Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Configure Offer Remote Assistance is a Windows policy for legacy unsolicited Remote Assistance—not a setting for Microsoft Intune Remote Help. For most organizations, set it to Disabled unless a tested support workflow specifically depends on Windows Remote Assistance. If you use Intune Remote Help, Quick Assist, Teams, or another approved support tool, configure that product separately.

What the policy controls

Offer Remote Assistance, also called unsolicited Remote Assistance, lets an approved helper proactively offer support to a Windows computer. It belongs to the older Windows Remote Assistance model associated with msra.exe: the person providing help is the helper, and the person receiving it is the sharer. When enabled, the policy lets administrators choose whether helpers can view the computer or control it, and specify which users or groups may offer assistance.

The policy’s Administrative Template name is Configure Offer Remote Assistance. Its Policy CSP name is UnsolicitedRemoteAssistance, and its registry-backed value is HKLMSOFTWAREPoliciesMicrosoftWindows NTTerminal ServicesfAllowUnsolicited. Microsoft documents the policy and its mapping in the RemoteAssistance Policy CSP reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is distinct from Configure Solicited Remote Assistance, which controls the user-initiated, ask-for-help workflow and maps to fAllowToGetHelp in the same registry key. Disabling Offer Remote Assistance does not disable every form of remote support—or necessarily every legacy Remote Assistance workflow.

Choose the setting before you create a profile

For a typical modern organization, explicitly configure Disabled. Microsoft’s Windows security baseline material and ACSC Windows hardening guidance recommend disabling the capability when it is not required. This limits unsolicited access through a legacy support mechanism and avoids maintaining helper and network rules without a documented need.

Enable it only if an approved support process depends on legacy Windows Remote Assistance and you have tested the required identities, network path, permissions, and recovery procedure. The choice is not a substitute for a broader review of solicited Remote Assistance, Quick Assist, Remote Help, Remote Desktop, Teams, or third-party tools.

What each policy state means

  • Enabled: Allows corporate technical support staff to offer unsolicited assistance, subject to the configured helper permissions and view/control choice.
  • Disabled: Prevents users from receiving help through Offer/Unsolicited Remote Assistance.
  • Not configured: Microsoft’s CSP description says users cannot receive corporate unsolicited assistance when this policy is not configured. Still, verify the effective state on the device rather than treating an unconfigured profile as an explicit security decision.

Check device compatibility and policy scope

Microsoft lists this CSP policy as device-scoped, with no user scope, for Windows 10 version 1703 and later. Listed editions include Pro, Enterprise, Education, IoT Enterprise, and IoT Enterprise LTSC. Intune’s available profile controls can vary, so confirm the setting is exposed for the device’s Windows edition and chosen profile type.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The direct CSP path is ./Device/Vendor/MSFT/Policy/Config/RemoteAssistance/UnsolicitedRemoteAssistance. The policy is ADMX-backed; Microsoft says direct CSP configuration of ADMX-backed policies requires SyncML. For that reason, prefer an Intune profile that exposes the setting instead of inventing a custom payload. Use a custom OMA-URI only when necessary and after validating the required SyncML and behavior on the Windows builds you manage.

Configure the policy in Intune

Intune labels and navigation can change. In the current admin center, look under Devices for Configuration or Configuration policies, then create a Windows device profile using Settings catalog or Administrative Templates—whichever exposes the setting in your tenant.

  1. In the Microsoft Intune admin center, open Devices, then Configuration or Configuration policies.
  2. Select Create or Create policy, and choose Windows 10 and later as the platform.
  3. Choose Settings catalog or Administrative Templates as the profile type, then create the profile.
  4. In the setting picker, search for Configure Offer Remote Assistance. If it does not appear, search for Unsolicited Remote Assistance and check the Remote Assistance category.
  5. Set the policy to Disabled unless you have approved and tested a requirement for unsolicited Remote Assistance. Do not rely on Not configured to express a deliberate security choice.
  6. If you intentionally enable it, configure the permitted helper identities and whether they can view only or remotely control the computer. Use a test device before assigning the profile broadly.
  7. Assign the profile to a test device group, review assignment and per-setting status, and confirm the device has checked in before expanding deployment.

The corresponding Group Policy setting is under Computer Configuration > Policies > Administrative Templates > System > Remote Assistance. Template or editor versions may place Remote Assistance under a different navigation grouping, so use the policy search field when browsing Group Policy.

If you enable it: constrain helpers and network access

Microsoft’s CSP documentation describes helper entries in domain-qualified forms such as <Domain Name><User Name> or <Domain Name><Group Name>. Do not assume that an Entra ID group, cloud-only identity, or Intune assignment group will work as a legacy helper entry. Test the exact identity format and join configuration on representative devices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The same Microsoft documentation says enabling Offer Remote Assistance requires appropriate firewall exceptions. For the legacy model, it identifies TCP port 135 and the executables %WINDIR%System32msra.exe and %WINDIR%System32raserver.exe. These are not a complete connectivity recipe: RPC behavior, Windows Firewall profiles, segmentation, VPN, NAT, endpoint firewall products, and local policy can all affect a session. Scope any required rules to the approved support architecture and network profiles; do not open broad inbound access based only on port 135.

Verify policy delivery and effective behavior

First verify that Intune delivered the setting. In the profile’s device status, check assignment, last check-in, setting status where available, filters, exclusions, and conflicting profiles. Then inspect the device’s policy-backed value from an elevated PowerShell session:

Get-ItemProperty `
  -Path 'HKLM:SOFTWAREPoliciesMicrosoftWindows NTTerminal Services' `
  -Name fAllowUnsolicited `
  -ErrorAction SilentlyContinue

The registry mapping is documented in Microsoft’s Policy CSP reference. A missing value is not by itself proof of a successful configuration; correlate it with the Intune profile state and the intended policy setting.

  • Confirm the device is enrolled and its management state under Settings > Accounts > Access work or school.
  • Review Intune device configuration reporting and relevant MDM policy-processing events in Event Viewer.
  • Use dsregcmd /status to inspect Entra registration and join state when identity or targeting is in question.
  • Check for domain Group Policy or another management profile setting the same value.
  • If testing an enabled configuration, test an actual helper workflow as well as policy delivery; correct registry state does not prove that identity resolution, firewall rules, RPC connectivity, and session interaction will work.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot missing settings or failed connections

The setting is not available in the profile

  • Search using both the friendly name and Unsolicited Remote Assistance.
  • Try the other profile type (Settings catalog versus Administrative Templates), since exposure can differ.
  • Confirm the Windows platform and edition are supported and that the setting is being searched in the Remote Assistance category.
  • If neither profile type exposes it, consider the CSP OMA-URI only after validating a suitable ADMX-backed SyncML configuration on a test device.

Intune reports success but the device does not match

Check for a domain Group Policy or competing profile, incorrect group targeting, assignment filters or exclusions, a stale device check-in, an unsupported edition, or a user-only targeting design for this device-scoped policy. Compare Intune reporting with the registry value and the device’s management events before changing assignments.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The policy is enabled but a helper cannot connect

Check the helper name syntax, domain membership and name resolution, firewall profile and exceptions, TCP 135 and related RPC behavior, network segmentation, VPN or NAT, and the presence and usability of msra.exe and raserver.exe. Also confirm the technician is trying the legacy Remote Assistance workflow, not Remote Help, and that the user can interact with the session as required.

You need to undo the configuration

Remove or change the Intune assignment deliberately, then trigger a device sync and verify the resulting effective state. Do not assume deleting a profile instantly removes every policy artifact: check the registry, reporting, and any domain policy that may still apply. If your objective is to disable legacy Remote Assistance more broadly, assess the solicited policy and relevant firewall rules as well.

Do not confuse this policy with Intune Remote Help

Microsoft Intune Remote Help is a separately licensed service with Microsoft Entra ID authentication, Intune RBAC, and a service connection over HTTPS/TCP 443. Microsoft’s Remote Help planning documentation says licenses are required for users targeted to use the service, including helpers and sharers. Its RBAC permissions include Remote Tasks – Offer remote assistance; that permission controls Remote Help workflows and does not automatically configure the legacy Windows helper list or this policy.

Area Configure Offer Remote Assistance Microsoft Intune Remote Help
Technology Legacy Windows Remote Assistance policy and msra.exe Intune Remote Help service
Control model Windows policy, ADMX or Policy CSP, and legacy helper entries Intune tenant settings, RBAC, licensing, and app deployment
Identity Documented helper entries use domain-qualified names; cloud-only identity behavior needs testing Microsoft Entra ID authentication
Network model Legacy Windows/RPC and firewall requirements; test in the actual network HTTPS/TLS service connection over port 443
Licensing No separate Remote Help license is required merely to configure this legacy policy Separate Remote Help licensing is required for targeted helpers and sharers

If you need Intune-governed support with Entra identity and RBAC, evaluate Remote Help and its licensing, app, and tenant requirements. For occasional user-present support, assess Quick Assist or Teams under your organization’s controls. None of these alternatives is enabled or disabled by the Offer Remote Assistance policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.