Remote desktop
Remote desktop shows the screen of a Windows device in a browser tab and, in control mode, lets you use its mouse and keyboard. It is built into Entrosity Axis: the agent captures the screen and the backend relays it to your browser over the same HTTPS address as the portal. There is nothing to install on your computer and no third-party service.
It needs the devices:remote permission (technicians, tenant admins and
global admins; see Roles) and a device that is online with
an agent that supports it (Windows agents from this release on).
Start a session
-
Open the device and click Remote desktop in its header. The button is disabled while the device is offline ("The device is offline").
-
Choose the mode:
- Control: see the screen and use the mouse and keyboard.
- View only: see the screen; no input is sent. The server drops input in view-only sessions, whatever the browser sends.
-
Ask the user for permission first shows the signed-in user a prompt on the device. If nobody is signed in (sign-in screen), the session starts without a prompt.
-
Show the session bar on the device shows the user who is connected, with a button to end the session (see below).
Both options are on by default. Only tenant admins and global admins can turn them off (permission
devices:remote_unattended); for technicians they are locked on, and the server refuses a request without them (remote_unattended_forbidden). -
Click Connect. The screen opens in a new browser tab; closing the tab ends the session.
While the device prepares the session, the tab shows Waiting for the
device…. When a prompt was requested, the user sees a Remote support
request window with the Entrosity logo:
What the user sees
Unless an administrator turned it off for the session, a small bar at the
top of the device's main screen, in the portal's style with the Entrosity
logo and a green dot,
says
Allow pop-ups for the portal: the viewer opens in a new tab.
A viewer link opened any other way (bookmarked, shared or typed) first asks Start a remote desktop session? with the device, the mode, whether the user will be asked for permission and whether the session bar is shown, and connects only after you click Connect. A link alone never starts a session.
The viewer
The toolbar shows the device, the signed-in user (Sign-in screen when nobody is signed in) and a View only badge in view-only sessions.
| Control | What it does |
|---|---|
| Ctrl+Alt+Del | Sends the secure attention sequence (control mode). |
| Lock keyboard and mouse | Locks the device's own keyboard and mouse (control mode): the user cannot interfere while you work; your input still works. Click Unlock keyboard and mouse to give them back. The lock ends with the session at the latest; Ctrl+Alt+Del on the device lifts it until that screen is gone. |
| Type text | Types up to 4096 characters on the device, independent of its keyboard layout. Use it to paste text. |
| Display | Switches between monitors (only with more than one). |
| Picture quality | Low, Medium (default) or High JPEG quality: lower is faster on slow links. |
| Refresh screen | Sends the whole screen again. |
| Show actual size / Fit to window | One device pixel per screen pixel with scrolling, or scaled to fit. |
| Full screen | Uses the whole monitor. |
| Disconnect | Ends the session. |
Mouse and keyboard (control mode): click the screen to give it the keyboard focus. Keys are sent by position, so the device's keyboard layout applies. Shortcuts that the browser keeps for itself (Ctrl+W, Ctrl+T, Alt+Tab, the Windows key) may not reach the device; use the toolbar instead. Held keys are released when the viewer loses focus.
When a session ends
| Message | Why |
|---|---|
| Session ended | You clicked Disconnect, another technician ended it, the device side closed, or access changed: the device was decommissioned, its agent revoked, the tenant suspended, or your account disabled or no longer allowed remote desktop (checked every 15 seconds). |
| Replaced by a newer session | Someone started a newer remote session on the same device: a device has one session at a time. |
| The user declined | The user clicked No or did not answer within 60 seconds. |
| The device could not start the session | The agent could not capture the screen; the reason is shown. Brief capture failures (lock screen, UAC prompts, Ctrl+Alt+Del) are retried; the session ends only after 15 seconds without a picture. |
| Session timed out | The device did not join within two minutes, or the session reached its maximum length of 8 hours. |
| Could not connect | The viewer's stream did not open within 15 seconds (see below); the session is ended. |
| Connection lost | The network between your browser and the server was interrupted. The server also pings both sides every 30 seconds and ends a session whose browser or device stopped answering. |
Start a new session tries again with the same settings.
The viewer's stream is a WebSocket on the portal's address
(/api/remote/v1/…). Anything between the browser and the server, such as
a reverse proxy, a load balancer or a corporate web filter, must pass
WebSocket upgrades through, as the bundled Caddy does. In development,
restart pnpm dev after changing vite.config.ts: Vite's automatic
restart does not re-arm its WebSocket proxy.
Audit
Every request, start and end is written to the audit log
(remote.session_request, remote.session_start, remote.session_end)
with the technician, the device, the mode and the duration. The screen
content is never recorded or stored.