Intune Remote Help - Unattended Windows - Insufficient Security?

Simon Belmont 30 Reputation points
2026-09-17T09:53:38.37+00:00

When using this feature, there is no need to install the Remote Help app. Rather the requirements are as following on the sharer's device:

  • Install AVD agent and AVD agent bootloader
  • Enable RDP connection
  • Give "Allow logon through RDS" to the user who will perform final logon (this step is not documented by Microsoft)

To start unattended session:

Log on to Intune Admin Center with sufficient RBAC permissions (an admin account) Logon performed with strong phishing resistant authentication method

Locate the relevant Win11 Device in Intune and start Remote Assistance (Unattended)

Log on to the Win11 Device with a user who has "Allow logon through RDS" permissions

**
The issue is that logon in step 3 only supports Username/Password logon.** Which means that said user's credentials and authentication token will be stored on the Win11 Device. Strong authentication is not supported.

Does anyone have any thoughts regarding this?

You could use a cloud only user which has to use PIM to activate a group that has the "allow logon through RDS" permission on the device. Apart from that the user would have no other privileges, but then you'd have to assign Remote Help license to such a user, and if your IT Helpdesk consists of 25 people, that means 25 additional licenses..

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.