Pro feature · unattended access

Unattended access — maintain devices with no one in front

With unattended access you connect to servers, kiosk systems and customer PCs without anyone having to confirm the connection. Secured by hardware-bound device tokens, mandatory two-factor authentication and a complete audit trail — peer-to-peer, hosting in Switzerland.

What is unattended access?

Unattended access refers to remote access to a device that no one is sitting in front of to confirm the connection. The host is installed as a service and accepts connections as soon as an authorized, authenticated technician signs in — around the clock. The trust relationship is established once during setup and secured by a hardware-bound device token.

The counterpart is attended access: there, a person present actively confirms every incoming connection. Both models have their place — unattended for plannable maintenance and device pools, attended for spontaneous help. More on the bigger picture on the remote maintenance page.

What you need unattended access for

  • Server maintenance — headless systems in the server room or data center that have no keyboard and no one sitting at the screen. See system administrators use case.
  • Device pools & fleets — IT service providers that patch dozens of customer PCs and roll out software at night. See IT service providers use case.
  • Kiosk & digital signage — display systems, info terminals and Raspberry Pi setups that are maintained remotely.
  • Maintenance outside office hours — apply updates when no one is working, instead of disrupting operations.
  • The family PC without asking — grant the parents' device permission once and help in future without anyone having to read out a code.

Security: unattended does not mean unprotected

A device with no one present is an attractive target — that is why unattended access at WinDesk is secured on several levels:

Hardware-bound device tokens

Every host receives a token encrypted with TPM 2.0 (Windows/Linux) or Secure Enclave (Apple Silicon). Copying the token file to another machine invalidates it — token replay is ruled out.

Mandatory two-factor

Compulsory for admin roles: TOTP or passkey (WebAuthn/FIDO2). New users must set up MFA at first login; sensitive actions require a fresh confirmation.

Visible session indicator

A permanently displayed banner on the host shows that a connection is active — not hideable by the technician. Permissions such as file transfer and clipboard are off by default.

Audit trail & kill switch

Every connection is logged immutably (who, when, how long, which host), exportable as CSV. An admin can immediately disconnect any session via remote kill switch and revoke devices.

In addition, device tokens rotate automatically every 90 days. The full overview on the security page.

How to set up unattended access

  • 1. Install the host as a service. Install the WinDesk host on the target device — it runs in the background, even when no one is logged in.
  • 2. Authorize the device. During setup the hardware-bound device token is generated and assigned to the account.
  • 3. Manage in the portal. All hosts appear centrally with online status and last connection, sortable into groups and assigned roles.
  • 4. Connect. As an authenticated technician you connect at any time — without anyone having to confirm on site.

An overview of all features on the Features page.

A Pro feature — clearly priced

Unattended access is part of WinDesk Pro (CHF 29.90/month). Included are 100 hosts, central host management, groups and roles, audit logs and passkey authentication. Every additional 100 hosts cost CHF 10/month — linear, without bundle tiers. Only the helping side needs a licence; the hosts draw from the host quota. Free and Light offer attended access. All prices compared.

Frequently asked questions — unattended access

What is unattended access?

Unattended access means connecting to a device that no one is sitting in front of to confirm the connection — such as a server, a kiosk system or a customer's PC outside office hours. The trust relationship is established once during setup (a hardware-bound device token, authorized by the owner); after that, your authenticated sign-in is enough to connect.

How does it differ from attended access?

With attended access, a person is present at the target device and actively confirms every incoming connection — typical for spontaneous support. With unattended access, the device accepts connections without this manual confirmation, provided the technician is authenticated — typical for server maintenance and device pools that need to be reachable around the clock.

Is unattended access secure?

Yes — unattended does not mean unprotected. Every host carries a hardware-bound device token (TPM 2.0 on Windows/Linux, Secure Enclave on Apple Silicon); copying the token file to another machine invalidates it. Two-factor authentication is mandatory for admin roles (TOTP or passkey), every session is logged, and permissions such as file transfer are off by default. Details on the security page.

Does the device owner have to approve every connection?

Consent is given once during setup: the owner installs the host as a service and authorizes the device. After that, no renewed confirmation per session is needed — that is exactly the point of unattended access. A permanently visible session indicator still shows when a connection is active, and access can be revoked at any time in the portal.

Is unattended access included in the free plan?

No. Unattended access is a Pro feature (CHF 29.90/month) and includes 100 hosts as well as central host management. The Free and Light plans offer attended access. A comparison of all plans is on the pricing page.

How many devices can I manage unattended?

Pro includes 100 hosts. Every additional 100 hosts cost CHF 10/month extra — linearly scalable, without bundle tiers. The hosts can be sorted into groups (customers, locations, servers) in the portal and assigned roles (admin, supporter, read-only).

What happens when an employee leaves the company?

An admin can revoke users and their device tokens at any time in the portal — access ends within minutes. In addition, there is a remote kill switch that immediately disconnects a connected session and removes the host from the account. Device tokens also rotate automatically every 90 days.

Set up unattended access

Try Pro free for 30 days — without a credit card. Servers, kiosk systems and customer PCs reachable around the clock.