/
/

How to Enable or Disable Remote Assistance Connections in Windows 11

by Ann Conte, IT Technical Writer
How to Enable or Disable Remote Assistance Connections in Windows 11 blog banner image
How to Enable or Disable Remote Assistance Connections in Windows 11 blog banner image

Key points

  • What Is Remote Assistance? Windows Remote Assistance lets IT support staff remotely view and control a user’s device (with permission) for troubleshooting.
  • Use System Properties (GUI): Press Win + R, type “SystemPropertiesRemote,” go to the “Remote” tab, and check or uncheck “Allow Remote Assistance connections.”
  • Use Group Policy: Configure via gpedit.msc under “Computer Configuration” > “Administrative Templates” > “System” > “Remote Assistance.”
  • Use the Registry Editor: Navigate to “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Remote Assistance” and set “fAllowToGetHelp” to 1 (enable) or 0 (disable).
  • Use PowerShell: Execute the “Set-ItemProperty” and “Get-ItemProperty” commands targeting the “fAllowToGetHelp” registry key.
  • Consider Quick Assist or Intune Remote Help: For ad-hoc support, use Quick Assist (Win + Ctrl + Q, port 443). Microsoft Intune Remote Help also offers conditional access enforcement, RBAC, full session audit logs, and Microsoft Defender for Endpoint integration.

Windows Remote Assistance connections allow an organization’s IT support staff to help a computer user troubleshoot and fix issues. This is done through screen sharing and other communication functions like live chat and file sharing. The support staff can take control of mouse and keyboard inputs with the user’s permission.

Remote Assistance is a useful tool, especially for IT professionals working in enterprise environments, but it could open up security vulnerabilities in the device. Learning different ways to enable or disable this feature is a useful skill to ensure that your managed devices are always compliant with your organization’s policies.

Different ways to enable or disable Remote Assistance in Windows 11

There are multiple ways to enable or disable Windows Remote Assistance. For most users, the most straightforward method is through System Properties. For enterprise environments, you can use Group Policy, the Registry Editor, or Windows PowerShell.

Before proceeding, take note of the following:

  • You’ll need administrator access for system-wide changes. To check if you have the necessary permissions, open the Start Menu > Settings > Accounts. The word “Administrator” should be shown under your username.
  • Remote Assistance uses port 3389 (TCP). This port is a frequent target of automated attacks and brute-force attempts. Unless your organization actively uses Remote Assistance or Remote Desktop, this port should be blocked at the firewall. If you do use it, restrict access via IP allowlisting, enable network-level authentication (NLA), and consider routing connections through a VPN or zero-trust network access (ZTNA) solution rather than exposing port 3389 directly to the internet. Keep systems fully patched; multiple critical RDP CVEs were disclosed in 2025.
  • This feature is available on all Windows 11 editions, including Home. However, Group Policy configuration (Method 2) requires Windows 11 Pro, Enterprise, or Education. Home users should use the Registry Editor (Method 3) or PowerShell (Method 4) instead.

View the full video walkthrough here: How to Enable or Disable Remote Assistance Connections in Windows 11.

Method 1: Enable or disable via System Properties (GUI)

Method 1 uses the built-in System Properties dialog and is the quickest option for individual users or lightly managed devices who need to make a one-time change without any additional tools.

  1. Press Win+R, type SystemPropertiesRemote, and press Enter.
  2. Go to the Remote tab.
  3. Under Remote Assistance, check Allow Remote Assistance connections to enable the feature. To disable it, uncheck it.
  4. Click Apply > OK.

Method 2: Configure via Group Policy (recommended for enterprises)

Method 2 uses the Local Group Policy Editor and is the recommended approach for IT administrators managing domain-joined or multi-user devices running Windows 11 Pro, Enterprise, or Education.

  1. Press Win+R, type gpedit.msc, and press Enter.
  2. Navigate to Computer Configuration > Administrative Templates > System > Remote Assistance.
  3. Configure the following policies:
    1. Configure Offer Remote Assistance — If you enable this, support staff from your organization can assist you with your issues. If you disable this, you can’t receive assistance from corporate support staff. If you don’t configure the policy, users won’t be able to get help from your organization’s technical support using Offer (Unsolicited) Remote Assistance.
    2. Configure Solicited Remote Assistance — If you enable this, users can use email or file transfer to ask for remote assistance. If you disable it, they can’t. If you leave it unconfigured, they can turn this setting on or off in Control Panel > System and Security > System > Remote settings.
  4. To apply these updates, open the Start Menu, search for Command Prompt, right-click it, and select Run as administrator.
  5. Type gpupdate /force and press Enter.

Method 3: Enable or disable via Registry Editor

Method 3 uses the Windows Registry Editor and works on all Windows 11 editions, including Home, making it the go-to option for users who don’t have access to the Group Policy Editor.

Note: Before making changes to the registry, make a backup.

  1. Open the start menu and search for Registry Editor to open the program.
  2. Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Remote Assistance.
  3. Locate the value fAllowToGetHelp. If you can’t find it, create it by following these steps:
    1. Right-click Remote Assistance> New > DWORD (32-bit) Value.
    2. Name it fAllowToGetHelp.
  4. Double-click fAllowToGetHelp.
  5. Change the value to 1 if you want to enable Remote Assistance connections. To disable them, change the value to 0.

The following steps are optional, but you can follow them to configure unsolicited or offer-based support.

  1. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services.
  2. Locate the value fAllowUnsolicited. If you can’t find it, create it by following these steps:
    1. Right-click Terminal Services> New > DWORD (32-bit) Value.
    2. Name it fAllowUnsolicited.

Method 4: Use PowerShell to view or configure the setting

Method 4 uses Windows PowerShell and is best suited for IT administrators who need to audit or deploy Remote Assistance settings across multiple devices simultaneously using remote scripts.

  1. Open the start menu and search for Windows PowerShell. Right-click and select Run as administrator.
  2. To view the current settings of Remote Assistance connections, use this script and press Enter:

Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Remote Assistance" -Name fAllowToGetHelp

To disable the feature, use this script and press Enter:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Remote Assistance" -Name fAllowToGetHelp -Value 0

To enable it, use this script and press Enter:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Remote Assistance" -Name fAllowToGetHelp -Value 1

Quick Assist: The modern alternative

Lastly, it’s important to note that Windows 11 ships with Quick Assist, Microsoft’s current recommended tool for ad-hoc remote support. Unlike the Remote Assistance feature covered in this guide, Quick Assist doesn’t use port 3389; it communicates over port 443 (HTTPS) and requires a Microsoft account for the helper.

As of early 2025, Microsoft moved Quick Assist to the Microsoft Store (app ID: 9P7BP5VNWKX5), replacing the built-in inbox version. You can launch it with Win + Ctrl + Q. For enterprise environments requiring compliance logging and advanced access controls, Microsoft recommends Microsoft Intune Remote Help over Quick Assist.

Additional considerations when enabling or disabling Remote Assistance in Windows 11

Remote Assistance vs. Remote Desktop

Remote Assistance and Remote Desktop are two different features. Keep in mind that disabling Remote Assistance won’t disable Remote Desktop.

Firewall configuration

Port 3389 is the default port of both Remote Desktop and Remote Assistance. If your organization uses Quick Assist instead, it operates over port 443 (HTTPS). If neither feature is in use, block port 3389 at the perimeter firewall.

Audit logs

Here are the steps to view the activity logs of Remote Assistance:

  1. Press Win + R, type eventvwr, and press Enter.
  2. Navigate to Applications and Services Logs > Microsoft > Windows > RemoteAssistance.
  3. For organizations that already have their own remote desktop tool, consider disabling Remote Assistance for additional security and policy consistency.

Why manage Remote Assistance connections?

Remote Assistance can help ensure that users have the assistance they need from your IT support staff, especially in enterprise environments. However, it can also pose some security risks. Disabling it will help ensure that you’re compliant with your organization’s security policies and minimizes a device’s attack surface.

If you already have a remote access tool for your organization, Remote Assistance can be redundant, and in this case, it may be best to disable it for policy consistency.

For enterprise environments already on Microsoft Intune, consider Microsoft Intune Remote Help as your primary remote support tool. It provides conditional access enforcement, RBAC, full session audit logs, and Microsoft Defender for Endpoint integration, capabilities that Quick Assist and legacy Remote Assistance don’t offer.

Optimize IT support tools by enabling or disabling Remote Assistance connections in Windows 11

Overall, Remote Assistance is a very helpful tool in Windows 11, but it can also present a security risk to your IT environment. If you’re planning to use it for your organization, make sure to review your firewall settings to ensure that they comply with your organization’s policies. You can also view the activity logs of Remote Assistance in Event Viewer for auditing purposes.

Most users can enable or disable this feature through System Properties. However, in enterprise environments, Group Policy is the most scalable and secure method. Windows Home users can also use the Registry Editor. If you’re using scripts to deploy these settings to all your managed devices, use Windows PowerShell.

Quick-Start Guide

Here’s information about enabling or disabling remote assistance connections in Windows 11:

NinjaOne offers several scripts and tools related to remote management, but the specific details for enabling or disabling remote assistance connections aren’t directly addressed in the documentation. However, we can provide some general guidance:

Enabling/Disabling Remote Assistance in Windows 11

1. In the NinjaOne Remote Tools section, there are options for:
– Remote Registry
– Remote Desktop
– Other remote access management tools

2. For direct remote assistance configuration, you might want to:
– Use Windows Settings
– Modify Group Policy
– Use a registry script

Recommended Steps:

1. Windows Settings Method:
– Open Windows Settings
– Go to System > Remote Desktop
– Toggle Remote Assistance settings

2. NinjaOne Potential Solutions:
– Use the “Enable or Disable Remote Desktop (RDP)” script in NinjaOne’s script library
– Leverage Remote Tools for configuration

Important Considerations:

– Always ensure proper security settings
– Verify network and firewall configurations
– Use least-privilege access principles

If you need a precise, automated solution, we recommend consulting with your NinjaOne administrator or support team for the most up-to-date and secure method specific to your environment.

FAQs

Yes. Using PowerShell remoting, administrators can run the Set-ItemProperty command against a remote machine by adding the -ComputerName parameter or deploy the setting at scale using Group Policy, Microsoft Intune, or a remote monitoring and management (RMM) tool. This is particularly useful for managing distributed devices without requiring hands-on access.

In most cases, no. Disabling Remote Assistance only affects the legacy msra.exe tool and its associated Group Policy settings. It doesn’t affect Quick Assist, Remote Desktop, or any third-party remote access tools your organization may use as those operate independently.

For System Properties and Registry Editor changes, a restart isn’t required; changes take effect immediately. For Group Policy, running gpupdate /force applies the policy without a reboot. PowerShell changes to the registry also take effect immediately.

The option to request or send a Remote Assistance invitation will be grayed out or unavailable in System Properties. If the feature has been disabled via Group Policy, users will also be unable to override the setting themselves, even if they have local administrator rights.

Blocking port 3389 at the firewall prevents external connections from reaching the service, but the feature remains technically enabled at the OS level.

Best practice is to do both—disable Remote Assistance in Windows and block the port at the firewall—so that the setting is enforced at multiple layers. This is especially important for compliance in audited environments.

Yes. The Configure Offer Remote Assistance policy includes a “Helpers” list where you can specify exactly which users or security groups are permitted to offer unsolicited remote assistance. This gives administrators granular control over who can initiate a session, rather than simply toggling the feature on or off.

Yes, potentially. As long as Remote Assistance is enabled and port 3389 is reachable, the device has an open attack surface regardless of active use.

Automated scanners routinely probe for open RDP and Remote Assistance ports across the internet. If your organization isn’t actively using the feature, the safest approach is to disable it and block port 3389 at the firewall.

You might also like

Ready to simplify the hardest parts of IT?