IntuneHow-to

Remote Help in Intune: licensing, setup, helper roles, deployment and troubleshooting

Set up Remote Help end to end: check licensing, enable the tenant settings, grant least-privilege helper roles, deploy the Windows app, handle Conditional Access, and fix sessions that won't connect.

Remote Help is Microsoft's remote assistance tool for Intune-managed estates: helpers and users both sign in with Microsoft Entra accounts, Intune RBAC decides who may view, control or elevate, and every session is logged. In this post I'll walk through what you need before you start, the tenant and RBAC configuration, deploying the Windows app, how a session flows, and the checks that resolve most "it won't connect" tickets.

How this guide is organised: Prerequisites → Step-by-step → How a session flows → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (4 steps: Enable Remote Help for the tenant; Grant helper permissions with RBAC; Deploy the Windows app; Decide on Conditional Access). 3. How a session flows. 4. Verify. 5. Tips & gotchas. Toolbox: Remote_help_*.log, remotehelpinstaller.exe, RemoteHelp.exe, RHService.exe, Remote Help › Settings.1Prerequisites2Step-by-step3How a sessionflows4Verify5Tips & gotchas1Enable Remote Help forthe tenant2Grant helper permissionswith RBAC3Deploy the Windows app4Decide on ConditionalAccessTOOLBOXRemote_help_*.logremotehelpinstaller.exeRemoteHelp.exeRHService.exeRemote Help › SettingsHow this guide is organised: Prerequisites → Step-by-step → How a session flows → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (4 steps: Enable Remote Help for the tenant; Grant helper permissions with RBAC; Deploy the Windows app; Decide on Conditional Access). 3. How a session flows. 4. Verify. 5. Tips & gotchas. Toolbox: Remote_help_*.log, remotehelpinstaller.exe, RemoteHelp.exe, RHService.exe, Remote Help › Settings.1Prerequisites2Step-by-step1Enable Remote Help for the tenant2Grant helper permissions with RBAC3Deploy the Windows app4Decide on Conditional Access3How a session flows4Verify5Tips & gotchasTOOLBOXRemote_help_*.logremotehelpinstaller.exeRemoteHelp.exeRHService.exeRemote Help › Settings
At a glance: how this guide is organised · 4 steps · 5 key settings and tools

Prerequisites#

  • Licensing. Remote Help is one of the Intune advanced capabilities, available through Microsoft Intune Plan 2, the Intune Suite and select Microsoft 365 bundles. In mid-2026 Microsoft began adding it to commercial Microsoft 365 E3 and E5 (through EMS E3), rolling out gradually with 30 days' notice in the Microsoft 365 admin center; Education and frontline plans weren't included at the time of writing. Helpers and sharers both need a license. Check eligibility under Tenant administration › Intune add-ons, where a 90-day trial for up to 250 users is also offered.
  • Same tenant. Helper, sharer and device must all be in your Microsoft Entra tenant. For outsourced helpdesks, that means devices or Cloud PCs joined to your tenant.
  • Platforms. For attended sessions on Windows: x86, x64 and ARM64, Windows 365 and Azure Virtual Desktop. Intune-enrolled devices must be registered with Microsoft Entra. Unattended sessions are limited to physical, corporate-owned, x64, Microsoft Entra joined or hybrid joined Windows devices with the Intune Management Extension installed.
  • Network. Port 443 to the documented endpoints, with SSL inspection excluded. Remote Help connects to remotehelp.microsoft.com over RDP wrapped in TLS 1.2.
  • Microsoft Edge WebView2 Runtime, which the installer adds if it's missing.

Step-by-step#

Step 1: Enable Remote Help for the tenant#

Go to Tenant administration › Remote Help › Settings. Set Enable Remote Help to Enabled (it's off by default and applies tenant-wide). Decide on Allow Remote Help to unenrolled devices: Enabled lets helpers assist Microsoft Entra registered devices that aren't enrolled, at the cost of no compliance information and limited reporting; it doesn't apply to unattended control. Disable chat removes the in-session chat if your policy requires it. Save, and allow time: newly assigned licenses can take from 30 minutes to about 8 hours to activate, during which sessions still report that Remote Help isn't enabled.

Step 2: Grant helper permissions with RBAC#

Remote Help permissions sit in the Remote Help app category of Intune RBAC, and a helper also needs Remote tasks › Offer remote assistance and Remote assistance connectors › Read.

PermissionWhat it allows
Remote Help app › View screenSee the sharer's screen without control
Remote Help app › Take full controlControl the sharer's device
Remote Help app › ElevationRespond to UAC prompts on the sharer's Windows device
Remote Help app › Windows unattended control remote sign-inStart an unattended session on a corporate Windows device without the user accepting
Remote Help app › Android unattended controlConnect to Android Enterprise dedicated devices without acceptance
Remote tasks › Offer remote assistanceRequired to start any session
Remote assistance connectors › ReadLets the app check that Remote Help is configured for the tenant

The built-in Help Desk Operator role includes everything except Windows unattended control. For least privilege, create custom roles under Tenant administration › Roles › Create: tier 1 with View screen only, tier 2 adding Take full control and Elevation, and a tightly scoped role for unattended sign-in limited to the device groups that genuinely need it. In each assignment the sharer or device must fall inside the Scope (Groups), or the helper can't assist. The All devices scope group doesn't include unenrolled devices, so use a user scope group when you allow those.

Step 3: Deploy the Windows app#

Attended support uses the Remote Help app, which must be installed on both the helper's and the sharer's device. The simplest route is the Enterprise App Catalog, if your licensing includes Enterprise Application Management, because Microsoft maintains the package. Otherwise download remotehelpinstaller.exe from aka.ms/downloadremotehelp, wrap it with the Win32 Content Prep Tool and add it as a Win32 app with these values:

Command Prompt
Install:   remotehelpinstaller.exe /quiet acceptTerms=1
Uninstall: remotehelpinstaller.exe /uninstall /quiet acceptTerms=1
Optional:  add enableAutoUpdates=0 to the install command to opt out of auto-updates

The switches acceptTerms and enableAutoUpdates are case sensitive. Use a file detection rule on C:\Program Files\Remote Help\RemoteHelp.exe with String (version), Greater than or equal to and the version you're deploying, which you can read with (Get-Item "$env:ProgramFiles\Remote Help\RemoteHelp.exe").VersionInfo on a test machine. Assign to device groups; user-group targeting isn't supported. By default the app updates itself. If your firewall filters outbound apps, allow RemoteHelp.exe, RHService.exe and RemoteHelpRDP.exe in C:\Program Files\Remote help.

Unattended control on Windows (added in the August 2026 service release) uses a different stack: deploy the Azure Virtual Desktop agent and then the agent bootloader as two Win32 apps with a dependency, leave the registration token at INVALID_TOKEN, enable Remote Desktop through a settings catalog profile (Allow users to connect remotely by using Remote Desktop Services), and keep the Intune Management Extension installed.

Step 4: Decide on Conditional Access#

Remote Help honours Conditional Access on Windows and macOS for attended sessions. Before the service shows up as a target resource, create its service principal once:

PowerShell
Connect-MgGraph -Scopes "Application.ReadWrite.All"
New-MgServicePrincipal -AppId "1dee7b72-b80d-4e56-933d-8b6b04f9a3e2"
Disconnect-MgGraph

RemoteAssistanceService then appears under Target resources, so you can require MFA or a compliant device for helpers, or exclude it from a policy that would otherwise break sessions. Microsoft recommends MFA for helper accounts because of the access they hold.

How a session flows#

From the admin center: Devices › All devices › (device) › New remote assistance session › Remote Help › Continue, then Initiate attended control. Intune notifies the device; the user selects Open Remote Help, both sides sign in, and each sees the other's name, job title, company, photo and verified domain. The user chooses Allow screen sharing or full control or declines; the helper can request full control later, and one with the Elevation permission can answer UAC prompts. A noncompliant device shows the helper a warning banner first. Alternatively, the helper opens the app and reads a session code to the user. Either side ends with Leave; if elevated actions happened and the sharer ends the session, the sharer is signed out of Windows.

Verify#

Run a test session between two IT accounts, then check Tenant administration › Remote Help: the Monitor tab counts active sessions and the Remote Help sessions tab records provider, recipient, device, start and end time and the session type (view only, full control or unattended). Records are kept for 30 days, elevation isn't reported, and sessions on unenrolled devices have limited data. Remote Help activity also appears under Tenant administration › Audit logs, and Microsoft Entra sign-in logs show who signed in to the Remote Help app and when.

Tips & gotchas#

  • "Remote Help isn't enabled" right after buying licenses is usually the activation delay. Wait, then confirm the Settings tab.
  • Helper can't start a session. Check the full combination: a Remote Help app permission, Offer remote assistance, Remote assistance connectors Read, and a scope that contains the sharer or device.
  • Notification never arrives. Do not disturb hides it; the user can open the app manually. Remote launch notifications depend on the Intune Management Extension, so keep it installed and current. The helper can select Retry, and an offline device returns an error.
  • Connection drops or hangs. Verify TCP 443 to remotehelp.microsoft.com, *.support.services.microsoft.com, remoteassistanceprodacs.communication.azure.com (EU tenants also use remoteassistanceprodacseu.communication.azure.com), *.trouter.communications.svc.cloud.microsoft, *.webpubsub.azure.com and the Azure Communication Services requirements, and exclude them from SSL inspection.
  • Logs. Operational events are in Event Viewer › Applications and Services Logs › Microsoft › Windows › RemoteHelp; installer logs Remote_help_*.log land in the user's %temp% folder. A dialog about WebView2 means Microsoft Edge or the WebView2 Runtime needs repairing or installing.
  • Offboarding. Remove leavers from the helper groups promptly; the role assignment is what stands between an account and your users' screens.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)