Set Up Microsoft Intune Remote Help with the Enterprise App Catalog
Microsoft Remote Help gives IT support teams a managed way to view and control Windows devices without relying on personal accounts or a separate remote access product.
It integrates with Microsoft Entra ID, Microsoft Intune role-based access control, device compliance and session reporting. This gives administrators more control over who can provide support, which users and devices they can access, and whether they can view a screen, take full control or interact with User Account Control prompts.
The other useful change is how Microsoft Remote Help can now be deployed.
Instead of downloading the installer, packaging it with the Microsoft Win32 Content Prep Tool and creating your own detection rules, eligible tenants can add Microsoft Remote Help directly from the Enterprise App Catalog.
In this guide, I will cover the full setup, including licensing, tenant configuration, helper permissions, application deployment, installation checks, support sessions, monitoring and the security controls I would put in place before using it in production.
For my test environment, I used two Microsoft Entra joined and Intune-enrolled Windows 11 virtual machines:
CADTB01 is the device providing support.
CADTB03 is the device receiving support.
Never miss an article and subscribe, and don’t forget to check out my YouTube channel, Control Alt Delete Tech Bits
Like the article? Feel free to buy me a coffee
Also check out my redact app, Redact PDFs and images, review email evidence and manage subject access requests without sending source files to a processing server.: https://redactninja.com
What is Microsoft Remote Help?
Microsoft Remote Help is a cloud-based remote support service that works with Microsoft Intune.
Microsoft refers to the technician providing support as the helper. The person receiving support is called the sharer because they are sharing access to their device.
Both users sign in with organisational Microsoft Entra accounts. Remote Help uses these identities to establish trust between the two people and confirm that they belong to the same tenant.
This is one of the main differences between Microsoft Remote Help and a basic screen-sharing tool. The support session is linked to your organisation, your Intune permissions and your managed users and devices.
On Windows, a helper can be granted one or more of the following capabilities:
• View the sharer’s screen without controlling it
• Take full control of the keyboard and mouse
• Interact with User Account Control prompts
• Chat with the sharer during the support session
• Launch a session from the Intune device record
• Review device compliance warnings before providing support
Microsoft Remote Help does not support cross-tenant assistance. A helper in one Microsoft Entra tenant cannot use Remote Help to support a user in another tenant.
Both helpers and sharers also require an eligible Microsoft Remote Help entitlement.
Microsoft Remote Help licensing changed in July 2026
Microsoft Remote Help previously required a separate add-on or the wider Microsoft Intune Suite.
Starting in July 2026, Microsoft began including several advanced Intune capabilities with its commercial Microsoft 365 enterprise plans.
Microsoft 365 E3 now includes:
• Microsoft Intune Plan 2
• Microsoft Remote Help
• Microsoft Intune Advanced Analytics
Microsoft 365 E5 includes those capabilities, plus:
• Microsoft Intune Endpoint Privilege Management
• Microsoft Cloud PKI
• Microsoft Intune Enterprise Application Management
Enterprise Application Management provides access to the Enterprise App Catalog used in this guide.
This means an eligible Microsoft 365 E3 tenant may have Microsoft Remote Help without having access to the Enterprise App Catalog deployment method.
An eligible Microsoft 365 E5 tenant should receive both Remote Help and Enterprise Application Management once the capability has been provisioned.
This licensing change applies to Microsoft 365 E3 and Microsoft 365 E5. It does not apply to the similarly named Office 365 E3 and Office 365 E5 plans, as those plans do not include Microsoft Intune.
The new capabilities are being provisioned gradually. Check your Microsoft 365 Message Centre, licensing agreement and the features visible in the Microsoft Intune admin centre before removing or cancelling an existing add-on.
My Microsoft 365 E5 developer tenant displayed a Remote Help trial banner even though Remote Help and the Enterprise App Catalog were available and working. I would not rely on one portal banner as the only licensing check.
This site and my YouTube channel are supported by Tech-Source.
Tech-Source is a UK-based technology supplier that works closely with IT teams across education, public sector, and commercial environments. They provide hardware, licensing, and infrastructure solutions, with a strong focus on practical advice rather than upselling.
Their support helps keep this site running and allows me to continue publishing in-depth, admin-focused content and walkthroughs without paywalls.
You can find out more about what they do at https://tech-source.co.uk/
Microsoft Remote Help prerequisites
Before configuring Microsoft Remote Help, you will need:
• An eligible Remote Help entitlement for every helper and sharer
• Supported Windows devices
• Microsoft Entra accounts from the same tenant
• Microsoft Intune-enrolled devices
• The Microsoft Remote Help application installed on both devices
• An Intune role assignment for the helper
• Network access to the required Microsoft endpoints over TCP 443
• Microsoft Edge WebView2 Runtime
The sharer’s device also needs the Microsoft Intune Management Extension if you want to launch a Remote Help session directly from the Intune device record.
For my lab, I created the following Microsoft Entra security groups:
Remote Help – Helpers
Remote Help – Test Users
Remote Help – Test Devices
CADTB01 and CADTB03 are members of Remote Help – Test Devices.
The helper account is a member of Remote Help – Helpers.
The normal test user is a member of Remote Help – Test Users.
Keeping these groups separate makes it easier to test the deployment and role assignments without giving access to every user or device in the tenant.
Enable Microsoft Remote Help in Intune
An eligible licence does not automatically enable Microsoft Remote Help.
Open the Microsoft Intune admin centre and go to:
Tenant administration > Remote Help > Settings
Select Configure.
Use the following settings:
Enable Remote Help > Enabled
Allow Remote Help to unenrolled devices > Not allowed
Disable chat > No
Select Save.
Keeping support for unenrolled devices disabled means the sharer must be using an Intune-enrolled device from the same tenant.
This gives the helper access to more useful management information, including the device compliance state.
Chat remains enabled so the helper and sharer can exchange short messages during the session.
Microsoft states that newly assigned licences or trial licences can take between 30 minutes and eight hours to become active.
You might successfully enable Remote Help but still receive a message saying the service is not enabled when attempting the first session. If that happens, allow additional time before changing the configuration.


Microsoft Remote Help settings for enrolled Windows devices
Configure Microsoft Remote Help permissions
Installing the application does not automatically make someone a helper.
Microsoft Remote Help uses Intune role-based access control to decide which users can provide assistance and what they can do during a session.
The built-in Help Desk Operator role contains the required Remote Help permissions.
That may be suitable for a quick test, but it can provide more access than a first-line support technician requires.
A custom role gives you more control.
Go to:
Tenant administration > Roles > All roles > Create
Create a role such as:
Remote Help – Elevated Helper
Add the following permissions:
Remote Help > View screen
Remote Help > Take full control
Remote Help > Elevation
Remote tasks > Offer remote assistance
Remote assistance connectors > Read
A helper needs the following combination:
• Remote tasks > Offer remote assistance
• Remote assistance connectors > Read
• At least one Microsoft Remote Help permission
The admin group in the role assignment determines who receives the permissions.
The scope groups determine which users and devices those helpers are allowed to support.
For my test role, I used:
Admin Groups > Remote Help – Helpers
Scope Groups > Remote Help – Test Users
Scope Groups > Remote Help – Test Devices
If the sharer or the sharer’s device is outside the helper’s assigned scope, the helper should not be able to provide assistance.
For production, I would not give every technician elevation rights.
A better structure would be:
First-line support > View screen
Second-line support > View screen and take full control
Selected senior technicians > View screen, full control and elevation
Intune permissions from multiple role assignments are cumulative. There is no deny permission that removes access granted by another role.
Check all role assignments before deciding that a helper has only been given limited access.
Deploy Microsoft Remote Help from the Enterprise App Catalog
The Enterprise App Catalog contains prepared Win32 applications that Microsoft hosts for Intune customers.
Microsoft supplies the package, installation command, uninstall command, requirements and detection rules.
This removes most of the manual work normally involved in deploying an executable application through Intune.
Microsoft recommends keeping the supplied settings unless you have a tested reason to replace them. Changing the installation commands or detection logic can cause the application to fail.
Open the Microsoft Intune admin centre and go to:
Apps > All apps > Create
Under Windows, select:
Enterprise App Catalog app
Select Select.
On the App information page, select:
Search the Enterprise App Catalog
Search for:
Microsoft Remote Help
Select Microsoft Remote Help and then select Next.
On Configuration, choose the package that matches your devices.
In my lab, I selected:
Package name > Remote Help
Language > en-US
Architecture > x64
Version > 5.2.1037.0
The screenshots in this guide show version 5.2.1037.0.
Select the version available in your tenant when you perform the deployment. The catalogue entry will change when Microsoft publishes a newer release.

Choose the Microsoft Remote Help update method
The Updates tab provides two update methods:
Automatically update
Update with supersedence
For this deployment, I selected Automatically update.
This allows Intune to update Microsoft Remote Help when a newer version becomes available in the Enterprise App Catalog.
Automatic updating applies to Enterprise App Catalog applications with a Required assignment.
The portal warns that this is a one-time choice for that application. You would need to create a new app if you later wanted to use a different update method.
Automatically update is the most straightforward option when you do not need custom installation scripts or staged application versions.
Update with supersedence gives you more control over individual versions, but you are responsible for creating and managing the supersedence relationship.
Automatic catalogue updates do not provide an automatic rollback.
If a version needs to be removed, administrators must take separate action, such as assigning the application with an Uninstall intent or deploying a remediation script.
Select the update method and then select Select to return to the App information page.
Review the Microsoft Remote Help application settings
After selecting the package, Intune populates the application details automatically.
Review the following information:
Name
Description
Publisher
Application version
Install behaviour
Restart behaviour
Requirements
Detection rules
Publisher should remain set to Microsoft.
The application installs in the System context. The signed-in user does not need local administrator rights for Intune to install it.
Leave the Microsoft-supplied install and uninstall commands unchanged.
Also leave the supplied requirements and detection rules in place.
Enterprise Application Management supports managed 64-bit Windows devices, and the x64 package is suitable for standard Windows 11 x64 devices.
Continue through:
Program
Requirements
Detection rules
Supersedence
Do not replace Microsoft’s prepared settings unless you have a specific requirement and have tested the change.
Assign Microsoft Remote Help to devices
Continue to Assignments.
Under Required, select:
Add group
Select:
Remote Help – Test Devices
Confirm that CADTB01 and CADTB03 are members of the group.
A Required device assignment means Intune installs the application automatically.
The user does not need to open Company Portal or select Install.
The deployment process is:
Required assignment
Device checks in with Intune
The Microsoft Intune Management Extension evaluates the application
The package downloads
Microsoft Remote Help installs in the System context
The detection rules confirm installation
Intune reports the application as Installed
Enterprise App Catalog applications are delivered through the Microsoft Intune Management Extension. They are not installed using Windows Package Manager or Winget.
Continue to Review + create.
Confirm the selected package, program settings, requirements, detection rules and Required assignment.
Select Add app.
Once created, Microsoft Remote Help appears in the Windows applications list with Auto-update shown as its update method.
Open Microsoft Remote Help on Windows
After installation, open the Windows Start menu and search for:
Remote Help
Do not open Quick Assist.
Quick Assist is a separate Windows application and does not use the same Intune RBAC, compliance or reporting controls.
On CADTB01, open Microsoft Remote Help and sign in with the helper account.
On CADTB03, open Microsoft Remote Help and sign in with the normal sharer account.
Both accounts must belong to the same Microsoft Entra tenant.
If Remote Help displays the following message:
You need an organisational account to use Remote Help
Select Sign in and use an account from your Microsoft Entra tenant.
Personal Microsoft accounts cannot be used.

Microsoft Remote Help organisational account sign-in screen
Once the helper is signed in, the Remote Help home screen displays Get Help and Give help.
The Get Help section accepts a security code from a helper.
The Give help section allows an authorised helper to generate a security code.

Start Microsoft Remote Help from the Intune device record
The first connection method starts the session from the managed device record in Intune.
On CADTB01, sign in to the Microsoft Intune admin centre using the helper account.
Go to:
Devices > All devices > CADTB03
From the remote actions menu, select:
New remote assistance session
Select:
Remote Help
Select Continue.
Intune sends a notification to CADTB03.
On CADTB01, select Launch Remote Help.
If Microsoft Edge asks for permission to open the application, select Open Remote Help.
On CADTB03, the sharer should receive a Windows notification.
Select Open Remote Help from the notification.
If the notification disappears, open the Windows notification centre and select it from there.
The helper should sign in to the Remote Help application using the same account used in the Intune portal.
Before allowing the session, the sharer can review the helper’s:
• Full name
• Company
• Job title
• Profile picture
• Verified domain
The sharer then chooses whether to allow screen sharing or full control.
Remote launch requires the Microsoft Intune Management Extension on the sharer’s Windows device.
If the device has only recently been enrolled, there can be a delay before remote launch notifications start working.
Do not disturb and blocked cloud notifications can also prevent the request from appearing.
Start Microsoft Remote Help using a security code
The second connection method starts directly from the Microsoft Remote Help application.
On CADTB01, go to:
Remote Help > Give help > Get a security code
Give the security code to the person using CADTB03.
Do not publish a live security code in a video, screenshot or support document.
On CADTB03, go to:
Remote Help > Get Help
Enter the code and select Submit.
Both users then see the organisational identity of the other person.
The helper can request screen sharing or full control.
The sharer decides whether to allow or decline the request.
The security-code method is useful when:
• The Intune notification does not arrive
• The support team already has the user on a call
• The technician does not know the device name
• The support process starts from a ticket rather than the Intune device record
The code does not bypass Microsoft Entra authentication, Intune RBAC or the sharer’s consent prompt.
Screen sharing, full control and elevation
Screen sharing allows the helper to see the device without interacting with it.
This should be the default choice when the technician only needs to guide the user through a task or inspect an error message.
Full control gives the helper access to the keyboard and mouse after the sharer approves the request.
A helper can request to move from screen sharing to full control during the session.
The sharer sees a new request and can allow or decline full control.
Elevation allows a suitably authorised helper to interact with User Account Control prompts and enter administrator credentials.
Full control alone does not automatically provide access to UAC prompts.
The helper needs the Remote Help Elevation permission and must request elevation through the session toolbar.
Microsoft documents that the EnableSecureCredentialPrompting policy can block elevation during a Microsoft Remote Help session.
Check that policy if the helper has the correct Intune role but cannot interact with the UAC prompt.
Use a dedicated endpoint administrator account for elevation.
Do not use the user’s password or a Global Administrator account for ordinary endpoint support.
Either the helper or the sharer can end the session by selecting Leave.
If elevated actions have taken place and the sharer ends the session, Windows can sign the sharer out.
If the helper ends the session, the sharer is not signed out.
Monitor Microsoft Remote Help sessions
Microsoft Remote Help includes session monitoring in the Microsoft Intune admin centre.
Go to:
Tenant administration > Remote Help > Monitor
The Remote Help sessions report includes:
• The helper
• The sharer
• The supported device
• Session start time
• Session end time
• The type of control used
Microsoft stores Remote Help session metadata for 30 days.
Microsoft does not record the device screen, helper actions or keystrokes.
Operational details are also written to the Windows event logs on the helper and sharer devices.

The local event log is available at:
Event Viewer > Applications and Services Logs > Microsoft > Windows > RemoteHelp
You can locate the available Remote Help event logs with PowerShell:
Get-WinEvent -ListLog '*RemoteHelp*' -ErrorAction SilentlyContinue |
Select-Object LogName, RecordCount, IsEnabled
To display recent events:
$RemoteHelpLogs = Get-WinEvent -ListLog '*RemoteHelp*' -ErrorAction SilentlyContinue
foreach ($Log in $RemoteHelpLogs) {
Get-WinEvent -LogName $Log.LogName -MaxEvents 10 -ErrorAction SilentlyContinue |
Select-Object TimeCreated, Id, LevelDisplayName, Message
}
The Remote Help sessions report does not show Windows elevation as a separate field.
Review the local event logs if you need more information when investigating a support session.
The Enterprise App Catalog makes Microsoft Remote Help much easier to deploy than the original manual Win32 process.
The application package, install commands, requirements and detection rules are already prepared.
A Required device assignment then installs the application automatically on the targeted devices.
The part that needs more planning is the support model around it.
Decide who can view devices, who can take full control, who can use elevation and which users or devices each support team is allowed to access.
You might also like this article
Is Microsoft Remote Help included with Microsoft 365 E3?
Starting in July 2026, eligible commercial Microsoft 365 E3 subscriptions include Microsoft Intune Plan 2, Microsoft Remote Help and Microsoft Intune Advanced Analytics.
The Enterprise App Catalog requires Enterprise Application Management, which is included with eligible Microsoft 365 E5 subscriptions.
Does Microsoft Remote Help replace Quick Assist?
Microsoft Remote Help and Quick Assist are separate products.
Remote Help adds Microsoft Entra authentication, Intune RBAC, compliance information and session reporting.
Quick Assist does not use the same Intune management controls.
Do both users need a Microsoft Remote Help licence?
Yes.
Both the helper providing support and the sharer receiving support need an eligible Microsoft Remote Help entitlement.
Can Microsoft Remote Help work across different tenants?
No.
The helper, sharer and supported device must belong to the same Microsoft Entra tenant.
Does Microsoft Remote Help require user consent?
On Windows, the sharer reviews the helper’s identity and approves either screen sharing or full control.
Full control cannot be started silently.
Can Microsoft Remote Help interact with UAC prompts?
Yes.
The helper needs the Remote Help Elevation permission.
The sharer must also approve the request before the helper can interact with the UAC prompt.
Does Microsoft Remote Help record the user’s screen?
No.
Microsoft stores limited session metadata for 30 days but does not record screen images, actions or keystrokes.
Does Microsoft Remote Help update automatically?
Yes.
Remote Help supports automatic updates.
When it is deployed from the Enterprise App Catalog with Automatically update selected and a Required assignment, Intune can deploy newer catalogue versions to the targeted devices.
Does the Enterprise App Catalog use Winget?
No.
Enterprise App Catalog applications are prepared and hosted by Microsoft and installed through the Microsoft Intune Management Extension.
Tags: Intune, Microsoft Entra
[…] You might also like this article […]