DocumentationAPI ReferenceRelease Notes
Documentation

Remote Support - Getting Started

What is Remote Support? Remote Support icon


BeyondTrust Remote Support is a secure remote support tool for IT teams. Your representatives use it to connect to and control remote computers and devices so they can fix problems. Service desks, help desks, and support teams use it every day.

Remote Support covers three kinds of work:

  • Attended support. A customer starts a session and asks for help. The customer enters a session key on your support portal, selects a representative from a list, or clicks a Support Button on the desktop. Your representative then joins the session.
  • Unattended access. Your representative connects to a computer when no one is sitting in front of it. Jump Clients and Gateways make this possible, so you can fix servers and offline machines after hours.
  • Security and audit control. You decide what each representative can do in a session. Remote Support records sessions, injects passwords without showing them, and keeps a full log of who did what.

Remote Support capabilities and benefits

Use Remote Support to run and resolve sessions:

  • Support many platforms from one tool, including Windows, macOS, Linux, iOS, and Android.
  • Take control of a remote screen, or share your own screen with the customer.
  • Chat with customers, transfer files in both directions, and push a web link to the customer's screen.
  • Reach a computer even when no user is signed in, so you can patch and repair systems outside of business hours.
  • Bring more than one representative into the same session when a problem needs a second opinion.

Use Remote Support to route, control, and audit access:

  • Route each request to the right person. Skills-based routing, called Equilibrium, sends a session to the least busy or best-skilled representative on the team.
  • Inject stored credentials into a remote system so a representative never sees or types the password.
  • Record sessions and pull reports for audits and compliance reviews.
  • Connect Remote Support to your service desk tools, such as ServiceNow, Salesforce, and Jira, so tickets and sessions stay in sync.
  • Add your own logo, colors, and wording to the customer-facing portal.

Together, these features raise your first-call resolution rate, cut downtime, and limit how much access a representative needs to solve a problem.

Prerequisites

Before you start using Remote Support, make a few decisions. The right choices depend on the size of your organization and your security rules. This is not a full checklist, but it gives you a solid starting point for planning.

  • Choose your deployment model, cloud or on-premises. Your choice usually depends on your infrastructure, your security policies, and how much you want to manage yourself.
  • Choose a web address for your site. Customers and representatives both use this Domain Name System (DNS) name, so keep it short and easy to say, such as support.example.com. Point a DNS A record or a canonical name (CNAME) record at your site.
  • Open the ports your deployment needs. Every client makes an outbound connection to the site, so TCP 443 is required in all deployments. On-premises deployments also need ports for Session Traversal Utilities for NAT (STUN) and Traversal Using Relays around NAT (TURN): UDP and TCP 3478 and 5349, plus UDP 49152–65535. They might also need ports for NTP, LDAP, syslog, DNS, and email.
ℹ️

For more information, see Network considerations and On-premises network infrastructure.

  • Get a TLS or SSL certificate. Your site needs a valid certificate before BeyondTrust can build your custom software package. A certificate from a trusted certificate authority is the best choice. A self-signed certificate works for short-term testing only. Import the full certificate chain.
ℹ️

For more information, see SSL certificate setup.

  • Decide how users sign in. Remote Support can check users against LDAP (including Active Directory), SAML, Kerberos, or OpenID Connect. You can also require two-factor authentication.
ℹ️

For more information, see Security providers.

  • Check your license count. Remote Support is licensed by concurrent users. You can create as many accounts as you want, but only the number of representatives you licensed can be signed in to the representative console at the same time.
ℹ️

For more information, see Remote Support licenses.

🚧

Important

Each user who signs in through an external identity provider must belong to at least one group policy. Without a group policy, the user cannot authenticate. Set your default group policy to the lowest level of privileges.

Deployment methods

Deploy Remote Support in the cloud, or on-premises on a B Series Appliance. Very large environments can also use Atlas clustering to spread the load across several appliances.

Remote Support Cloud

With Remote Support Cloud, BeyondTrust hosts your site on a single-tenant instance and manages the servers, the database, and the updates. You choose the region that stores your data. Your site gets an address such as yoursite.beyondtrustcloud.com, and you can add a CNAME record to use your own web address with your own SSL certificate.

Cloud deployments keep your firewall work small. Your network needs only outbound TCP 443 to reach the site. BeyondTrust applies critical updates for you and backs up your data on a schedule.

ℹ️

For more information, see Appliance deployment | RS Cloud.

On-premises (B Series Appliance)

The B Series Appliance is a self-contained appliance that hosts Remote Support in your own data center. It is the central routing point for every connection, and it encrypts all session traffic end to end. You can run it as physical hardware or as a Virtual Appliance on VMware, Hyper-V, Nutanix AHV, AWS, or Azure.

BeyondTrust recommends placing the appliance in your perimeter network. You own the appliance updates, the backups, and the network setup.

The following table compares the two deployment methods.

AreaRemote Support CloudOn-premises (B Series Appliance)
HostingHosted by BeyondTrustHosted by you, in your data center
Site addressAddress on beyondtrustcloud.com, or your own address by CNAMEYour own DNS record and IP address
PortsOutbound TCP 443 onlyFull inbound and outbound port list you manage
UpdatesCritical updates applied by BeyondTrustYou install updates from /appliance
Backup and recoveryAutomatic backups and disaster recoveryBackups and recovery are your responsibility
Availability99.9 percent availability commitmentAvailability is yours to engineer
Appliance interfaceReduced /appliance interfaceFull /appliance interface, including networking and storage
ClusteringAtlas set up by BeyondTrustYou build and manage clustering and failover
LocationRegion chosen at setupLocated wherever you install it

Remote Support essentials

When you set up Remote Support, learn a few terms first. The following table defines the building blocks you create during setup, which control who can connect, to what, and with which tools.

TermDefinition
RepresentativeA person on your support team who helps customers through Remote Support. Each signed-in representative uses one license.
Representative consoleThe application a representative uses to run sessions, available as a desktop console, a web console at /console, and Android and iOS apps.
Customer clientThe small application the customer runs during a session, used to chat, share a screen, and hand over control.
Jump ClientAn application you install on a remote computer so it stays connected to your site and you can reach it at any time, whether a user is present or not, and on any network.
GatewaySoftware you install inside a remote network so you can reach many systems on that network without installing anything on each one. Gateways are required for Remote Jump, RDP, VNC, SSH, and Intel vPro sessions, and were previously called Jumpoints.
AssetAny saved endpoint you connect to, no matter how you reach it. Assets were previously called Jump Items.
Asset GroupA collection of assets, used to organize endpoints by site, department, or team and to control which representatives can reach them. Asset Groups were previously called Jump Groups.
Asset PolicyA rule that controls when an asset can be accessed, such as limiting access to business hours or requiring two-factor authentication. Asset Policies were previously called Jump Policies.
Asset RoleA set of permissions that controls how a representative can manage and use assets. Asset Roles were previously called Jump Item Roles.
Session PolicyA reusable rule set that controls which tools are available in a session, such as screen sharing, file transfer, and the command shell. Each permission can be set to Allow, Deny, or Not Defined.
Group PolicyA set of permissions and settings you apply to a group of users instead of one user at a time. Group policies also control team, Gateway, asset group, and Vault memberships.
Support TeamA group of representatives who work together. Each team gets its own queue in the representative console, and each member has a role of Team Member, Team Lead, or Team Manager.
IssueA problem category a customer selects on your support portal, such as email problems, that routes the request to the team handling it.
SkillA named strength you assign to representatives and link to issues. Equilibrium uses skills to match a request to the right person.
EquilibriumThe feature that hands out waiting sessions automatically, either to the least busy representative or to the best-skilled and least busy representative.
Session keyA one-time code with a time limit that a representative gives a customer. The customer enters the key on your portal, which routes them to the right person. A session key is not a password and does not authenticate anyone.
Support ButtonA shortcut you place on a customer's desktop, or embed on a web page, that starts a session with one click.
Rep inviteA one-time invitation for a trusted outside expert to join a single session, valid for as long as that session lasts.
VaultThe credential store built into Remote Support. Vault saves passwords and SSH keys and injects them into a remote system so the representative never sees them.
Endpoint Credential ManagerA Windows service you install to pull credentials from an external credential store, such as BeyondTrust Password Safe, instead of the built-in Vault.
Canned scriptA script you write ahead of time so a representative can run a common fix during screen sharing or in the command shell.
Endpoint automationA feature that runs scripts across many endpoints at once without starting a support session.
B Series ApplianceThe physical or virtual appliance that hosts Remote Support on-premises. Every connection between components routes through it.
🚧

Important

Several Jump terms were renamed. For the full list, see the Remote Support glossary.

Former termCurrent term
Jump ItemAsset
Jump GroupAsset Group
Jump PolicyAsset Policy
Jump Item RoleAsset Role
JumpointGateway
Jump ClientJump Client (unchanged)

Connection types

In Remote Support, an endpoint is any remote computer or device you support. Endpoints include Windows, macOS, and Linux computers, iOS and Android devices, and network equipment you reach over SSH or Telnet, such as switches and appliances.

Know the difference between how a session starts and how you reach the endpoint, because that difference determines what you install first. The following table describes the four connection types.

Connection typeDefinition
AttendedThe customer is present and starts the session. The customer uses a session key, selects a representative on the portal, submits an issue, or clicks a Support Button. Nothing is installed ahead of time.
UnattendedThe representative starts the session, and no user needs to be present. This requires a Jump Client on the endpoint, or a Gateway on the endpoint's network.
Local JumpA connection from the representative console to a Windows system on the same network segment. No Gateway is needed.
Remote JumpA connection to a system on a different network, routed through a Gateway.

Remote Support and Privileged Remote Access

Remote Support and BeyondTrust Privileged Remote Access are closely related, so it can be unclear which one a feature belongs to. Both run on the same B Series Appliance, and together they are called Secure Remote Access. The difference is the audience:

  • Remote Support serves your service desk. Representatives help employees and customers fix problems on their devices, usually one session at a time.
  • Privileged Remote Access serves vendors and internal staff who need ongoing, controlled access to critical systems.
ℹ️

For more information, see What is Secure Remote Access?

Administrative interfaces and the public portal

Remote Support uses separate interfaces on purpose. This keeps hardware administration apart from user administration, and both apart from what your customers see. The following table describes the differences and when to use each one.

InterfaceDescription
/applianceThe appliance administrator's interface for managing the appliance itself. On-premises, it covers networking, storage, encryption, TLS, the firewall, and software updates. On Remote Support Cloud it is smaller, because BeyondTrust manages the infrastructure. For more information, see Appliance user guide.
/loginThe site administrator's interface for managing users, group policies, session policies, teams, assets, Vault, the public portal, reports, and integrations. This is where you do most of your day-to-day configuration. For more information, see Remote Support for admins.
/consoleThe web representative console. Representatives use it to run sessions from a browser instead of the installed desktop console. For more information, see Web rep console user guide.
Public portal (your site root)The customer-facing website. Customers go here to enter a session key, choose a representative, or submit an issue, which then downloads the customer client. You can brand it and require SAML authentication. For more information, see Public portals.
🚧

Important

The /appliance and /login interfaces use separate credentials. Both start with a default username and password and require you to change them at first sign-in, but you must manage each one separately.

Initial setup

Before your team starts taking sessions, complete the initial setup. This adds your users, your policies, your teams, and your endpoints so access is controlled from the start.

🚧

Important

Complete the steps in the order presented. Policies must exist before you deploy Jump Clients and Gateways, because you choose the asset group and asset policy while you build the installer.

1. Deploy your site

For Remote Support Cloud, BeyondTrust provisions your site. To deploy an on-premises site:

  1. Install the appliance and place it in your perimeter network.
  2. Point a DNS record at the site.
  3. Open the required ports.
  4. Import your SSL certificate.
ℹ️

For more information about deployments, see Appliance deployment | RS Cloud or Appliance deployment | RS On-premises.

2. Sign in to /appliance

  1. Go to your site address followed by /appliance.
  2. Sign in with the default credentials.
  3. Change the default credentials.
  4. On-premises sites only: turn on automatic critical updates so security fixes install during your maintenance window.

3. Sign in to /login

  1. Go to your site address followed by /login.
  2. Accept the license agreement.
  3. Change the default credentials.
  4. Select your language.
  5. Go to Status > Information and confirm your support license count.
ℹ️

For more information about licenses, see Remote Support licenses.

4. Add a security provider and group policies

Set up the security provider first, because it determines how your representatives sign in. Create your group policies at the same time. Any user who authenticates against an external identity provider must belong to at least one group policy, so account setup is blocked without one.

To add a security provider:

  1. From /login, go to Users & Security > Security Providers.
  2. Click Add.
  3. Select your provider type, such as LDAP, SAML, Kerberos, or OpenID Connect.
  4. Enter your server details.
  5. If you use LDAPS or TLS, upload the root SSL certificate in PEM format.
  6. Click Save.

To create group policies:

  1. Go to Users & Security > Group Policies.
  2. Create a policy for each type of user, such as help desk representative, team lead, and administrator.
  3. Grant only the permissions each group needs.
  4. Set the default group policy to the lowest privileges.
  5. Click Save.

You can also require two-factor authentication in a group policy. See Two-factor authentication guide.

ℹ️

Active Directory is not a separate provider type. You connect to Active Directory through the LDAP provider.

5. Create session policies

A session policy controls which tools a representative can use in a session.

  1. Go to Users & Security > Session Policies.
  2. Create one policy per level of access, such as view-only and full control.
  3. Set each permission to Allow, Deny, or Not Defined.
  4. Click Save.

Remote Support evaluates session policies one tool at a time, and the most specific policy takes precedence. The order of priority is:

  1. Asset or Jump Client policy
  2. Support portal policy
  3. User policy
  4. Global default
🚧

Important

To understand how group policies and session policies are ordered, see Understanding Session and Group policy behavior.

6. Create support teams, skills, and issues

Teams give you queues, and skills and issues route each request to the right queue.

  1. Go to Configuration > Support Teams and create your teams.
  2. Add members, and assign each member a role of Team Member, Team Lead, or Team Manager.
  3. Go to Configuration > Skills and add the skills your team supports.
  4. Assign those skills to your representatives.
  5. Rank each skill as More Preferred, Less Preferred, or Ignored.
  6. Go to Configuration > Issues and create the problem categories customers see.
  7. Link each issue to a team and a skill.
  8. Turn on Equilibrium routing for the team so waiting sessions are handed out automatically.
ℹ️

For more information on teams, skills, and Equilibrium, see Equilibrium guide.

7. Configure the public portal

The public portal is where your customers start a session, so set it up before your team goes into production.

  1. Go to Public Portals.
  2. Configure your site address.
  3. Configure the HTML template and branding.
  4. Select the default Support Button profile.
  5. Add any customer notices.
  6. To require customers to sign in first, turn on Require SAML Authentication.
  7. Click Save.
ℹ️

For more information about public portals, see Public portals.

8. Install the representative console

  1. Go to Consoles & Downloads.
  2. Download the desktop representative console, or send your team to /console for the web console.
  3. For mobile representatives, install the Android or iOS app.
  4. Have each representative sign in and run a test session against the public portal.
ℹ️

For more information about consoles, see Consoles and downloads.

9. Set up unattended access

After your policies exist, deploy unattended access. Complete these steps in order:

  1. Add Asset Roles, so you control who can manage and use endpoints.
  2. Add Asset Policies, so you control when endpoints can be accessed.
  3. Add Asset Groups, so you can organize endpoints and limit who reaches them.
  4. Go to Asset Management > Jump Clients and deploy Jump Clients with the Mass Deployment Wizard, or install a Gateway on a machine inside each remote network.
  5. Choose the asset group and asset policy while you build the installer.
  6. Create your assets in the representative console, or import them from /login.
ℹ️

For more information, see Jump Client guide and Gateway guide.

10. Configure Vault

Vault stores credentials so your representatives can sign in to remote systems without seeing the password.

  1. Set the Vault role in each group policy to Inject, or to Inject and Checkout if the user also needs to check credentials out from /login.
  2. Click Save.
  3. Run discovery to find accounts.
  4. Add your accounts and account groups.
  5. Apply account policies.
ℹ️

For more information on Vault and discovery, see Configure Vault and Credential injection.

11. Connect your integrations and audit tools

Finally, connect Remote Support to the rest of your environment.

  1. Connect your service desk tool so sessions and tickets stay linked.
  2. Point syslog at your logging platform.
  3. Use the Integration Client if you need to move session logs and recordings to SQL Server or a file share.
ℹ️

For more information, see Integrations, Syslog, and Integration Client.


©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.