Idolbe Patch

Remote desktop

Start an interactive session to a Windows endpoint: consent, encryption, the TURN relay, permissions and audit.

Remote desktop opens an interactive session to a managed Windows endpoint: you see the screen and control the mouse and keyboard from your browser, without installing anything on your side. It is meant for hands-on support and troubleshooting when a script or an update is not enough.

Start a session

Open Endpoints, click the endpoint, and on the General tab press Remote Desktop. The endpoint must be online (the agent connected in the last few minutes) and running Windows. The session opens in a full-screen viewer with the connection state, the round-trip time, and, on multi-monitor machines, a monitor selector. Press F8 or Disconnect to leave; the session also ends on its own after two hours of inactivity.

Who can start a session is controlled by the Remote Desktop permission (Users & API Credentials → Roles). Managers and Enterprise Admins have it by default; give it to a custom role to allow help-desk staff to connect without any other management rights.

By default a session is attended: the person signed in on the endpoint sees a request naming the console and the operator, and must accept before anything is shared. If nobody accepts within 45 seconds, or nobody is signed in, the session is refused. While a session is running the user sees a start and an end notice on their screen, and the moving cursor makes the control visible.

An administrator can allow unattended sessions (Advanced → *Unattended Remote Desktop*). Sessions then start without a prompt, but are still refused when no user is signed in, and every session is still recorded in the Audit Trail. Turn this on only where your policy allows silent remote control.

How the connection works

The video and input travel over a direct, end-to-end encrypted WebRTC channel (DTLS-SRTP) between your browser and the endpoint agent. The console only relays the small setup messages; it never sees the screen. When both sides are behind NAT, a TURN relay hosted with the console carries the encrypted stream so the session still connects — see the relay setup in the deployment notes. Without a relay, sessions connect whenever a direct or STUN-assisted path exists.

The screen is streamed as JPEG tiles: only the parts of the screen that change are sent, and the frame rate drops automatically when the screen is idle, which keeps bandwidth low.

Audit

Every session writes to the Audit Trail: who started it and against which endpoint, whether the user accepted or declined, and when it ended. Combine this with roles so that remote control is both limited to the right people and fully traceable.