Showing posts with label Intune suite. Show all posts
Showing posts with label Intune suite. Show all posts

Monday, 8 June 2026

You have Intune Remote Help already, you might as well use it

You may remember the surprise announcement late last year when Microsoft announced that they would unify the key capabilities of endpoint management by adding the components of the Intune Suite to Microsoft 365 E3 and Microsoft 365 E5 SKUs. These advanced Intune capabilities include Remote Help, which will be included in Microsoft Enterprise Mobility and Security E3 (EMS E3) and therefore Microsoft 365 E3. We believe that this change will be rolled out starting in July 2026.

I have already implemented Remote Help for a number of enterprise and SMB customers and I’m confident that this licensing change will prompt many other customers to move from third party solutions with a view to reducing costs.

What does Remote Help give to your organization?

  • Deliver simple, cloud-connected, and secure assistance to workers anywhere, anytime. 
  • Secure screen sharing and full control of Windows, macOS and Android (Zebra and Samsung) so that helpers (administrators) can support sharers (end users).
  • Role Based Access Control (RBAC); helpers do not need to have excessive permissions on Intune or the devices.
  • Ability to monitor Remote Help sessions; every session is logged with details like helper name, sharer name, device name and length of session.
  • Allows helpers to enter UAC credentials when prompted on the sharer's device for elevated permissions.
  • Enhanced chat in multiple languages.

What are the advantages of Remote Help over other third-party tools?

  • Remote sessions can be launched natively from the Intune admin center by selecting a device.
  • Intune can be integrated with ServiceNow to show a real time list of ServiceNow incidents for a user from the Troubleshooting pane. Remote sessions can be launched from there. 
  • Zero Trust enforcement; uses Microsoft Entra authentication and can be protected with Conditional access. For example, you can require multifactor authentication (MFA) for helpers or restrict access to specific locations or compliant devices.
  • Compliance checks and warnings; helpers can see a noncompliance warning before connecting to a non-compliant device.
  • You can choose to limit remote sessions to Intune enrolled devices only (although you can allow unenrolled devices also).
  • Remote sessions are restricted to your tenant only. This is useful for privacy reasons, especially in Europe, where there are GDPR restrictions. 
  • The data from Remote Help sessions can be combined with Endpoint Analytics to identify common issues.

It won’t hurt to try it out in advance of the licensing changes.

From the Microsoft Intune admin center, navigate to Tenant administration > Intune add-ons. Click View details for Remote Help and this will connect you to the Microsoft 365 admin center where you can request a trial.

Click Start free trial for 250 Remote Help licenses to be added to your tenant for 90 days. You can then assign the licenses to users. Remember that both the helper and sharer need a Remote Help license.


Enable Remote Help

This operation is carried out at the tenant level. In the Microsoft Intune admin center, navigate to Tenant administration > Remote Help. On the Settings tab, click Configure.

  • Set Enable Remote Help to Enabled to allow the use of Remote Help. By default, this setting is disabled.
  • Set Allow Remote Help to unenrolled devices to Enabled if you want to allow this option. By default, this setting is disabled.
  • Set Disable chat to Yes to remove the chat functionality in the Remote Help app. By default, chat is enabled and this setting is set to No.


RBAC and permissions

It is recommended to enforce least privilege and grant the minimum Remote Help permissions for each support role. The Help Desk Operator role already contains the necessary permissions to use Remote Help. However, consider using a custom role to be more granular with the permissions. In the Microsoft Intune admin center, navigate to Tenant administration > Roles. Click Create and choose Intune role.

Select the permissions for the Remote Help app only.

  • View screen allows the helper to view the sharer’s device when Remote Help is enabled.
  • For Android devices, Unattended control will start Remote Help as soon as the helper selects a new session, without a sharer having to grant access. At the time of writing, Unattended control is not yet supported for Windows, this would be useful for managing kiosks. 
  • Take full control allows the helper to control the sharer’s device when Remote Help is enabled.
  • Elevation allows the helper to enter UAC credentials when prompted on the sharer’s Windows device.

The custom role can be assigned to Admin Groups (Entra groups containing the helpers) and targeted at Scope Groups (Entra groups containing the sharers; this can also be All Users or All devices).


Remote Help app

Windows

Download the Remote Help app for Windows. At under 8MB, it’s very lightweight. It must be installed on the helpers device and any device where support is to be offered. There are a few ways to deploy this app.

  • Install manually; requires local administrator permissions and is not sustainable.
  • Add Remote Help to Intune as an Enterprise App Catalog app and assign to your users or devices. There is a cost associated with this method.
  • Deploy Remote Help as a Win32 app. The following parameters can be used.
    • Install command line, specify remotehelpinstaller.exe /quiet acceptTerms=1
    • Uninstall command line, specify remotehelpinstaller.exe /uninstall /quiet acceptTerms=1
    • Detection Path, specify C:\Program Files\Remote Help
    • Detection File or folder, specify RemoteHelp.exe

macOS

Download the Remote Help app for macOS. It can be automatically deployed to your estate of Intune enrolled macOS device. 

Web App

In situations where the sharer needs assistance but is unable to install the full client application for Windows or macOS, the sharer can use the Web App to share their screen to a helper. This web app provides view only capabilities to the helper.

Android

Remote Help app for Android is available on the Google Play store for installation on Zebra and Samsung devices.


The Remote Help experience on Windows

I have two users in my lab. Fred is the helper and Joe is the sharer. Both have Windows 11 devices with the Remote Help app installed.


Fred’s device is on the left in the screenshot. He navigates to Joe’s device in the Intune admin center and chooses New remote assistance session.

The New remote assistance session blade opens, and Fred selects Remote Help > Continue.

Joe receives a Remote Help notification that Fred is available to help him. He is invited to Open Remote Help

Fred is also invited to Open Remote Help.

The Remote Help app launches on Fred’s device, and he can see that Joe is ready for support. Fred can choose to Take full control or View screen. For now, he chooses View Screen.

Joe gets a notification to Allow the remote help session.

The remote help session is established and Fred can see Joe’s screen.


 
Fred and Joe can chat during the session.

Fred can Request control. Joe gets a notification to Allow.

Now Fred can control Joe’s device. Joe can Cancel control at any time.

Fred can elevate his permissions on Joe’s device by entering administrator credentials at the UAC prompt.

Note that I had to create and deploy an Intune configuration policy so that Fred could see the UAC prompt on Joe’s device.

Settings catalog > Local Policies Security Options > User Account Control Allow UI Access Applications To Prompt For Elevation > enabled (allow UIAccess applications to prompt for elevation without using the secure desktop).


The Remote Help experience on macOS

Fred is still the helper and Joe is the sharer. Fred is using his Windows 11 device and Joe wants to share his MacBook with Fred for assistance, although the MacBook is not enrolled in Intune. This time we will use the web app, which supports screen sharing but not full control. If full control is needed, then you have to use the full macOS client application.


 
Fred browses to https://aka.ms/rhh and signs in. Note that rhh = Remote Help helper. 

The long format is https://remotehelp.microsoft.com/helper

A Security code is generated which Fred shares with Joe. 

On the MacBook, Joe browses to https://aka.ms/rh and signs in. Note that this time rh = Remote Help

The long format is https://remotehelp.microsoft.com/sharer

Joe must accept the privacy terms by clicking OK.

Joe enters the security code and selects Share screen.


 
Fred is notified that Joe is ready and clicks Screen sharing to start the session.

Joe sees Fred’s session request and clicks Allow to continue.

Fred gets a compliance warning to say that the MacBook is not enrolled in Intune. He can Leave or choose to continue by clicking OK.


Finally, Joe can choose which screen to share. He clicks Share screen.


Joe has shared his MacBook screen with Fred for assistance. 

I hope that this blog post has been useful to explore the functionality and configuration of Intune Remote Help.

Until next time……

Thursday, 23 May 2024

Secure email with Intune Cloud PKI in less than 15 minutes

This is incredible. I have experience with deploying PKI solutions in the past and it can be time-consuming and complex. My customer has a requirement to encrypt email but they have no internal PKI. I wanted to see how this could be achieved with the new Intune Cloud PKI. I was amazed, I was able to configure the entire solution in my lab in less than 15 minutes and now I can concentrate on the rest of my day.

Licensing first, Cloud PKI is part of the Intune Suite so I ensured that my test users had this license. Then on with the configuration. It's so easy. We'll have a look at how to create and deploy a Microsoft Cloud PKI root CA and issuing CA in Microsoft Intune. We will then create certificate profiles so that the issuing CA can issue certificates to devices.

The account you use to sign into the Microsoft Intune admin center must have permission to create CAs. The roles with built-in permissions include Microsoft Entra Global administrator and Intune service administrator account. 


Alternatively, you can assign Cloud PKI CA permissions to an admin user.


Root CA

In the Microsoft Intune admin center, navigate to Tenant administration > Cloud PKI, and then select Create.


Enter a name and optional description for your CA. Click Next.


Now we have the configuration settings. For CA type you have to choose Root CA, as this is the first one. For validity period, select 5, 10, 15, 20, or 25 years. For Extended Key Usages, select how you intend to use the CA. To prevent potential security risks, CAs are limited to select use. I need Email protection for now, but I may need Client authentication at a later stage. 


Enter a common name for the root CA and optionally enter other attributes.


Enter the required Key size and algorithm. The options are:
  • RSA-2048 and SHA-256
  • RSA-3096 and SHA-384
  • RSA-4096 and SHA-512
Click Next to continue. Configure a scope tag if required and click Next.


Review the configuration. You won't be able to edit these properties after you create the CA. If you need to change something later must create a new CA. If you are happy select Create.


After a short time you will see your root CA.


Have a look at the properties. Download the certificate, you will need it later.


Here is the certificate in .cer format.

Issuing CA

Next we will configure the Issuing CA. An issuing CA is required to issue certificates for Intune-managed devices. Cloud PKI automatically provides a SCEP service that acts as a certificate registration authority. It requests certificates from the issuing CA on behalf of Intune-managed devices using a SCEP profile.

In the Microsoft Intune admin center, navigate to Tenant administration > Cloud PKI, and then select Create.


Enter a name and optional description for your CA. Click Next.


This time we have more options (as we already have one Root CA). Choose Issuing CA as the CA type and Intune as the Root CA Source. Select your Root CA to link with the Issuing CA.


What is the function of the issuing CA? You will only see the options made available through the Root CA. 


I've selected email protection and client authentication again.


Common name is the only required field here.


You cannot configure the key size and algorithm as they are inherited from the root CA.


Review the summary and create the issuing CA.


Root CA and Issuing CA have now been created and are available in the Intune admin center. Note that, at the moment, it is not possible to delete these CAs without a support ticket.


Download the certificate and copy the SCEP URI. You will need them later.


Here we have our Root and Intermediate certificates.

Certificate Profiles

Now we need to create three certificate profiles.
  • Trusted certificate profile for the Cloud PKI root CA
  • Trusted certificate profile for the Cloud PKI issuing CA
  • SCEP certificate profile for the Cloud PKI issuing CA
Let's do the Root CA first.


Create a configuration profile using the Trusted certificate template.


Browse to the .CER file download earlier from the Root CA.


Assign the profile to a group.


Create a second profile using the Trusted Certificate template. Browse to the CA file downloaded from the Issuing CA.


Next we need a configuration profile based on the SCEP certificate template.


Default settings will work here. Note that key storage provider, key usage, key size and hash algorithm are not pre-configured but are required.


Select your Root CA and extended key usage. I've chosen secure email and client authentication again. Enter the SCEP URI that you copied earlier.


Create and assign the SCEP profile.

On the test device

So, what do we see on the test device?


The root and intermediate certificates can be seen in the Trusted Root Certificate Authority store.


The SCEP certificate for the logged in user can be seen in the Personal store.


In the Intune admin center, browse to Tenant Admin > Cloud PKI > Issuing CA > View all certificates to see a list of all the SCEP certificates issued to users.  


Drill into a certificate to see the details.


Now, in the Outlook client, select File from the main menu, then click Options. Select Trust Center at the bottom of the menu on the left side of the Outlook Options. Click the Trust Center Settings button. Select Email Security from the left-hand menu of the Trust Center window and you will see the email encryption settings.


Click Settings to see the certificate details.


The user now has the option to encrypt emails using S/MIME.

I hope this help, until next time........