Remote control
The Remote Control feature allows you to configure remote control policies for managed endpoints. Each policy defines which users or devices it applies to, the default remote assistance behavior, and who can initiate remote assistance sessions. When multiple policies match the same endpoint, policies are evaluated by priority.
Create a remote control policy
Log on to the SASE console. In the left-side navigation pane, choose Endpoint Management > Remote Control.
On the Remote Control page, click Create Remote Control Policy.
In the Create Policy Configuration panel, configure the following parameters.
Basic settings
Parameter
Description
Policy Name
Required. The name of the policy. Maximum 128 characters.
Policy Description
Optional. A description of the policy. Maximum 256 characters.
Policy Status
Specifies whether the policy is enabled. Default value: enabled.
Effective scope
Parameter
Description
Effective Scope
Required. The scope of users or devices to which the policy applies. Valid values: All Users (default), Specific User Group, Specified Device Group, Specific Device Tag. If you select a value other than All Users, specify the target user groups, device groups, or device tags. Mobile devices cannot be selected.
Exception User
Optional. Users who are exempt from this policy. Enter one or more usernames.
Policy configuration
Parameter
Description
Endpoint Remote Assistance Default Status
Specifies whether remote assistance is enabled on endpoints by default. Default value: enabled.
Bypass User Confirmation
Specifies whether to skip endpoint user confirmation before a remote assistance session is established. When enabled (default), no confirmation is required. When disabled, endpoint users must confirm before the session starts.
Initiator Scope
Required. Specifies who can initiate remote assistance sessions. Valid values: All Users (default), Specific User Group. When set to Specific User Group, specifiy the user groups allowed to initiate remote assistance sessions.
Priority
The priority of the policy. Value range: 1 to 100. Default value: 100. A lower value indicates a higher priority.
Click OK.
The policy is created and appears in the policy list.
When no remote control strategy is set, remote control is disabled by default for all users.
Manage remote control policies
Edit a policy
On the Remote Control page, find the policy that you want to edit.
In the Actions column, click Edit. Alternatively, click the policy name to open the Policy Details panel, and then click Edit.
In the Edit Policy Configuration panel, modify the parameters as needed.
Click OK.
The policy settings are updated.
Enable or disable a policy
On the Remote Control page, find the target policy and click the toggle in the Status column.
To enable a policy: In the Enable Policy? dialog box, click OK.
To disable a policy: In the Disable Policy dialog box, click OK.
The Status column reflects the updated state.
Delete a policy
Deleted policies cannot be recovered.
On the Remote Control page, find the policy that you want to delete.
In the Actions column, click Delete.
In the Delete Policy dialog box, click OK.
The policy is removed from the policy list.
View policy details
On the Remote Control page, click a policy name to open the Policy Details panel. The panel displays the following information.
Field | Description |
Policy Name | The name of the policy. |
Description | The description of the policy. |
Priority | The priority of the policy. |
Status | The current status of the policy: enabled or disabled. |
Created At | The time when the policy was created. |
Effective Scope
Field | Description |
Match Mode | The effective scope type of the policy. |
Target | The specific user groups, device groups, or device tags to which the policy applies. Displayed when Match Mode is not All Users. |
Exception User | Users who are exempt from this policy. Displayed when exception users are configured. |
Policy Settings
Field | Description |
Endpoint Remote Assistance Default Status | Whether remote assistance is enabled on endpoints by default. |
Bypass User Confirmation | Whether endpoint users are required to confirm before a remote assistance session is established. |
Initiator Scope | Who can initiate remote assistance sessions. |
Initiator User Group | The user groups allowed to initiate remote assistance sessions. Displayed when the initiator scope is Specific User Group. |