Skip to content
drawing

👋 Introduction ​

Remote Help is a Microsoft cloud-based remote support tool designed for IT teams. It enables support staff (helpers) to securely connect to users’ devices (sharers) using their Microsoft Entra ID work accounts.

With Remote Help, you can use Intune’s role-based access control (RBAC) to define who can provide support and what level of access they have. This gives organizations control over remote assistance and helps maintain security and compliance.

Features

  • Support for unenrolled devices: You can enable assistance for users on devices not enrolled in Intune.
  • Organization sign-in: To prevent impersonation, both the helper and the person receiving support use Microsoft Entra accounts to verify their identities.
  • Compliance warnings: If a device doesn’t meet your organization’s compliance policies, helpers will see a warning before connecting.
  • Role-based access control (RBAC): Admins can control who can provide assistance, which permissions they have on the remote device and whether they can view the device or take full control.
  • Monitor sessions: View real-time and historical reports in the Intune admin center, including who helped whom, which device was involved, session duration and audit logs.

Security

ControlHow It Works
Corporate-Only AccessOnly Microsoft Entra joined or Microsoft Entra hybrid joined, Intune-enrolled physical devices are supported.
Explicit RBAC PermissionUses dedicated RBAC permissions.
Least PrivilegeHelpers can only perform actions allowed by the Windows account used to sign in.
User AwarenessIf a user is signed in, they receive a notification and have 30 seconds to accept or reject the request.
Session IsolationSupport runs in a separate session, keeping the user's session locked and their apps and data isolated.
Full Audit TrailAll unattended sessions are logged for auditing, compliance and accountability.
12-Hour Maximum Session DurationSessions automatically disconnect after 12 hours to prevent abandoned connections.

✅ Prerequisites ​

General prerequisites ​

License

Remote Help add-on, Intune Suite or Microsoft 365 E3/E5 licenses for all helpers and sharers

Prerequisites

Both the helper and sharer authenticate with Microsoft Entra ID to establish a trusted Remote Help session.

PlatformControlRequirements
WindowsAttendedIf support is restricted to enrolled devices, the sharer's device must be enrolled in the same tenant as the one where the session starts
WindowsUnattendedThe device must be enrolled, powered on and online, with the Azure Virtual Desktop agent and bootloader, Intune Management Extension and Remote Desktop enabled
WindowsUnattendedThe helper needs the Remote Help app - Windows unattended control remote sign-in permission, scoped to the target devices
macOSIf support is restricted to enrolled devices, configure the Microsoft Enterprise SSO plug-in and have the user open and sign in to Company Portal
macOSDevices without user affinity don't support Company Portal. Set Remote Help for unenrolled devices to Allowed
AndroidOnly enrolled devices are supported
AndroidSamsung/Zebra Android Dedicated (COSU) devices don't require a Sharer license; only the Helper needs a Remote Help license
Web AppSame requirements as the sharer's platform

Supported tenants

AreaSupported / Limitation
TenantSessions between different tenants aren't supported
AvailabilityRemote Help may not be available in all markets or localizations
GCCSupported on Windows, Windows ARM64, Windows 365, Samsung/Zebra Android Enterprise dedicated devices and macOS 13–15
GCC HighSupported for eligible Microsoft cloud environments
DoDNot supported

Supported platforms

PlatformRequirements / Supported versions
Windows – AttendedWindows x86/x64/ARM64, Windows 365 and Azure Virtual Desktop (desktop and RemoteApp)
Windows – UnattendedPhysical, Intune-managed, corporate-owned Windows device; x64; Microsoft Entra joined or hybrid joined. Not supported: Windows 365, AVD, virtual, unenrolled or BYOD devices
Windows – Unattended prerequisitesThe Intune Management Extension (IME) is required for notifications and requests. Keep Windows and IME up to date.
Azure Virtual DesktopDo not remotely initiate Remote Help sessions for Azure Virtual Desktop users
macOSmacOS 13 (Ventura), 14 (Sonoma), 15 (Sequoia) and 26.0+ with Remote Help 1.0.2509231+
Android – SamsungSamsung Knox is required. Non-Knox devices support screen sharing only, not full control or unattended access.
Android – ZebraMX 8.3 or later; unattended control requires MX 9.3 or later. Zebra OEMConfig is required.
Android – GeneralAndroid Enterprise dedicated mode, Managed Google Play and Intune app version 5.0.5541.0 or later. Device configuration must allow screen capture.
Web App – BrowsersSafari 16.4.1+, Chrome 109+, Edge 109+, Firefox 122+
Web App – macOSmacOS 11 Big Sur (web app only), 12 Monterey, 13 Ventura, 14 Sonoma
Web App – WindowsWindows 11
Web App – LinuxLinux isn't officially supported, but the web app may work with a supported browser
Web App – VMsVirtual machines aren't supported


App modes ​

Remote Help supports native apps for Windows, macOS and Android, as well as a web app with reduced capabilities.

  • Attended: The sharer participates and grants access.
    • View only: View the remote screen without control.
    • Full control: Control the remote device.
    • Elevation: Allows interaction with Windows UAC prompts.
  • Unattended: Authorized helpers can access and control Intune-managed Windows and Android devices without an active sharer.

The following table shows which modes are supported by the helper and sharer apps.

-Helping from:
Windows native
Helping from:
Windows web
Helping from:
macOS web
Sharing from:
Windows native
✅ View only
✅ Full control
✅ Elevation
✅ UnattendedUnsupported
Sharing from:
macOS native
Unsupported✅ View only
✅ Full control
✅ View only
✅ Full control
Sharing from:
Android native
Unsupported✅ View only
✅ Full control
✅ Unattended
✅ View only
✅ Full control
✅ Unattended
Sharing from:
macOS web app
Unsupported✅ View only✅ View only
Sharing from:
Windows web app
Unsupported✅ View only✅ View only

NOTE

On Windows, attended and unattended sessions use separate Remote Help apps. Attended sessions support view only, full control and elevation, while unattended sessions support unattended control.



Endpoints ​

  • Outbound connectivity: TCP 443 (HTTPS)
  • Inbound port: /
  • Protocol: RDP (Remote Desktop Protocol)
  • Encryption: TLS 1.2
Remote Help Endpoints
DescriptionPortsAddresses
MEM - Remote Help FeatureTCP.support.services.microsoft.com
remoteassistance.support.services.microsoft.com
teams.microsoft.com
remoteassistanceprodacs.communication.azure.com
edge.skype.com
aadcdn.msftauth.net
aadcdn.msauth.net
alcdn.msauth.net
wcpstatic.microsoft.com
.aria.microsoft.com
browser.pipe.aria.microsoft.com
.events.data.microsoft.com
v10c.events.data.microsoft.com
.monitor.azure.com
js.monitor.azure.com
edge.microsoft.com
.trouter.communication.microsoft.com
.trouter.teams.microsoft.com
*.trouter.communications.svc.cloud.microsoft
go-amer.trouter.communications.svc.cloud.microsoft(only for NA, ROW customers)
go-apac.trouter.communications.svc.cloud.microsoft(only for APAC customers)
go-eu.trouter.communications.svc.cloud.microsoft(only for EU customers)
api.flightproxy.skype.com
ecs.communication.microsoft.com
remotehelp.microsoft.com
remoteassistanceprodacseu.communication.azure.com(only for EU customers)
Dependency - Remote Help web pubsubTCP*.webpubsub.azure.com
AMSUA0101-RemoteAssistService-pubsub.webpubsub.azure.com
Remote Help Dependency for GCC customersTCPremoteassistanceweb-gcc.usgov.communication.azure.us
gcc.remotehelp.microsoft.com
gcc.relay.remotehelp.microsoft.com
*.gov.teams.microsoft.us
Remote Help for Windows unattended access - Remote Sign-in dependenciesRemote Sign-in requires
the AVD session host endpoints
Launch Remote HelpTCP*.trouter.communications.svc.cloud.microsoft
Remote Assistance ServiceTCPremotehelp.microsoft.com
Session host virtual machines

Session host VMs require outbound access to the following Azure Virtual Desktop FQDNs and endpoints (inbound ports are not required). Select your cloud environment tab below.

Azure Cloud
AddressProtocolPortPurposeService tag
login.microsoftonline.comTCP443Authentication to MS Online ServicesAzureActiveDirectory
51.5.0.0/16UDP3478Relayed RDP connectivityWindowsVirtualDesktop
*.wvd.microsoft.comTCP443Service traffic with TCP based RDPWindowsVirtualDesktop
catalogartifact.azureedge.netTCP443Azure MarketplaceAzureFrontDoor.Frontend
*.prod.warm.ingest.monitor.core.windows.netTCP443Agent traffic - Diagnostic outputAzureMonitor
gcs.prod.monitoring.core.windows.netTCP443Agent trafficAzureMonitor
azkms.core.windows.netTCP1688Windows activationInternet
mrsglobalsteus2prod.blob.core.windows.netTCP443Agent and side-by-side stack updatesStorage
wvdportalstorageblob.blob.core.windows.netTCP443Azure portal supportAzureCloud
oneocsp.microsoft.comTCP80CertificatesAzureFrontDoor.FirstParty
www.microsoft.comTCP80CertificatesN/A
*.aikcertaia.microsoft.comTCP80CertificatesN/A
azcsprodeusaikpublish.blob.core.windows.netTCP80CertificatesN/A
*.microsoftaik.azure.netTCP80CertificatesN/A
ctldl.windowsupdate.comTCP80CertificatesN/A
aka.msTCP443MS URL shortenerN/A
*.service.windows.cloud.microsoftTCP443Service TrafficWindowsVirtualDesktop
*.windows.cloud.microsoftTCP443Service TrafficN/A
*.windows.static.microsoftTCP443Service TrafficN/A
Government Cloud
AddressProtocolPortPurposeService tag
*.service.windows.usgovcloud.microsoftTCP443Service TrafficWindowsVirtualDesktop
20.140.236.0/22UDP3478Relayed RDP connectivityWindowsVirtualDesktop
*.windows.usgovcloud.microsoftTCP443Service TrafficN/A
*.windows.usgovcloud-static.microsoftTCP443Service TrafficN/A
login.microsoftonline.usTCP443Authentication to MS Online ServicesAzureActiveDirectory
*.wvd.azure.usTCP443Service trafficWindowsVirtualDesktop
*.prod.warm.ingest.monitor.core.usgovcloudapi.netTCP443Agent traffic - Diagnostic outputAzureMonitor
gcs.monitoring.core.usgovcloudapi.netTCP443Agent trafficAzureMonitor
azkms.core.usgovcloudapi.netTCP1688Windows activationInternet
mrsglobalstugviffx.blob.core.usgovcloudapi.netTCP443Agent and side-by-side stack updatesAzureCloud
wvdportalstorageblob.blob.core.usgovcloudapi.netTCP443Azure portal supportAzureCloud
ctldl.windowsupdate.comTCP80CertificatesN/A
ocsp.msocsp.comTCP80CertificatesN/A
Communication Services

Communication Services require internet connectivity to specific ports and IP addresses to deliver high-quality multimedia. Without proper access, these services will fail to function correctly.

Azure Cloud
CategoryIP ranges or FQDNPorts
Media trafficAzure public cloud IP range 20.202.0.0/16. This range contains the IP addresses of the media processor or Azure Communication Services TURN service.UDP 3478 through 3481, TCP ports 443
Signaling, telemetry, registration*.skype.com, *.microsoft.com, *.azure.net, *.azure.com, *.office.comTCP 443, 80
Call Automation Media52.112.0.0/14, 52.122.0.0/15, 2603:1063::/38UDP: 3478, 3479, 3480, 3481
Call Automation callback URLs*.lync.com, *.teams.cloud.microsoft, *.teams.microsoft.com, teams.cloud.microsoft, teams.microsoft.com, 52.112.0.0/14, 52.122.0.0/15, 2603:1027::/48, 2603:1037::/48, 2603:1047::/48, 2603:1057::/48, 2603:1063::/38, 2620:1ec:6::/48, 2620:1ec:40::/42TCP: 443, 80 UDP: 443
Government Cloud
CategoryIP ranges or FQDNPorts
Media traffic52.127.88.0/21, 52.238.114.160/32, 52.238.115.146/32, 52.238.117.171/32, 52.238.118.132/32, 52.247.167.192/32, 52.247.169.1/32, 52.247.172.50/32, 52.247.172.103/32, 104.212.44.0/22, 195.134.228.0/22UDP 3478 through 3481, TCP ports 443
Signaling, telemetry, registration*.gov.teams.microsoft.us, *.infra.gov.skypeforbusiness.us, *.online.gov.skypeforbusiness.us, gov.teams.microsoft.usTCP 443, 80

📊 Data and 🔒 privacy ​

Microsoft logs a minimal amount of session data to monitor Remote Help. This includes:

  • Session times: When a session starts and ends (retained for 30 days).
  • Session details: Includes the identities of the helper and sharer and the device involved (retained for 30 days).
  • Errors: Issues like disconnections are logged on the sharer's device in Event Viewer.
  • Features used: Actions performed during the session, such as view-only mode or elevation requests (retained for 30 days).

Remote Help logs session details locally in Windows Event Logs for both helper and sharer.
Microsoft cannot access session content or see actions or keystrokes.

Both the helper and sharer can see the following details from each other's organizational profiles:

  • Profile picture (if you have one)
  • Company name
  • Verified domain
  • First and last name
  • Job title

INFO

Microsoft retains this data for no longer than 30 days.

🧑‍🔧 Configuration ​

Tenant configuration ​

To configure Remote Help in your tenant for any supported platform, follow these steps:

Turn on Remote Help

  1. Sign in to the Microsoft Intune admin center and go to Tenant administration → Remote Help.
  2. Select the Settings tab.
    1. Enable Remote Help
    2. Choose whether to allow users to receive help on unenrolled devices, then set this option to Allowed if desired.
    3. Choose whether to allow helpers and sharers to chat with each other during a session, then set this option to No if desired.
drawing

Set up permissions for Remote Help

Remote Help uses Intune’s role-based access control (RBAC) to determine who can provide help and what they’re allowed to do.

The Help Desk Operator role includes the permissions needed for a Remote Help session.

drawing

Here are the main permissions you can configure for Remote Help sessions:

drawing
    Category: Remote Help app
    • Elevation
    • View screen
    • Unattended control
    • Take full control
drawing
    Category: Remote tasks
    • Offer remote assistance

NOTE

Some permissions are dependent on others. When you enable a setting, related permissions are automatically granted:

  • Enabling Take full control also enables View screen.
  • Enabling Elevation also enables both Take full control and View screen.
  • Enabling Unattended control automatically grants all other permissions.

The default Help Desk Operator role comes pre-configured with all necessary Remote Help permissions enabled. You can assign this role as-is or create custom roles to tailor permissions for different support scenarios. For more details on configuring RBAC, see Role-based access control.

Assign users to roles

To grant helpers the necessary permissions, assign them to the appropriate role:

  1. Sign in to the Microsoft Intune admin center and navigate to Tenant administration → Roles and select a role.
  2. Now open Assignments, then click Assign to create a new role assignment.
  3. On the Basics page, enter a name and description and click Next.
  4. On the Admin Groups page, select your helper group and click Next.
  5. If needed, enter a scope tag, then create the assignment.

Set up Conditional Access for Remote Help

Registering this service principal lets you apply Conditional Access to attended Remote Help sessions. Conditional Access is not used for unattended Windows Remote Help sessions.

PowerShell
Connect-MgGraph -Scopes "Application.ReadWrite.All"

New-MgServicePrincipal -AppId "1dee7b72-b80d-4e56-933d-8b6b04f9a3e2"
PowerShell
DisplayName                                     Id AppId                                   ServicePrincipalType
----                                         ------- -----------                                   ---------------
RemoteAssistanceService                      3d5ff82b-a5f2-483a-xxxx-9514ed66f7c5        1dee7b72-b80d-4e56-933d-8b6b04f9a3e2
drawing

App deployment ​

You can deploy the app through Intune or install it directly on the target devices.

To install it manually, download the latest version of Remote Help from Microsoft or install it with winget.

powershell
Winget install Microsoft.RemoteHelp

To deploy the app through Intune, you have two main options:

  • Download and package: Download the installer, package it as an .intunewin file and deploy it as a Win32 app through Intune.
  • Universal app deployment (no packaging): Use my Universal App deployment method to install the app directly with winget, without packaging it.

If you choose the INTUNEWIN method, use the following information for deployment:

powershell
# Install command
remotehelpinstaller.exe /quiet acceptTerms=1 enableAutoUpdates=1
powershell
# Uninstall command
remotehelpinstaller.exe /uninstall /quiet acceptTerms=1

Detection Rule

  • For Rule type, select File
  • For Path, specify C:\Program Files\Remote Help
  • For File or folder, specify RemoteHelp.exe
  • For Detection method, select String (version)
  • For Operator, select Greater than or equal to
  • For Value, enter the Remote Help version to deploy (e.g., 10.0.22467.1000).
  • Leave Associated with a 32-bit app on 64-bit clients set to No

Web app

Sharer: https://aka.ms/rhRemote Helper: https://aka.ms/rhh
drawingdrawing

macOS

On macOS, you can download the latest version of Remote Help from Microsoft.

Android

To use Remote Help on Android Enterprise devices, install the Intune app or open the web app in a supported browser.

Additionally, ensure that screen capture is allowed in your Android device policies.

For Zebra devices: Configure Zebra OEMConfig as described in the Microsoft documentation.



Unattended Windows access setup ​

With unattended capabilities, your helpdesk can connect directly to the Windows login screen and sign in with their own credentials, even when no user is currently connected to the device. If a user is already signed in, they receive a notification and can choose to accept or reject the remote access request.

Once connected, the helpdesk works in a separate Windows session, while the user's existing session remains locked and untouched. This allows support to work on the device without interrupting the user's session or affecting their open applications and work.

Security is also important to keep in mind with an unattended access feature. Access is based on least-privilege permissions, with a dedicated RBAC permission and a complete audit trail to ensure that access is controlled and can always be traced back to the person who used it.

The dedicated permission also needs to be explicitly assigned as a custom role and scoped to specific device groups. It is not included in any built-in Intune role.

Remote Help app -> Windows unattended control remote sign-in

The support session includes features such as file transfer, clipboard passthrough, Remote Desktop Virtual Printer and multi-monitor support, giving the help desk useful tools for troubleshooting devices.

  1. To get started, create a custom RBAC role.

    1. Open the Intune admin center, go to Tenant administration -> Roles and select + Create -> Intune role.
    2. Enter a Name and Description in the Basics tab and click Next.
    3. In the Permissions tab, you open Remote Help app and toggle Windows unattended control remote sign-in to Yes.
    drawing
    1. Click Next, select a Scope tag if needed and create the Custom Role on the tab after that with Create.
    2. Open the new role again and select the Assignments tab. Here, you can assign the new role to your admins and select its targets with + Assign.
    3. Enter again a Name and Description for the assignment and click Next.
    4. On the Admin Groups tab, select a group containing the support users who should be able to initiate unattended control, then click Next.
    5. On the Scope Groups tab, select a group containing the users or devices that the selected helpers can access, then click Next.
    6. Select a Scope tag if needed and create the assignment on the tab after that with Create.

    INFO

    All Devices doesn't include unenrolled devices. Use a user scope group instead.

    Remote Help RBAC Permissions
    PermissionDescription
    View screenView the sharer's screen without control
    Take full controlFull control of the sharer's device
    ElevationInteract with Windows UAC prompts
    Android unattended controlUnattended access to Intune-enrolled Android Dedicated devices; explicitly scope to target devices
    Windows unattended control remote sign-inUnattended sign-in to targeted physical, corporate-owned Windows devices; explicitly scope to target devices
    Remote Tasks - Offer remote assistanceAllows offering remote assistance
    Remote Assistance Connector - ReadAllows checking whether Remote Help is configured for the tenant

    Built-in Intune roles

    • Help Desk Operator: View screen, full control, elevation android unattended control, remote assistance, connector read
    • School Administrator: View screen, full control, elevation, remote assistance, connector read

    Required for providing help: Remote Tasks - Offer Remote Assistance + Remote Assistance Connector - Read + at least one Remote Help permission.

  2. Now that the permissions are in place, you need to roll out the Azure Virtual Desktop Agent and Azure Virtual Desktop Agent Bootloader, which will facilitate the unattended control.

    1. Download the Azure Virtual Desktop Agent and Azure Virtual Desktop Agent Bootloader, package them as .intunewin files and upload them to Intune as Win32 apps. Ensure you deploy the Azure Virtual Desktop Agent first, then configure a dependency on the Azure Virtual Desktop Agent Bootloader requiring the base agent to be present before installation.

      Alternatively, you can use my custom script to handle the entire workflow automatically. It fetches the latest agent versions, installs both components, generates a log file, copies the output to the Intune Management Extension logs directory and cleans up all temporary files afterward.

      You can grab the install script below or download it directly from my GitHub (Download Uninstall Script). Deploy it as a Platform script or package it as a Win32 app. Ensure it runs with administrative privileges.

    INFO

    If you install the agents manually, the installer may display INVALID_TOKEN. This is expected.

    drawing
    Download & Install PowerShell Script
    PowerShell
    
    <#PSScriptInfo
        .VERSION
            1.1.0
        .AUTHOR
            Michael Frank
        .COMPANYNAME
            michaelsendpoint.com
        .Name
            InstallAVDAgent.ps1
        .SYNOPSIS
            Download and install the Azure Virtual Desktop Agent & Azure Virtual Desktop Agent Bootloader.
        .creationdate
            22.09.2026
        .lasteditdate
            23.09.2026
    #>
    
    # Force TLS 1.2 and suppress GUI progress output to maximize download speed in PS 5.1
    [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
    $ProgressPreference = 'SilentlyContinue'
    
    # ------------------------------------------------- Parameter --------------------------------------------------------------
    
    $Location = "C:\AVDDownload"
    $Uri = "https://learn.microsoft.com/en-gb/intune/remote-help/deploy?tabs=windows#configure-remote-help-apps"
    
    # ------------------------------------------------- Get Download Links -----------------------------------------------------
    
    # Request raw HTML with BasicParsing (no IE dependency)
    $webResponse = Invoke-WebRequest -Uri $Uri -UseBasicParsing
    
    # Extract MSI links using RegEx directly from raw HTML
    $avdMatch  = [regex]::Match($webResponse.Content, 'href="([^"]+)"[^>]*>Azure Virtual Desktop Agent<\/a>')
    $bootMatch = [regex]::Match($webResponse.Content, 'href="([^"]+)"[^>]*>Azure Virtual Desktop Agent Bootloader<\/a>')
    
    $AVDUri  = $avdMatch.Groups[1].Value
    $BootUri = $bootMatch.Groups[1].Value
    
    # ------------------------------------------------- Download ---------------------------------------------------------------
    
    New-Item -type Directory $Location
    Set-Location $Location
    
    $files = @(
        @{
            Uri = $AVDUri
            OutFile = 'AzureVirtualDesktopAgent.msi'
        },
        @{
            Uri = $BootUri
            OutFile = 'AzureVirtualDesktopAgentBootloader.msi'
        }
    )
    
    Write-Host "Downloads started..."
    
    foreach ($file in $files) {
        Write-Host "Downloading $($file.OutFile)..."
        Invoke-WebRequest -Uri $file.Uri -OutFile $file.OutFile -UseBasicParsing
    }
    
    Write-Host "Downloads finished."
    
    # ------------------------------------------------- Installation ------------------------------------------------------------
    
    $files = Get-ChildItem -Path .\*.msi
    
    Write-Host "Install started..."
    
    Foreach ($file in $files) {
    $DataStamp = get-date -Format yyyyMMddTHHmmss
    $logFile = '{0}-{1}.log' -f $file.fullname,$DataStamp
    $MSIArguments = @(
        "/i"
        ('"{0}"' -f $file.fullname)
        "/qn"
        "/norestart"
        "/L*v"
        $logFile
    )
    Start-Process "msiexec.exe" -ArgumentList $MSIArguments -Wait -NoNewWindow 
    }
    
    Write-Host "Install finished"
    
    # ------------------------------------------------- Move logs --------------------------------------------------------------
    
    Move-Item -Path .\*.log -Destination "C:\ProgramData\Microsoft\IntuneManagementExtension\Logs"
    
    Set-Location "C:\"
    
    Remove-Item $Location -recurse
    App Detection Scripts
    Azure Virtual Desktop Agent
    PowerShell
    
    <#PSScriptInfo
        .VERSION
            1.0.0
        .AUTHOR
            Michael Frank
        .COMPANYNAME
            michaelsendpoint.com
        .Name
            Detect-AzureVirtualDesktopAgent.ps1
        .SYNOPSIS
            Detects Azure Virtual Desktop Agent using registry
        .creationdate
            22.09.2026
        .lasteditdate
            22.09.2026
    #>
    
    # ------------------------------------------------- Parameter --------------------------------------------------------------
    
    $appname = "Remote Desktop Services Infrastructure Agent"
    
    # ------------------------------------------------- detects an app using registry ------------------------------------------
    
    # This is for 64-bit applications on 64-bit systems
    $app = Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Where-Object { $_.DisplayName -eq "$($appname)" }
    
    if ($app) {
        Write-Host "Found app $($appname)!"
        exit 0
    }
    
    # This is for 32-bit applications on 64-bit systems
    $app = Get-ItemProperty HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* | Where-Object { $_.DisplayName -eq "$($appname)" }
    
    if ($app) {
        Write-Host "Found app $($appname)!"
        exit 0
    }
    else {
        Write-Host "Did not find app $($appname)!"
        exit 1
    }
    Azure Virtual Desktop Agent Bootloader
    PowerShell
    
    <#PSScriptInfo
        .VERSION
            1.0.0
        .AUTHOR
            Michael Frank
        .COMPANYNAME
            michaelsendpoint.com
        .Name
            Detect-AzureVirtualDesktopAgentBootloader.ps1
        .SYNOPSIS
            Detects Azure Virtual Desktop Agent Bootloader using registry
        .creationdate
            22.09.2026
        .lasteditdate
            22.09.2026
    #>
    
    # ------------------------------------------------- Parameter --------------------------------------------------------------
    
    $appname = "Remote Desktop Agent Boot Loader"
    
    # ------------------------------------------------- detects an app using registry ------------------------------------------
    
    # This is for 64-bit applications on 64-bit systems
    $app = Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Where-Object { $_.DisplayName -eq "$($appname)" }
    
    if ($app) {
        Write-Host "Found app $($appname)!"
        exit 0
    }
    
    # This is for 32-bit applications on 64-bit systems
    $app = Get-ItemProperty HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* | Where-Object { $_.DisplayName -eq "$($appname)" }
    
    if ($app) {
        Write-Host "Found app $($appname)!"
        exit 0
    }
    else {
        Write-Host "Did not find app $($appname)!"
        exit 1
    }
    Download & Uninstall PowerShell Script
    PowerShell
    
    <#PSScriptInfo
        .VERSION
            1.1.0
        .AUTHOR
            Michael Frank
        .COMPANYNAME
            michaelsendpoint.com
        .Name
            InstallAVDAgent.ps1
        .SYNOPSIS
            Download and uninstall the Azure Virtual Desktop Agent & Azure Virtual Desktop Agent Bootloader.
        .creationdate
            22.09.2026
        .lasteditdate
            23.09.2026
    #>
    
    # Force TLS 1.2 and suppress GUI progress output to maximize download speed in PS 5.1
    [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
    $ProgressPreference = 'SilentlyContinue'
    
    # ------------------------------------------------- Parameter --------------------------------------------------------------
    
    $Location = "C:\AVDDownload"
    $Uri = "https://learn.microsoft.com/en-gb/intune/remote-help/deploy?tabs=windows#configure-remote-help-apps"
    
    # ------------------------------------------------- Get Download Links -----------------------------------------------------
    
    # Request raw HTML with BasicParsing (no IE dependency)
    $webResponse = Invoke-WebRequest -Uri $Uri -UseBasicParsing
    
    # Extract MSI links using RegEx directly from raw HTML
    $avdMatch  = [regex]::Match($webResponse.Content, 'href="([^"]+)"[^>]*>Azure Virtual Desktop Agent<\/a>')
    $bootMatch = [regex]::Match($webResponse.Content, 'href="([^"]+)"[^>]*>Azure Virtual Desktop Agent Bootloader<\/a>')
    
    $AVDUri  = $avdMatch.Groups[1].Value
    $BootUri = $bootMatch.Groups[1].Value
    
    # ------------------------------------------------- Download ---------------------------------------------------------------
    
    New-Item -type Directory $Location
    Set-Location $Location
    
    $files = @(
        @{
            Uri = $AVDUri
            OutFile = 'AzureVirtualDesktopAgent.msi'
        },
        @{
            Uri = $BootUri
            OutFile = 'AzureVirtualDesktopAgentBootloader.msi'
        }
    )
    
    Write-Host "Downloads started..."
    
    foreach ($file in $files) {
        Write-Host "Downloading $($file.OutFile)..."
        Invoke-WebRequest -Uri $file.Uri -OutFile $file.OutFile -UseBasicParsing
    }
    
    Write-Host "Downloads finished."
    
    # ------------------------------------------------- Installation ------------------------------------------------------------
    
    $files = Get-ChildItem -Path .\*.msi
    
    Write-Host "Uninstall started..."
    
    Foreach ($file in $files) {
    $DataStamp = get-date -Format yyyyMMddTHHmmss
    $logFile = '{0}-{1}.log' -f $file.fullname,$DataStamp
    $MSIArguments = @(
        "/x"
        ('"{0}"' -f $file.fullname)
        "/qn"
        "/norestart"
        "/L*v"
        $logFile
    )
    Start-Process "msiexec.exe" -ArgumentList $MSIArguments -Wait -NoNewWindow 
    }
    
    Write-Host "Uninstall finished"
    
    # ------------------------------------------------- Move logs --------------------------------------------------------------
    
    Move-Item -Path .\*.log -Destination "C:\ProgramData\Microsoft\IntuneManagementExtension\Logs"
    
    Set-Location "C:\"
    
    Remove-Item $Location -recurse
    1. Lastly, deploy a policy to enable unattended access by allowing users to connect through RDP.
    2. Open the Intune admin center -> Devices -> Configuration and click + Create -> + New Policy.
    3. For Platform, select Windows 10 and later. For Profile type, select Settings catalog, then click Create.
    4. Enter a Name and Description on the Basics tab, then click Next.
    5. On the Configuration tab, select Allow users to connect remotely using Remote Desktop from the catalog and set it to Enable.
    drawing
    1. Click Next, select the required Scope tags, assign the policy to the device or user groups you want to support and create the policy on the final tab.


Conditional Access ​

To control Remote Help with Conditional Access, create a service principal using the Remote Assistance Service app ID.

powershell
New-MgServicePrincipal -AppId "1dee7b72-b80d-4e56-933d-8b6b04f9a3e2"
drawingdrawing

⌨️ Usage ​

To start a remote session, you can either open the app and exchange a security code with the end user or start a session directly through Intune. When you start a session through Intune, it handles the security code for you.

  1. To start a remote session from Intune, open the Intune admin center, go to Devices, select the device you want to help and choose Remote actions -> Begin a remote assistance session.
drawing
  1. A flyout will appear where you select Remote Help and click Continue.
drawing
  1. On the next screen, choose whether to start a session with a user at the device (Initiate attended control) or without one (Initiate unattended control), then click Select.
drawing
  1. If you selected attended control, a notification will appear on the end user's device announcing the remote session. When the user selects the toast notification, Remote Help launches automatically and waits for you to start the session. No code exchange is required.
drawing

    If you start an unattended session while a user is signed in, they will see a dialog and have 30 seconds to cancel the session. Otherwise, it starts automatically.

    drawing

    The helper will see a message that someone is signed in and be asked whether to continue. Selecting Yes locks the user’s session without closing anything and connects the helper to a separate Windows session.

    drawing
  1. Once Remote Help starts on the end user's device or the unattended session is ready, the flyout shows a green checkmark next to Open Remote Help.

    Before each connection, Intune checks the configuration and displays a message if a check fails:

    ConditionWhat happens
    Missing RBAC permissionSession initiation is disabled with the message: "You can only select session types for which you have permission."
    Personal deviceSession initiation is disabled with the message: "Unattended control is not available on personal devices."
    Device not compliantA warning indicates that the device doesn't meet security or compliance requirements.
    Device offlineThe session fails with the message: "Make sure the user's device is on and connected to the internet."
    Missing prerequisitesIntune indicates that required agents, policies, permissions or settings aren't configured.
    Attended controlUnattended control
    drawingdrawing
  1. Once connected, authenticate to the device.

To start a remote session without Intune, use the following instructions.

  1. The user must first sign in to the Remote Help client or have SSO enabled.
    drawingdrawing
  1. Next, the helper selects Get security code and has 10 minutes to share the code with the sharer (the end user who needs help).
  2. The sharer enters the security code in the appropriate field in the Remote Help client.
    Helper viewSharer view
    drawingdrawing
  1. The sharer sees a waiting screen while the helper chooses whether to Take full control or View screen.

    Security Check

    Before the helper can take control or view the screen, both parties will see each other's organizational details (name, company, domain, etc.) to confirm identities and prevent impersonation. This step ensures that only authorized helpers from your organization can provide assistance.

    Helper viewSharer view
    drawingdrawing
  1. Once the helper has selected their desired action, the sharer receives a pop-up window displaying the helper’s account details and the requested action (view screen or take control). The sharer can then choose to allow or decline the connection.
drawing

    Information

    If you do not have the required RBAC permissions in Intune to act as a helper, a notification window will appear informing you that you lack the necessary permissions to provide remote assistance.

    drawing
  1. The sharer sees a bar at the top where they can end the session by selecting X or start a chat 💬.

    Unattended session

    • The end user’s console displays the lock screen, so they cannot see the helper’s actions. The helper works in a separate Windows session.
    • The end user can regain control at any time by signing back in from the lock screen. The helper is notified and can then choose to disconnect.
drawing
  1. The helper has several tools in the toolbar to manage the session:
    • Request Control
    • Admin Session 🖥️
    • Laser pointer 📍
    • On-Screen Pen 🖊️
    • Fullscreen 🪟
    • Chat 💬
    • Restart machine ↩️ (only in admin mode)
    • Task manager 📟 (only in admin mode)
    • Leave
drawing
  1. If the helper requests control, the sharer receives the request in the Remote Help bar and can select Allow or Deny.
drawing
  1. If you need to open an elevated window during a Remote Help session, the UAC prompt appears on the secure desktop by default. Your session view will go black and display a ⏸️ symbol because the secure desktop isn't visible until an Admin Session is enabled.
    Helper viewSharer view
    drawingdrawing
  1. If the helper needs to enter credentials or interact with the UAC prompt, you can enable an Admin Session.
drawing
  1. Once the Admin Session is enabled, if a UAC prompt appears, the helper will be able to view and interact with the elevated windows directly.
    Helper viewSharer view
    drawingdrawing

    IMPORTANT

    While the Admin Session is enabled you will see a warning message reminding you of closing all elevated windows before leaving the session. drawing

    If the session is closed by the sharer while an admin session is still active, the user will be signed out immediately. This ensures that all elevated windows are closed, protecting admin credentials. drawing

  1. When either party ends the session, everyone sees a corresponding message.
    Helper viewSharer view
    drawingdrawing

🔍 Monitoring ​

You can monitor Remote Help usage in the Intune admin center.

  1. Sign in to the Microsoft Intune admin center and go to Tenant admin → Remote Help.
  2. The Monitor tab shows active sessions and information about past sessions.
drawing
  1. The Remote Help sessions tab shows details about past sessions.
drawing

    Information

    • For Android Enterprise Dedicated devices, you’ll see “--” for Recipient ID and Recipient name since these devices don’t have user affinity.
    • Reporting is more limited for unenrolled devices.

💡 Conclusion ​

Remote Help is a good, straightforward option for providing remote support through Intune, with great auditing features. If your organization already licenses its helpers and users with Microsoft 365 E3 or E5, Remote Help is included at no additional charge.

It is integrated into the Microsoft ecosystem, so helpers and users can sign in with their existing Entra ID work accounts. Access is managed through Intune RBAC, rather than a separate account system or permissions portal.

Remote Help is not perfect and may still be missing some features you expect. However, Microsoft continues to add new features, so it’s worth keeping an eye on its development.

When considering adoption, weigh its capabilities against your support needs, costs and the convenience of managing support from a single pane of glass in Intune.

References