Governed support path
Remote support should retain the identity of the requesting technician, the target device, authorization context, session lifecycle and resulting audit evidence.
Remote support transport is separate from ordinary endpoint inventory and heartbeat collection.
Security expectations
- Device-scoped authorization rather than a permanent shared remote credential.
- Explicit session start, end, expiry or revoke semantics.
- Backend credentials remain server-side and are not exposed through the public website.
- Remote Desktop and Remote Terminal support status should follow the current release evidence rather than generic marketing claims.
Audit questions
- Who requested the session?
- Which device was targeted?
- When did the session start and end?
- Was access revoked or allowed to expire?
- What evidence remains available to the operator or auditor?