## TL;DR
Give your helpdesk technicians the Remote Help add-on license, deploy the Remote Help app to managed devices through Intune, then grant the technicians a role with the Remote Help permission scoped to the devices they support. A session starts when the user reads a security code from their app to the technician and accepts the consent prompt. Pilot it with tier 2 before handing it to tier 1.

## Steps
1. Verify licensing in the Microsoft 365 admin center: each technician who will act as a helper needs the Remote Help add-on license assigned. Expected: licenses show as assigned to your helpdesk group.
2. Deploy the app: Intune admin center / Apps / Windows / Add / Microsoft Store app (new) / search for Remote Help, then assign it to all managed devices. Expected: the app appears in Company Portal or installs automatically per your assignment intent.
3. Set up access: Intune admin center / Tenant administration / Roles / create a role with the Remote Help permission, and assign it to the helpdesk group with a scope tag covering the devices they support. Expected: technicians see only their in-scope devices.
4. Run a test session: the user opens Remote Help on their device and reads out the security code; the technician enters it in their Remote Help app. Expected: the session connects within seconds.
5. Test elevation: the technician requests full control and the user accepts the elevation consent prompt. Expected: the technician can interact with admin prompts on the user's screen. Then document the flow for tier 1 and roll out.

## Use this when
- Standing up remote assistance for an Intune-managed fleet
- Replacing TeamViewer, Bomgar, or similar with the native Intune option
- A technician needs to see or control a user's screen for a ticket

## Not for this skill when
- You need unattended access with no user present (Remote Help requires the user to share a code)
- The device is not enrolled in Intune
- The device is a Mac or a phone (both helper and sharer must be Windows)

## Compatibility
- Windows 10 and Windows 11 enrolled in Intune
- Intune Plan 1 plus the Remote Help add-on for helpers; sharers need Intune enrollment only

## Variants
### View-only triage
Helpers can start view-only when they just need to see the problem. Elevation to full control is a separate consent step the user must accept.
### Conditional Access blocking the helper
If technicians cannot sign into the Remote Help app, check Conditional Access policies targeting the app. Exclude or allow the helpdesk group explicitly.

## Why it happens
Remote Help is a brokered session, not a listening agent: Microsoft brokers the connection after both sides authenticate, and the security code binds the helper to the right sharer. Most setup failures are licensing (helper has no add-on) or RBAC (role missing the permission), not network.

## Edge cases
- Technicians supporting multiple regions: scope tags must include all the devices they cover or sessions fail silently.
- Users on metered or restricted networks may fail to connect; the session needs outbound connectivity to Microsoft endpoints.
- Record the consent policy decision (who approved Remote Help) in your change log; auditors ask about remote-access tooling.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_8m5ZE_6MdJE5gRyhVZ0mmg
