A remote support session that cannot exist without two of your own signed-in accounts.
Remote Help opens a session only after the technician and the employee have each authenticated with your organization's Entra ID, applies role-based limits to what the technician may do once inside, flags a policy-noncompliant device before the connection is made, and writes every session into reporting and audit logs. When a SOC 2 auditor or a cyber insurance questionnaire asks how endpoint remote access is governed, that combination is the answer they are looking for.

- Both sign inHelper and user, every session
- Role scopedView, control and elevation split by role
- LoggedEvery session lands in reports and audit logs
- Tenant onlyExternal organizations are unreachable
Disabled until you switch it on, and locked to your own tenant.
Both facts come straight from the documentation, and the second decides whether Remote Help replaces your current tool or merely joins it.
- Intune tenants ship with Remote Help disabled, and the enable switch applies to the whole tenant at once. Treat that as a design deadline: the helper role model should exist on paper before the feature exists in production.
- Because every session demands organizational Entra sign-in from both sides, Microsoft states the tool functions only inside your own tenant. A helper has no way to assist a user who lives in a different tenant or an outside organization.
- Judge that boundary against who you actually support. Internal staff only: the restriction costs nothing and buys real security. Client tenants, contractors or partners outside your directory: some other tool must remain for that slice of the population.
- Unenrolled Windows and macOS devices can be brought in through an optional setting, disabled by default, without weakening the sign-in requirement. Budget for the documented catch that their sessions produce a thinner audit trail than enrolled ones.
Eight properties that set Remote Help apart from a generic screen-sharing tool.
Two authenticated identities or no session
Each session requires both the helper and the sharer to sign in with Entra accounts belonging to your organization. There is no session code to phish, no standing agent listening for connections, and no anonymous path onto a device. Considering how often US incident reports trace back to a misused remote access product, closing that door by design is worth a great deal.
Helper permissions divided by role, not handed out flat
The role model separates who may view a screen from who may request full control, and separately governs which helpers can exercise elevated privileges during a session, an example Microsoft itself calls out. Compare that with the typical deployment of a commercial tool, where every technician holds identical unrestricted access from day one.
The device's compliance state disclosed up front
When the target device fails its assigned compliance policies, the helper is shown a warning before the connection opens. The timing is the point: the person who may be about to enter admin credentials on that machine learns it is out of policy at the exact moment the knowledge can change their behavior.
A session history you can hand to an assessor
The Intune admin center reports capture which helper assisted which user, on which device, and the session duration, with active sessions visible too, and sessions recorded in the audit logs under tenant administration. One documented gap to plan around: sessions on unenrolled devices leave a reduced audit record.
Admin credentials entered by the admin, not dictated to the user
Windows elevation lets the helper respond to UAC prompts on the sharer's device with their own administrative credentials, and enabling it also permits view and control once the user consents. It exists to retire a habit every support team recognizes: an admin password spoken over a call or typed in front of the person being helped.
Connections with nobody on the other end, for Android only
On Android, a helper can attach without per-session acceptance from a user, and Microsoft ties this strictly to devices enrolled as Android Enterprise dedicated devices. That scoping matches reality: digital signage, kiosk hardware, shared scanners and similar equipment have no operator available to click accept.
A chat thread that persists and speaks more than English
The enhanced chat keeps every message in one continuous thread and handles special characters and additional languages, with Chinese and Arabic named in the documentation. For US employers with multilingual staff, correct rendering of non-Latin scripts plus a thread that outlives the session turns chat from a convenience into part of the record.
Your Conditional Access policies govern the tool too
Conditional Access can be pointed at Remote Help itself: Microsoft's examples include demanding multifactor authentication from helpers and confining access to particular locations or compliant devices. The product that can take over any endpoint arguably deserves your strictest access policy, and here that is actually configurable.
Four parts of a deployment that decide whether it sticks.
Roles drawn up before the feature goes live
Enablement is tenant-wide and immediate, so the sequencing matters: view-only rights, full-control rights and elevation rights get mapped to your actual support tiers first, then the switch flips. A desk whose first tier starts at view only has made a deliberate, defensible choice, and that choice is easiest to make before anyone has acquired broader access.
The tenant boundary tested against reality, early
The documentation is unambiguous that helpers cannot assist users in another tenant or an external organization. We inventory who your desk actually supports before the pilot, because discovering mid-rollout that contractors or client users sit outside the boundary turns a clean replacement project into an awkward partial one.
Elevation deployed as a password-hygiene fix
The recurring anti-pattern in support work is an administrative credential disclosed to a user so a fix can proceed. Windows elevation ends it: the helper answers the UAC prompt on the remote machine with their own credentials, the user never hears a password, and the privileged action still happens. We configure it, restrict who holds it, and retire the old habit.
The consolidation math done before renewal season
Because Remote Help ships within the Intune advanced capabilities, plenty of tenants already own a governed remote support product while renewing an ungoverned one. Where the tenant boundary fits your support model, the project can end with one fewer subscription and one fewer agent on every endpoint, which tends to settle the business case on its own.
Six situations where governed remote support earns its keep.
Answering the assessor's remote access question well
HIPAA risk analyses, SOC 2 audits, FTC Safeguards reviews and cyber insurance applications all probe the same nerve: who can remotely reach endpoints, under what restrictions, with what record. Per-role helper scoping, dual organizational sign-in and session reports naming helper, user, device and duration convert that from an uncomfortable question into a short one.
Untangling a desk where access is one-size-fits-all
The intern and the senior engineer hold identical full-control rights because the incumbent tool knows no better. Moving to role-scoped access, view only for early tiers, elevation for a named few, matches technician capability to technician responsibility without slowing anyone's work down.
Fixing kiosks and signage without a road trip
Unattended Android access, restricted by Microsoft to Android Enterprise dedicated devices, is purpose-built for hardware with no human attendant: menu boards, self-service kiosks, warehouse scanners. For estates strung across states, it is frequently the line between a remote fix and a day of windshield time.
Shrinking the support loop for a scattered workforce
Remote launch pushes a notification to the user's Windows device that opens the session from Intune, deleting the several minutes of walking someone through finding and starting a tool. Across a distributed company, that overhead multiplied by every ticket is real capacity being returned.
Supporting employees in their working language
Session chat renders special characters and additional languages, Chinese and Arabic among those the documentation names, and holds the whole exchange in one continuous thread. Support teams serving multilingual US workforces get both a better conversation and a durable record of it.
Cutting a redundant subscription at renewal
A tenant licensed for the Intune advanced capabilities may already own everything this page describes while paying a separate remote support vendor. If everyone you support lives in your directory, the consolidation check takes an afternoon and can retire a contract plus an agent from every device.
Three ways US companies run remote support access today.
| Feature | Remote Help | A general remote tool | Improvised access |
|---|---|---|---|
Organizational sign-in required from both sides | Yes | Rarely | No |
Technician rights differ by role | Yes | Rarely | No |
View-only distinct from full control | Yes | Sometimes | No |
Compliance state surfaced pre-connection | Yes | No | No |
Admin rights without disclosing a password | Yes | Varies | No |
Conditional Access enforceable on the tool | Yes | No | No |
Per-session record of helper, user, device, duration | Yes | Sometimes | No |
Reaching an outside tenant | Impossible by design | Possible | Possible |
Additional subscription required | Within Intune capabilities | Usually yes | Sometimes |
Stands up to a security questionnaire | Yes | Sometimes | No |
Capability coverage across Windows, macOS and Android.
Capability
Organizational sign-in for both parties
- Where it applies
- Every platform, every session
Capability
Compliance warning before connecting
- Where it applies
- Across supported platforms
Capability
Role-based access control on helper actions
- Where it applies
- Across supported platforms
Capability
Session reporting and audit logs
- Where it applies
- Across supported platforms, limited for unenrolled devices
Capability
Elevation using administrative credentials
- Where it applies
- Windows
Capability
Remote launch from Intune
- Where it applies
- Windows
Capability
Unattended access
- Where it applies
- Android, on Android Enterprise dedicated devices only
Capability
Conditional Access on the tool itself
- Where it applies
- Windows and macOS
Capability
Enhanced multilingual chat with a continuous thread
- Where it applies
- Windows and macOS
Capability
Support for unenrolled devices
- Where it applies
- Windows and macOS, off by default
Capability
Web app for the user, view only
- Where it applies
- Where the native application cannot be installed
Five steps, lighter on engineering than on decisions.
- 1
Establish licensing and map the boundary
Two gating facts first: whether your tenant's licensing already covers Remote Help among the Intune advanced capabilities, and whether everyone your desk supports authenticates in your tenant, since external tenants and organizations are unreachable by design. The answers set the project's shape.
- 2
Write the role model down
View only, full control and elevation assigned against your real support tiers, on paper, reviewed, before enablement, because the switch is tenant-wide the moment it flips. Day one then starts governed instead of retrofitted.
- 3
Make the three scope calls
Unenrolled Windows and macOS device support: on or off, knowing it defaults off and audits those sessions less completely. Android unattended access: needed or not, noting the Android Enterprise dedicated enrollment prerequisite. Conditional Access on helpers: which conditions, applied when.
- 4
Run a live-ticket pilot
The support team works genuine tickets through the tool for a week, deliberately exercising elevation, which replaces spoken admin passwords, and remote launch, which removes the guided-setup preamble from every call. Real traffic exposes fit issues that a demo never will.
- 5
Wire up the records and decide the old tool's fate
Session reports and audit log entries assigned to a named reviewer on a schedule. Then the incumbent product either leaves entirely or stays scoped to the populations outside the tenant boundary, and either way the decision gets documented.
What organizations ask about Remote Help.
Fifteen questions to settle before the tenant-wide switch.
Does it fit
- Is any part of your support population outside your tenant?The tool cannot reach across that line.
- Will unenrolled devices need coverage?Optional on Windows and macOS, disabled by default.
- Any kiosks or signage needing unattended reach?Android Enterprise dedicated enrollment is the prerequisite.
- Does your licensing already include it?It sits among the Intune advanced capabilities.
- Is macOS in scope alongside Windows?The two platforms carry different feature sets.
Role design
- Which tiers get full control rights?Distinct from view-only permission.
- Which few people get elevation rights?The role model controls this directly.
- Does tier one start at view only?A defensible default for most desks.
- Will Conditional Access gate the helpers?MFA, location or device compliance conditions.
- Who owns reading the session reports?Records nobody reads convince nobody.
What you are replacing
- What does remote support run on today?And what governance, if any, surrounds it.
- Is there a renewal you could cancel?Consolidation may fund the project by itself.
- Today, who can connect to which machines?If the answer is everyone to everything, write that down.
- Do admin passwords ever get spoken on support calls?Elevation exists to end exactly that.
- Could you evidence last quarter's sessions to an assessor?Try it; the gap is usually immediate.
The pages around this one.
Intune Suite and advanced capabilities
The licensing home of Remote Help, its sibling capabilities and the trial mechanics.
Remote IT support
Our remote support service as a whole: coverage, process and response, beyond any single tool.
Endpoint Privilege Management
Standing elevation rules for users working alone, where Remote Help handles the assisted case.
Try to reconstruct last month's remote sessions: who connected, to what, for how long.
If that reconstruction is impossible today, you have found the gap this tool closes. Dual sign-in on every session, role-scoped technician rights, and a report that answers the question in one export.
Related Services
Explore more solutions that work great with this service