role-based access control (rbac)
6 TopicsRemote Help on Windows: Unattended Support with Remote Sign-In Is Here
By: Rodolfo Bermudez | Sr. Product Manager & Kara Wang | Product Manager 2 - Microsoft Intune Helpdesk teams have long asked for a way to remotely troubleshoot Windows devices without needing the user to be present. Whether it’s after-hours maintenance on a shared device in a call center, or a device sitting idle at a remote office, waiting for a user to be available shouldn’t be the blocker to getting work done. With Intune’s August release, we’re excited to announce Remote Help Windows Unattended Support with Remote Sign-In a new capability that lets helpdesk staff remotely access physical Windows devices by signing in with credentials they have access to, without requiring the user to grant access or even be logged in. Why this matters Previously, every Remote Help session on Windows required the user to be present at the device to accept the connection. Now Remote Help Windows Unattended Support enables: After-hours support - Devices that need maintenance outside business hours can be serviced without scheduling time with users. Improved Helpdesk efficiency - Tier 2 support staff don't spend extra time coordinating schedules that often take only minutes to fix. Remote locations get the help they need - Branch offices without on-site IT have path to immediate remediation. With unattended capabilities your helpdesk connects directly to the Windows login screen, authenticates with their own credentials, and works in a separate Windows session, all while the user’s session remains safely locked and preserved. What the feature enables Capability Details Remote Access Without User Presence Helpers can sign in with their own credentials and establish a new Windows session on the target device, even when no user is actively connected. Session Isolation The user's existing session remains locked and preserved, preventing disruption while support activities are performed in a separate session. Security-First Design Uses least-privilege access, a dedicated RBAC permission, and a complete audit trail to help maintain security and compliance requirements. User Awareness If a user is currently signed in, they receive a notification and can choose to accept or reject the remote access request. Rich Session Features Supports file transfer, clipboard passthrough, Remote Desktop Virtual Printer, multi-monitor support, and other productivity-enhancing capabilities. Prerequisites Licensing Remote Help is included with Microsoft Intune Suite, Remote Help standalone add-on, or Microsoft 365 E3/E5. Remote Help must be enabled in the tenant. You can find step-by-step instructions in the following article: Deploy Remote Help with Microsoft Intune. Device requirements Requirement Details Ownership Supports corporate-owned enrolled devices that are Microsoft Entra joined or Hybrid Microsoft Entra joined. Personal and BYOD devices aren't supported. Platform Requires physical Windows devices running x64-based operating systems. Virtual machines aren't currently supported. Device State The device must be powered on, connected to the internet, able to reach the required Microsoft service endpoints, and have the Intune Management Extension installed. Role-based access control (RBAC) permission This feature uses a dedicated permission: Remote Help app > Windows unattended control remote sign-in. It must be explicitly assigned to helpdesk roles targeting specific device groups. To maintain a higher security boundary, this permission isn’t included in any Intune built-in role, including existing roles such as Help Desk Operator or School Administrator, and must be granted through a custom role assignment. Tip: Limit Access to Unattended Support Consider creating a dedicated custom role for unattended support rather than including it in your standard Remote Help roles. Because unattended access enables support sessions without an end user present, it's a best practice to restrict this capability to Tier 2 and Tier 3 support staff or senior administrators, and scope access only to the devices they are responsible for managing. Figure 1: Remote Help app settings in the Microsoft Intune admin center showing enabled and disabled permissions, including elevation, screen viewing, full control, and Windows unattended control at remote sign-in. How to set it up Step 1: Configure RBAC In the Intune admin center, go to Tenant administration > Roles Create or edit a custom role Under Permissions > Remote Help app, enable Windows unattended control remote sign-in Assign to your helpdesk groups, scoping to the device groups that should receive unattended support Step 2: Deploy Azure Virtual Desktop agents Required agents Azure Virtual Desktop Agent. Azure Virtual Desktop Agent Bootloader. Package both the AVD Agent MSI and AVD Agent Bootloader MSI as Win32 apps in Intune. Deploy to the same target device groups that are intended to receive unattended support from Step 1. No ongoing maintenance is required - the components auto-update. Step 3: Enable Remote Desktop Go to Devices > Windows > Configuration profiles > Create profile Platform: Windows 10 and later | Profile type: Settings catalog Add setting: Search for Remote Desktop > Enable "Allow users to connect remotely using Remote Desktop" Assign to your target device groups Verify: Devices > Configuration profiles > Device status The helper experience: A walkthrough Starting the session From the Intune admin center, navigate to the target device and select "..." > New remote assistance session. A side panel appears with two options: Initiate attended control: sessions in which a signed-in end user is present and grants access to the helper Initiate unattended control: sessions in which an authorized helper can access and control an Intune managed device without a signed in end user present Select Initiate unattended control and click Select. Figure 2: Microsoft Intune admin center device overview with the Remote Help panel open, showing the option to initiate an unattended control session on a corporate Windows device. Built-in safety checks Before connecting, the Intune portal validates several conditions: Condition What You'll See Missing RBAC Permission The unattended control option is disabled and displays the message: "You can only select session types for which you have permission." Personal Device The unattended control option is disabled and displays: "Unattended control is not available on personal devices." Device Noncompliant A warning appears indicating the device doesn't meet your organization's security or compliance requirements. Device Offline The connection attempt fails and displays: "Make sure the user's device is on and connected to the internet." Missing Prerequisites The Remote Help pane in the Intune admin center indicates that required agents, policies, permissions, or device settings haven't been configured. Microsoft Intune Remote Help panel displaying a notice that unattended control is unavailable for a personally owned device, with session options disabled. Connection progress and success A progress panel shows real-time status: "Starting unattended session on user’s device" followed by green checkmarks when successful, with an "Open Remote Help" link. If the connection fails, for example because the device is offline or there is a network connectivity related issue, you’ll see a clear error with a Retry option. Microsoft Intune Remote Help panel confirming that an unattended remote session has started on a managed Windows device, with a link to open Remote Help. This will launch a new browser tab opening the Windows App (web client). The helper may need to authenticate again using the same username and credentials used to authenticate to Intune Admin portal. Signing in to the remote device Once connected, the helper then needs to authenticate to the device within the remote session. You can sign in using a local Windows account (ComputerName\UserName), an Active Directory domain account (Domain\UserName or UPN), or a Microsoft Entra ID account (UPN), whichever is appropriate based on the join state of the device and the scenario. Least privilege is enforced - a standard user account does not gain Administrator permissions. When a user is currently signed in If someone is actively using the device, the helper sees: "Another user is signed in. If you continue, they’ll be disconnected. Do you want to sign in anyway?" Windows sign-in screen displaying a prompt warning that another user is signed in and asking whether to continue with a remote sign-in session. Choosing "Yes" locks the user’s session (preserving their work) and connects the helper to a separate Windows session. The device-side experience User notification (when someone is present) If a user is signed in, they see a notification: "Do you want to allow the helper to connect to this machine? Click OK to disconnect your session immediately or click Cancel to stay connected. No action will disconnect your session in 30 seconds." Windows 11 desktop showing a Remote Desktop Connection dialog requesting approval for a remote user to connect, with options to allow or cancel the session. If they don’t respond in 30 seconds, the unattended session starts automatically. During the session The end user’s console shows their lock screen. They cannot see what the helper is doing. The helper works in a separate Windows session. Taking back control The end user can regain control at any time by signing back into their session from the lock screen. The helper is notified and can choose to disconnect. Monitoring and audit Unattended sessions are fully auditable using the same reporting infrastructure as existing Remote Help: Session monitoring: Tenant administration > Remote Help > Monitor tab (active sessions, average time, total sessions) Session history: Remote Help sessions tab with Provider, Recipient, Device, OS, session type (Unattended/Attended), and export capability Audit logs: Tenant administration > Audit logs - filter by category "RemoteHelp" for complete session lifecycle events For detailed step-by-step instructions on monitoring, reporting, and auditing Remote Help sessions, see: Troubleshoot and monitor Remote Help for Microsoft Intune. Security at a glance Control How It Works Corporate-Only Access Only Intune-enrolled, corporate-owned physical devices that are Microsoft Entra joined or Hybrid Microsoft Entra joined are eligible for unattended support. Explicit RBAC Permission Uses a dedicated permission separate from traditional Remote Help scenarios that require user presence. This permission is included in the built-in Intune Help Desk Operator role. Least Privilege The helper's actions are limited to the permissions associated with the Windows account used to sign in to the target device. User Awareness If a user is actively signed in, they receive a notification and a 30-second window to accept or reject the unattended access request. Session Isolation Support occurs in a separate Windows session, keeping the user's active session locked and preventing access to in-use applications or data. Full Audit Trail All unattended support sessions are logged to support auditing, compliance reviews, and operational accountability. 12-Hour Maximum Session Duration Unattended sessions automatically terminate after 12 hours to help reduce security risk and prevent abandoned connections. Key things to remember Things to Keep in Mind ✅ Three setup steps: RBAC role + AVD agents + Remote Desktop config profile, all targeting the same device groups. ✅ Corporate-owned physical devices only: Personal and virtual devices are not supported at GA. ✅ Dedicated RBAC permission: Use Windows unattended control remote sign-in. ✅ Devices must be online: Sleep, hibernate, and powered-off devices cannot receive unattended sessions. ✅ User sessions are preserved: If a user is signed in, their session is locked, not terminated. ✅ Auto-updating agents: The AVD agent updates automatically, so no ongoing deployment maintenance is required. Frequently asked questions Can I start an unattended session from the Remote Help app? No. Unattended sessions can only be initiated from the device page in the Intune admin center. What if a user rejects the connection? If they click Cancel, nothing happens and the session doesn't start. What happens if no one responds to the notification? After 30 seconds with no response, the unattended session starts automatically. Does this work on Windows 365 or AVD? We are working towards providing support for Windows 365 and Azure Virtual Desktop in the future. What's the maximum session length? Sessions can last up to 12 hours. After 12 hours, the session automatically disconnects. This limit isn't configurable. What credentials can I use to sign in? Users can sign in using a local Windows account (ComputerName\UserName), an Active Directory domain account (Domain\UserName or UPN), or a Microsoft Entra ID account (UPN), whichever is appropriate based on the join state of the device and the scenario. Resources to learn more Remote Help overview Microsoft 365 Roadmap Role-based access control (RBAC) with Microsoft Intune Remote Help Documentation: aka.ms/remotehelpdocs We’d love to hear your feedback! Share your thoughts in the comments below, follow us on LinkedIn or reach out to us on X @IntuneSuppTeam or @MSIntune.2KViews0likes3Comments