Skip to main content

Remote desktop

Remote desktop shows the screen of a Windows device in a browser tab and, in control mode, lets you use its mouse and keyboard. It is built into Entrosity Axis: the agent captures the screen and the backend relays it to your browser over the same HTTPS address as the portal. There is nothing to install on your computer and no third-party service.

It needs the devices:remote permission (technicians, tenant admins and global admins; see Roles) and a device that is online with an agent that supports it (Windows agents from this release on).

Start a session​

  1. Open the device and click Remote desktop in its header. The button is disabled while the device is offline ("The device is offline").

  2. Choose the mode:

    • Control: see the screen and use the mouse and keyboard.
    • View only: see the screen; no input is sent. The server drops input in view-only sessions, whatever the browser sends.
  3. Ask the user for permission first shows the signed-in user a prompt on the device. If nobody is signed in (sign-in screen), the session starts without a prompt.

  4. Show the session bar on the device shows the user who is connected, with a button to end the session (see below).

    Both options are on by default. Only tenant admins and global admins can turn them off (permission devices:remote_unattended); for technicians they are locked on, and the server refuses a request without them (remote_unattended_forbidden).

  5. Click Connect. The screen opens in a new browser tab; closing the tab ends the session.

While the device prepares the session, the tab shows Waiting for the device…. When a prompt was requested, the user sees a Remote support request window with the Entrosity logo: from IT support wants to control your screen (or view), what that allows, and Decline and Allow buttons with a 60-second countdown. Decline has the focus, so Enter or Esc declines; closing the window or letting it expire declines too. If the user's session is locked, they cannot answer, so the request is declined at once. When someone else signs in during a session (fast user switching), that user is asked again.

What the user sees​

Unless an administrator turned it off for the session, a small bar at the top of the device's main screen, in the portal's style with the Entrosity logo and a green dot, says is controlling your screen (or is viewing your screen) with an End session button. It stays on top of other windows without taking the focus, and the user can drag it aside. End session ends the session at once, and your viewer shows the user ended the session. The bar is not shown on the sign-in or lock screen, where Windows allows no ordinary windows, and it appears in your view too.

note

Allow pop-ups for the portal: the viewer opens in a new tab.

A viewer link opened any other way (bookmarked, shared or typed) first asks Start a remote desktop session? with the device, the mode, whether the user will be asked for permission and whether the session bar is shown, and connects only after you click Connect. A link alone never starts a session.

The viewer​

The toolbar shows the device, the signed-in user (Sign-in screen when nobody is signed in) and a View only badge in view-only sessions.

ControlWhat it does
Ctrl+Alt+DelSends the secure attention sequence (control mode).
Lock keyboard and mouseLocks the device's own keyboard and mouse (control mode): the user cannot interfere while you work; your input still works. Click Unlock keyboard and mouse to give them back. The lock ends with the session at the latest; Ctrl+Alt+Del on the device lifts it until that screen is gone.
Type textTypes up to 4096 characters on the device, independent of its keyboard layout. Use it to paste text.
DisplaySwitches between monitors (only with more than one).
Picture qualityLow, Medium (default) or High JPEG quality: lower is faster on slow links.
Refresh screenSends the whole screen again.
Show actual size / Fit to windowOne device pixel per screen pixel with scrolling, or scaled to fit.
Full screenUses the whole monitor.
DisconnectEnds the session.

Mouse and keyboard (control mode): click the screen to give it the keyboard focus. Keys are sent by position, so the device's keyboard layout applies. Shortcuts that the browser keeps for itself (Ctrl+W, Ctrl+T, Alt+Tab, the Windows key) may not reach the device; use the toolbar instead. Held keys are released when the viewer loses focus.

When a session ends​

MessageWhy
Session endedYou clicked Disconnect, another technician ended it, the device side closed, or access changed: the device was decommissioned, its agent revoked, the tenant suspended, or your account disabled or no longer allowed remote desktop (checked every 15 seconds).
Replaced by a newer sessionSomeone started a newer remote session on the same device: a device has one session at a time.
The user declinedThe user clicked No or did not answer within 60 seconds.
The device could not start the sessionThe agent could not capture the screen; the reason is shown. Brief capture failures (lock screen, UAC prompts, Ctrl+Alt+Del) are retried; the session ends only after 15 seconds without a picture.
Session timed outThe device did not join within two minutes, or the session reached its maximum length of 8 hours.
Could not connectThe viewer's stream did not open within 15 seconds (see below); the session is ended.
Connection lostThe network between your browser and the server was interrupted. The server also pings both sides every 30 seconds and ends a session whose browser or device stopped answering.

Start a new session tries again with the same settings.

Could not connect

The viewer's stream is a WebSocket on the portal's address (/api/remote/v1/…). Anything between the browser and the server, such as a reverse proxy, a load balancer or a corporate web filter, must pass WebSocket upgrades through, as the bundled Caddy does. In development, restart pnpm dev after changing vite.config.ts: Vite's automatic restart does not re-arm its WebSocket proxy.

Audit​

Every request, start and end is written to the audit log (remote.session_request, remote.session_start, remote.session_end) with the technician, the device, the mode and the duration. The screen content is never recorded or stored.