New · Release 2026.04, Multi-tenant audit exports & SLA dashboards now live See changelog →
Remote support

In-browser remote desktop for endpoints you manage

Connect to enrolled devices with in-app remote desktop — screen, input, file transfer, clipboard and multi-monitor — with MeshCentral integration and per-organization isolation.

Product illustration · sample data
Mobile Device Management
6 OS
AndroidiOSWindowsLinux
94%
Compliance · 128 enrolled
Enrolled devices128
Non-compliant8
Pending commands3
Linux agentsActive
Product proof

Already live in the product

Backed by app modules

Running in production today: in-app remote desktop with MeshCentral integration, built into device management.

Protected app route: /mdm-dashboard
How it works

Built around real workflows

Highlights below describe capabilities already present in the protected app behind this page.

In-app remote desktop viewer
File transfer and clipboard
Multi-monitor and session recording
Per-organization Mesh isolation
Workflow

What teams can do here

Step 1
Enrol a device
Step 2
Start a remote session
Step 3
Assist the user live
Step 4
End session with audit trail
How it works

How it works

01
Enrol the device
Remote access runs against a device already enrolled in device management, so the same agent that reports the device also carries the remote session. No separate remote tool has to be installed on the endpoint.
02
Open a session over one socket
The operator browser and the device agent join the same per-device WebSocket relay. The agent authenticates with a hashed device token, and the viewer is authorized only if the operator organization owns that device, keeping sessions isolated per tenant.
03
Control the endpoint
The agent streams the screen as changed tiles with periodic keyframes while the viewer injects mouse and keyboard input. The protocol also carries multi-monitor switching, two-way clipboard, a live chat channel and chunked file transfer over the same connection.
04
Require consent and record
A remote session is stored as an audit record with a one-time session password and a consent flag, and the session can be recorded. Recordings are saved as timestamped frame logs that replay onto a canvas at the original cadence for later review.
Example

A worked example

Say an MSP technician supports 700 managed endpoints across a dozen client tenants, and a finance client reports a broken VPN profile on a director's laptop. The technician opens a native remote session from the browser; the agent joins the per-device relay with its hashed token, and the viewer is admitted only because that tenant owns the device. The director approves the consent prompt, a one-time session password guards the connection, and recording is switched on. The fix takes minutes — new config pasted through the synced clipboard, an installer dropped over the same socket — and the audit record plus frame-by-frame replay are there if the client ever asks who connected and why.

FAQ

Frequently asked questions

Is this native remote desktop or MeshCentral?
Both are available. There is an in-app native remote desktop that streams over a single per-device WebSocket, and MeshCentral integration is wired in as well. A remote session is tracked as an audit record whichever tool carries it.
What can I do inside a session?
The wire protocol carries screen streaming as changed tiles with keyframes, mouse and keyboard input injection, multi-monitor selection, two-way clipboard sync, a chat channel, and chunked file transfer, all over the same connection, with capability negotiation for older agents.
Does the end user have to consent?
A remote session record carries a consent-required flag and a granted state, and each session is protected by a one-time session password. That keeps unattended access an explicit choice rather than a silent capability.
Can I record and audit sessions?
Yes. Each session is stored as an audit record noting the device, who started it and when it ended, and a session can be recorded to a timestamped frame log. Playback replays the captured frames onto a canvas at their original timing.
Which operating systems are supported?
Windows, macOS and Linux agents support interactive control, and Android participates in a view-only capacity. There is no iOS or iPadOS agent today, so iPhones and iPads cannot be remote-controlled. Capability negotiation lets the viewer adapt to what each agent advertises.
Does remote access reach devices outside the office network?
Yes. Both the viewer and the agent connect outbound to the same per-device WebSocket relay, so a managed laptop on home Wi-Fi is reachable without inbound firewall rules or a VPN back into the office.
How is access kept separate between tenants?
A viewer is only authorized when the operator organization owns the target device, and each device has its own relay channel. Combined with per-organization isolation, one tenant cannot open a session against another tenant device.

See also: Guide: best remote desktop software · Guide: what is RMM? · RMM & endpoint management · Mobile device management · MDM overview

Related

Explore connected offerings

Fix any managed endpoint without leaving the browser

Consent-gated, recorded sessions over one WebSocket — screen, input, clipboard, chat and file transfer on the same agent that already manages the device.