The Console operates on the computer or address explicitly entered or selected by an authorized user.
Controls that remain visible to users, administrators and security teams
LanRemoteAssist is designed to support authorized computers without evading Windows protections or obscuring its processes, service, files or network activity.
Authentication, firewall, application control, RDP, VNC and domain policies are respected rather than silently changed.
Windows connection passwords are kept only for the active attempt and are never saved to settings or logs.
Attended approval and active-session indicators keep the supported user informed when local policy requires them.
Attended and organization-managed access are separate choices
Attended sessions require local approval. Organization-managed access requires explicit administrator-selected enrollment for the confirmed target.
Local approval for every session
Best for employee assistance and situations where the person at the target should review each request.
Policy-based access for enrolled targets
Best for approved servers, kiosks or managed workstations where a documented support role is authorized.
Review before transfer
The Console confirms the exact resolved target, package identity, version, filename, size, SHA-256 and selected access mode before an authorized installation.
Metadata-only audit records
Record what action was attempted, against which exact target, when it occurred and whether it succeeded. Passwords, screen content, clipboard content and typed input do not belong in the audit trail.
Preparing for SOC or EDR review?
Request the current hashes, dependencies, expected behavior, ports, network flows and audit-event definitions.