Scope & evidence

Authorised IT support and administration. Actual consent prompts, elevation behaviour and supported devices vary by product and operating system.

Research-based; no hands-on test claim.

Match the access model to the job

Attended support fits a user asking for help on a device in front of them. They can describe the symptom, approve the connection and observe the work. Unattended access fits managed systems that need maintenance when nobody is present, such as a server or a scheduled endpoint change.

The choice is not a measure of trust in a particular user. It is an operational design decision about when access is needed and how authorisation is recorded. Avoid installing persistent access for a one-off session unless there is a separate approved need.

Treat persistent access as an asset

For unattended agents, record the enrolled device, service owner, permitted technician group and review date. Verify deployment source and policy. Restrict access to the smallest useful set of systems rather than making every device visible to every technician.

Test what happens after a technician leaves, a device is reassigned or the supplier account is disabled. Removing a local user account may not remove a remote-support agent or its cloud permissions. Check both the endpoint and the management console.

Close and verify the session

Record the actions taken and the outcome. Remove temporary files, elevated credentials or temporary access introduced for the task. For attended support, confirm that the user understands the result and that the session has ended.

Review session logs and their retention. Recording can capture sensitive data, so enable it only under an appropriate policy and access model. For unattended access, periodically verify that the business need still exists and that revocation works.

References

Next useful steps

Read our editorial and corrections policy.