Advertisement
Promo

Office applications Toolkit

Consider security when using Remote Assistance

Brien M Posey

Published: 24 Apr 2002 12:21 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Stuck with the end user's permissions
The remote user has access to the exact same resources as the local user. This can be both a benefit and a hazard. The benefit is that the remote user can see exactly what's going on without running into permissions problems. For example, a number of times, I've tried to help a user, but I wasn't initially able to re-create the problem because it was related to insufficient permissions and I had administrative rights.

Another benefit of common permissions is that if you've done a good job of implementing a tough group policy, it should be impossible for a remote user to do anything to damage the system, because the remote user won't be able to do anything that the local user doesn't have permission to do.

On the other hand, common permissions can also prevent a support tech from being able to correct the problem because the local user may not have the necessary privileges.

Other means of managing Remote Assistance
Along with controlling inbound and outbound traffic on port 3389, there are other ways the IT department can control Remote Assistance. For example, administrators can disable Remote Assistance at the individual workstation. If your organisation uses an Active Directory Windows 2000 Server environment, you can use group policies to manage Remote Assistance. These policies can:

  • Permit or prohibit users from requesting help via Remote Assistance.
  • Control whether users can request assistance from friends and/or coworkers or from the help desk only.
  • Control whether users can allow a helper to remotely control their computer or if the helper can just view the user's screen.
  • Plan before implementing
    So what's the moral of the story? In a word, plan. Before your help desk embraces Windows XP's Remote Assistance, examine your current network structure, consider the time involved in administering Remote Assistance, and evaluate the security implications. As with any IT project, you should consider alternative products, such as pcAnywhere, Virtual Network Computing, and Microsoft's own Systems Management Server (SMS) or Remote Desktop, before making a final decision.


    Have your say instantly in the Tech Update forum.

    Let the editors know what you think in the Mailroom.

    Next

    Previous

    1 2


    • Email
    • Trackback
    • Clip Link
    • Print friendlyPrint with EPSON

    Did you find this article useful?
    136 out of 219 people found this useful


    Full Talkback thread

    0 comments

    Company/Topic Alerts

    Create a new alert from the list below:













    Video icon

    Video

    Win a BlackBerry with Vlingo voice recognition

    Win a BlackBerry with Vlingo voice recognition

    What is ZDNet UK's usual tagline?

    Competition closes - 14 Jan 2010

    Discussions

    Shibley R Shibley R

    Copyright in a new light

    Monday 28 December 2009, 1:29 PM

    7 comments
    Shibley R Shibley R

    Eigg

    Sunday 27 December 2009, 1:04 PM

    1 comment

    Vista Upgrade Blog

    How to Upgrade From Windows Vista to W...

    Did you get the news? Microsoft has unzipped its kitty and kept its latest, supposedly the best, offering on display. This is the brand new version of Microsoft operating system, named... More

    Post a comment

    Tinsel on the TARDIS

    There were shepherds on the hill, and the Doctor popped his head out of the TARDIS and said "you might want to see this" and they were astounded. WHY do we pay for a TV license?... More

    Post a comment

    Can I have fries with that? (Consumer...

    Licence policies of Tech company's have been for a long time both complicated and 'Dick Turpin-esque', people just click 'I agree' without reading the Agreement. I do the same, but... More

    1 comment


    Skip Sub Navigation Links to CNET Brand Links

    Help

    Become part of the ZDNet community.

    Newsletters