# Target the correct AVD user when starting Remote Help

> How should a helper reach one Azure Virtual Desktop user instead of broadcasting a request to a shared host?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-201-target-the-correct-avd-user-when-starting-remote-help/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:35+00:00
- Modified: 2026-09-10T01:20:45+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

How should a helper reach one Azure Virtual Desktop user instead of broadcasting a request to a shared host?

## Potentially affected

Use this procedure when the person needing help is inside an AVD desktop or RemoteApp session. Confirm which session and published resource the user is actually using before choosing how to start assistance.

## DSE recommendation

Make user-session identification part of the support handoff.

## Article

## Source facts

In Azure Virtual Desktop desktop sessions, an Intune-initiated Remote Help request is broadcast to all active users on the host. RemoteApp sessions cannot be directly targeted from the Intune admin center. Microsoft recommends the security-code method for both cases to reach the correct user session. Within a RemoteApp session, help is limited to the published app rather than the full desktop. The restart option is unavailable when remotely helping AVD. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/remote-help/start-session).

## Applicability

Use this procedure when the person needing help is inside an AVD desktop or RemoteApp session. Confirm which session and published resource the user is actually using before choosing how to start assistance.

## DSE recommendation

Make user-session identification part of the support handoff. Exchange the code through the approved contact channel and ask the user to open Remote Help inside the affected session. Do not treat the shared host’s device record as sufficient identification of the person needing support. Keep the expected view limited to the desktop or app appropriate to that session.

## Verification

During a controlled support test, confirm that the intended user enters the code and that the helper sees the expected session. For RemoteApp, verify the published application’s scope rather than expecting unrelated desktop access. Document the session identity without capturing unnecessary application content. If the wrong user or resource appears, end the connection and correct the targeting before continuing assistance.

## Official references

[Microsoft Learn: Using Remote Help on Windows to Assist Authenticated Users](https://learn.microsoft.com/en-us/intune/remote-help/start-session).

## Primary reference

- Name: Using Remote Help on Windows to Assist Authenticated Users - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/remote-help/start-session
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Target the correct AVD user when starting Remote Help,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-201-target-the-correct-avd-user-when-starting-remote-help/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
