User and Group Settings
RealmJoin Client settings and features like LAPS applied at tenant, group, or user scope, with narrower scopes overriding broader ones.
Overview
Settings can be used to control RealmJoin Client's behavior and configure features like LAPS.
If settings have been created/assigned to users, you can review them under
- User Settings
Accordingly, if settings have been applied to any group, including "RealmJoin - All Users", these can be reviewed under
- Group Settings.
Tenant Default Values
Default setting values can be defined at different scopes. The broadest scope is the tenant-wide client configuration, found in the Settings section of the RealmJoin Portal and accessible to any administrator. Settings defined there apply to all users unless overridden at a narrower scope.

The built-in RealmJoin group "RealmJoin - All Users" can be used to override tenant-wide defaults across all users. Settings assigned to a real user or group scope will in turn override both of these, as individual group and user assignments carry the highest priority.
The resulting priority order is: tenant-wide client config < RealmJoin - All Users < group scope < user scope.
If the same setting is assigned to several of the user's groups, one of those group values is applied; assign a setting to a single group per user to keep the result predictable. A setting assigned directly to the user always overrides any group value.
Example:
To define a baseline channel for all users, set the RealmJoin Agent Channel to "release" in the tenant-wide client config. To override this for all users at once, set "beta" on the "RealmJoin - All Users" group. To target only a specific set of users, assign "beta" directly to a dedicated group. The more specific scope always takes precedence.
Settings Editor

Be aware: The value of the setting must be valid JSON, which includes singular values like true or strings (without brackets).
The switches in the lower half of the wizard allow scoping this setting to certain scenarios like VDI / Windows365 machines. A setting that is filtered out by these switches behaves as if it had never been assigned:
Only in VDI / Ignore in VDI — apply the setting only on, or never on, VDI (W365/AVD) devices. The two switches are mutually exclusive.
Only on hybrid-joined devices / Ignore on hybrid-joined devices — apply the setting only on, or never on, hybrid-joined devices. These two are mutually exclusive as well.
Ignore on private devices — skip the setting on private devices (not Entra ID joined).
You can modify and delete settings from the Settings Editor. You cannot create new settings here - Please navigate to the user or group you want a setting applied to and create the setting there.
See Available Settings to review which settings can be used.
Last updated
Was this helpful?