Skip to content

Remote Support Overview

Remote Support is part of the Secure Remote Access product by Admin By Request, that allows you to share screens and remotely control devices inside of your Admin By Request inventory, while using all of the well-known features of the Admin By Request ecosystem, such as: inventory, auditlog, settings and sub-settings, approval flows etc.

Remote Support allows either end users or IT admins to initiate a secure, just-in-time, remote support session – allowing them to share and control the end-user’s device – and tear everything down once the session is done – eliminating any access points for bad actors.


In order to use the full power of Remote Support, there are several requirements that must be met:

RequirementSpecificationPurpose
Portal Accesshttps://www.adminbyrequest.com/LoginCentral management interface
Client SoftwareAdmin By Request for Windows 8.4.0, Build 31936+Endpoint agent functionality
API ConnectivityPort 443Communication with AdminByRequest services
Data LocationIP AddressDNS Endpoints
Europe137.117.73.20api.adminbyrequest.com
api1.adminbyrequest.com
api2.adminbyrequest.com
macapi1.adminbyrequest.com
macapi2.adminbyrequest.com
USA104.45.17.196api.adminbyrequest.com
api1.adminbyrequest.com
api2.adminbyrequest.com
macapi1.adminbyrequest.com
macapi2.adminbyrequest.com
ServicePortEndpoints
MQTT Broker8883FastTrackHubEU1.azure-devices.net
FastTrackHubUS1.azure-devices.net
Unattended Access3389RDP needs to be enabled on the device
Endpoint EnrollmentVariesMust be enrolled with Admin By Request Secure Remote Access

For environments with strict firewall policies, the following additional connectivity may be required:

RequirementPortCloudflare Endpoints
Cloudflare Tunnel7844region1.v2.argotunnel.com
region2.v2.argotunnel.com
SNI EnforcementVariescftunnel.com
h2.cftunnel.com
quic.cftunnel.com

Note: Refer to Cloudflare’s documentation for more information on “tunnel with firewall” configuration.


Remote Support is based on the same gateway concept as the Unattended Access gateway, which is also part of the Admin By Request Secure Remote Access product. It allows a just-in-time setup between the gateway and the endpoint by establishing a secure Cloudflare tunnel.

StepActionResult
1. Tunnel EstablishmentSecure Cloudflare tunnel created between gateway and endpointEncrypted communication channel
2. Session CreationJust-in-time server session created on endpointScreen sharing and remote control capability
3. Session TerminationTunnel and server session terminated when session endsEndpoint returned to original secure state

The setup is fully cloud-based and does not require any on-premise setup besides what’s mentioned in the prerequisites.

Ideal for: Organizations seeking immediate remote support capabilities without extensive infrastructure deployment.


Remote Support sessions can be initiated through two primary methods:

StepProcessSecurity Control
Request SubmissionEnd user requests Remote Support session from their endpoint with reason justificationDocuments legitimate business need
Admin ApprovalIT admin approves or denies request via Admin By Request portalMaintains authority over session access
Session ActivationSecure tunnel established upon approvalEnsures only authorized sessions occur
StepProcessSecurity Control
Device SelectionIT admin navigates to specific device in portal inventory and clicks SupportTargets specific endpoint for assistance
User ApprovalEnd user asked to approve incoming Remote Support sessionEnsures user consent and awareness
Session EstablishmentSecure Cloudflare tunnel initiated and just-in-time server session createdProvides secure, audited connection

FeatureImplementationBusiness Value
Multi-Factor Authentication (MFA)Required for session initiation and accessPrevents unauthorized session access
View-Only AccessOptional mode limiting admin to observation onlyProtects sensitive information during review
Session ExpirationAutomatic termination after predefined timePrevents forgotten active sessions
Session RecordingComplete video capture of all session activitiesProvides audit trail for compliance and training
CapabilityFunctionCompliance Benefit
Session LoggingAll remote support sessions logged in audit logComplete visibility into support activities
Video RecordingDownloadable recordings of session activitiesEvidence for compliance audits and incident review
User Consent TrackingDocumentation of user approval for sessionsSupports privacy and compliance requirements

ComponentRoleTechnical Specification
Cloudflare TunnelSecure connection establishmentEncrypted tunnel between gateway and endpoint
Session ServerJust-in-time remote desktop serviceTemporary RDP/VNC session on endpoint
Audit LoggerSession activity recordingComprehensive logging and video capture
  1. Initiation → Session request from user or admin
  2. Approval → Authorization through portal workflows
  3. Connection → Cloudflare tunnel establishment
  4. Session → Remote desktop/screen sharing activation
  5. Termination → Automatic cleanup of all connections

PracticeImplementationSecurity Benefit
Always Use MFAEnable multi-factor authentication for all sessionsPrevents credential-based attacks
Record SessionsEnable video recording for compliance and auditProvides complete audit trail
Set Time LimitsConfigure appropriate session expiration timesReduces risk of abandoned sessions
Review Audit LogsRegularly review session activitiesEnables early threat detection
PracticeImplementationOperational Benefit
User TrainingEducate users on session request processReduces support delays and improves efficiency
Clear Approval WorkflowsDefine who can approve sessions and under what conditionsStreamlines authorization process
Session DocumentationRequire detailed reasons for session requestsImproves audit quality and justification
Regular Access ReviewsPeriodically review who can initiate sessionsMaintains security hygiene

IssuePossible CauseResolution
Connection FailedFirewall blocking required portsVerify port 443, 8883, and 7844 are open
Session Not RecordingRecording feature disabledEnable recording in Remote Support settings
Approval DelaysApprovers not receiving notificationsCheck notification settings and approver availability
Poor PerformanceNetwork bandwidth limitationsVerify adequate bandwidth for video streaming

Key Takeaway: Remote Support provides a secure, just-in-time remote assistance solution that maintains comprehensive security controls while enabling efficient IT support through temporary, audited sessions that automatically terminate to eliminate persistent access points.


Remote Support by Admin By Request offers a comprehensive solution for secure, temporary remote assistance that combines the flexibility of on-demand support with the security of just-in-time access. By leveraging secure Cloudflare tunnels, comprehensive approval workflows, and detailed session recording, organizations can provide efficient IT support while maintaining strict security controls and complete audit trails.

The cloud-based architecture ensures rapid deployment without extensive infrastructure requirements, while the dual initiation methods (user and admin-initiated) provide flexibility for various support scenarios. With features like MFA, session expiration, and comprehensive logging, Remote Support enables organizations to balance operational efficiency with security and compliance requirements.