Microsoft Intune Remote Help
Windows

Using Remote Help on Windows to Assist Authenticated Users

In brief

The documentation now covers initiating attended and unattended Remote Help sessions from the Intune admin center, including connection steps, account types, local-resource access, and eligibility checks.

What Intune admins need to know

Admins can access Intune-managed Windows devices without an active participant when permitted, while personal devices and devices missing prerequisites aren't supported. No action is required.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Using Remote Help with Microsoft Intune

  1. Verify the helper's identity by viewing their information, including their full name, job title, company, profile picture, and verified domain. Then choose to Allow screen sharing or full control or Decline the request.
  2. The session is established, and the helper can then help in resolving any issues on the device.

During the session:

  • You can chat with the helper using the chat window in the Remote Help app.

To provide help, you must reach out to the user who needs assistance. You can reach out by phone, chat, or email, and you're the helper during the session.

:::image type="icon" source="../media/icons/16/windows.svg"::: Windows from the Intune admin center

Attended support

During the session:

  • You can chat with the helper using the chat window in the Remote Help app.

To provide help, you must reach outAn attended support session requires an end user to participate and grant access to the user who needs assistance. You can reach out by phone, chat, or email,helper. Attended sessions support view-only access, full control, and you're the helper during the session.optional UAC elevation.

Windows from Windows native app

As a helper, after receiving a request from a user who wants assistance by using the Remote Help app:

  1. Launch a session on the remote device from within the Microsoft Intune admin center:

    1. Sign in to the [Microsoft Intune admin center] and, go to Devices > All devices, and select the device on which assistance is needed.

    2. From the remote actions bar across the top of the device view, select New remote assistance session and select> Remote Help, and then > Continue.

  1. Select Initiate attended control to request view or full control of the device that requires the user to accept the session.

  2. A notification is sent to the sharer's device, and you see an update that the notification was successfully sent. Select Open Remote Help to join the session.

    1. If the notification is sent but not received by the user, you can resend the notification by selecting Retry.

    2. If the sharer's device isn't connected to the internet, an error message is displayed.

    3. If the device that you're trying to connect to is noncompliant, a warning banner is displayed.

  3. After the issues are resolved, or at any time during the session, both the sharer and helper can end the session. To end the session, select Leave in the upper right corner of the Remote Help app. If a helper performs elevated actions on a user's device and the sharer ends the session, at the end of the session the sharer is automatically signed out.

Unattended support

An unattended support session allows an authorized helper to access and control an Intune-managed device without an active participant in the session.

  1. Launch a session on the remote device from within the Microsoft Intune admin center:

    1. Sign in to the [Microsoft Intune admin center], go to Devices > All devices, and select the device on which assistance is needed.

    2. From the remote actions bar across the top of the device view, select New remote assistance session > Remote Help > Continue.

  2. Select Initiate unattended control to take full control of the device without an end user present.

  3. Remote Help starts the unattended session on the target device.

    • If you don't have permission to perform unattended control, you're notified.
    • If the target device is marked as a personal (BYOD) device, unattended control isn't supported and you're notified.
    • If the device that you're trying to connect to is noncompliant, a warning banner is displayed.
    • If the target device doesn't meet the prerequisites for unattended control, you're notified which requirements are missing.
    • If the sharer's device isn't connected to the internet, an error message is displayed.
  4. A progress panel shows the real-time status as Intune orchestrates the connection. When the session is ready, select Open Remote Help to join the unattended session.

  5. Remote Help opens a new browser tab and launches Windows App (web client). Sign in by using the same account that you used to access the Intune admin center.

  6. When prompted, choose whether to allow access to local resources such as:

    • File transfer
    • Clipboard paste-through
    • Remote Desktop virtual printer
  7. After connecting to the target device, sign in within the remote session using one of the following account types:

    • Local Windows account (ComputerName\UserName)
    • Active Directory domain account (Domain\UserName)
    • User principal name (UPN)
    • Microsoft Entra ID account (UPN)

    Least-privilege access is enforced. Signing in with a standard user account doesn't grant administrator privileges.

  1. If a user is actively signed in to the device, they're notified and can choose whether to allow the unattended session:

    • Select Yes to continue the unattended connection.
    • Select No to cancel the unattended connection.

    If no one is signed in to the device, the unattended session starts automatically.

    If the user doesn't respond, the notification is displayed for 30 seconds, and then the unattended session starts automatically. After the timeout:

    • The user's current session is locked and their work is preserved.
    • Remote Help connects to a separate Windows session.
    • The user sees the Windows lock screen and can't view activity in the unattended session.
  2. During an unattended session, the signed-in user can regain control of the device at any time by signing back in from the lock screen. When this occurs, they're notified and can choose to:

    • Continue the unattended session.
    • Disconnect the unattended session.
  3. During the unattended session, you can use supported Remote Desktop web client features, such as clipboard and device redirection, as available in your environment.

  4. When troubleshooting is complete, end the session.

  5. After the session ends:

    • The device returns to its previous state.
    • The user's session remains available.
    • The user can sign back in and resume their work.

:::image type="icon" source="../media/icons/16/windows.svg"::: Windows from Windows native app

  1. Provide help to unenrolled Windows devices

    Navigate toIf the device that you're trying to help fromisn't enrolled in Microsoft Intune, follow the Microsoft Intune admin center:process described in this section to provide help.

    1. SignOpen the Remote Help app on your device and sign in to the [Microsoft Intune admin center] and go to Devices > All devices. Select the macOS device on which assistance is needed.with your organizational account.

    2. FromUnder Give help, select Get a security code. Give the remote action bar acrossgenerated security code to the top of the device view, select New remote assistance session and select Remote Help. sharer requesting assistance.

    3. SelectThe sharer opens Remote Help, signs in with their organizational account, enters the security code, and selects ContinueSubmit.

  2. Copy and share the eight-digit session code withVerify the sharer that you're trying to help. Then select Start to launch a new Remote Help session.

  3. When Remote Help opens in a new tab for the first time, you must sign in to authenticate to your organization.

  4. After the sharer navigates to the Remote Help session, as the helper you'll see information about the sharer,s identity by reviewing their information, including their full name, job title, company, profile picture, and verified domain. The sharer sees similar information about you.

  5. At this time, you can request a session withRequest view-only access or full control of the sharer's device or choose only screen sharing.control. The sharer can choose to Allowallow or to Declinedecline the request.

  6. When troubleshooting is complete, either participant can select Leave to end the session.

Enrolled macOS

Provide help in Azure Virtual Desktop desktop and RemoteApp sessions

In an Azure Virtual Desktop (AVD) desktop session, helpers can access and control a user's entire remote desktop. In an AVD RemoteApp session, helpers can only view and interact with the published app the user is running, not the full desktop.

Although helpers can initiate Remote Help from the Intune admin center for AVD desktop sessions, the request is broadcast to all active users on the host. AVD RemoteApp sessions can't be directly targeted from the Intune admin center. In both scenarios, use the security code method to connect to the correct user session.

  1. Open the Remote Help app on your device and sign in with your organizational account.

  2. Under Give help, select Get a security code. Give the generated security code to the sharer requesting assistance.

  3. The sharer enters the security code to establish the connection:

    • AVD desktop session: Open Remote Help in the active AVD session and enter the security code.
    • AVD RemoteApp session: Open Remote Help within the RemoteApp session and enter the security code. After the connection is established, helpers can view and interact only with the published app available in that session.

:::image type="icon" source="../media/icons/16/intune.svg"::: macOS from the Intune admin center

  1. The helper navigates to the device to connect to the [Microsoft Intune admin center].

  2. To invite a user to a session, provide the user with the security code.

    • If the sharer is also using the web app:

      • Copy and share the session link with the user (the link is limited to View Only) (For example: https://aka.ms/rh?passcode=4060r0gx). The link opens in the user's web browser. You can only request a screen sharing session of the device.
    • If the sharer is using the macOS application:

      • Share the eight-character security code with the user. You can request a screen sharing session. View only and full control are supported.
  3. When Remote Help opens in a new tab for the first time, you must sign in to authenticate to your organization.

  4. After the sharer either selects the link or enters the code into Remote Help for macOS, they're joined to the session. If the user isn't already signed in to the app, they're prompted to do so.

    • The sharer can see information about the helper.
  5. You can request a session with full control of the sharer's device or choose only screen sharing. The sharer can choose to Allow or to Decline the request after viewing the trust screen.request.

  6. If the sharer's device isn't compliant with your organization's policies, Remote Help displays a compliance warning that encourages the helper to be cautious.

Provide help to unenrolled macOS unenrolled device

If the device that you're trying to help isn't enrolled in Microsoft Intune, follow the process described in this section to provide help.

b. From the remote action bar across the top of the device view, select New remote assistance session. Select Remote Help, and then select Continue.

c. Select the session type from the options for which you have permission: screen sharing, full control, unattended control. Then select LaunchOpen Remote Help.

  1. On the device, the user sees a prompt showing a request to grant screen share or control of the device.

  2. After the sharer enters the session code, as the helper you'll see information about the sharer, including their full name, job title, company, profile picture, and verified domain. The sharer sees similar information about you.

  3. At this time, you can request a session with full control of the sharer's device or choose only screen sharing. The sharer can choose to Allow or to Decline the request.


Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…