Using Remote Help on Windows to Assist Authenticated Users
In brief
The documentation now covers initiating attended and unattended Remote Help sessions from the Intune admin center, including connection steps, account types, local-resource access, and eligibility checks.
What Intune admins need to know
Admins can access Intune-managed Windows devices without an active participant when permitted, while personal devices and devices missing prerequisites aren't supported. No action is required.
This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Using Remote Help with Microsoft Intune
- Verify the helper's identity by viewing their information, including their full name, job title, company, profile picture, and verified domain. Then choose to Allow screen sharing or full control or Decline the request.
- The session is established, and the helper can then help in resolving any issues on the device.
During the session:
- You can chat with the helper using the chat window in the Remote Help app.
To provide help, you must reach out to the user who needs assistance. You can reach out by phone, chat, or email, and you're the helper during the session.
:::image type="icon" source="../media/icons/16/windows.svg"::: Windows from the Intune admin center
Attended support
During the session:
You can chat with the helper using the chat window in the Remote Help app.
To provide help, you must reach outAn attended support session requires an end user to participate and grant access to the user who needs assistance. You can reach out by phone, chat, or email,helper. Attended sessions support view-only access, full control, and you're the helper during the session.optional UAC elevation.
Windows from Windows native app
As a helper, after receiving a request from a user who wants assistance by using the Remote Help app:
Launch a session on the remote device from within the Microsoft Intune admin center:
Sign in to the [Microsoft Intune admin center]
and, go to Devices > All devices, and select the device on which assistance is needed.From the remote actions bar across the top of the device view, select New remote assistance session
and select> Remote Help, and then> Continue.
Select Initiate attended control to request view or full control of the device that requires the user to accept the session.
A notification is sent to the sharer's device, and you see an update that the notification was successfully sent. Select Open Remote Help to join the session.
If the notification is sent but not received by the user, you can resend the notification by selecting Retry.
If the sharer's device isn't connected to the internet, an error message is displayed.
If the device that you're trying to connect to is noncompliant, a warning banner is displayed.
After the issues are resolved, or at any time during the session, both the sharer and helper can end the session. To end the session, select Leave in the upper right corner of the Remote Help app. If a helper performs elevated actions on a user's device and the sharer ends the session, at the end of the session the sharer is automatically signed out.
Unattended support
An unattended support session allows an authorized helper to access and control an Intune-managed device without an active participant in the session.
Launch a session on the remote device from within the Microsoft Intune admin center:
Sign in to the [Microsoft Intune admin center], go to Devices > All devices, and select the device on which assistance is needed.
From the remote actions bar across the top of the device view, select New remote assistance session > Remote Help > Continue.
Select Initiate unattended control to take full control of the device without an end user present.
Remote Help starts the unattended session on the target device.
- If you don't have permission to perform unattended control, you're notified.
- If the target device is marked as a personal (BYOD) device, unattended control isn't supported and you're notified.
- If the device that you're trying to connect to is noncompliant, a warning banner is displayed.
- If the target device doesn't meet the prerequisites for unattended control, you're notified which requirements are missing.
- If the sharer's device isn't connected to the internet, an error message is displayed.
A progress panel shows the real-time status as Intune orchestrates the connection. When the session is ready, select Open Remote Help to join the unattended session.
Remote Help opens a new browser tab and launches Windows App (web client). Sign in by using the same account that you used to access the Intune admin center.
When prompted, choose whether to allow access to local resources such as:
- File transfer
- Clipboard paste-through
- Remote Desktop virtual printer
After connecting to the target device, sign in within the remote session using one of the following account types:
- Local Windows account (
ComputerName\UserName) - Active Directory domain account (
Domain\UserName) - User principal name (UPN)
- Microsoft Entra ID account (UPN)
Least-privilege access is enforced. Signing in with a standard user account doesn't grant administrator privileges.
- Local Windows account (
If a user is actively signed in to the device, they're notified and can choose whether to allow the unattended session:
- Select Yes to continue the unattended connection.
- Select No to cancel the unattended connection.
If no one is signed in to the device, the unattended session starts automatically.
If the user doesn't respond, the notification is displayed for 30 seconds, and then the unattended session starts automatically. After the timeout:
- The user's current session is locked and their work is preserved.
- Remote Help connects to a separate Windows session.
- The user sees the Windows lock screen and can't view activity in the unattended session.
During an unattended session, the signed-in user can regain control of the device at any time by signing back in from the lock screen. When this occurs, they're notified and can choose to:
- Continue the unattended session.
- Disconnect the unattended session.
During the unattended session, you can use supported Remote Desktop web client features, such as clipboard and device redirection, as available in your environment.
When troubleshooting is complete, end the session.
After the session ends:
- The device returns to its previous state.
- The user's session remains available.
- The user can sign back in and resume their work.
:::image type="icon" source="../media/icons/16/windows.svg"::: Windows from Windows native app
Provide help to unenrolled Windows devices
Navigate toIf the device that you're trying to helpfromisn't enrolled in Microsoft Intune, follow theMicrosoft Intune admin center:process described in this section to provide help.SignOpen the Remote Help app on your device and sign into the [Microsoft Intune admin center] and go toDevices>All devices. Select the macOS device on which assistance is needed.with your organizational account.FromUnder Give help, select Get a security code. Give theremote action bar acrossgenerated security code to thetop of the device view, selectNew remote assistance sessionand selectRemote Help.sharer requesting assistance.SelectThe sharer opens Remote Help, signs in with their organizational account, enters the security code, and selectsContinueSubmit.
Copy and share the eight-digit session code withVerify the sharerthat you're trying to help. Then selectStartto launch a new Remote Help session.When Remote Help opens in a new tab for the first time, you must sign in to authenticate to your organization.After the sharer navigates to the Remote Help session, as the helper you'll see information about the sharer,s identity by reviewing their information, including their full name, job title, company, profile picture, and verified domain.The sharer sees similar information about you.At this time, you can request a session withRequest view-only access or fullcontrol of the sharer's device or choose only screen sharing.control. The sharer canchoose toAllowallow ortoDeclinedecline the request.When troubleshooting is complete, either participant can select Leave to end the session.
Enrolled macOSProvide help in Azure Virtual Desktop desktop and RemoteApp sessions
In an Azure Virtual Desktop (AVD) desktop session, helpers can access and control a user's entire remote desktop. In an AVD RemoteApp session, helpers can only view and interact with the published app the user is running, not the full desktop.
Although helpers can initiate Remote Help from the Intune admin center for AVD desktop sessions, the request is broadcast to all active users on the host. AVD RemoteApp sessions can't be directly targeted from the Intune admin center. In both scenarios, use the security code method to connect to the correct user session.
Open the Remote Help app on your device and sign in with your organizational account.
Under Give help, select Get a security code. Give the generated security code to the sharer requesting assistance.
The sharer enters the security code to establish the connection:
- AVD desktop session: Open Remote Help in the active AVD session and enter the security code.
- AVD RemoteApp session: Open Remote Help within the RemoteApp session and enter the security code. After the connection is established, helpers can view and interact only with the published app available in that session.
:::image type="icon" source="../media/icons/16/intune.svg"::: macOS from the Intune admin center
The helper navigates to the device to connect to the [Microsoft Intune admin center].
To invite a user to a session, provide the user with the security code.
If the sharer is also using the web app:
- Copy and share the session link with the user
(the link is limited to View Only)(For example: https://aka.ms/rh?passcode=4060r0gx). The link opens in the user's web browser. You can only request a screen sharing session of the device.
- Copy and share the session link with the user
If the sharer is using the macOS application:
- Share the eight-character security code with the user.
You can request a screen sharing session. View only and full control are supported.
- Share the eight-character security code with the user.
When Remote Help opens in a new tab for the first time, you must sign in to authenticate to your organization.
After the sharer either selects the link or enters the code into Remote Help for macOS, they're joined to the session. If the user isn't already signed in to the app, they're prompted to do so.
- The sharer can see information about the helper.
You can request a session with full control of the sharer's device or choose only screen sharing. The sharer can choose to Allow or to Decline the
request after viewing the trust screen.request.If the sharer's device isn't compliant with your organization's policies, Remote Help displays a compliance warning that encourages the helper to be cautious.
Provide help to unenrolled macOS unenrolled device
If the device that you're trying to help isn't enrolled in Microsoft Intune, follow the process described in this section to provide help.
b. From the remote action bar across the top of the device view, select New remote assistance session. Select Remote Help, and then select Continue.
c. Select the session type from the options for which you have permission: screen sharing, full control, unattended control. Then select LaunchOpen Remote Help.
On the device, the user sees a prompt showing a request to grant screen share or control of the device.
After the sharer enters the session code, as the helper you'll see information about the sharer, including their full name, job title, company, profile picture, and verified domain. The sharer sees similar information about you.
At this time, you can request a session with full control of the sharer's device or choose only screen sharing. The sharer can choose to Allow or to Decline the request.
@@ -1,9 +1,12 @@ ----title: Using Remote Help on Windows to Assist Authenticated Users +title: Using Remote Help on Windows to Assist Authenticated Users description: Use the Remote Help app to provide remote assistance to authenticated users who also run the Remote Help app, and to troubleshoot for frontline workers (FLW).-ms.date: 06/24/2026+ms.date: 08/13/2026 ms.topic: how-to+ai-usage: ai-assisted+ms.custom: msecd-doc-authoring-1023 ms.reviewer: Karawang+#customer intent: As a helper or sharer, I want to start and participate in Remote Help sessions so that I can provide or receive remote assistance. --- # Using Remote Help with Microsoft Intune@@ -27,6 +30,9 @@ To get help, you must reach out to your support staff to request assistance. You 1. Verify the helper's identity by viewing their information, including their full name, job title, company, profile picture, and verified domain. Then choose to **Allow screen sharing or full control** or **Decline the request**. 1. The session is established, and the helper can then help in resolving any issues on the device. +> [!NOTE]+> If your organization allows unattended control, a support request can appear on your device even when you aren't actively using it. If you accept the request, or if you don't respond within 30 seconds, the unattended session starts automatically. If you decline the request, the session is canceled. You can't view the session while it's in progress, but you can reclaim your device at any time by signing back in to your previous session. Your session and open work are preserved, and no data is lost. The helper is notified when you sign back in.+ **During the session:** - You can chat with the helper using the chat window in the Remote Help app.@@ -118,25 +124,29 @@ Remote Help displays a warning if the sharer's device isn't enrolled in Microsof To provide help, you must reach out to the user who needs assistance. You can reach out by phone, chat, or email, and you're the helper during the session. -### [**Windows from Windows native app**](#tab/windowsnative)+### [:::image type="icon" source="../media/icons/16/windows.svg"::: **Windows from the Intune admin center**](#tab/windowsintune)++#### Attended support++An attended support session requires an end user to participate and grant access to the helper. Attended sessions support view-only access, full control, and optional UAC elevation. As a helper, after receiving a request from a user who wants assistance by using the Remote Help app: 1. Launch a session on the remote device from within the Microsoft Intune admin center:- - 1. Sign in to the [Microsoft Intune admin center] and go to **Devices** > **All devices** and select the device on which assistance is needed.+ 1. Sign in to the [Microsoft Intune admin center], go to **Devices** > **All devices**, and select the device on which assistance is needed.++ 1. From the remote actions bar across the top of the device view, select **New remote assistance session** > **Remote Help** > **Continue**. - 2. From the remote actions bar across the top of the device view, select **New remote assistance session** and select **Remote Help**, and then **Continue**.+ > [!NOTE]+ > If you launch the session from Intune, sign in to the Remote Help app with the same credentials to establish the connection. - > [!NOTE]- > If you're launching the session from Intune, sign in to the Remote Help app with the same credentials for a successful- > connection.+1. Select **Initiate attended control** to request view or full control of the device that requires the user to accept the session. -1. A notification is sent to the sharer's device, and you see an update that the notification was successfully sent. Select **Launch Remote Help** to join the session.+1. A notification is sent to the sharer's device, and you see an update that the notification was successfully sent. Select **Open Remote Help** to join the session. 1. If the notification is sent but not received by the user, you can resend the notification by selecting **Retry**. - 2. If the sharer's device isn't online or not connected to the internet, an error message is displayed.+ 1. If the sharer's device isn't connected to the internet, an error message is displayed. 3. If the device that you're trying to connect to is noncompliant, a warning banner is displayed. @@ -155,42 +165,106 @@ As a helper, after receiving a request from a user who wants assistance by using 1. After the issues are resolved, or at any time during the session, both the sharer and helper can end the session. To end the session, select **Leave** in the upper right corner of the Remote Help app. If a helper performs elevated actions on a user's device and the sharer ends the session, at the end of the session the sharer is automatically signed out. -#### Provide help in Azure Virtual Desktop desktop and RemoteApp sessions +#### Unattended support++An unattended support session allows an authorized helper to access and control an Intune-managed device without an active participant in the session.++1. Launch a session on the remote device from within the Microsoft Intune admin center:+ 1. Sign in to the [Microsoft Intune admin center], go to **Devices** > **All devices**, and select the device on which assistance is needed.++ 1. From the remote actions bar across the top of the device view, select **New remote assistance session** > **Remote Help** > **Continue**.++1. Select **Initiate unattended control** to take full control of the device without an end user present.++1. Remote Help starts the unattended session on the target device.++ - If you don't have permission to perform unattended control, you're notified.+ - If the target device is marked as a personal (BYOD) device, unattended control isn't supported and you're notified.+ - If the device that you're trying to connect to is noncompliant, a warning banner is displayed.+ - If the target device doesn't meet the prerequisites for unattended control, you're notified which requirements are missing.+ - If the sharer's device isn't connected to the internet, an error message is displayed.++1. A progress panel shows the real-time status as Intune orchestrates the connection. When the session is ready, select **Open Remote Help** to join the unattended session.++1. Remote Help opens a new browser tab and launches Windows App (web client). Sign in by using the same account that you used to access the Intune admin center.++1. When prompted, choose whether to allow access to local resources such as:+ - File transfer+ - Clipboard paste-through+ - Remote Desktop virtual printer++1. After connecting to the target device, sign in within the remote session using one of the following account types:+ - Local Windows account (`ComputerName\UserName`)+ - Active Directory domain account (`Domain\UserName`)+ - User principal name (UPN)+ - Microsoft Entra ID account (UPN)++ Least-privilege access is enforced. Signing in with a standard user account doesn't grant administrator privileges.++ > [!NOTE]+ > Only one helper can establish an unattended connection to a target device at a time, and only one unattended session can be active on a device at a time.++1. If a user is actively signed in to the device, they're notified and can choose whether to allow the unattended session:+ - Select **Yes** to continue the unattended connection.+ - Select **No** to cancel the unattended connection. -In an Azure Virtual Desktop (AVD) desktop session, helpers can access and control a user's entire remote desktop. In an AVD RemoteApp session, helpers can only view and interact with the published app the user is running, not the full desktop. + If no one is signed in to the device, the unattended session starts automatically. -Although helpers can initiate Remote Help from the Intune admin center for AVD desktop sessions, the request is broadcast to all active users on the host. AVD RemoteApp sessions can't be directly targeted from the Intune admin center. In both scenarios, use the security code method to connect to the correct user session. + If the user doesn't respond, the notification is displayed for 30 seconds, and then the unattended session starts automatically. After the timeout:+ - The user's current session is locked and their work is preserved.+ - Remote Help connects to a separate Windows session.+ - The user sees the Windows lock screen and can't view activity in the unattended session.++1. During an unattended session, the signed-in user can regain control of the device at any time by signing back in from the lock screen. When this occurs, they're notified and can choose to:+ - Continue the unattended session.+ - Disconnect the unattended session.++1. During the unattended session, you can use supported [Remote Desktop web client features](/previous-versions/remote-desktop-client/client-features-web-cloud), such as clipboard and device redirection, as available in your environment.++1. When troubleshooting is complete, end the session.++1. After the session ends:+ - The device returns to its previous state.+ - The user's session remains available.+ - The user can sign back in and resume their work.++### [:::image type="icon" source="../media/icons/16/windows.svg"::: **Windows from Windows native app**](#tab/windowsnative)++#### Provide help to unenrolled Windows devices++If the device that you're trying to help isn't enrolled in Microsoft Intune, follow the process described in this section to provide help. 1. Open the Remote Help app on your device and sign in with your organizational account. 1. Under **Give help**, select **Get a security code**. Give the generated security code to the sharer requesting assistance. -1. The sharer enters the security code to establish the connection: - - AVD desktop session: Open Remote Help in the active AVD session and enter the security code. - - AVD RemoteApp session: Launch Remote Help within the RemoteApp session and enter the security code. After the connection is established, helpers can view and interact only with the published app available in that session. +1. The sharer opens Remote Help, signs in with their organizational account, enters the security code, and selects **Submit**. ->[!NOTE]-> The restart option isn't available for helpdesk agents remotely helping AVD.+1. Verify the sharer's identity by reviewing their information, including their full name, job title, company, profile picture, and verified domain. -### [:::image type="icon" source="../media/icons/16/intune.svg"::: **macOS from the Intune admin center**](#tab/macosintune)+1. Request view-only access or full control. The sharer can allow or decline the request. -1. Navigate to the device you're trying to help from the Microsoft Intune admin center:+1. When troubleshooting is complete, either participant can select **Leave** to end the session. - 1. Sign in to the [Microsoft Intune admin center] and go to **Devices** > **All devices**. Select the macOS device on which assistance is needed.+#### Provide help in Azure Virtual Desktop desktop and RemoteApp sessions - 1. From the remote action bar across the top of the device view, select **New remote assistance session** and select **Remote Help**. +In an Azure Virtual Desktop (AVD) desktop session, helpers can access and control a user's entire remote desktop. In an AVD RemoteApp session, helpers can only view and interact with the published app the user is running, not the full desktop. - 1. Select **Continue**. +Although helpers can initiate Remote Help from the Intune admin center for AVD desktop sessions, the request is broadcast to all active users on the host. AVD RemoteApp sessions can't be directly targeted from the Intune admin center. In both scenarios, use the security code method to connect to the correct user session. -1. Copy and share the eight-digit session code with the sharer that you're trying to help. Then select **Start** to launch a new Remote Help session.+1. Open the Remote Help app on your device and sign in with your organizational account. -1. When Remote Help opens in a new tab for the first time, you must sign in to authenticate to your organization.+1. Under **Give help**, select **Get a security code**. Give the generated security code to the sharer requesting assistance. -1. After the sharer navigates to the Remote Help session, as the helper you'll see information about the sharer, including their full name, job title, company, profile picture, and verified domain. The sharer sees similar information about you.+1. The sharer enters the security code to establish the connection:+ - AVD desktop session: Open Remote Help in the active AVD session and enter the security code.+ - AVD RemoteApp session: Open Remote Help within the RemoteApp session and enter the security code. After the connection is established, helpers can view and interact only with the published app available in that session. -1. At this time, you can request a session with full control of the sharer's device or choose only screen sharing. The sharer can choose to **Allow** or to **Decline** the request. +> [!NOTE]+> The restart option isn't available for help desk agents remotely helping AVD.++### [:::image type="icon" source="../media/icons/16/intune.svg"::: **macOS from the Intune admin center**](#tab/macosintune) -### Enrolled macOS device 1. The helper navigates to the device to connect to the [Microsoft Intune admin center]. @@ -203,10 +277,12 @@ Although helpers can initiate Remote Help from the Intune admin center for AVD d 1. To invite a user to a session, provide the user with the security code. - If the sharer is also using the web app:- - Copy and share the session link with the user (the link is limited to View Only) (For example: https://aka.ms/rh?passcode=4060r0gx). The link opens in the user's web browser. You can only request a screen sharing session of the device.+ - Copy and share the session link with the user (For example: https://aka.ms/rh?passcode=4060r0gx). The link opens in the user's web browser. You can only request a screen sharing session of the device. - If the sharer is using the macOS application:- - Share the eight-character security code with the user. You can request a screen sharing session. View only and full control are supported. + - Share the eight-character security code with the user.++1. When Remote Help opens in a new tab for the first time, you must sign in to authenticate to your organization. 1. After the sharer either selects the link or enters the code into Remote Help for macOS, they're joined to the session. If the user isn't already signed in to the app, they're prompted to do so. @@ -216,11 +292,11 @@ Although helpers can initiate Remote Help from the Intune admin center for AVD d - The sharer can see information about the helper. -1. The sharer can choose to **Allow** or to **Decline** the request after viewing the trust screen.+1. You can request a session with full control of the sharer's device or choose only screen sharing. The sharer can choose to **Allow** or to **Decline** the request. 1. If the sharer's device isn't compliant with your organization's policies, Remote Help displays a compliance warning that encourages the helper to be cautious. -#### macOS unenrolled device +#### Provide help to unenrolled macOS device If the device that you're trying to help isn't enrolled in Microsoft Intune, follow the process described in this section to provide help. @@ -244,7 +320,7 @@ Remote Help displays a warning if the sharer's device isn't enrolled in Microsof b. From the remote action bar across the top of the device view, select **New remote assistance session**. Select **Remote Help**, and then select **Continue**. - c. Select the session type from the options for which you have permission: screen sharing, full control, unattended control. Then select **Launch Remote Help**.+ c. Select the session type from the options for which you have permission: screen sharing, full control, unattended control. Then select **Open Remote Help**. 1. On the device, the user sees a prompt showing a request to grant screen share or control of the device. @@ -278,6 +354,8 @@ Remote Help displays a warning if the sharer's device isn't enrolled in Microsof 1. After the sharer enters the session code, as the helper you'll see information about the sharer, including their full name, job title, company, profile picture, and verified domain. The sharer sees similar information about you. 1. At this time, you can request a session with full control of the sharer's device or choose only screen sharing. The sharer can choose to **Allow** or to **Decline** the request. ++ --- > [!NOTE]