Microsoft Intune Remote Help: My Overview

Microsoft Intune Remote Help has been around for a couple of years now and solves a real everyday problem – how do you support users remotely without relying on third-party tools that sit outside your managed environment?

In 2025 Microsoft announced that Remote Help will be added to the Microsoft 365 E3 and E5 licenses! This is big news for a lot of organisations, as it means you can start using Remote Help without paying for any additional licenses on top of what you already have. A nice added value to the E3 and E5 subscriptions! https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272

Remote support is something pretty much every IT team deals with on a daily basis. A user can’t get into an application, something broke after an update, a new starter needs help getting set up… the list goes on. A lot of organisations have been handling this with third-party tools, which means extra licensing costs, extra security considerations, and yet another thing to manage. Remote Help brings all of that into Intune, where you already are.

Licensing

Remote Help has historically been available only as part of the Microsoft Intune Suite add-on or as a standalone per-user add-on license. Microsoft has announced that Remote Help is being added to Microsoft 365 E3 and E5 as part of a broader expansion of advanced Intune solutions. We will see these changes start happening 2026-July, but it may take some time before it hits our tenant.

For current licensing details, refer to:

💡A Remote Help license must be assigned to every user who interacts with the service – both helpers (IT support staff) and sharers (end users receiving support).

Prerequisites

Before you can use Remote Help, the following conditions must be met:

  • A valid Remote Help license assigned to all helpers and sharers
  • Microsoft Intune Plan 1 or Plan 2 subscription
  • Devices must be registered with Microsoft Entra ID
  • Remote Help must be explicitly enabled in the Intune admin center – it is off by default
  • Both helpers and sharers must sign in with an organizational Microsoft Entra account
  • Helpers and sharers must belong to the same Entra ID tenant – cross-tenant sessions are not supported

💡macOS only (enrolled devices): Users must have the Enterprise SSO plugin configured and must open and sign into Company Portal so that Remote Help can recognize the device as enrolled.
Note: Company Portal is not supported on devices enrolled without user affinity – for those devices, set the tenant to allow Remote Help on unenrolled devices.

Supported Operating Systems and Platforms

Windows (Native App)

  • Windows 10 (build 19042 or later)
  • Windows 11
  • Windows 365
  • Azure Virtual Desktop
  • Architectures: x86, x64, ARM64

💡Azure Virtual Desktop (AVD): Multi-session hosts are supported but it is recommended to ask the sharer to manually open the Remote Help app to put the code manually. Sending a notification from the Intune portal will hit all sessions on the host and not necessarily the intended session.

Optional Windows updates to improve Remote Help notification reliability:

  • Windows 11: KB5028245 (OS Build 22000.2245)
  • Windows 10: KB5029331 (OS Build 19045.3393)

macOS (Native App)

  • macOS 13 Ventura
  • macOS 14 Sonoma
  • macOS 15 Sequoia
  • macOS 26.0 (requires Remote Help app version 1.0.2509231 or later)

Android (Native App)

💡Remote Help on Android is scoped exclusively to Android Enterprise dedicated devices, shared or kiosk devices.

Supported hardware:

  • Samsung Knox devices – Knox is required for full control and unattended mode. Samsung devices without Knox support screen share only.
  • Zebra devices – requires MX version 8.3 or later; unattended control requires MX 9.3 or later, plus Zebra OEMConfig configured for your tenant.

Additional Android requirements:

  • Managed Google Play must be configured for your tenant
  • Intune app version 5.0.5541.0 or later installed on devices
  • Devices must not have a policy blocking screen capture
  • Unenrolled devices are not supported on Android

Web App (Browser-Based Fallback for Sharers)

💡A web app is available for sharers who cannot install the native client. It provides view-only capability to the helper.


Supported browsers:

  • Microsoft Edge 109 or later
  • Google Chrome 109 or later
  • Safari 16.4.1 or later
  • Firefox 122 or later

Supported OS versions for the web app:

PlatformSupported versions
WindowsWindows 11 only
macOSmacOS 11 Big Sur, 12 Monterey, 13 Ventura, 14 Sonoma

Network Requirements

Remote Help communicates over HTTPS on port 443, using the Remote Desktop Protocol (RDP) as the underlying transport. All traffic is encrypted with TLS 1.2 and routed through Microsoft’s cloud relay – not directly between devices. The primary endpoint is https://remotehelp.microsoft.com.

Both helpers and sharers need outbound access to Microsoft’s Remote Help endpoints. Full list: Network endpoints for Remote Help

If your organization uses SSL inspection on a corporate proxy, add the Remote Help domains to your inspection bypass list – SSL inspection breaking the TLS handshake is a common cause of failed connections.

Session Modes

Remote Help supports four session modes. Availability depends on the platform combination between helper and sharer.

ModeDescription
View onlyHelper sees the sharer’s screen without interacting. Recommended as the default to minimize privacy impact.
Full controlHelper can interact with the sharer’s device. Requires explicit acceptance from the sharer.
ElevationHelper can respond to UAC (User Account Control) prompts on Windows with elevated credentials, without the user needing admin rights.
UnattendedHelper connects to an Android Enterprise dedicated device without the sharer needing to be present.

Mode Availability by Platform Combination

Sharer platformHelper appAvailable modes
Windows (native)Windows (native)View only, Full control, Elevation
macOS (native)Windows or macOS (web)View only, Full control
Android (native)Windows or macOS (web)View only, Full control, Unattended
macOS (web app)Windows or macOS (web)View only
Windows (web app)Windows or macOS (web)View only

Note that a Windows native helper app can only assist Windows native sharer sessions. All cross-platform sessions (macOS and Android) require the helper to use the web app.

Features by Platform

Windows

  • Remote Launch: IT can initiate a session directly from the Intune admin center, pushing a notification to the user’s device. Requires the Intune management extension on the sharer’s device.
  • UAC Elevation: helpers can enter elevation credentials during a session to resolve admin-level issues without exposing passwords to the user.
  • Unenrolled device support: optionally configurable for Entra-registered but unenrolled devices. Audit data is reduced for unenrolled sessions.
  • Conditional Access integration: enforce MFA or compliant device status for helpers.
  • In-session chat

macOS

  • Full control and view-only sessions via the native app
  • Conditional Access support for helpers
  • Unenrolled device support (configurable)
  • In-session chat
  • Web app available for sharers who cannot install the native client (view-only mode for helper)

Android

  • Unattended access for Android Enterprise dedicated devices: manage devices without an end user present
  • Full control and view-only sessions
  • App updates delivered automatically through Managed Google Play

Security Hardening

I have created another post about security hardening of Remote Help which is found here: rockenroll.tech/2024/02/18/remote-help-security-hardening/. This post covers how to use RBAC, scope tags, conditional access, PIM and security keys with Remote Help.

Audit Logging and Data Retention

All Remote Help sessions are logged in the Intune admin center under Tenant Administration > Audit Logs. Each entry includes:

  • Helper and sharer identity
  • Device involved
  • Session start and end time
  • Features used during the session (e.g., whether elevation was invoked)

Active sessions can be monitored in real time from the admin center. Audit logging is limited for unenrolled devices.

Data retention: Microsoft stores session metadata for 30 days. No session recordings, keystrokes, or screen content are stored. Microsoft explicitly states it cannot access session content.

Limitations

LimitationDetail
Same-tenant onlyNo cross-tenant sessions. All participants must be in the same Entra ID tenant.
No Linux native appWeb app may function on Linux with a supported browser, but is not officially supported.
No session recordingSessions cannot be recorded through Remote Help.
Government cloudSupported in GCC (Windows, Windows 365, Samsung/Zebra Android dedicated, macOS 13–15). Not supported in GCC High or DoD. Azure Virtual Desktop is not supported in GCC.
Azure Virtual DesktopSupported for Windows generally, but Microsoft advises against using Remote Launch to AVD sessions.
Virtual machinesThe web app does not support VMs.
Android scopeLimited to Android Enterprise dedicated (kiosk) devices – not personal or work profile devices.
Market availabilityRemote Help may not be available in all markets or localizations.

Getting started

The first thing we want to do is configure the Remote Help settings in the Intune portal.

Now we want to install the Remote Help app on our devices. I will use Intune to install it on my Windows 11 devices.

From here we can connect to our supported devices by sharing a code between helper and sharer, or even better directly from the Intune portal. In this example I will connect to my CloudPC by initiating the Remote assistance session directly from the portal, this is pretty cool!

Identify and click on the device you want to connect to. In below example you can see that I have added a scope tag called W365 – Malmo. This means that only helpers with sufficient RBAC for this scope tag are allowed to connect.

The next thing that happens is that the user will receive a nice notification that IT wants to connect to their device. All we need to do is click the notification and approve the connection to start the remote session.
💡If the user has manually muted notifications by setting the device in DND-mode the notification will be hidden/muted.

From here we can support the user throught the Remote Help session.

Final words

Microsoft Intune Remote Help is a great tool for connecting to a device during a support session. However, Microsoft Intune also provides other capabilities that can assist with troubleshooting modern devices, such as Device Query. As a result, I find that the need to establish a remote screen-sharing session is becoming less frequent.

That said, I strongly recommend that organizations include a remote support solution in their toolbox to handle situations where direct device access and screen sharing are still necessary.

Leave a Comment

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.

This website uses cookies. By continuing to use this site, you accept our use of cookies.