Unattended access
Reach your own computer when nobody is there to accept, give other people limited access, and set rules for who may connect at all.
What unattended access is#
Unattended access lets you connect to a computer you look after when nobody is there to press Allow. It is optional and off unless you turn it on yourself on that computer. It uses its own password, separate from the one-time password.
Important
Anyone who knows the computer's ID and the unattended password can view and control it without anyone approving. Choose a password you do not use anywhere else, and never share it with someone who contacted you unexpectedly.
Note
The computer has to be switched on, signed in to Windows and unlocked. RFDesk cannot sign in to Windows for you.
Set your own unattended password#
- On the computer, open RFDesk and go to its settings, then Security.
- Under Unattended access, choose Set password and type a password of at least 8 characters, twice. It is kept on that computer and is never shown again.
- Switch on Allow unattended access and confirm.
To connect, enter the computer's ID and this password on the connect page or in the app, in the same password box. The security panel of the session then says that you connected with the unattended-access password, and the computer's own screen shows the session as unattended.
The one-time password is not affected: a connection made with it still needs approval.
Add an authenticator code#
For a second step, switch on Require an authenticator code in the same place. Scan the code shown with an authenticator app, then enter the six digits the app shows to confirm. Nothing changes until a code is accepted.
From then on, anyone connecting with an unattended password is also asked for the current six-digit Authenticator code. The code itself is not sent; the computer checks a proof made from it. A wrong code ends that attempt.
Note
Keep the authenticator app. Without it unattended access will not work until you turn the code off at the computer.
Privacy mode#
Privacy mode blacks out the computer's screen for anyone near it and ignores its own mouse and keyboard while you work on it remotely. It is only for connections made with your own unattended password, and only after you switched on Privacy mode for my own unattended access on that computer.
During the session, turn it on under Session tools, Privacy mode. It always ends with the session. A person at the computer cannot see or stop what is done meanwhile, except by restarting it.
Access for other people#
Instead of sharing your own unattended password, a computer can hold separate access for a named person.
- Each person has their own password, of at least 8 characters, different from every other password on that computer.
- You choose what that person may do: control, clipboard and file transfer are separate.
- You can add a time window, from a start time until an end time. This is how access is scheduled for one visit or made to expire.
- They connect with the computer's ID and their own password. Nobody at the computer is asked, exactly as with your own unattended access, but they stay within what you gave them.
- The session is shown under that person's name on the computer and in its history.
- Removing a person's access stops their password working.
Note
If the computer belongs to a team whose policy forbids unattended access, all of this is switched off as well.
Rules for who may connect at all#
For a computer on your account you can set rules that the RFDesk server checks before the computer is even told that someone asked. Whoever the rules turn away never reaches it; whoever is let through still needs a password or your approval.
- Add the computer to your account: in RFDesk on that computer, sign in and choose Add this computer to my account.
- On this website open My devices, find the computer and press Details.
- Under Access rules, set Who may connect: Anyone with the ID and password, Listed accounts only or Listed devices only.
- Optionally switch on Allowed hours and choose the days, the times and the time zone. Outside these times connections are refused.
- Optionally list Allowed networks: single public internet addresses, or ranges such as 203.0.113.0/24. Leave it empty to allow any network.
- Press Save rules. They apply to the next connection.
Important
With Listed devices only nobody can connect from this website, including you: a browser has no device identity. Use the RFDesk app on a listed device.
Waking a sleeping computer#
In My devices, a computer that is offline can show a Wake button. It asks another of your devices that is online on the same network to send a wake-on-LAN signal. The sleeping computer must have wake-on-LAN switched on in its firmware, and it comes online within a minute or two if it wakes.
Turning it off#
On the computer, switch Allow unattended access off, or choose Remove password. Removing the password switches unattended access off; connections again need the one-time password and your approval. You can also change the password at any time with Change password.