Insights

Your helpdesk can now sign in to a Windows laptop with nobody at it

Braintree Insights | 26 August 2026

Your helpdesk can now sign in to a Windows laptop with nobody at it

Microsoft Intune service release 2608 added unattended Remote Help for Windows: an authorised helper signs in to a corporate device with their own credentials, without the user being present or accepting anything. It is licensed at both ends on top of Intune Plan 1 or 2, it is limited to physical corporate-owned Entra-joined machines, it requires the Azure Virtual Desktop agent and bootloader on the target, and the only detailed record of what happened is the Windows event log.

What changed

Microsoft Intune’s what’s-new page records service release 2608, published in the week of 25 August 2026, as adding unattended Remote Help sessions on physical Windows devices, stating that authorised helpdesk agents can sign in to a remote device with their own credentials without requiring the user to be present or take action. The planning documentation, refreshed to the same timestamp, is where the operational shape of it lives. The capability requires a subscription in addition to Microsoft Intune Plan 1 or Plan 2, and Microsoft is explicit that a licence is needed for everyone targeted to use the service, both helpers and the users being helped. The target device must be a physical, Intune-managed, corporate-owned Windows device running an x64 operating system, joined or hybrid joined to Microsoft Entra. Virtual devices are excluded, including Windows 365 Cloud PCs and Azure Virtual Desktop, as are unenrolled and personally owned devices; those can still receive attended support. The prerequisites on the target are unusual enough to be worth stating plainly: the Azure Virtual Desktop agent and the Azure Virtual Desktop agent bootloader must both be installed, the agent first and then the bootloader, on what may be an ordinary corporate laptop. The Intune Management Extension must be present to orchestrate the session, Remote Desktop must be enabled, and the device must be powered on and connected to the internet, because Microsoft states that devices that are asleep, hibernating or shut down cannot receive unattended support. Access is granted by one permission, Remote Help app – Windows unattended control remote sign-in, and Microsoft’s own guidance is to create a dedicated custom Intune role for it and scope that role only to the device groups that require unattended support.

The operational risk is easy to miss because the service can continue to look healthy. The control becomes visible only when a capacity request fails, an unsupported runtime is removed, or an extension blocks an enforced ERP update. Waiting for that moment transfers a planned decision into an incident.

What the term means in plain language

Remote Help is Microsoft’s Intune-integrated remote assistance tool. Microsoft calls the support agent the helper and the person receiving help the sharer. An attended session is the familiar model: the user is present and grants access, and the helper may view only, take full control, or respond to elevation prompts. An unattended session removes the acceptance step entirely, so the helper connects and signs in without a person at the device. Role-based access control is the Intune mechanism that decides which administrators hold which permissions over which groups of devices, which is why the scoping of one specific permission is the whole control here.

This distinction matters because product status is not the same as business readiness. Availability, support and compatibility are separate questions. A service can be available but unsupported, supported but capacity-constrained, or technically updated while a customer-specific process has stopped working.

Why this matters to a South African organisation

South African teams often operate with tight specialist capacity, rand-sensitive budgets and business processes that cannot be paused while a replacement is sourced. Localisation, regional cloud capacity and long procurement lead times can narrow the recovery options. The practical response is to use the available test window before it becomes an emergency window.

The consequence belongs to the business process, not only the technology team. Finance month-end, customer transactions, data pipelines and ERP extensions all cross technical and operational ownership. A change should therefore be accepted only when the service owner and the business owner can see the same evidence.

The hidden exposure

Microsoft Intune service release 2608 added unattended Remote Help for Windows: an authorised helper signs in to a corporate device with their own credentials, without the user being present or accepting anything. It is licensed at both ends on top of Intune Plan 1 or 2, it is limited to physical corporate-owned Entra-joined machines, it requires the Azure Virtual Desktop agent and bootloader on the target, and the only detailed record of what happened is the Windows event log.

Normal operation is weak evidence. It proves only that yesterday’s combination of platform, configuration and workload completed. It does not prove that the next capacity allocation, lifecycle enforcement or major release will preserve the same result. An owner needs an inventory, a representative test and a dated decision.

Decision path

This is a policy decision wearing the clothes of a licensing decision, and the order matters. The capability is genuinely useful. A machine that will not reach the sign-in screen, an overnight remediation, a device in a branch with nobody technical nearby: these are real problems that attended support cannot solve. The question is not whether to have it but who holds it, over which devices, and what the organisation can show afterwards. Start with the permission. Microsoft’s guidance is unusually direct about least privilege here, recommending a dedicated custom role rather than an addition to an existing one, and scoping to specific device groups. The built-in Help Desk Operator role already carries view, full control, elevation and Android unattended control, so an organisation that treats unattended Windows control as just another helpdesk permission has effectively granted it to everyone on the desk. Next, the record. Microsoft states that no session recordings are stored by the service, that Remote Help logs session details to the Windows event logs on both the helper’s and the sharer’s device, and that its own service records, covering the start and end time of a session and who helped whom on what device, are kept for 30 days. Braintree’s view, not Microsoft’s, is that the event log therefore has to be collected before the capability is enabled rather than after an incident, because a control whose only evidence lives on the endpoint being controlled is not much of a control. Then the people. Microsoft’s privacy guidance states that users cannot observe the actions performed by support personnel during unattended access but are notified when an unattended session is active, that all sessions are clearly indicated to users, and that organisations should consider documenting these behaviours in IT policy and user guidance. In a South African context that documentation is not optional courtesy: staff are entitled to know that a company device can be operated while they are not at it, and the honest way to introduce this is in writing before the first session, not in an explanation afterwards. Finally the practical limit. The device must be awake and online, which in a week of load shedding removes a large part of the fleet from reach at exactly the times support is most needed, so unattended access should be planned as an addition to existing support routes rather than a replacement for them.

Record the alternatives that were rejected and why. That prevents the next reviewer from reopening the entire question without context. Where the preferred path cannot be completed inside seven days, approve a time-bound exception with a responsible owner, expiry date and compensating control.

Technical test plan

Sequence the rollout so that nothing is switched on before it can be observed. Confirm the licence position first, at both ends, because Microsoft states the unattended option does not appear where both sides are not licensed. Build the custom Intune role next, containing the Windows unattended control remote sign-in permission, and assign it to a named set of support staff scoped to a named set of device groups; keep the group small enough that the list can be read in one screen. Prepare the target devices as Win32 app deployments: the Azure Virtual Desktop agent, then the bootloader, in that order, with the Intune Management Extension present and Remote Desktop enabled through a settings catalog configuration profile. Confirm that the devices in scope are physical, corporate-owned, x64 and Entra joined or hybrid joined, and exclude Cloud PCs and Azure Virtual Desktop hosts explicitly rather than assuming the platform will filter them. Microsoft also recommends Conditional Access for helper accounts, requiring multifactor authentication or a compliant device, on the reasoning that a helper account is now an elevated route into other people’s machines; Conditional Access for Remote Help is supported on Windows and macOS. Before the first production session, prove the logging: run a session against a test device, then confirm the expected entries appear in the Windows event log on both machines and are being shipped wherever logs are retained. Keep the Remote Help applications current on both sides, since Microsoft states it might enforce upgrades of older versions. And note the tenant boundary: helpers, sharers and devices must be in the same tenant, which is the constraint that decides whether an outsourced service desk can use this at all.

Use production-representative conditions without exposing production data unnecessarily. Capture the starting configuration, exact version, time of test and expected result. A pass requires evidence from the real workflow, not only a successful login or an unchanged dashboard.

Primary owner

Primary owner: The IT manager or service-desk owner, with whoever is accountable for information security and staff privacy policy.

The named owner coordinates platform, application, commercial and business-process decisions. Contributors may perform the work, but accountability cannot be distributed across a meeting invite. The owner closes the test, exception and evidence record.

Action within seven days

Action within seven days: Decide the policy before enabling the capability. Create a dedicated custom Intune role carrying the Windows unattended control remote sign-in permission, scoped to named device groups, rather than adding the permission to the role the whole service desk already holds. Confirm the licence position at both ends, write the capability into the acceptable-use or IT policy staff have seen, and confirm Windows event logs from the affected devices are being collected before the first session runs.

Start with the highest-consequence workload. Assign the people, date and pass criteria before the test begins. If the first test fails, record the failure as evidence and open remediation with a deadline rather than hiding it behind a general project status.

Evidence to retain

Evidence to retain: The role definition with its assignment and scope groups, the list of devices in scope, the licence assignment record for helpers and for target devices, the dated policy text that tells staff unattended support exists and when it is used, and the log-collection configuration proving session events from both helper and target devices are retained.

Store the evidence with the platform or change record. Include source exports and machine-readable results where possible. The next reviewer should be able to reproduce the conclusion without rebuilding it from email, chat or memory.

Frequently asked questions

Does the user have to agree to the session?

No. That is the change. Microsoft states the helper can sign in without requiring the user to be present or take action. The user is notified while an unattended session is active but cannot observe what the helper is doing.

Is the session recorded?

No session recordings are stored by the service. Session details are written to the Windows event logs on both the helper’s and the sharer’s device, and Microsoft keeps the start and end time and who helped whom on what device for 30 days.

What does it cost?

Microsoft states the feature requires a subscription in addition to Intune Plan 1 or Plan 2, and that a licence is needed for everyone targeted to use it, both the support staff and the users being helped.

Will it work on a Cloud PC or an Azure Virtual Desktop session host?

No. Microsoft excludes virtual devices from unattended control, naming Windows 365 and Azure Virtual Desktop, along with unenrolled and personally owned devices. Those can still receive attended support.

What has to be installed on the target machine?

The Azure Virtual Desktop agent and then its bootloader, in that order, plus the Intune Management Extension, with Remote Desktop enabled.

What if the device is asleep or switched off?

It cannot receive a session. Microsoft states the device must be powered on and connected to the internet, and that devices that are asleep, hibernating or shut down cannot receive unattended support.

Who should hold the permission?

As few people as the service can function with. Microsoft’s own guidance is to create a dedicated custom Intune role containing the unattended permission and to scope it only to the device groups that require unattended support, rather than adding it to a general helpdesk role.

Do we have to tell staff?

Microsoft advises organisations to document these behaviours in IT policy and user guidance. Braintree’s view is that this should be treated as a requirement rather than advice, because the capability operates a person’s device while they are not there.

The Braintree view

Microsoft’s announcement supplies the platform fact. The customer control begins after that fact: identify the exposed process, name the owner, test the real dependency and retain a decision that can survive audit or staff turnover. Braintree can help structure the inventory, build the representative test and translate the result into a controlled implementation plan.

Use the seven-day action as the entry point. Do not wait for a renewal, support refusal or enforced update to reveal work that can be measured now.

Related Posts

Azure SRE Agent's 30-day trial reached general availability...
Microsoft published research on 26 August 2026 describing...
Azure Bastion shareable links let someone with no...