language and culture, installed RealmJoin Agent version

Enrollment

Entra ID tenant, device and user IDs, Workplace Join data, Intune account and device ID

Security

Firewall profile states, installed antivirus products, BitLocker volume states, TPM information, Defender for Endpoint onboarding state

Updates

Windows Update state

Network

Resolved RealmJoin CDN endpoints, proxy configuration, metered-connection flag

Content delivery

Delivery Optimization group, BranchCache mode, cache size and hit counters

Software

State of all RealmJoin-managed packages plus a full software inventory (installed programs and Microsoft Store apps)

LAPS

Local admin accounts managed by RealmJoin and their password status — see Local Admin Password Solution (LAPS)

Integrations

AnyDesk ID, notification message states

Session

Deployment phase, logged-on user, logon time, whether the user is a local administrator

What Advanced Telemetry adds

The RealmJoin Telemetry Package (generic-realmjoin-publishstate-computersystem-information) adds the following information to the device state:

Information
Values

Computer system information

Manufacturer, model, serial number, BIOS version

Enhanced machine information

CPU name and speed, installed memory, disk drives, MAC addresses, OEM license key, last boot time, Secure Boot / UEFI 2023 CA certificate state

Microsoft 365 Apps (Click-to-Run)

Update channel, reported version, platform, excluded apps

Windows Update safeguard holds

Active safeguard holds blocking feature updates, including their severity

Windows logon

Last used logon provider — reveals whether users sign in with Windows Hello for Business (fingerprint / facial recognition) or with a password

Device certificates

Subject, thumbprint, issuer and validity of the certificates on the device

BIOS management

RealmJoin BIOS Management report: BIOS version, BIOS password status, BIOS settings status

Assign the Telemetry Package to users, not devices. See Recommended Packages for the packages we recommend alongside the Agent.

Where the data appears in the Portal

Once the Telemetry Package is deployed, the additional information shows up throughout the Portal:

  • Device details — manufacturer, model and serial number, CPU and memory, last boot time, Microsoft 365 Apps update channel, the UEFI 2023 CA badge, and an alert when a device has critical Windows Update safeguard holds.

  • Device list — the Manufacturer, Model and Serial Number columns, and "Last Seen" enriched with Agent telemetry where available.

  • Advanced Search — filter your device list on the reported values, see Advanced Search.

  • Exports — the device export includes serial number, CPU name and speed, memory and Office channel columns, see Data Export.

Data protection and retention

The device state is transmitted to the RealmJoin backend together with the regular configuration request and is stored in the Azure region West Europe. It is archived for 90 days, after which retention policies remove the data.

Custom telemetry is visible to everyone who is permitted to view the device in the Portal. For details on data processing, storage and sub-processors, see Security & Privacy.

Last updated

Was this helpful?