Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

Windows Vista: Support Users to Use Remote Assistance

Understand Windows Vista: Support Users to Use Remote Assistance with clear background, essential details, and practical takeaways.

Table of Contents

This updated guide examines Windows Vista: Support Users to Use Remote Assistance and organizes the essential facts, background, and practical takeaways in clear American English.

Remote Assistance and Remote Desktop

Remote Assistance and Remote Desktop are different features available in Windows Vista. Remote Desktop relies primarily on Microsoft terminal services and is a tool for remote login to remote computers. When you use Remote Desktop to connect to a remote computer, a new user session will be established. Remote Desktop can also establish sessions with a computer without an interactive session running (no users log on locally) like servers without a machine. Remote Assistance is a tool that helps troubleshoot problems for users on their computers. To use Remote Assistance, both users and helpers must be present on their computers. Unlike Remote Desktop, Remote Assistance does not create a new session, but instead allows the Helper to work in the user's existing session. The user's desktop is remote controlled by a helper, the helper can view the user's desktop with the user's consent, sharing control on the desktop. This is a completely different way to summarize the differences between these two features: In Remote Assistance, both the relevant user is searching at the same desktop using the same login information and can share permissions. control on that desktop;As for Remote Desktop, when the remote operator logs in, the logged-in user must log out.

RA improvements in Windows Vista Windows Vista includes some new and advanced features of RA than in Windows XP:

  • Improve connectivity by using Teredo and IPv6.
  • Improved user interface, allowing easy launch and use.
  • Independent executable file (msra.exe) applies command line arguments and can easily be scripted.
  • Improve performance with faster startup and connection times, optimized bandwidth performance for screen upgrades.
  • Improve security with passwords and mandatory integration with UAC (User Account Control).
  • Offer RA new via IM (Instant Message) and an open API for integrating peer applications.
  • Traditional Group Policy settings are improved to be easily managed.

Remote Assistance in Vista does not have the following features already in XP:

  • Not much support for MAILTO method of Remote Assistance
  • Not much support for voice sessions.

How Remote Assistance works In Remote Assistance, the person who needs help is defined as a user ( User (or Novice )) and the support person provides support to the user ( Helper (or Expert )). RA is launched from the Start menu by selecting All Programs, clicking Maintenance, and then selecting Windows Remote Assistance. You can also launch it from the command prompt by typing msra.exe . Remote Assistance has two basic operating modes: 1. Solicited RA . In Solicited RA (also known as Escalated RA) the user requests assistance from the Helper by initiating an RA session by email, IM or by providing the Helper with a copy of a saved file. (*. MsRcIncident). These methods use a different mechanism:

- Solicited RA Using E-mail (Solicited RA using Email) This method requires that the email client is being used by a simple mail client application interface - User support Simple Mail Application Programming Interface (SMAPI). One of the examples of email clients that supports SMAPI is Windows Mail included in Windows Vista. Other examples are Microsoft Outlook and third-party clients. In this method, the user launches the RA user interface to create an email message with an RA file (*. MsRcIncident) attached to the message. The user must enter a password for the RA session, which must be communicated to the Helper with another method (OOB) such as dialing a telephone number to the Helper. When the Helper receives the user's RA invitation, they will open the attached card, enter the password that the user has given, and the RA session starts. The Helper must respond to an invitation from a user within a certain time limit (default is 6 seconds) or the invitation will expire and a new invitation will be needed. In a domain environment, this card's lifetime can also be configured with Group Policy, and we will show you how to manage Remote Assistance using Group Policy in the following articles. - Solicited RA Using File Transfer (Solicited RA uses File Transfer ) This method requires both users and helpers to access a shared directory (such as a shared network on a file server) or they use a number of other methods to transfer file information (for example, by using a USB key to transfer files or upload files to an FTP site). Users create an RA invitation file and save it in a shared folder. The user must provide a password, which is used to communicate with the helper using the same calling method. The Helper gets the card and must respond to the invitation within a specific time or the invitation will expire and must wait for the following invitation. (Time limit is configured in Group Policy). - Solicited RA Using Instant Messaging (Solicited RA with IM) This method requires IM applications that are being used by both users and helpers that support Microsoft's new Rendezvous API. Windows Live Messenger is an example of an IM application that supports Rendezvous (exchange). Windows Live Messenger is available online for download. In this method, the user requests assistance from someone on his buddy list. To make sure that the remote driver is actually a close friend of this user (not someone pretending to be a friend to trick you), Remote Assistance requires a password that is relayed from the user to the helper by Different ways (such as calling) before helpers can connect. To learn more about the Rendezvous API, you can see the Windows SDK on MSDN at http://windowssdk.msdn.microsoft.com/en-us/library/default.aspx. 2. Unsolicited RA . In Unsolicited RA (also known as Offer RA), helpers help users by initiating an RA session. - Offer RA using DCOM (Create RA using DCOM) This is a typical Help Desk scenario in which all users are in a domain. Helper enters the full name of the user (FQDN) or the computer's IP address to connect to the user's computer. This method requires the Helper to be authenticated with domain administrator rights to be able to provide RA to the user. This method also requires the Helper to know the name (server name on the local subnet; full name) or address (IPv4 or IPv6) of the user's computer. - Offer RA using Instant Messaging This method requires instant messaging (IM) applications used by both users and assistants that support Rendezvous API. In this method, the helper supports someone on his buddy list. If this person agrees, he must enter a password for the helper to use. The password must be transferred by another method to ensure that the remote person is actually a close friend of the user (to avoid being a fake person). For more details about the Rendezvous API, you can see the URL at http://windowssdk.msdn.microsoft.com/en-us/library/default.aspx.

How RA invitation files work

RA invitation files (. MsRcIncident) are XML-formatted files that contain information used by the Helper's computer, the computer will make a connection. This card information is encrypted to prevent unauthorized users from accessing, using email or transferring files used to send invitations on unsecured networks. If the email method is used to send the invitation file to the helper, the invitation file is sent as an email attachment with a file name of RATicket. MsRcIncident. If the file transfer method is used, the invitation file will be created by default on the desktop of the user's computer and the file name of this invitation file is Invitation. MsRcIncident.

Operation status of RA Remote Assistance has the following three operating states: - Waiting For Connect (Waiting for connection) This status appears when:

  • The Helper has provided RA to the user but the user has not yet agreed to allow the Helper to connect to his computer.
  • The user has sent an invite to the Helper but the Helper has not responded by opening it or opening the invitation file and the user has not yet agreed to allow the Helper to connect to his computer.

In the state of waiting for the connection, the Helper cannot view or control the user's computer screen until an RA connection is established and both computers have entered the shared screen state. When the RA application is started and running in connection waiting state, the application will not be closed until another group responds and establishes a connection. For example, if the user uses the Solicit RA Using E-mail method and sends an invitation file to the Helper, the RA application opens on the user's computer and waits until the Helper accepts the invitation. If the user closes the RA on his computer before the Helper accepts the invitation, the Helper will not be able to connect to the user and the user needs to send a new invitation. - Screen Sharing This status appears when the user has agreed to allow the helper to connect to his computer - after the user has sent to the helper an invitation or support file. Help has provided RA to users. In the shared screen state, the RA session is set and the Helper can view but cannot control the screen of the user's computer. When the user is prompted to allow the Helper to connect to his computer, a message will appear on the user's computer, indicating that the Helper wants to connect to the computer. he. This message can be customized using Group Policy. - Control Sharing This status appears after the sharing screen state, when the Helper has requested control of the user's computer and the user has agreed to allow the Helper to control computer. In this mode, the Helper has the same access level for the computer the user has and the Helper can use his own mouse and keyboard to perform actions on the user's computer. Special:

  • If the user is a standard user on the computer, the Helper can only perform actions on the user's computer as a standard user.
  • If the user is a local administrator on the computer, the Helper can perform actions on the user's computer as an administrator.

For more detailed information about the level of control a Helper has on a user's computer, you can follow in the following articles. Functions of users and helpers Once the RA connection has been established and both computers have entered the shared screen state, users and helpers can perform the tasks listed in the table below:

Describe theHelperUsertasks

Chat

Yes Yes

Send file

Yes Yes

Save the session action record

Yes (default) Yes (default)

Configure bandwidth usage

Yes No

Stop (temporarily hidden screen)

Yes No

Request shared control

No Yes

Give up control of sharing

Yes Yes

Cancel the connection

Yes Yes

Disconnect with Esc key

Yes No Table 1: Tasks can be performed by the user and the assistant during an RA session

Remote Assistance and NAT Traversal Remote Assistance works by setting up peer connections between the user's computer and the helper's computer. One difficulty in this connection is that it is very difficult to establish peer connectivity if one or both of these computers are behind the gateway or router that uses Network Address Translation (NAT). NAT is a routing technology described by RFC 1631, used to translate IP addresses and TCP / UDP port numbers in forwarded packets. NAT is typically used to map a set of private IP addresses to a public IP address (or to multiple public addresses). Home networks that are using wired or wireless routers also use this NAT technology. To overcome this difficulty, Vista was built with Teredo support, an IPv6 transition technique described in RFC 4380, which provides address assignment and automatic tunneling. for unicast IPv6 connection via IPv4 Internet. The NAT traversal capability provided by Teredo in Vista allows RA connectivity when one or both users in an RA session are hidden behind NAT. The perception of RA is transparent based on the user's perspective, regardless of which NAT is being used on the user's network. For most small businesses and home user environments, Vista's RA will seamlessly follow NAT-enabled routers without additional router configuration. Note: Providing RA by using DCOM is not always a Teredo script because business users are always behind the company's firewall and cannot be distinguished by NATs. RA will not connect in certain configurations. Special:

  • Teredo cannot follow a symmetric NAT. RA can only connect through restricted NATs and cone NATs. In some cases, this is not an important limitation because most of the deployed NATs are restricted or conical.
  • RA will not work if the NAT-enabled router is configured to block certain ports used by RA.
  • RA will not work if the user's NAT-enabled router is configured to block all UDP traffic.

Note : To determine the type of NAT that a network is using, open a command prompt and type netsh interface teredo show state. Remote Assistance and IP ports are used The ports used by the RA session depend on the session between Vista computers or between a Vista computer and an XP computer. Specifically:

  • Vista with Vista : Dynamic ports are located by the system in the TCP / UDP range 49152–65535
  • Vista with XP : 3389 TCP Port (local / remote)

In addition, the Offer RA script via DCOM uses port 135 (TCP). Remote Assistance and Windows Firewall Windows Firewall is configured with a group exception for RA. The exception of this group has many attributes that are included as part of the RA exception. RA exception attributes will vary depending on the computer's network location (private, public, or domain). For example, the default RA exception when the computer is in public places will be more accurate when the computer is in its own location. In public points (such as airports), the RA exception is disabled by default, does not open Universal Plug-and-Play ports (UpnP) and the Simple Service Discovery Protocol (SSDP) traffic. In a private network (home network, for example) the RA exception will be enabled by default and the uPnP and SSDP traffic will be allowed. Table 2 summarizes the status of the RA firewall's access exceptions for each network location. However, the RA exception also has outbound properties, Windows Firewall is not configured by default to enable properties.

Network location

Status of RA exception

Default properties of the RA exception

Private network (family or workplace)

Activated by default

  • Exception Msra.exe application
  • uPnP is enabled for communication with uPnP NATs
  • Edge traversal is activated to support Teredo

Public

Disabled by default - must be enabled by administrator privileges

  • Exception Msra.exe application
  • Edge traversal is activated to support Teredo

Domain

Disabled by default - enabled by Group Policy

  • Exception Msra.exe application
  • Exception RAServer.exe application (RA COM server)
  • DCOM port 135
  • uPnP is enabled for communication with uPnP NATs

Table 2: Default state of the Remote Assistance Firewall input exception for each network location type

In the Windows Firewall profile, the default configuration of the RA exception is as follows: - Private profile Exception RA in Windows Firewall is enabled by default when the computer location is set to 'private.' It is configured with NAT traversal by using Teredo by default so that users in a private network environment (for example, a home environment) can get help from other users who may be on the same side. after NAT. Private files include appropriate exceptions needed for communication with uPnP NAT devices. If there is a uPnP NAT in this environment, the RA will use uPnP for NAT traversal. Offer RA via DCOM is not configured in this profile. - Public profile Exception RA is disabled by default and does not allow RA traffic. Windows Firewall is configured in this way by default to better protect users in public network environments (such as cafes or airports). When the RA exception is enabled, NAT traversal using Teredo is enabled. However, traffic to uPnP devices is not enabled and Offer RA via DCOM is not enabled. - Domain Profile . The RA exception when the computer is in a domain environment is relayed to the Offer RA script. This exception is disabled by default and enabled via Group Policy. Teredo is not enabled in this profile because the corporate network usually has a firewall to block Teredo UDP traffic. However, uPnP is enabled so that the NAT uPnP can communicate. Remote Assistance and Secure Desktop When the user agrees that the Helper can share control on his computer during an RA session, the user has the option to allow the Helper to respond to UAC prompts (Figure 1).. Typically, User Account Control (UAC) prompts appear on the Secure Desktop (the remote control component) and so the Helper cannot see or respond to Secure Desktop prompts. Secure Desktop mode is similar to the mode that users see when they log on to the computer or press the key combination (Ctrl + Alt + Delete). UAC prompts are displayed on the Secure Desktop instead of the user's normal desktop to protect them from malware threats. Users must follow UAC prompts to return to their regular desktop and continue working. This consent requires either clicking Continue (if the user is a local administrator on the computer) or by entering local administrative information (if he is a standard user).

Windows Vista: Support Users to Use Remote Assistance — contextual image 2 Figure 1: Users have the option to allow helpers to respond to reminders UAC when the RA session is in the control sharing state.

It is also important to understand the Secure Desktop on a user's computer that is not remotely controlled. In other words, the helper can only respond to UAC reminders on the user's computer using the user's credentials. That means, if the user is a standard user on the computer while the helper is a local administrator on the user's computer, the helper can only have administrative rights on the user's computer. If the user gives him the necessary information. The introduction of this limitation is necessary to ensure the security of Vista computers. The reason behind the decision to design this is that if the RA is designed to allow remote control helpers with user rights, the user may stop the RA session and so can take management information. local treatment from the helper. Logging of RA Remote Assistance can record sessions of RA-related actions. This session logging is enabled by default and includes time-stamped records to identify RA-related actions on each computer. Session logs include information about RA-related actions, such as who initiated the session,. These session logs do not have information about the current task that the user and the helper have actually done. show up during a session. For example, if the Helper receives sharing control, start an administrative command prompt and perform steps to reconfigure TCP / IP on the user's computer during an RA session, the logs session s? không có b?n ghi c?a hành ??ng này. Các b?n ghi session g?m có c? các hành ??ng chat ???c trao ??i trong su?t m?t session RA. B?n ghi ?ã t?o ra trong su?t m?t session c?ng ???c hi?n th? bên trong c?a s? chat ?? c? ng??i dùng và ng??i tr? giúp có th? nhìn th?y nh?ng gì ?ã ???c ghi trong su?t session. Các b?n ghi này c?ng g?m có hành ??ng trao ??i file x?y ra trong su?t session, và c?ng ghi l?i khi session b? d?ng. M?c ?ích c?a vi?c ghi session RA Các b?n ghi session cho RA ???c d? ??nh chính cho ho?t ??ng kinh doanh yêu c?u duy trì các b?n ghi h? th?ng và hành ??ng ng??i dùng cho m?c ?ích ghi chép. Chúng không ???c d? ??nh ?? ghi các hành ??ng ???c th?c hi?n b?i cá nhân tr? giúp khi các v?n ?? kh?c ph?c s? c? v?i máy tính c?a ng??i dùng. M?t môi tr??ng ?i?n hình trong vi?c ghi chép session là ? các ngân hàng, t?i ?ây các tình hu?ng tài chính b? yêu c?u b?ng lu?t là ph?i gi? các b?n ghi c?a nh?ng ng??i ?ã truy c?p vào máy tính và th?i ?i?m nào. Vì ACL tên các b?n ghi session này cho phép toàn quy?n ?i?u khi?n c?a ng??i dùng trên các b?n ghi ?ã ???c l?u trên máy tính c?a chính h?, m?c ??nh các b?n ghi session ???c t?o ra trên c? máy tính c?a ng??i dùng và ng??i tr? giúp ?? ng??i tr? giúp có th? b?o v? và th?c hi?n chúng khi b? xáo tr?n. Trong môi tr??ng doanh nghi?p, Group Policy có th? ???c s? d?ng ?? kích ho?t ho?c vô hi?u hóa vi?c ghi session. N?u vi?c ghi chép này không ???c c?u hình b?ng Group Policy, thì c? ng??i dùng và ng??i tr? giúp hoàn toàn vô hi?u hóa vi?c ghi chép session trên máy tính c?a chính h?. ???ng d?n b?n ghi session và vi?c ??t tên thông th??ng B?n ghi session là các tài li?u XML ?? chúng có th? d? dàng tích h?p vào các ki?u d? li?u khác – ví d?, b?ng cách import chúng thành m?t c? s? d? li?u ???c qu?n lý b?i Microsoft SQL Server 2005. T?t c? các b?n ghi session ??u ???c l?u trong th? m?c Documents c?a ng??i dùng bên trong ???ng d?n sau:

Users user_name DocumentsRemote Assistance Logs

File b?n ghi session duy nh?t này ???c t?o cho m?i session RA trên máy tính. Các file b?n ghi ?ã l?u bên trong th? m?c này ???c ??nh d?ng XML và ???c ??t tên v?i ?uôi thông th??ng YYYYMMDDHHMMSS.xml. N?i dung bên trong c?a m?t file b?n ghi session ?i?n hình ???c cho d??i ?ây:

fe80::2856:e5b0:fc18:143b%10 jdow jdow: test jchen: ok

Windows Vista: Support Users to Use Remote Assistance — contextual image 3 Windows Vista: Supporting users using Remote Assistance (Part 2) Windows Vista: Support Users to Use Remote Assistance — contextual image 4 Windows Vista: Supporting users using Remote Assistance (Part 3)

FAQ

What is Windows Vista: Support Users to Use Remote Assistance about?

It provides a structured overview of user, explains the main context, and highlights practical takeaways for readers.

Why does this topic matter?

Understanding the main concepts helps readers evaluate the issue, avoid common mistakes, and make better-informed decisions.

How should readers use this information?

Use the guidance as a practical starting point, confirm details that may have changed, and follow current product, safety, or security recommendations.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.