Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Configure Offer Remote Assistance is a Windows policy for legacy unsolicited Remote Assistance—not a setting for Microsoft Intune Remote Help. For most organizations, set it to Disabled unless a tested support workflow specifically depends on Windows Remote Assistance. If you use Intune Remote Help, Quick Assist, Teams, or another approved support tool, configure that product separately.
What the policy controls
Offer Remote Assistance, also called unsolicited Remote Assistance, lets an approved helper proactively offer support to a Windows computer. It belongs to the older Windows Remote Assistance model associated with msra.exe: the person providing help is the helper, and the person receiving it is the sharer. When enabled, the policy lets administrators choose whether helpers can view the computer or control it, and specify which users or groups may offer assistance.
The policy’s Administrative Template name is Configure Offer Remote Assistance. Its Policy CSP name is UnsolicitedRemoteAssistance, and its registry-backed value is HKLMSOFTWAREPoliciesMicrosoftWindows NTTerminal ServicesfAllowUnsolicited. Microsoft documents the policy and its mapping in the RemoteAssistance Policy CSP reference.
This is distinct from Configure Solicited Remote Assistance, which controls the user-initiated, ask-for-help workflow and maps to fAllowToGetHelp in the same registry key. Disabling Offer Remote Assistance does not disable every form of remote support—or necessarily every legacy Remote Assistance workflow.
#1 Best Overall
Choose the setting before you create a profile
For a typical modern organization, explicitly configure Disabled. Microsoft’s Windows security baseline material and ACSC Windows hardening guidance recommend disabling the capability when it is not required. This limits unsolicited access through a legacy support mechanism and avoids maintaining helper and network rules without a documented need.
Enable it only if an approved support process depends on legacy Windows Remote Assistance and you have tested the required identities, network path, permissions, and recovery procedure. The choice is not a substitute for a broader review of solicited Remote Assistance, Quick Assist, Remote Help, Remote Desktop, Teams, or third-party tools.
What each policy state means
- Enabled: Allows corporate technical support staff to offer unsolicited assistance, subject to the configured helper permissions and view/control choice.
- Disabled: Prevents users from receiving help through Offer/Unsolicited Remote Assistance.
- Not configured: Microsoft’s CSP description says users cannot receive corporate unsolicited assistance when this policy is not configured. Still, verify the effective state on the device rather than treating an unconfigured profile as an explicit security decision.
Check device compatibility and policy scope
Microsoft lists this CSP policy as device-scoped, with no user scope, for Windows 10 version 1703 and later. Listed editions include Pro, Enterprise, Education, IoT Enterprise, and IoT Enterprise LTSC. Intune’s available profile controls can vary, so confirm the setting is exposed for the device’s Windows edition and chosen profile type.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #2
The direct CSP path is ./Device/Vendor/MSFT/Policy/Config/RemoteAssistance/UnsolicitedRemoteAssistance. The policy is ADMX-backed; Microsoft says direct CSP configuration of ADMX-backed policies requires SyncML. For that reason, prefer an Intune profile that exposes the setting instead of inventing a custom payload. Use a custom OMA-URI only when necessary and after validating the required SyncML and behavior on the Windows builds you manage.
Configure the policy in Intune
Intune labels and navigation can change. In the current admin center, look under Devices for Configuration or Configuration policies, then create a Windows device profile using Settings catalog or Administrative Templates—whichever exposes the setting in your tenant.
- In the Microsoft Intune admin center, open Devices, then Configuration or Configuration policies.
- Select Create or Create policy, and choose Windows 10 and later as the platform.
- Choose Settings catalog or Administrative Templates as the profile type, then create the profile.
- In the setting picker, search for
Configure Offer Remote Assistance. If it does not appear, search forUnsolicited Remote Assistanceand check the Remote Assistance category. - Set the policy to Disabled unless you have approved and tested a requirement for unsolicited Remote Assistance. Do not rely on Not configured to express a deliberate security choice.
- If you intentionally enable it, configure the permitted helper identities and whether they can view only or remotely control the computer. Use a test device before assigning the profile broadly.
- Assign the profile to a test device group, review assignment and per-setting status, and confirm the device has checked in before expanding deployment.
The corresponding Group Policy setting is under Computer Configuration > Policies > Administrative Templates > System > Remote Assistance. Template or editor versions may place Remote Assistance under a different navigation grouping, so use the policy search field when browsing Group Policy.
Rank #3
If you enable it: constrain helpers and network access
Microsoft’s CSP documentation describes helper entries in domain-qualified forms such as <Domain Name><User Name> or <Domain Name><Group Name>. Do not assume that an Entra ID group, cloud-only identity, or Intune assignment group will work as a legacy helper entry. Test the exact identity format and join configuration on representative devices.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallThe same Microsoft documentation says enabling Offer Remote Assistance requires appropriate firewall exceptions. For the legacy model, it identifies TCP port 135 and the executables %WINDIR%System32msra.exe and %WINDIR%System32raserver.exe. These are not a complete connectivity recipe: RPC behavior, Windows Firewall profiles, segmentation, VPN, NAT, endpoint firewall products, and local policy can all affect a session. Scope any required rules to the approved support architecture and network profiles; do not open broad inbound access based only on port 135.
Verify policy delivery and effective behavior
First verify that Intune delivered the setting. In the profile’s device status, check assignment, last check-in, setting status where available, filters, exclusions, and conflicting profiles. Then inspect the device’s policy-backed value from an elevated PowerShell session:
Rank #4
Get-ItemProperty `
-Path 'HKLM:SOFTWAREPoliciesMicrosoftWindows NTTerminal Services' `
-Name fAllowUnsolicited `
-ErrorAction SilentlyContinue
The registry mapping is documented in Microsoft’s Policy CSP reference. A missing value is not by itself proof of a successful configuration; correlate it with the Intune profile state and the intended policy setting.
- Confirm the device is enrolled and its management state under Settings > Accounts > Access work or school.
- Review Intune device configuration reporting and relevant MDM policy-processing events in Event Viewer.
- Use
dsregcmd /statusto inspect Entra registration and join state when identity or targeting is in question. - Check for domain Group Policy or another management profile setting the same value.
- If testing an enabled configuration, test an actual helper workflow as well as policy delivery; correct registry state does not prove that identity resolution, firewall rules, RPC connectivity, and session interaction will work.
Troubleshoot missing settings or failed connections
The setting is not available in the profile
- Search using both the friendly name and
Unsolicited Remote Assistance. - Try the other profile type (Settings catalog versus Administrative Templates), since exposure can differ.
- Confirm the Windows platform and edition are supported and that the setting is being searched in the Remote Assistance category.
- If neither profile type exposes it, consider the CSP OMA-URI only after validating a suitable ADMX-backed SyncML configuration on a test device.
Intune reports success but the device does not match
Check for a domain Group Policy or competing profile, incorrect group targeting, assignment filters or exclusions, a stale device check-in, an unsupported edition, or a user-only targeting design for this device-scoped policy. Compare Intune reporting with the registry value and the device’s management events before changing assignments.
The policy is enabled but a helper cannot connect
Check the helper name syntax, domain membership and name resolution, firewall profile and exceptions, TCP 135 and related RPC behavior, network segmentation, VPN or NAT, and the presence and usability of msra.exe and raserver.exe. Also confirm the technician is trying the legacy Remote Assistance workflow, not Remote Help, and that the user can interact with the session as required.
Best Value
You need to undo the configuration
Remove or change the Intune assignment deliberately, then trigger a device sync and verify the resulting effective state. Do not assume deleting a profile instantly removes every policy artifact: check the registry, reporting, and any domain policy that may still apply. If your objective is to disable legacy Remote Assistance more broadly, assess the solicited policy and relevant firewall rules as well.
Do not confuse this policy with Intune Remote Help
Microsoft Intune Remote Help is a separately licensed service with Microsoft Entra ID authentication, Intune RBAC, and a service connection over HTTPS/TCP 443. Microsoft’s Remote Help planning documentation says licenses are required for users targeted to use the service, including helpers and sharers. Its RBAC permissions include Remote Tasks – Offer remote assistance; that permission controls Remote Help workflows and does not automatically configure the legacy Windows helper list or this policy.
| Area | Configure Offer Remote Assistance | Microsoft Intune Remote Help |
|---|---|---|
| Technology | Legacy Windows Remote Assistance policy and msra.exe |
Intune Remote Help service |
| Control model | Windows policy, ADMX or Policy CSP, and legacy helper entries | Intune tenant settings, RBAC, licensing, and app deployment |
| Identity | Documented helper entries use domain-qualified names; cloud-only identity behavior needs testing | Microsoft Entra ID authentication |
| Network model | Legacy Windows/RPC and firewall requirements; test in the actual network | HTTPS/TLS service connection over port 443 |
| Licensing | No separate Remote Help license is required merely to configure this legacy policy | Separate Remote Help licensing is required for targeted helpers and sharers |
If you need Intune-governed support with Entra identity and RBAC, evaluate Remote Help and its licensing, app, and tenant requirements. For occasional user-present support, assess Quick Assist or Teams under your organization’s controls. None of these alternatives is enabled or disabled by the Offer Remote Assistance policy.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

