Catch Advisors
Cybersecurity

Remote Support Renewal: Reconcile Every Technician and Unattended Endpoint

A remote support renewal often starts with a seat count and an endpoint count. That is not enough.

The platform may still include technicians who changed roles, old MSP accounts, retired devices, and unattended access nobody remembers approving. Meanwhile, the proposal may add features without proving the current environment is under control.

Before you renew, match every technician to a current role and every unattended agent to a real endpoint. Then test how access is approved, what the technician can do, what the session records, and how you would remove the platform if the relationship ended.

Remote support is useful because it gives people fast access to distant systems. That is also why vague ownership is expensive and dangerous.

Build one remote support register

Do not begin with the renewal quote. Begin with a working register that combines the commercial, identity, endpoint, and security views.

Create one row per technician identity and one row per endpoint agent. Record at least:

AreaWhat to record
Technician identityNamed user, employer, department, manager, employment status, and business purpose
Access roleViewer, help desk, administrator, script operator, tenant administrator, or other assigned role
AuthenticationIdentity provider, MFA method, local account status, emergency account, and last successful sign-in
EndpointDevice name, serial number or asset ID, owner, location, operating system, agent version, and last contact
Access modeAttended, unattended, on-demand, persistent, temporary, or vendor initiated
Approval pathUser consent, ticket, manager approval, maintenance window, emergency authority, or standing access
Session evidenceStart and end time, technician, target device, actions, file transfer, commands, recording, and ticket reference
Commercial scopeTechnician license, endpoint license, concurrent session, add-on, storage, support tier, and contract owner
DecisionKeep, correct, restrict, remove, consolidate, replace, or investigate

The two sides need to connect. A clean technician list does not prove the agent population is clean or that the right people can reach those devices.

Your endpoint management renewal audit is a useful input, but do not assume the RMM, MDM, asset system, directory, and remote support platform count devices the same way. Compare them. The differences are where stale agents and coverage gaps tend to surface.

Separate technicians from accounts

A shared account called “Support” may be convenient. It is terrible evidence.

Every human technician should use a named identity tied to a current employer and manager. Separate internal IT, MSP staff, contractors, software vendors, equipment providers, and temporary project teams. If a provider uses a multi-tenant console, require a current list of the people and roles that can reach your environment.

Check directory records, HR records, provider rosters, local accounts, service accounts, emergency accounts, and invitation history. Compare them with recent sign-ins and sessions.

The CISA-led Guide to Securing Remote Access Software recommends auditing inactive and obsolete accounts, using least privilege, enabling just-in-time access or two-factor authentication based on risk, and treating MSP accounts with customer access as privileged. Those are practical renewal tests, not abstract policy language.

For each identity, ask:

  • Does this person still need access?
  • Which customers, sites, groups, or devices can the role reach?
  • Can the person transfer files, run scripts, open a command line, change configuration, or add another administrator?
  • Does strong authentication apply to every access path, including local accounts and emergency access?
  • Can the role be reduced for common support work?
  • Who reviews the access, and how often?

Read-only monitoring and interactive control do not need the same privilege. Password resets and routine desktop support do not justify broad server access. Mass scripting deserves tighter approval than a single attended session.

Use the privileged access management guide to identify the roles that can create a large blast radius. The renewal packet should show why those roles exist, who owns them, and what evidence proves they are still required.

Reconcile every unattended agent

Unattended access works without a user approving each connection. That may be necessary for servers, overnight maintenance, remote sites, kiosks, and devices without a normal user. It should not become the default because deployment was easy.

Export the full agent inventory from the remote support platform. Compare it with the asset register, endpoint management system, directory, EDR inventory, server inventory, virtualization platforms, cloud instances, network records, and provider documentation.

Investigate endpoints that are duplicated, long offline, tied to retired assets, missing from the asset register, assigned to former employees, or sitting in the wrong group. Also look for active endpoints with no approved agent. You need to understand which paths into the environment exist.

CISA’s guidance tells organizations to audit remote access software and its configuration on network devices to identify currently used and authorized RMM software. It also recommends application controls, approved RMM programs, segmentation, regular patching, and monitoring for unauthorized tools.

That matters because your approved platform may not be the only platform installed. Search endpoint and software inventory for portable remote tools, free trials, vendor-specific support utilities, old MSP agents, and products deployed during a project or incident. Decide whether each tool is authorized, restricted, monitored, or removed.

Test attended and unattended sessions

A vendor demo proves the product can start a session. Your renewal test should prove the operating rules survive real use.

Choose representative scenarios:

  1. A help desk technician supporting a standard employee laptop.
  2. An administrator reaching a production server through unattended access.
  3. An MSP technician entering your environment from the provider’s console.
  4. A software vendor requesting temporary access for a maintenance window.
  5. An emergency session outside normal support hours.

For each scenario, record how the technician authenticated, what role was assigned, whether a ticket or approval was required, whether the user saw a consent notice, which actions were available, what the session log captured, and who received an alert.

Test file transfer, clipboard use, command and script execution, privilege elevation, recording, and handoff where those features are in scope. Confirm that policy blocks what should be blocked. A setting marked “enabled” is not proof.

Then test the evidence. Can your team find the session by technician, endpoint, time, or ticket? Does the record show enough detail to understand what happened? Can a technician or tenant administrator alter or delete the evidence?

The CISA guide recommends complete logging that includes the executing binary, request types, IP addresses, and date and time. For MSP and SaaS customers, it also recommends contract terms that provide visibility into provider activity and connections, proper monitoring and auditing of MSP accounts, and keeping direct access to log servers plus the ability to delete or alter logs out of reach of RMM tools.

If session records exist only inside the provider’s tenant and disappear at termination, that is a contract problem as much as a technical one.

Inspect the provider’s side of the connection

Your controls can be solid while the provider’s controls remain vague.

Ask the provider to document:

  • The named roles that can access your tenant or endpoints
  • Authentication and MFA requirements for those roles
  • How customer environments and credentials are separated
  • Whether administrative credentials are reused across customers
  • How privileged sessions, scripts, and file transfers are approved and monitored
  • How provider staff changes trigger access removal
  • How suspected compromise is reported to you
  • What happens if the provider’s console, identity system, or administrative network is compromised
  • Which logs and session records you receive during normal service and after termination

CISA’s guidance says contracts should make clear which security services customers are purchasing, which services they are not purchasing, and the contingencies for incident response and recovery. It also says contracts should detail how and when providers notify customers about incidents affecting the customer’s environment.

Do not accept “industry standard security” as the answer. Put the responsibilities, evidence, timing, and access boundaries into the agreement.

The MSP bundled tool stack audit can help when remote support is one part of a larger managed service. You need to know whether the remote access license, tenant, configuration, logs, and offboarding work belong to you, the provider, or both.

Price the access you intend to keep

Once the register is clean, rebuild the commercial scope.

Separate named technicians, concurrent technicians, attended sessions, unattended endpoints, mobile devices, servers, add-on security, session-recording storage, integrations, APIs, support tiers, and professional services. Vendors package these differently, so a lower seat price may hide a higher endpoint, storage, or add-on cost.

Ask what happens when you add a temporary contractor, exceed an endpoint tier, retain recordings, export logs, or require premium support. Confirm whether disabled technicians and offline agents still count toward billing.

Run the exit test before renewal

Test whether you can export technicians, roles, endpoints, policies, session history, recordings, audit logs, and integration settings in usable formats. Document how agents will be removed from online and offline devices, including servers, remote sites, dormant equipment, and endpoints controlled by a departing provider.

Decide who can revoke provider access immediately if the relationship changes or an incident occurs. Make sure that emergency action does not depend entirely on the same remote support console you are trying to contain.

If the tool is replaced, define the overlap period and removal evidence. Two remote support agents may be necessary during migration. Leaving both installed forever is not a migration plan.

Make the renewal decision from evidence

Keep the service when technician access is current, endpoint scope is reconciled, privileges match the work, session evidence is usable, provider responsibilities are clear, and pricing fits the access you intend to retain.

Correct or restrict the service when roles, approvals, endpoint groups, authentication, logging, or contract language do not match the risk.

Remove accounts and agents when the person, device, provider, or use case no longer exists.

Compare alternatives when the current platform cannot support the required identity controls, privilege boundaries, audit evidence, deployment model, provider separation, or exit process at a reasonable operating cost.

Investigate anything with no owner, unclear purpose, unknown endpoint, unreviewed privilege, or missing session evidence. Do not turn an unknown access path into another paid year because procurement needs a signature.

If your remote support, RMM, MSP, or service desk agreement is approaching renewal, request a Contract and Spend Risk Review. Bring the agreement, renewal proposal, invoices, technician and role exports, endpoint-agent inventory, sign-in and session logs, identity records, asset records, and provider access terms. Catch Advisors will help you decide what to keep, correct, restrict, remove, consolidate, replace, or investigate before you sign.

Sources