Microsoft Intune Remote Help has been around for a couple of years now and solves a real everyday problem – how do you support users remotely without relying on third-party tools that sit outside your managed environment?
In 2025 Microsoft announced that Remote Help will be added to the Microsoft 365 E3 and E5 licenses! This is big news for a lot of organisations, as it means you can start using Remote Help without paying for any additional licenses on top of what you already have. A nice added value to the E3 and E5 subscriptions! https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272
Remote support is something pretty much every IT team deals with on a daily basis. A user can’t get into an application, something broke after an update, a new starter needs help getting set up… the list goes on. A lot of organisations have been handling this with third-party tools, which means extra licensing costs, extra security considerations, and yet another thing to manage. Remote Help brings all of that into Intune, where you already are.
Licensing
Remote Help has historically been available only as part of the Microsoft Intune Suite add-on or as a standalone per-user add-on license. Microsoft has announced that Remote Help is being added to Microsoft 365 E3 and E5 as part of a broader expansion of advanced Intune solutions. We will see these changes start happening 2026-July, but it may take some time before it hits our tenant.
For current licensing details, refer to:
- Microsoft Intune plans and pricing
- Microsoft 365 Security Enterprise Plans
- Microsoft 365 adds advanced Intune solutions at scale
💡A Remote Help license must be assigned to every user who interacts with the service – both helpers (IT support staff) and sharers (end users receiving support).
Prerequisites
Before you can use Remote Help, the following conditions must be met:
- A valid Remote Help license assigned to all helpers and sharers
- Microsoft Intune Plan 1 or Plan 2 subscription
- Devices must be registered with Microsoft Entra ID
- Remote Help must be explicitly enabled in the Intune admin center – it is off by default
- Both helpers and sharers must sign in with an organizational Microsoft Entra account
- Helpers and sharers must belong to the same Entra ID tenant – cross-tenant sessions are not supported
💡macOS only (enrolled devices): Users must have the Enterprise SSO plugin configured and must open and sign into Company Portal so that Remote Help can recognize the device as enrolled.
Note: Company Portal is not supported on devices enrolled without user affinity – for those devices, set the tenant to allow Remote Help on unenrolled devices.
Supported Operating Systems and Platforms
Windows (Native App)
- Windows 10 (build 19042 or later)
- Windows 11
- Windows 365
- Azure Virtual Desktop
- Architectures: x86, x64, ARM64
💡Azure Virtual Desktop (AVD): Multi-session hosts are supported but it is recommended to ask the sharer to manually open the Remote Help app to put the code manually. Sending a notification from the Intune portal will hit all sessions on the host and not necessarily the intended session.
Optional Windows updates to improve Remote Help notification reliability:
- Windows 11: KB5028245 (OS Build 22000.2245)
- Windows 10: KB5029331 (OS Build 19045.3393)
macOS (Native App)
- macOS 13 Ventura
- macOS 14 Sonoma
- macOS 15 Sequoia
- macOS 26.0 (requires Remote Help app version 1.0.2509231 or later)
Android (Native App)
💡Remote Help on Android is scoped exclusively to Android Enterprise dedicated devices, shared or kiosk devices.
Supported hardware:
- Samsung Knox devices – Knox is required for full control and unattended mode. Samsung devices without Knox support screen share only.
- Zebra devices – requires MX version 8.3 or later; unattended control requires MX 9.3 or later, plus Zebra OEMConfig configured for your tenant.
Additional Android requirements:
- Managed Google Play must be configured for your tenant
- Intune app version 5.0.5541.0 or later installed on devices
- Devices must not have a policy blocking screen capture
- Unenrolled devices are not supported on Android
Web App (Browser-Based Fallback for Sharers)
💡A web app is available for sharers who cannot install the native client. It provides view-only capability to the helper.
Supported browsers:
- Microsoft Edge 109 or later
- Google Chrome 109 or later
- Safari 16.4.1 or later
- Firefox 122 or later
Supported OS versions for the web app:
| Platform | Supported versions |
| Windows | Windows 11 only |
| macOS | macOS 11 Big Sur, 12 Monterey, 13 Ventura, 14 Sonoma |
Network Requirements
Remote Help communicates over HTTPS on port 443, using the Remote Desktop Protocol (RDP) as the underlying transport. All traffic is encrypted with TLS 1.2 and routed through Microsoft’s cloud relay – not directly between devices. The primary endpoint is https://remotehelp.microsoft.com.
Both helpers and sharers need outbound access to Microsoft’s Remote Help endpoints. Full list: Network endpoints for Remote Help
If your organization uses SSL inspection on a corporate proxy, add the Remote Help domains to your inspection bypass list – SSL inspection breaking the TLS handshake is a common cause of failed connections.
Session Modes
Remote Help supports four session modes. Availability depends on the platform combination between helper and sharer.
| Mode | Description |
| View only | Helper sees the sharer’s screen without interacting. Recommended as the default to minimize privacy impact. |
| Full control | Helper can interact with the sharer’s device. Requires explicit acceptance from the sharer. |
| Elevation | Helper can respond to UAC (User Account Control) prompts on Windows with elevated credentials, without the user needing admin rights. |
| Unattended | Helper connects to an Android Enterprise dedicated device without the sharer needing to be present. |
Mode Availability by Platform Combination
| Sharer platform | Helper app | Available modes |
| Windows (native) | Windows (native) | View only, Full control, Elevation |
| macOS (native) | Windows or macOS (web) | View only, Full control |
| Android (native) | Windows or macOS (web) | View only, Full control, Unattended |
| macOS (web app) | Windows or macOS (web) | View only |
| Windows (web app) | Windows or macOS (web) | View only |
Note that a Windows native helper app can only assist Windows native sharer sessions. All cross-platform sessions (macOS and Android) require the helper to use the web app.
Features by Platform
Windows
- Remote Launch: IT can initiate a session directly from the Intune admin center, pushing a notification to the user’s device. Requires the Intune management extension on the sharer’s device.
- UAC Elevation: helpers can enter elevation credentials during a session to resolve admin-level issues without exposing passwords to the user.
- Unenrolled device support: optionally configurable for Entra-registered but unenrolled devices. Audit data is reduced for unenrolled sessions.
- Conditional Access integration: enforce MFA or compliant device status for helpers.
- In-session chat
macOS
- Full control and view-only sessions via the native app
- Conditional Access support for helpers
- Unenrolled device support (configurable)
- In-session chat
- Web app available for sharers who cannot install the native client (view-only mode for helper)
Android
- Unattended access for Android Enterprise dedicated devices: manage devices without an end user present
- Full control and view-only sessions
- App updates delivered automatically through Managed Google Play
Security Hardening
I have created another post about security hardening of Remote Help which is found here: rockenroll.tech/2024/02/18/remote-help-security-hardening/. This post covers how to use RBAC, scope tags, conditional access, PIM and security keys with Remote Help.
Audit Logging and Data Retention
All Remote Help sessions are logged in the Intune admin center under Tenant Administration > Audit Logs. Each entry includes:
- Helper and sharer identity
- Device involved
- Session start and end time
- Features used during the session (e.g., whether elevation was invoked)
Active sessions can be monitored in real time from the admin center. Audit logging is limited for unenrolled devices.
Data retention: Microsoft stores session metadata for 30 days. No session recordings, keystrokes, or screen content are stored. Microsoft explicitly states it cannot access session content.
Limitations
| Limitation | Detail |
| Same-tenant only | No cross-tenant sessions. All participants must be in the same Entra ID tenant. |
| No Linux native app | Web app may function on Linux with a supported browser, but is not officially supported. |
| No session recording | Sessions cannot be recorded through Remote Help. |
| Government cloud | Supported in GCC (Windows, Windows 365, Samsung/Zebra Android dedicated, macOS 13–15). Not supported in GCC High or DoD. Azure Virtual Desktop is not supported in GCC. |
| Azure Virtual Desktop | Supported for Windows generally, but Microsoft advises against using Remote Launch to AVD sessions. |
| Virtual machines | The web app does not support VMs. |
| Android scope | Limited to Android Enterprise dedicated (kiosk) devices – not personal or work profile devices. |
| Market availability | Remote Help may not be available in all markets or localizations. |
Getting started
The first thing we want to do is configure the Remote Help settings in the Intune portal.

Now we want to install the Remote Help app on our devices. I will use Intune to install it on my Windows 11 devices.

From here we can connect to our supported devices by sharing a code between helper and sharer, or even better directly from the Intune portal. In this example I will connect to my CloudPC by initiating the Remote assistance session directly from the portal, this is pretty cool!
Identify and click on the device you want to connect to. In below example you can see that I have added a scope tag called W365 – Malmo. This means that only helpers with sufficient RBAC for this scope tag are allowed to connect.

The next thing that happens is that the user will receive a nice notification that IT wants to connect to their device. All we need to do is click the notification and approve the connection to start the remote session.
💡If the user has manually muted notifications by setting the device in DND-mode the notification will be hidden/muted.

From here we can support the user throught the Remote Help session.

Final words
Microsoft Intune Remote Help is a great tool for connecting to a device during a support session. However, Microsoft Intune also provides other capabilities that can assist with troubleshooting modern devices, such as Device Query. As a result, I find that the need to establish a remote screen-sharing session is becoming less frequent.
That said, I strongly recommend that organizations include a remote support solution in their toolbox to handle situations where direct device access and screen sharing are still necessary.