Microsoft Intune Remote Help
Android

Plan for Remote Help with Microsoft Intune

In brief

The plan page now defines unattended sessions as authorized helper access without an active participant and documents support for Windows and Android. It adds guidance on dedicated Intune roles, Conditional Access, privacy, and limitations.

What Intune admins need to know

Administrators planning unattended support should review helper permissions, security controls, and privacy implications, including reduced oversight for unenrolled devices.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Planning for Remote Help with Microsoft Intune

Use these considerations to prepare your organization for Remote Help.

  • Enforce least privilege: Only grant the minimum Remote Help permissions needed for each support role. Use custom Intune roles if necessary to limit who can take full control or perform unattended sessions. For example, level-1 support might get view-only rights, while tier-2 gets full control rights. This principle helps protect user privacy and device integrity.

  • Scope unattended control narrowly: Unattended control allows a helper to troubleshoot to a device without an end user present. Create a dedicated custom Intune role that includes the Windows unattended control remote sign-in and Android unattended control permissions, and assign it only to authorized support personnel, such as Tier 3 helpdesk staff or senior administrators. Scope the role to only the device groups that require unattended support.

  • Use Conditional Access for helpers: Since helpers have elevated access intoto user devices, add an extra layer of security. Requiring MFA or compliant device status for helper accounts viathrough Conditional Access is highly recommended. These measures ensure thathelp prevent a compromised helper account can't easily befrom being used maliciously to access devices. Microsoft Entra ID Conditional Access policies for Remote Help are supported only supported on Windows and macOS.

  • Enable unenrolled device support only if needed: Allowing Remote Help on unenrolled devices (Entra(Microsoft Entra registered only) is convenient for supporting personal devices, but it comes with reduced oversight (nooversight, such as no device compliance infoinformation or limited audit data).data. Enable thatthis feature thoughtfullythoughtfully, and consider limiting which support staff can help unenrolled devices (perhaps viaby using separate roles).roles.

  • Network and firewall: Verify that corporate network policies don't interfere with Remote Help. The app communicates over port 443 to Azure cloud endpoints. If your users are on a corporate network, ensure proxy or SSL inspection doesn't break the connection. If your proxy servers are using SSL inspection, the domains listed for Remote Help should be excluded to avoid issues. For more information, see Network endpoints for Remote Help.

  • Combine with Endpoint Analytics: Use data from Remote Help sessions to identify common issues. For example, if many sessions show compliance warnings, consider improving your device compliance policies. Remote Help audit logs combined with Intune Endpoint Analytics might provide insights into support trends, such as frequently problematic apps or policies.

  • Keep the Remote Help apps up to date: New versions of Windows and macOS bring improvements and required fixes. Microsoft might enforce upgrades for older versions. Use automatic updates on both platforms, or regularly deploy the latest package through Intune after testing. For Android, updates are available through Google Play. Monitor devices during regular maintenance windows to ensure that they receive the latest version.

  • Plan for privacy and compliance: Remote Help may raise privacy concerns. To help address these concerns, communicate that Remote Help requires user consent for attended sessions. For unattended access on Windows and Android devices, users can't observe the actions performed by support personnel but they're notified when an unattended session is active. All Remote Help sessions are clearly indicated to users, and no session recordings are stored by the service. Consider documenting these behaviors in your organization's IT policies and user guidance. Because unattended access allows support without an active user present, use it only for appropriate administrative and support scenarios.

  • Rollout in phases: If possible, deploy Remote Help in a pilot phase. Start with IT or a small department to work out any issues. Gather feedback from both helpers and users. Once you are confident, expand to the whole organization. A phased approach can prevent overwhelming the helpdesk with unexpected technical issues.

These are the different modes:

  • Attended: Support session in which an end user participates and grants access to the helper. Attended sessions support view-only access, full control, and optional UAC elevation.

    View only: Request view of the remote screen. To minimize effect on end user privacy, this option is recommended unless full control is necessary.

    Request full control: Request full control of the remote device.

    Elevation: Allows helpers to enter User Account Control (UAC) credentials when prompted on the sharer's device. Enabling elevation also allows the helper to view and control the sharer's device when the sharer grants the helper access.

  • Unattended: A support session that allows authorized helpers to access and control an Intune-managed device without an active participant in the session. This capability is supported on Windows and Android devices.

This table shows the mode support by helper app and sharer app.

Helping from:
Windows native
Helping from:
Windows web
Helping from:
macOS web
Sharing from:
Windows native
✅ View only
✅ Full control
✅ Elevation
✅ Unattended Unsupported
Sharing from:
macOS native
Unsupported ✅ View only
✅ Full control
✅ View only
✅ Full control
Sharing from:
Android native
Unsupported ✅ View only
✅ Full control
✅ Unattended
✅ View only
✅ Full control
✅ Unattended
Sharing from:
macOS webapp
Unsupported ✅ View only ✅ View only
Sharing from:
Windows webapp
Unsupported ✅ View only ✅ View only

For information about deploying the Remote Help apps, see Deploy Remote Help.

Authentication and permissions

Permission Description
Remote Help app - View screen Allows the helper to view the sharer's screen without taking control.
Remote Help app - Take full control Allows the helper to take full control of the sharer's device.
Remote Help app - Elevation Allows the helper to interact with the user account control prompts on Windows.
Remote Help app - UnattendedAndroid unattended control Allows the helper to connect to Android devices without requiring the sharer to accept the connection each time. This capability requires the Android device to be enrolled in Intune as a dedicated device. Assign this permission explicitly and scope it to the specific devices that can receive unattended support.
Remote Help app - Windows unattended control remote sign-inAllows the helper to start an unattended remote sign-in session to a targeted, physical, corporate-owned Windows device without requiring the sharer to accept the connection each time. Assign this permission explicitly and scope it to the specific devices that can receive unattended support.
Remote Tasks - Offer remote assistance Allows the helper to offer remote assistance to users.
Remote Assistance Connector - Read Required to allow the user to see if Remote Help is configured for the tenant when starting a session.

The following Intune built-in roles include Remote Help permissions:

  • Help Desk Operator (View screen, take full control, elevation, unattended,Android unattended control, Remote Tasks - Offer remote assistance, Remote Assistance Connector - Read)
  • School Administrator (View screen, take full control, elevation, Remote Tasks - Offer remote assistance, Remote Assistance Connector - Read)

:::image type="icon" source="../media/icons/16/windows.svg"::: Windows

For attended control, Remote Help supports:

  • Windows x86, x64, and ARM64
  • Windows 365
  • Azure Virtual Desktop (desktop and RemoteApp sessions)

There are optionalFor unattended control, additional requirements apply. The target device must be a physical, Intune-managed, corporate-owned Windows updatesdevice running an x64-based operating system and be Microsoft Entra joined or Microsoft Entra hybrid joined. Virtual devices, including Windows 365 and Azure Virtual Desktop, as well as unenrolled and personally owned (BYOD) devices, aren't supported for higher notification reliability:unattended control. Devices that don't meet these requirements can still receive attended support.

Theand the Intune management extension is required onManagement Extension up to date to ensure the sharer's device for the remote launch feature. Specifically for Windows 10 the OS builds need to be greater than or equal to version 19042 and have KB5018410 patch installed. The OS version should be greater than or equal to 10.0.19042.2075 or 10.0.19043.2075 or 10.0.19044.2075.most reliable experience. For more information about the Intune management extension,information, see Intune management extension.

We don't recommend remotely starting a session to users on Azure virtual desktops. For more information, see Provide help in Azure Virtual Desktop desktop and RemoteApp sessions.

Remote Help communicates over port 443 (https) and connects to the Remote Assistance Service at https://remotehelp.microsoft.com by using the Remote Desktop Protocol (RDP). The traffic is encrypted with TLS 1.2.

Requirements if Remote Help is restricted to enrolled devicesand prerequisites

:::image type="icon" source="../media/icons/16/windows.svg"::: Windows

Attended control

If your organization restricts Remote Help to enrolled devices only, there are extra requirements.

:::image type="icon" source="../media/icons/16/windows.svg"::: Windows

Thethe sharer's Windows device must be enrolled into the same tenant where the Remote Help session is starting from.

Unattended control

Remote Help for unattended control is supported only on enrolled devices. The following requirements also apply to the target device:

  • The Azure Virtual Desktop agent and Azure Virtual Desktop agent bootloader must be installed. Install the agent first, and then install the bootloader. No further configuration is required after installation. You can deploy both as Win32 apps. For more information, see Deploy Remote Help.
  • The Intune Management Extension must be installed. It's required to orchestrate the unattended session.
  • Remote Desktop must be enabled on the device. You can enable this setting through an Intune settings catalog configuration profile.
  • The device must be powered on and connected to the internet. Devices that are asleep, hibernating, or shut down can't receive unattended support.
  • The helper must be assigned the Remote Help app - Windows unattended control remote sign-in permission scoped to the target devices.

:::image type="icon" source="../media/icons/16/macos.svg"::: macOS

TheIf your organization restricts Remote Help to enrolled devices, the following requirements ensure Remote Help can authenticate the user and recognize the device as enrolled:

  1. Configure the Microsoft Enterprise SSO plug-in. For more information, see Use Enterprise SSO Plug-in on macOSUse Enterprise SSO Plug-in on macOS.
  2. Open and sign in to Company Portal. The user must open and sign in to Company Portal for Remote Help to recognize the device is enrolled.

:::image type="icon" source="../media/icons/16/android.svg"::: Android

Remote Help doesn't support unenrolled devices on Android.only supports enrolled Android devices.

:::image type="icon" source="../media/icons/16/globe.svg"::: Web App

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…