Επεξεργασία

Using Remote Help with Microsoft Intune

The use of Remote Help depends on whether you're requesting help or providing help. In this article, we cover both scenarios.

Get help

To get help, you must reach out to your support staff to request assistance. You can reach out by way of call, chat, or email, and you're the sharer during the session.

Tip

The Remote Help app needs to be installed on your device. If Remote Help isn't installed, you can install Remote Help yourself by following the download instructions in the Install and update Remote Help section.

Starting the session:

  1. The helper can initiate a session or you can manually start the Remote Help app and enter a session code provided by the helper.

    Note

    If the helper initiates the session from Intune, a notification is sent to your device. Select Open Remote Help in the notification to open the Remote Help app and continue. If your computer is in do not disturb mode, you might not see the notification. In this case, manually open the Remote Help app to continue or check the notifications center.

  2. Verify the helper's identity by viewing their information, including their full name, job title, company, profile picture, and verified domain. Then choose to Allow screen sharing or full control or Decline the request.
  3. The session is established, and the helper can then help in resolving any issues on the device.

Note

If your organization allows unattended control, a support request can appear on your device even when you aren't actively using it. If you accept the request, or if you don't respond within 30 seconds, the unattended session starts automatically. If you decline the request, the session is canceled. You can't view the session while it's in progress, but you can reclaim your device at any time by signing back in to your previous session. Your session and open work are preserved, and no data is lost. The helper is notified when you sign back in.

During the session:

  • You can chat with the helper using the chat window in the Remote Help app.

  • Helpers that have the elevation permission can enter local admin permissions on your shared device. Elevation allows the helper to run executable programs or take similar actions when you lack sufficient permissions.

    Important

    During a Remote Help session, when a helper has the elevation permission, the helper can perform elevated actions on the sharer's device. When the sharer ends the Remote Help session, a dialog box warns them that if they continue, they're logged off. If the helper ends the session, the sharer isn't logged off.

  • The helper can request to move from screen sharing to full control if the session started with screen sharing only. You can choose to Allow full control or to Decline the request.

When the issues are resolved or you're ready to end the session:

  • Both the sharer and helper can end the session. To end the session, select Leave in the upper-right corner of the Remote Help app.

Provide help

To provide help, you must reach out to the user who needs assistance. You can reach out by phone, chat, or email, and you're the helper during the session.

Attended support

An attended support session requires an end user to participate and grant access to the helper. Attended sessions support view-only access, full control, and optional UAC elevation.

As a helper, after receiving a request from a user who wants assistance by using the Remote Help app:

  1. Launch a session on the remote device from within the Microsoft Intune admin center:

    1. Sign in to the Microsoft Intune admin center, go to Devices > All devices, and select the device on which assistance is needed.

    2. From the remote actions bar across the top of the device view, select New remote assistance session > Remote Help > Continue.

      Note

      If you launch the session from Intune, sign in to the Remote Help app with the same credentials to establish the connection.

  2. Select Initiate attended control to request view or full control of the device that requires the user to accept the session.

  3. A notification is sent to the sharer's device, and you see an update that the notification was successfully sent. Select Open Remote Help to join the session.

    1. If the notification is sent but not received by the user, you can resend the notification by selecting Retry.

    2. If the sharer's device isn't connected to the internet, an error message is displayed.

    3. If the device that you're trying to connect to is noncompliant, a warning banner is displayed.

  4. When Remote Help opens, you must sign in to authenticate to your organization.

  5. After the sharer opens the Remote Help app through the notification, as the helper you see information about the sharer, including their full name, job title, company, profile picture, and verified domain. The sharer sees similar information about you.

    At this time, you can request a session with full control of the sharer's device or choose only screen sharing. If you request full control, the sharer can choose to Allow full control or to Decline the request.

  6. After establishing that the session uses a shared display or full control, Remote Help displays a compliance warning if the sharer's device fails to meet the conditions of its assigned compliance policies.

    During assistance, helpers that have the elevation permission can enter local admin permissions on your shared device. Elevation allows the helper to run executable programs or take similar actions when you lack sufficient permissions.

    Note

    When the EnableSecureCredentialPrompting policy is enabled, it blocks the elevation process during Remote Help sessions. To allow elevation, disable this policy. For more information, see Enable secure credential prompting.

  7. After the issues are resolved, or at any time during the session, both the sharer and helper can end the session. To end the session, select Leave in the upper right corner of the Remote Help app. If a helper performs elevated actions on a user's device and the sharer ends the session, at the end of the session the sharer is automatically signed out.

Unattended support

An unattended support session allows an authorized helper to access and control an Intune-managed device without an active participant in the session.

  1. Launch a session on the remote device from within the Microsoft Intune admin center:

    1. Sign in to the Microsoft Intune admin center, go to Devices > All devices, and select the device on which assistance is needed.

    2. From the remote actions bar across the top of the device view, select New remote assistance session > Remote Help > Continue.

  2. Select Initiate unattended control to take full control of the device without an end user present.

  3. Remote Help starts the unattended session on the target device.

    • If you don't have permission to perform unattended control, you're notified.
    • If the target device is marked as a personal (BYOD) device, unattended control isn't supported and you're notified.
    • If the device that you're trying to connect to is noncompliant, a warning banner is displayed.
    • If the target device doesn't meet the prerequisites for unattended control, you're notified which requirements are missing.
    • If the sharer's device isn't connected to the internet, an error message is displayed.
  4. A progress panel shows the real-time status as Intune orchestrates the connection. When the session is ready, select Open Remote Help to join the unattended session.

  5. Remote Help opens a new browser tab and launches Windows App (web client). Sign in by using the same account that you used to access the Intune admin center.

  6. When prompted, choose whether to allow access to local resources such as:

    • File transfer
    • Clipboard paste-through
    • Remote Desktop virtual printer
  7. After connecting to the target device, sign in within the remote session using one of the following account types:

    • Local Windows account (ComputerName\UserName)
    • Active Directory domain account (Domain\UserName)
    • User principal name (UPN)
    • Microsoft Entra ID account (UPN)

    Least-privilege access is enforced. Signing in with a standard user account doesn't grant administrator privileges.

    Note

    Only one helper can establish an unattended connection to a target device at a time, and only one unattended session can be active on a device at a time.

  8. If a user is actively signed in to the device, they're notified and can choose whether to allow the unattended session:

    • Select Yes to continue the unattended connection.
    • Select No to cancel the unattended connection.

    If no one is signed in to the device, the unattended session starts automatically.

    If the user doesn't respond, the notification is displayed for 30 seconds, and then the unattended session starts automatically. After the timeout:

    • The user's current session is locked and their work is preserved.
    • Remote Help connects to a separate Windows session.
    • The user sees the Windows lock screen and can't view activity in the unattended session.
  9. During an unattended session, the signed-in user can regain control of the device at any time by signing back in from the lock screen. When this occurs, they're notified and can choose to:

    • Continue the unattended session.
    • Disconnect the unattended session.
  10. During the unattended session, you can use supported Remote Desktop web client features, such as clipboard and device redirection, as available in your environment.

  11. When troubleshooting is complete, end the session.

  12. After the session ends:

    • The device returns to its previous state.
    • The user's session remains available.
    • The user can sign back in and resume their work.

Note

  • Remote Help displays a compliance warning if the sharer's device fails to meet the conditions of its assigned compliance policies.
  • If the tenant is configured to allow Remote Help on unenrolled devices, you receive a warning when connecting to unenrolled devices. This warning doesn't block access but provides transparency about the risk of using sensitive data, like administrative credentials, during the session.

Next steps

Get support in the Microsoft Intune admin center.