Intune's Remote Help now lets helpers sign directly into a locked Windows device without the user present.
Intune's Remote Help now lets helpers sign directly into a locked Windows device without the user present. Here is what the new remote sign-in permission actually requires, and why it still will not solve cross-tenant support for MSPs.
Helpdesk teams have asked for years for a way to fix a Windows PC after hours without waiting for a user to click accept. Intune is finally delivering it. Unattended Remote Help with Windows remote sign-in lets an authorized helper connect straight to a device's lock screen, authenticate with their own credentials, and work in a separate Windows session, while the original user's session stays locked and preserved rather than being logged off.
Before rolling this out to a helpdesk team, check the fine print:
- The target device must be a physical, corporate-owned Windows x64 device that is Microsoft Entra joined or hybrid joined. Windows 365, Azure Virtual Desktop, and personal or BYOD PCs are not eligible for unattended control.
- The device needs the Azure Virtual Desktop agent and bootloader, the Intune Management Extension, and Remote Desktop enabled, and it has to be powered on and online. Sleeping or shut-down devices cannot receive an unattended session.
- Access runs through a brand new RBAC permission, Remote Help app - Windows unattended control remote sign-in, and it is deliberately left out of every built-in Intune role, including Help Desk Operator. Admins have to build a custom role and scope it to specific device groups themselves.
- A Remote Help license is still required for both the helper and the person being helped, on top of Intune Plan 1 or 2.
For MSPs, the detail that matters most is one that has not changed: helper and sharer still have to sign in from the same tenant. There is no cross-tenant unattended session, so a technician working across ten customer tenants still needs a properly scoped identity and device inside each one.