Remote Support - Getting Started
What is Remote Support? 

BeyondTrust Remote Support is a secure remote support tool for IT teams. Your representatives use it to connect to and control remote computers and devices so they can fix problems. Service desks, help desks, and support teams use it every day.
Remote Support covers three kinds of work:
- Attended support. A customer starts a session and asks for help. The customer enters a session key on your support portal, selects a representative from a list, or clicks a Support Button on the desktop. Your representative then joins the session.
- Unattended access. Your representative connects to a computer when no one is sitting in front of it. Jump Clients and Gateways make this possible, so you can fix servers and offline machines after hours.
- Security and audit control. You decide what each representative can do in a session. Remote Support records sessions, injects passwords without showing them, and keeps a full log of who did what.
Remote Support capabilities and benefits
Use Remote Support to run and resolve sessions:
- Support many platforms from one tool, including Windows, macOS, Linux, iOS, and Android.
- Take control of a remote screen, or share your own screen with the customer.
- Chat with customers, transfer files in both directions, and push a web link to the customer's screen.
- Reach a computer even when no user is signed in, so you can patch and repair systems outside of business hours.
- Bring more than one representative into the same session when a problem needs a second opinion.
Use Remote Support to route, control, and audit access:
- Route each request to the right person. Skills-based routing, called Equilibrium, sends a session to the least busy or best-skilled representative on the team.
- Inject stored credentials into a remote system so a representative never sees or types the password.
- Record sessions and pull reports for audits and compliance reviews.
- Connect Remote Support to your service desk tools, such as ServiceNow, Salesforce, and Jira, so tickets and sessions stay in sync.
- Add your own logo, colors, and wording to the customer-facing portal.
Together, these features raise your first-call resolution rate, cut downtime, and limit how much access a representative needs to solve a problem.
Prerequisites
Before you start using Remote Support, make a few decisions. The right choices depend on the size of your organization and your security rules. This is not a full checklist, but it gives you a solid starting point for planning.
- Choose your deployment model, cloud or on-premises. Your choice usually depends on your infrastructure, your security policies, and how much you want to manage yourself.
- Choose a web address for your site. Customers and representatives both use this Domain Name System (DNS) name, so keep it short and easy to say, such as
support.example.com. Point a DNS A record or a canonical name (CNAME) record at your site. - Open the ports your deployment needs. Every client makes an outbound connection to the site, so TCP 443 is required in all deployments. On-premises deployments also need ports for Session Traversal Utilities for NAT (STUN) and Traversal Using Relays around NAT (TURN): UDP and TCP 3478 and 5349, plus UDP 49152–65535. They might also need ports for NTP, LDAP, syslog, DNS, and email.
For more information, see Network considerations and On-premises network infrastructure.
- Get a TLS or SSL certificate. Your site needs a valid certificate before BeyondTrust can build your custom software package. A certificate from a trusted certificate authority is the best choice. A self-signed certificate works for short-term testing only. Import the full certificate chain.
For more information, see SSL certificate setup.
- Decide how users sign in. Remote Support can check users against LDAP (including Active Directory), SAML, Kerberos, or OpenID Connect. You can also require two-factor authentication.
For more information, see Security providers.
- Check your license count. Remote Support is licensed by concurrent users. You can create as many accounts as you want, but only the number of representatives you licensed can be signed in to the representative console at the same time.
For more information, see Remote Support licenses.
- Confirm your systems are supported. Review Remote Support supported platforms for the operating systems and browsers each component supports.
ImportantEach user who signs in through an external identity provider must belong to at least one group policy. Without a group policy, the user cannot authenticate. Set your default group policy to the lowest level of privileges.
Deployment methods
Deploy Remote Support in the cloud, or on-premises on a B Series Appliance. Very large environments can also use Atlas clustering to spread the load across several appliances.
Remote Support Cloud
With Remote Support Cloud, BeyondTrust hosts your site on a single-tenant instance and manages the servers, the database, and the updates. You choose the region that stores your data. Your site gets an address such as yoursite.beyondtrustcloud.com, and you can add a CNAME record to use your own web address with your own SSL certificate.
Cloud deployments keep your firewall work small. Your network needs only outbound TCP 443 to reach the site. BeyondTrust applies critical updates for you and backs up your data on a schedule.
For more information, see Appliance deployment | RS Cloud.
On-premises (B Series Appliance)
The B Series Appliance is a self-contained appliance that hosts Remote Support in your own data center. It is the central routing point for every connection, and it encrypts all session traffic end to end. You can run it as physical hardware or as a Virtual Appliance on VMware, Hyper-V, Nutanix AHV, AWS, or Azure.
BeyondTrust recommends placing the appliance in your perimeter network. You own the appliance updates, the backups, and the network setup.
For more information, see Appliance deployment | RS On-premises and Virtual Appliance installation.
The following table compares the two deployment methods.
| Area | Remote Support Cloud | On-premises (B Series Appliance) |
|---|---|---|
| Hosting | Hosted by BeyondTrust | Hosted by you, in your data center |
| Site address | Address on beyondtrustcloud.com, or your own address by CNAME | Your own DNS record and IP address |
| Ports | Outbound TCP 443 only | Full inbound and outbound port list you manage |
| Updates | Critical updates applied by BeyondTrust | You install updates from /appliance |
| Backup and recovery | Automatic backups and disaster recovery | Backups and recovery are your responsibility |
| Availability | 99.9 percent availability commitment | Availability is yours to engineer |
| Appliance interface | Reduced /appliance interface | Full /appliance interface, including networking and storage |
| Clustering | Atlas set up by BeyondTrust | You build and manage clustering and failover |
| Location | Region chosen at setup | Located wherever you install it |
Remote Support essentials
When you set up Remote Support, learn a few terms first. The following table defines the building blocks you create during setup, which control who can connect, to what, and with which tools.
| Term | Definition |
|---|---|
| Representative | A person on your support team who helps customers through Remote Support. Each signed-in representative uses one license. |
| Representative console | The application a representative uses to run sessions, available as a desktop console, a web console at /console, and Android and iOS apps. |
| Customer client | The small application the customer runs during a session, used to chat, share a screen, and hand over control. |
| Jump Client | An application you install on a remote computer so it stays connected to your site and you can reach it at any time, whether a user is present or not, and on any network. |
| Gateway | Software you install inside a remote network so you can reach many systems on that network without installing anything on each one. Gateways are required for Remote Jump, RDP, VNC, SSH, and Intel vPro sessions, and were previously called Jumpoints. |
| Asset | Any saved endpoint you connect to, no matter how you reach it. Assets were previously called Jump Items. |
| Asset Group | A collection of assets, used to organize endpoints by site, department, or team and to control which representatives can reach them. Asset Groups were previously called Jump Groups. |
| Asset Policy | A rule that controls when an asset can be accessed, such as limiting access to business hours or requiring two-factor authentication. Asset Policies were previously called Jump Policies. |
| Asset Role | A set of permissions that controls how a representative can manage and use assets. Asset Roles were previously called Jump Item Roles. |
| Session Policy | A reusable rule set that controls which tools are available in a session, such as screen sharing, file transfer, and the command shell. Each permission can be set to Allow, Deny, or Not Defined. |
| Group Policy | A set of permissions and settings you apply to a group of users instead of one user at a time. Group policies also control team, Gateway, asset group, and Vault memberships. |
| Support Team | A group of representatives who work together. Each team gets its own queue in the representative console, and each member has a role of Team Member, Team Lead, or Team Manager. |
| Issue | A problem category a customer selects on your support portal, such as email problems, that routes the request to the team handling it. |
| Skill | A named strength you assign to representatives and link to issues. Equilibrium uses skills to match a request to the right person. |
| Equilibrium | The feature that hands out waiting sessions automatically, either to the least busy representative or to the best-skilled and least busy representative. |
| Session key | A one-time code with a time limit that a representative gives a customer. The customer enters the key on your portal, which routes them to the right person. A session key is not a password and does not authenticate anyone. |
| Support Button | A shortcut you place on a customer's desktop, or embed on a web page, that starts a session with one click. |
| Rep invite | A one-time invitation for a trusted outside expert to join a single session, valid for as long as that session lasts. |
| Vault | The credential store built into Remote Support. Vault saves passwords and SSH keys and injects them into a remote system so the representative never sees them. |
| Endpoint Credential Manager | A Windows service you install to pull credentials from an external credential store, such as BeyondTrust Password Safe, instead of the built-in Vault. |
| Canned script | A script you write ahead of time so a representative can run a common fix during screen sharing or in the command shell. |
| Endpoint automation | A feature that runs scripts across many endpoints at once without starting a support session. |
| B Series Appliance | The physical or virtual appliance that hosts Remote Support on-premises. Every connection between components routes through it. |
ImportantSeveral Jump terms were renamed. For the full list, see the Remote Support glossary.
Former term Current term Jump Item Asset Jump Group Asset Group Jump Policy Asset Policy Jump Item Role Asset Role Jumpoint Gateway Jump Client Jump Client (unchanged)
Connection types
In Remote Support, an endpoint is any remote computer or device you support. Endpoints include Windows, macOS, and Linux computers, iOS and Android devices, and network equipment you reach over SSH or Telnet, such as switches and appliances.
Know the difference between how a session starts and how you reach the endpoint, because that difference determines what you install first. The following table describes the four connection types.
| Connection type | Definition |
|---|---|
| Attended | The customer is present and starts the session. The customer uses a session key, selects a representative on the portal, submits an issue, or clicks a Support Button. Nothing is installed ahead of time. |
| Unattended | The representative starts the session, and no user needs to be present. This requires a Jump Client on the endpoint, or a Gateway on the endpoint's network. |
| Local Jump | A connection from the representative console to a Windows system on the same network segment. No Gateway is needed. |
| Remote Jump | A connection to a system on a different network, routed through a Gateway. |
Remote Support and Privileged Remote Access
Remote Support and BeyondTrust Privileged Remote Access are closely related, so it can be unclear which one a feature belongs to. Both run on the same B Series Appliance, and together they are called Secure Remote Access. The difference is the audience:
- Remote Support serves your service desk. Representatives help employees and customers fix problems on their devices, usually one session at a time.
- Privileged Remote Access serves vendors and internal staff who need ongoing, controlled access to critical systems.
For more information, see What is Secure Remote Access?
Administrative interfaces and the public portal
Remote Support uses separate interfaces on purpose. This keeps hardware administration apart from user administration, and both apart from what your customers see. The following table describes the differences and when to use each one.
| Interface | Description |
|---|---|
/appliance | The appliance administrator's interface for managing the appliance itself. On-premises, it covers networking, storage, encryption, TLS, the firewall, and software updates. On Remote Support Cloud it is smaller, because BeyondTrust manages the infrastructure. For more information, see Appliance user guide. |
/login | The site administrator's interface for managing users, group policies, session policies, teams, assets, Vault, the public portal, reports, and integrations. This is where you do most of your day-to-day configuration. For more information, see Remote Support for admins. |
/console | The web representative console. Representatives use it to run sessions from a browser instead of the installed desktop console. For more information, see Web rep console user guide. |
| Public portal (your site root) | The customer-facing website. Customers go here to enter a session key, choose a representative, or submit an issue, which then downloads the customer client. You can brand it and require SAML authentication. For more information, see Public portals. |
ImportantThe
/applianceand/logininterfaces use separate credentials. Both start with a default username and password and require you to change them at first sign-in, but you must manage each one separately.
Initial setup
Before your team starts taking sessions, complete the initial setup. This adds your users, your policies, your teams, and your endpoints so access is controlled from the start.
ImportantComplete the steps in the order presented. Policies must exist before you deploy Jump Clients and Gateways, because you choose the asset group and asset policy while you build the installer.
1. Deploy your site
For Remote Support Cloud, BeyondTrust provisions your site. To deploy an on-premises site:
- Install the appliance and place it in your perimeter network.
- Point a DNS record at the site.
- Open the required ports.
- Import your SSL certificate.
For more information about deployments, see Appliance deployment | RS Cloud or Appliance deployment | RS On-premises.
2. Sign in to /appliance
/appliance- Go to your site address followed by
/appliance. - Sign in with the default credentials.
- Change the default credentials.
- On-premises sites only: turn on automatic critical updates so security fixes install during your maintenance window.
For more information, see Enable automatic critical updates for Remote Support.
3. Sign in to /login
/login- Go to your site address followed by
/login. - Accept the license agreement.
- Change the default credentials.
- Select your language.
- Go to Status > Information and confirm your support license count.
For more information about licenses, see Remote Support licenses.
4. Add a security provider and group policies
Set up the security provider first, because it determines how your representatives sign in. Create your group policies at the same time. Any user who authenticates against an external identity provider must belong to at least one group policy, so account setup is blocked without one.
To add a security provider:
- From
/login, go to Users & Security > Security Providers. - Click Add.
- Select your provider type, such as LDAP, SAML, Kerberos, or OpenID Connect.
- Enter your server details.
- If you use LDAPS or TLS, upload the root SSL certificate in PEM format.
- Click Save.
To create group policies:
- Go to Users & Security > Group Policies.
- Create a policy for each type of user, such as help desk representative, team lead, and administrator.
- Grant only the permissions each group needs.
- Set the default group policy to the lowest privileges.
- Click Save.
You can also require two-factor authentication in a group policy. See Two-factor authentication guide.
Active Directory is not a separate provider type. You connect to Active Directory through the LDAP provider.
5. Create session policies
A session policy controls which tools a representative can use in a session.
- Go to Users & Security > Session Policies.
- Create one policy per level of access, such as view-only and full control.
- Set each permission to Allow, Deny, or Not Defined.
- Click Save.
Remote Support evaluates session policies one tool at a time, and the most specific policy takes precedence. The order of priority is:
- Asset or Jump Client policy
- Support portal policy
- User policy
- Global default
ImportantTo understand how group policies and session policies are ordered, see Understanding Session and Group policy behavior.
6. Create support teams, skills, and issues
Teams give you queues, and skills and issues route each request to the right queue.
- Go to Configuration > Support Teams and create your teams.
- Add members, and assign each member a role of Team Member, Team Lead, or Team Manager.
- Go to Configuration > Skills and add the skills your team supports.
- Assign those skills to your representatives.
- Rank each skill as More Preferred, Less Preferred, or Ignored.
- Go to Configuration > Issues and create the problem categories customers see.
- Link each issue to a team and a skill.
- Turn on Equilibrium routing for the team so waiting sessions are handed out automatically.
For more information on teams, skills, and Equilibrium, see Equilibrium guide.
7. Configure the public portal
The public portal is where your customers start a session, so set it up before your team goes into production.
- Go to Public Portals.
- Configure your site address.
- Configure the HTML template and branding.
- Select the default Support Button profile.
- Add any customer notices.
- To require customers to sign in first, turn on Require SAML Authentication.
- Click Save.
For more information about public portals, see Public portals.
8. Install the representative console
- Go to Consoles & Downloads.
- Download the desktop representative console, or send your team to
/consolefor the web console. - For mobile representatives, install the Android or iOS app.
- Have each representative sign in and run a test session against the public portal.
For more information about consoles, see Consoles and downloads.
9. Set up unattended access
After your policies exist, deploy unattended access. Complete these steps in order:
- Add Asset Roles, so you control who can manage and use endpoints.
- Add Asset Policies, so you control when endpoints can be accessed.
- Add Asset Groups, so you can organize endpoints and limit who reaches them.
- Go to Asset Management > Jump Clients and deploy Jump Clients with the Mass Deployment Wizard, or install a Gateway on a machine inside each remote network.
- Choose the asset group and asset policy while you build the installer.
- Create your assets in the representative console, or import them from
/login.
For more information, see Jump Client guide and Gateway guide.
10. Configure Vault
Vault stores credentials so your representatives can sign in to remote systems without seeing the password.
- Set the Vault role in each group policy to Inject, or to Inject and Checkout if the user also needs to check credentials out from
/login. - Click Save.
- Run discovery to find accounts.
- Add your accounts and account groups.
- Apply account policies.
For more information on Vault and discovery, see Configure Vault and Credential injection.
11. Connect your integrations and audit tools
Finally, connect Remote Support to the rest of your environment.
- Connect your service desk tool so sessions and tickets stay linked.
- Point syslog at your logging platform.
- Use the Integration Client if you need to move session logs and recordings to SQL Server or a file share.
For more information, see Integrations, Syslog, and Integration Client.
Updated about 1 hour ago