How-to guides
Step-by-step guides for setting up and running MyRemoting — from your first machine to fleet-wide automation.
Getting started
Stand up your control server and run the readiness check
MyRemoting runs from a single control server you own — put it on a physical box, a VM, or any cloud, on Windows (IIS) or Linux. A built-in readiness check confirms it's reachable before you add machines.
- Choose where to run it: Windows with IIS, or a Linux host. You own the license and can move the server later, so start wherever is convenient.
- Install the control server for your platform and point it at the domain name operators will use to sign in.
- Make sure the required ports are open and a valid HTTPS certificate is in place (on Linux the server can auto-issue one via Let's Encrypt for your domain).
- Open the readiness check and let it confirm your domain, ports, and certificate. Resolve anything it flags.
- Once the readiness check passes, browse to your server's address to reach the sign-in page and continue setup.
Create your first operator account and turn on two-factor
Your first sign-in creates the operator (admin) account that runs the console. Two-factor authentication is required, so keep an authenticator app handy.
- Browse to your control server's address and open the initial setup/bootstrap page.
- Create your operator login with an email address and password. This first account is your administrator.
- Set up mandatory TOTP two-factor: scan the QR code with an authenticator app and enter the 6-digit code to confirm.
- Configure email recovery so you can regain access if you lose your authenticator, and save any recovery codes shown.
- Optional: add a passkey (Face ID, Touch ID, or Windows Hello via WebAuthn) for faster future sign-ins.
- Sign in with your new credentials plus the 2FA code to reach the server dashboard.
Add your first machine with an installer or install link
You add machines straight from the dashboard, which hands you a pre-configured installer or a shareable install link that drops the machine into a group. Agents are available for Windows, macOS, and Linux.
- On the server dashboard, choose to add a machine.
- Pick the target group so the new machine (and the access it inherits) lands where you want it — new machines inherit the group's access.
- Select the platform: Windows, macOS, or Linux.
- Either download the pre-configured installer and run it on the target machine, or copy the shareable install link and send it to whoever is at that machine.
- Run the installer/link on the machine; the lightweight agent installs and enrolls itself into the group you chose.
- Return to the dashboard and confirm the machine appears online with its last-seen time updating.
Make your first connection from a browser or iPad
Everything works from any modern browser and from an installable iPad/desktop app — no operator-side client to install. Controlling a machine also requires that machine's own login or access code on top of your console sign-in.
- Sign in to the console in your browser (or the iPad app) with your operator credentials and 2FA code.
- On the dashboard, find your online machine using search, sort, or its group.
- Open the machine and start a remote session; the screen opens in the browser with full keyboard, mouse, scroll, and live cursor.
- When prompted by the per-machine credential gate, enter that machine's local login or its access code to unlock control.
- Use the on-screen controls to pick or cycle monitors, and switch between fit-to-window and 1:1 as needed.
- On iPad, pinch to zoom and use 'Add to Home Screen' to install MyRemoting as an app for quick access.
Note: remote screen control and on-demand screenshots are available on Windows and macOS. Linux machines are managed through terminal, files, processes, and power actions rather than screen sharing.
Remote control & screen
Start a remote-control session
Take full keyboard, mouse, and screen control of any online machine from your browser. Remote control needs the machine's own local login or access code on top of your console sign-in.
- Sign in to your control server from any modern browser and open the dashboard.
- Find the machine on the live dashboard (search, sort, or filter by group) and confirm it shows online.
- Open the machine's page and click Connect (or Control) to launch the browser session.
- When the per-machine credential gate prompts, enter that machine's local login or its access code to unlock control.
- You now have full screen plus real keyboard, mouse, scroll, and live-cursor control; use the session toolbar for monitors, quality, special keys, and privacy toggles.
- Close the browser tab or click Disconnect to end the session.
Note: remote screen control and on-demand screenshots are available on Windows and macOS. Linux machines are managed through terminal, files, processes, and power actions rather than screen sharing.
Work with multiple monitors
When a remote machine has more than one display, MyRemoting lets you choose exactly what you see and how it fits your screen. All controls live in the session toolbar.
- Start a remote-control session on the machine (see "Start a remote-control session").
- In the session toolbar, open the monitor control to see every display the machine reports.
- Pick a single monitor to focus on it, or use cycle to step through displays one at a time.
- Choose side-by-side to view all monitors together in one view.
- Use pop-out to open a monitor in its own browser window and spread displays across your local screens.
- Toggle Fit-to-window to scale the remote display to your browser, or switch to 1:1 for true native resolution (with lossless refine when you zoom in).
Tune quality on a slow link
MyRemoting streams at native resolution and adapts automatically, but on a constrained or high-latency connection you can trade sharpness for responsiveness. Adjust these from the session toolbar mid-session.
- Start the remote-control session and open the session toolbar.
- If the view feels laggy, lower the quality so the stream stays responsive over limited bandwidth.
- Switch to Fit-to-window so the whole desktop scales to your browser instead of sending full native pixels.
- Zoom in on the area you actually need; MyRemoting sends a lossless refresh for the zoomed region while keeping motion smooth.
- When you need pixel-accurate detail on a fast link, switch back toward higher quality or 1:1.
Send special keys (Ctrl-Alt-Del, BIOS, KVM)
MyRemoting sends real hardware scancodes, so system-level key combinations reach the machine even at the BIOS, a KVM, or a login screen where an ordinary web app can't. Use the special-keys control in the session toolbar.
- Start the remote-control session on the target machine.
- Open the special keys (or send-keys) menu in the session toolbar.
- Choose Ctrl-Alt-Del to reach the Windows secure attention sequence or sign-in screen.
- Select other special keys from the menu as needed; because MyRemoting injects genuine scancodes, BIOS/UEFI, KVM switches, and games respond just like a physically attached keyboard.
- Type normally for everything else; the session passes keyboard, mouse, scroll, and live-cursor input straight through.
Use MyRemoting from an iPad
MyRemoting runs in the browser with full touch support and installs as an app, so an iPad works as a portable control console. No separate download from an app store is required.
- Open Safari on the iPad and sign in to your control server.
- To install it as an app, tap the Share button and choose Add to Home Screen, then launch MyRemoting from the new home-screen icon.
- Open a machine and tap Connect, then clear the per-machine credential gate as usual.
- Use pinch to zoom in and out of the remote screen and drag to pan around a large or multi-monitor desktop.
- Use the session toolbar for monitors, quality, and special keys exactly as you would on a desktop browser.
Blank the screen and lock input during a session
For private work on a remote machine, you can hide the desktop from anyone standing at it and block its local keyboard and mouse. These privacy toggles auto-revert when the session ends so no one is left locked out.
- Start the remote-control session on the machine.
- In the session toolbar, turn on blank screen to black out the remote display so onlookers at the machine can't see what you're doing.
- Turn on lock input to disable the machine's physical keyboard and mouse while you work.
- Optionally enable lock-on-disconnect so the workstation locks the moment your session ends.
- Finish your work; the blank-screen and input-lock toggles automatically revert when you disconnect. (The person at the machine can also confirm the agent, pause control, or set a time limit from the tray/menu-bar icon.)
Stream remote audio and chat with the person there
During a remote session you can hear what the remote machine is playing and exchange typed messages with whoever is sitting at it. The audio is one-way (you hear the machine; it is not a two-way voice call), and chat is text only, which is handy when you're guiding a user through something.
- From the machine's page or the dashboard, start a remote control session to the Windows or macOS machine.
- In the session toolbar, turn on remote audio to stream the remote machine's sound to you. You'll hear the machine's audio; this is one-way and does not send your microphone or open a voice call.
- Adjust your own local volume as needed while you listen. Use the audio to confirm things like alert sounds, media playback, or that an app is actually producing sound.
- Open the chat panel in the session to send typed messages to the person at the machine, and read their replies. This lets you coordinate without a separate phone call.
- Use chat to ask the person to confirm what they see, approve an action, or step aside while you work.
- When you're done, close chat and turn off remote audio, then end the session as usual. Note that Linux machines provide terminal, files, processes, and power only, so audio and screen-based features aren't available there.
Files, terminal & processes
Transfer files with the file manager (upload, download, drag to desktop)
MyRemoting's file manager gives you a machine's whole filesystem from any browser, so you can move files in and out without a separate tool.
- Open the machine's page from your server dashboard and open the File Manager tool.
- Browse to the folder you want using the path bar or folder tree.
- To pull a file to your computer, select it and click Download (or drag it from the file manager onto your desktop).
- To push a file to the machine, click Upload and pick a file, or drag a file from your desktop into the file manager window.
- Refresh the folder to confirm the file landed where you expect.
Copy files directly between two machines
MyRemoting can move a file straight from one managed machine to another without routing it through your computer — the transfer is sent server-to-server.
- Open the source machine's page and open its File Manager.
- Browse to and select the file or folder you want to copy.
- Choose the machine-to-machine copy action and pick the destination machine from your fleet.
- Choose the destination folder on that machine.
- Confirm — the file is sent server-to-server and appears on the destination machine.
Open the remote console (terminal)
The remote console is a real terminal (ConPTY on Windows, rendered with xterm.js in your browser) that runs as the user currently logged in on the machine.
- Open the machine's page from your server dashboard and open the Console tool.
- Wait for the shell to connect — it runs in the session of the logged-in user.
- Type commands as you would locally; output streams live in the terminal.
- Note that Console access requires the Console permission plus the machine's own credential gate (its local login or access code) on top of your console sign-in.
Manage processes and Scheduled Tasks
The process and task manager shows what's running on a machine and lets you work with Windows Scheduled Tasks, right from the browser.
- Open the machine's page and open the Process / Task Manager tool.
- Review the running processes; search or sort to find the one you want.
- Select a process and click Kill / End task to stop it.
- Switch to the Scheduled Tasks view to list existing tasks.
- From there you can view a task, run it on demand, or create a new Scheduled Task.
Copy and paste text, images, and real files via the clipboard
During a remote-control session the clipboard syncs both ways, so you can move text, images, and real files (including Windows Explorer file copy/paste) between your computer and the machine.
- Start a remote-control session for the machine in your browser.
- Copy text or an image on one side, then paste it on the other — the clipboard syncs in both directions.
- To move real files, copy them in Explorer on one machine, then paste in Explorer on the other.
- If your browser restricts clipboard access, MyRemoting routes the session through its secure loopback proxy so copy/paste keeps working.
Edit the Windows registry remotely
On Windows machines you can browse and change the registry from the browser, much like running regedit locally.
- Open the Windows machine's page and open the Registry Editor tool.
- Navigate the hive and key tree to the key you need.
- Select a value to view or edit it, or create a new key or value.
- Save the change — it applies on the remote machine immediately.
Power actions: reboot, shut down, or restart the agent
Power management lets you restart just the agent or reboot and shut down the whole machine from its page.
- Open the machine's page from your server dashboard.
- Open the Power menu.
- Choose Restart agent to restart only the MyRemoting agent, Reboot or Force reboot to restart the operating system, or Shut down to power the machine off.
- Confirm the action; watch the dashboard for the machine to go offline and come back online.
Fleet automation
Run a script across a group of machines
Use the script runner to execute PowerShell, Bash, or batch commands on one machine or a whole group. Saved scripts speed up repeat work, run credentials are never stored, and every run is captured in an audit trail.
- From the server dashboard, open the Fleet automation script runner.
- Pick your target: a single machine or a machine group.
- Choose a saved script or paste a new one (PowerShell, Bash, or batch), and optionally save it for reuse.
- If the script needs specific rights, enter the run credentials for the job. They are used for this run only and are never stored.
- Set the retry window so machines that are offline pick the job up when they next check in.
- Run it, then review the per-machine results and the audit trail.
Patch a fleet on demand or on a schedule
Push OS updates across Windows, macOS, and Linux from one place, either right now or on a recurring schedule, and see the outcome for every machine.
- Open Patch management from the server dashboard.
- Choose the platform and targets: a machine or a group running Windows Update, macOS software updates, or Linux apt/dnf/yum.
- Select on-demand to run now, or set a schedule for recurring patching.
- Start the job. Agents install the updates headlessly in the background.
- Review the per-machine results, including any machine reporting a needs-reboot state.
Deploy software to one machine or a group
Install applications across your fleet using each operating system's package manager or a direct installer URL, targeting a single machine or a whole group.
- Open Software deployment from the server dashboard.
- Select the target machine or group.
- Pick the source: winget, Chocolatey, or an MSI URL on Windows, or Homebrew on macOS.
- Start the deployment. Agents install the package in the background.
- Check the per-machine results to confirm each install succeeded.
Wake a sleeping machine with Wake-on-LAN
Power on an offline machine remotely. MyRemoting sends the magic packet through an online neighbor on the same LAN, using the target's MAC address from inventory.
- Make sure at least one machine on the same LAN as the target is online, since it relays the wake packet.
- Confirm the target has been inventoried so its MAC address is on file.
- On the target machine's page in the dashboard, choose Wake (Wake-on-LAN).
- The online neighbor sends the magic packet, and the machine powers on and checks back in shortly after.
Create a one-click remote-desktop shortcut
Make a desktop shortcut or an installable per-machine app that opens straight into a specific machine's remote session in your browser.
- Open the target machine's page (the connect/shortcuts area) on the server dashboard.
- Choose to create a remote-desktop shortcut.
- Pick the format: a one-click desktop shortcut (.url, .webloc, or .desktop) or an installable per-machine app.
- Save or download it to your device.
- Open it anytime to jump straight into that machine's session. You will still sign in and pass the machine's credential gate.
Deploy the agent to many machines with the MSI and Group Policy
For enrolling many Windows machines at once, MyRemoting provides a signed MSI installer with your server URL and enrollment token baked in, so each machine installs and enrolls into your fleet silently. Push it with Group Policy (or any deployment tool) instead of running the per-machine installer by hand.
- On the Server page, obtain your enrollment token and confirm your server's base URL. These are the values that get baked into the installer so agents know where to enroll.
- Get the signed Windows MSI for the agent and confirm it carries your server URL and enrollment token, so installs enroll silently with no per-machine prompts.
- Place the MSI on a network share that the target machines can reach during installation, and make sure the computer accounts have read access to it.
- In Group Policy Management, create or edit a GPO and add the MSI under Computer Configuration software installation so it installs per machine (Windows installs assigned MSIs silently at boot).
- Scope the GPO to the organizational unit that contains the machines you want enrolled.
- Roll out to a small pilot OU first, let those machines apply the policy and restart, and confirm they appear in your fleet.
- Verify enrollment on the live dashboard: the newly deployed machines should show up with a status and last-seen time.
- Once the pilot looks good, widen the GPO scope to the rest of your machines. Because agents auto-update from your server after they connect, you deploy the agent once and don't have to reinstall it for later updates.
- For a handful of machines, or where Group Policy isn't available, use the shareable install link or the per-machine installer instead.
Monitoring, inventory & alerts
Read the live dashboard and take an on-demand screenshot
The dashboard is your fleet's home base: online status, last seen, last boot, and a quick visual check without starting a full remote session.
- Sign in to your control server from any browser or the iPad app to open the dashboard.
- Scan each machine tile for online/offline status, last seen, and last boot time.
- Use the search box and the sort and group controls to filter by name or organize machines by group.
- On any online machine, take an on-demand screenshot to capture the current desktop without opening a remote-control session.
- Click a machine to open its page for full control, inventory, health, and history.
Note: remote screen control and on-demand screenshots are available on Windows and macOS. Linux machines are managed through terminal, files, processes, and power actions rather than screen sharing.
Collect and browse machine inventory (hardware, software, updates)
MyRemoting builds a full picture of every agent -- hardware, OS, installed software, network, GPU, and security posture -- so you can audit your fleet from the browser.
- Make sure your account has the Inventory permission (an admin grants it through roles).
- Open a machine from the dashboard and go to its Inventory view.
- Review the hardware, operating system, installed-software, network, GPU, and security-posture sections.
- Check the updates section to see which OS patches the machine has installed or is still missing.
- To get a recurring rollup by email, enable the scheduled inventory digest so a summary lands in your inbox on a set cadence.
Choose fleet-wide inventory or the per-machine gate
Full inventory is collected across your whole fleet by default; as an admin you can instead require each machine's credential gate before deep inventory is gathered.
- Sign in as an admin and open your server's admin settings.
- Leave the default in place to collect full inventory fleet-wide with no per-machine gate -- the fastest way to get complete data.
- To tighten collection, turn on RequireInventoryGate so full inventory waits behind each machine's credential gate (its local login or access code).
- With the gate on, supply the per-machine credentials when prompted; your console sign-in alone will not unlock deep collection.
- Save the setting; it takes effect as agents check in.
Create an alert rule and route it to email, Slack, webhook, or PagerDuty
Alert rules watch events and metrics across your fleet and notify you the moment a machine crosses a line.
- With the Alerts permission, open the Alerts page from your server dashboard.
- Create a rule and pick a condition -- offline, high CPU or memory, low disk, pending OS updates, needs-reboot, machine rebooted, protection off, a security change, and more.
- Set the threshold and choose the scope: which machines or groups the rule applies to.
- Add one or more delivery channels: email, Slack, webhook, or PagerDuty.
- Set the Platforms OS hint so a condition is labeled for Windows, macOS, or Linux and only meaningfully fires where it applies (for example, protection-off maps to Windows security posture).
- Save the rule; it evaluates automatically and notifies you when a machine matches.
Watch a single machine for a personal notification
When you care about one specific machine, watch it to get personal push and email alerts without building a fleet-wide rule.
- Open the machine from your dashboard.
- Click Watch this machine on its page.
- Choose what to be notified about for that machine, such as it going offline or rebooting.
- Confirm push and/or email delivery -- notifications go to your account only and do not affect other operators.
- Click Unwatch on the machine's page anytime to stop your personal notifications.
Read the machine-health roll-up and get the email digest
The health roll-up turns live metrics and inventory into a simple OK, warning, or critical status for each of your machines, with an optional emailed summary.
- Open the Health page from your server dashboard.
- Review each machine's roll-up status -- OK, warning, or critical -- based on live CPU, memory, and disk, per-volume storage, offline state, and agent-version drift.
- Sort or filter to surface warning and critical machines first.
- Open any machine to see the underlying metrics and the idle-gated performance baseline behind its status.
- Turn on the Health Summary toggle in the scheduled email digest to have the roll-up delivered to your inbox on a regular cadence.
Track live performance and storage
MyRemoting shows live health for each machine so you can spot a struggling endpoint before anyone reports it. Use these steps to read live CPU, memory, and disk, check per-volume storage and the performance baseline, and catch machines running an outdated agent.
- Open the live dashboard to see your fleet at a glance: each machine's status, when it was last seen, and its last boot time.
- Click a machine to open its page, where its live metrics are shown.
- Read the live CPU, memory, and disk usage for that machine. These update while you watch, so you can confirm whether a spike is momentary or sustained.
- Review per-volume storage to see free and used space on each drive or volume, not just an overall total, so you can tell which disk is filling up.
- Compare current usage against the idle-gated performance baseline. Because the baseline is measured while the machine is idle, it reflects the machine's normal resting state and makes an abnormal load easier to recognize.
- Check the reported agent version against the rest of your fleet to catch agent-version drift. A machine on an older agent than its peers is a candidate to bring back in line (connected agents auto-update from your server).
- For a broader view, open the machine-health roll-up, which combines these signals into an overall status so you can prioritize which machines to look at first.
- To be told about problems automatically instead of watching, set up alerting for conditions such as offline, high CPU or memory, and low disk. Inventory can also be delivered as an email digest.
Collaboration & attended support
Run a two-technician session with handoff and view-only guests
When two people need to work on the same machine at once, MyRemoting drops you both into one shared session with live presence, chat, and shared cursors. Whoever holds input is the driver; you can hand off the driver role or pin guests to view-only.
- From the server dashboard, open the machine's page and start a remote-control session in your browser (clear the machine's credential gate as usual).
- Have your teammate sign in and open the same machine's page and session; MyRemoting joins them into the same room automatically, so you each see the other's presence and cursor.
- Use the in-session chat and follow-the-driver view to stay in sync while one person drives.
- To pass control, hand the driver role to your teammate from the session's participants/presence controls; keyboard and mouse input moves to them.
- For an invited guest who should only observe, pin them to view-only from the participants list; they keep shared cursors and chat but their input is hard-blocked.
Help someone with a code and link (nothing permanent installed)
Code and link support lets you assist a person who has no agent installed. They open a link, enter a one-time code, and run a small helper that leaves nothing permanent behind.
- From the server dashboard, start a code and link (remote support) session; MyRemoting generates a share link and a one-time code.
- Send the person the link and the code by email, chat, or phone.
- They open the link in any modern browser, enter the code, then download and run the one-time helper.
- Once the helper connects, assist or control them through the browser session; the helper survives a reboot, so you can keep working across a restart.
- End the session when you're finished; the helper self-removes, so nothing stays installed on their machine.
Mint an instant share link for a screen or a single file
Instant share links grant time-limited access to one machine's screen (view-only or full-control) or hand off a single file, without giving the recipient a full account.
- Open the machine's page on the server dashboard.
- Choose to mint a share link, then pick the type: a screen link (view-only or full-control) or a single-file link.
- Set the time limit so the link expires on its own.
- Copy the link and send it to the recipient; they open it in any browser and get exactly what you granted (a view, full control, or a one-file download).
- Alternatively, the person sitting at the machine can mint the same link themselves from the agent's tray/menu-bar icon.
Do zero-install, browser-only "show me your screen" support
For a quick look with nothing to install on either side, browser-only view-only support lets you watch someone's screen straight from a browser tab. It's ideal for a fast diagnosis where full control isn't needed.
- From the server dashboard, start a browser-only view-only support session (or mint a view-only screen share link).
- Send the recipient the link.
- They open it in any modern browser; there is no download and nothing to install.
- They share their screen from the browser and you watch read-only; you can guide them by chat while they stay in control.
- End the session when you're done; because it was browser-only, nothing was left installed on their machine.
Security, access & policy
Add operators and organize access with roles, groups, and scoped admins
Every person who signs in gets their own login, and roles + groups control exactly what they can see and do. Set them up from your control server dashboard.
- Sign in to your control server dashboard as an admin and open the users/admin area.
- Add a new operator by email; on their first sign-in they set a password and are required to enroll TOTP two-factor.
- Create machine groups and assign machines to them. New machines added to a group automatically inherit that group's access.
- Assign the operator a role that scopes both which features they get (remote control, console, inventory, patching, and so on) and which machine groups they can reach.
- To create a scoped admin, give a group lead the manage-users permission plus a group scope. They can then manage users only within their own machines and groups, never beyond them.
Turn on two-factor authentication and add a passkey
MyRemoting requires TOTP two-factor for every account, and you can add a passkey (Face ID, Touch ID, or Windows Hello) for faster, phishing-resistant sign-in.
- On your first sign-in, scan the displayed QR code with an authenticator app (such as Google Authenticator or 1Password) and enter the 6-digit code to finish TOTP enrollment.
- Confirm an email recovery address so you can regain access if you lose your authenticator.
- To add a passkey, open your account security settings in the browser and choose to add a passkey.
- Follow the browser prompt to register Face ID, Touch ID, or Windows Hello via WebAuthn.
- On future sign-ins, authenticate with your passkey instead of typing a code.
Set up the per-machine access gate and save credentials safely
On top of your console sign-in, controlling any machine requires that machine's own local login or an access code, so a compromised console alone can't take over a device. Credentials you save are encrypted per operator and unreadable by the server.
- Understand the gate: after you sign in to the console and start remote control on a machine, you're prompted for that machine's local login or its access code.
- Set or rotate the access code at the machine itself from the tray/menu-bar icon (change the access code).
- When you connect from the browser, enter the machine's local login or its access code at the prompt.
- Optionally save those credentials for that machine. They're encrypted with your own operator key, so the server stores only ciphertext it can't read and they're never shared with other operators.
Set an unattended-access policy for your team
Unattended-access policies let you require conditions (business hours, MFA, a typed reason) before an operator can reach a machine without someone present, scoped per operator and per machine group. Configure them in the dashboard.
- In the control server dashboard, open the unattended-access policy settings.
- Choose which operator(s) and/or machine group(s) the policy applies to.
- Set the allowed business hours, require MFA at connect time, and/or require the operator to type a reason before connecting.
- Enable the endpoint consent banner if you want the person at the machine to see and consent to the session.
- Save. The policy is enforced at every path that reaches the agent, not just the main connect button.
Restrict the operator console with access allow/block lists
Access lists limit which source IP addresses can reach the operator console, while your machines and agents always stay exempt so they never get locked out. Built-in fail-safes prevent you from locking yourself out.
- In the dashboard, open the access allow/block list settings.
- Add the source IPs or ranges allowed to reach the operator console, or block specific addresses.
- Before enforcing, confirm your own current IP is on the allow list.
- Remember that machines and agents are always exempt; only the operator console surface is restricted.
- If your control server sits behind a reverse proxy or IIS, make sure the real client IP is forwarded (an X-Forwarded-For rewrite) so the rules match the true source address.
Turn on session recording and export the audit log
MyRemoting keeps an append-only audit log of who accessed what and when, and can record sessions for browser playback. Enable both from the dashboard.
- In the control server dashboard, enable session recording; recorded sessions play back directly in the browser.
- Choose where recordings live: rotate them locally on the server, or ship them to S3-compatible storage.
- Open the session audit log to review each operator's machine-access events (who, what, and when).
- Use the export option to download the audit log as a CSV for reporting or compliance.
Running your control server
What you need to run the control server
The MyRemoting control server is light to run. The control plane itself is modest, and you size up mainly for your fleet size and relay bandwidth rather than for the raw number of machines. Here is what to have in place before you install.
- Pick an operating system for the server: Windows (running under IIS) or Linux.
- Provide modest hardware. The control plane is light, and a small VM of about 1 CPU and 1 GB of RAM runs it fine. Add resources mainly as your fleet grows or as relay bandwidth demands.
- Have a domain name for the server plus an HTTPS certificate for it. On Linux the server can obtain and renew a certificate automatically from Let's Encrypt for your domain. On Windows you run under IIS with your own certificate.
- Make the server reachable from outside. The built-in readiness check confirms your domain resolves, the port is open, and the certificate is valid.
- Confirm your machines are on a supported agent OS: Windows (10/11 and Windows Server), macOS, or Linux, with one agent per machine. Note that Linux agents provide terminal, files, processes, and power only, with no screen sharing or screenshots.
- Confirm your operators can connect. Any modern browser on desktop or mobile works, plus an installable iPad or desktop app.
- After installing, open the Server page and run the readiness check to confirm your domain, ports, and certificate, and that the server is reachable from outside.
Run the readiness check and read the results
The Server page includes a readiness panel that verifies your deployment is exposed and secured correctly. It checks your setup locally and also asks the central host to connect back to you, so you catch domain, port, and certificate problems before rolling out agents.
- Open the Server page in the operator console.
- Find the readiness panel. It confirms that your base URL is HTTPS, that enrollment is protected, and that email is configured.
- Review the connect-back checks. The central host connects back to confirm that your domain resolves, that the port is open, and that the certificate is valid.
- Read each row by color: green means the check passed, amber means it needs attention, and red means there is a problem. Each row shows a fix-it hint.
- Work through any amber or red rows using the hints, for example correcting your domain or DNS, opening the port, or fixing the certificate.
- Click Re-check to run the checks again after you make a change.
- Aim for all green before you roll agents out to your fleet.
Back up your control server
A backup is a single archive of your server's state: its configuration, users, enrollment tokens, and certificates. On a self-hosted deployment you are responsible for keeping your own backups; a hosted deployment is backed up by the vendor.
- Open the Server page.
- Choose the download-backup option. The server produces one archive that contains its configuration, users, enrollment tokens, and certificates.
- Save the archive somewhere safe, and keep a copy off the server itself.
- Repeat on a regular schedule so you always have a recent copy.
- For an offline alternative, stop the server and run the server binary with its backup/restore flag from the command line to produce a backup without using the console.
- Keep the archive handy. It is what you use to restore the server, migrate to new hardware, or seed a hosted deployment later.
Restore or migrate your server to new hardware from a backup
You can restore a backup onto the same server or onto fresh hardware. When you migrate, your agents reconnect automatically using their saved tokens, so you never have to re-enroll them.
- Open the Server page on the target server.
- Upload your backup archive. It is staged rather than applied immediately.
- Restart the server. The staged backup is applied on the next start.
- To migrate to new hardware, first stand up a fresh control server (see the system-requirements article).
- Restore your backup onto the fresh server using the upload-and-restart steps above.
- Re-point your domain and DNS to the new server.
- Let your agents reconnect. They reconnect automatically using their saved tokens, with no need to re-enroll.
- Run the readiness check on the new server to confirm the domain, port, and certificate all show green.
Update your control server and let agents auto-update
The Server page tells you when a newer build is published and applies it for you. Once the server is updated, connected agents update themselves from it, so you do not touch each machine by hand.
- Open the Server page.
- Look for the notice that a newer build is published.
- Apply the update from the Server page.
- Leave your agents alone. Connected agents auto-update themselves from your server after it updates.
- Note your entitlement. Year 1 of updates is included with a license. After that, updates are optional and the software keeps working without them.
- Do not worry about brief license-service outages. Licensing is verified offline, so a self-hosted server keeps working through them.
- On the On-Prem / air-gapped edition, import signed offline update packages by hand instead. The signature is verified before the update is applied, so the isolated network never needs internet access to stay current.
See your license and update entitlement
The Server page shows the license your deployment is running under and whether your update entitlement is still active. Your license is yours to keep, and you can move between self-hosted and hosted at any time without losing it or your data.
- Open the Server page.
- Find the license section. It shows your deployment's license, including the customer and edition.
- Check whether update entitlement is active. This tells you whether you are still within your included update window.
- Understand what owning the license means for your plan. Self-host and On-Prem own the license outright on purchase, the no-upfront monthly plan owns it after 36 months, and hosted uses the same owned license.
- Remember there is no lock-in. Because the license is yours, you can have the vendor host your server or move back to self-hosting later, keeping your license and your data either way.
Move to managed hosting (convert your self-hosted server to a hosted one)
You can hand off running your control server to the vendor at any time. You keep your owned license and pay a service-only monthly fee, and because the managed server is seeded from your own backup there is no data loss. Your agents don't need to be reinstalled or re-enrolled.
- Open the Server page and run the readiness check first, so you start from a known-good, fully working deployment.
- On the Server page, download a backup. This is a single archive of your server's state: its configuration, users, enrollment tokens, and certificates. Keep it somewhere safe.
- Ask the vendor to convert your deployment to managed hosting and provide your backup. The move seeds the managed control server from that backup, so your users, groups, tokens, and settings all carry over intact.
- Once the managed server is live, re-point your domain's DNS to it. Because your agents keep their saved enrollment tokens, they reconnect automatically to the server at your domain with no re-enrollment.
- Confirm the cutover on the dashboard: your machines should return to online and show recent last-seen times. Run the readiness check on the new server to confirm the domain, port, and certificate are all green.
Your license stays yours throughout. There is no lock-in in either direction, so you can move back to self-hosting later while keeping the same license and data.
Move a hosted deployment back to self-hosting
If you're on managed hosting and want to run the control server yourself again, you can. You keep your owned license and all of your data. The move is the same kind of backup-and-restore migration used everywhere else, so your agents reconnect on their own.
- Stand up a fresh control server on your own infrastructure. It runs on a modest small VM (roughly 1 CPU / 1 GB RAM is enough for the control plane); size up mainly for fleet size and relay bandwidth. Run it on Windows under IIS with your certificate, or on Linux where it can obtain and renew a Let's Encrypt certificate automatically for your domain.
- Obtain a current backup of your hosted deployment to restore from.
- On your new server's Server page, restore the backup. It is staged and applied on the next server start, bringing back your configuration, users, enrollment tokens, and certificates.
- Cancel your managed hosting so only your self-hosted server remains authoritative for your domain.
- Re-point your domain's DNS to your new self-hosted server. Your agents reconnect automatically using their saved tokens, with no need to re-enroll them.
- Run the readiness check on the Server page to confirm your base URL is HTTPS, enrollment is protected, email is configured, and the central host can reach your domain, port, and certificate. Then confirm your machines are back online on the dashboard.
As a self-hosted admin you are again responsible for keeping your own backups. Your license remains yours, exactly as before.
Import signed offline updates on the On-Prem / air-gapped edition
The On-Prem / air-gapped edition runs fully offline, so it never reaches out to the internet for updates. Instead you import signed offline update packages by hand. The signature is verified before the update is applied, so an isolated network can stay current without any outbound access.
- On an internet-connected machine, obtain the signed offline update package from the vendor and transfer it into your isolated network by whatever approved method you use (for example, removable media).
- Open the Server page on your control server. It indicates when a newer build is available to apply.
- Import the signed update package on the Server page. The server verifies the package signature before doing anything with it; if the signature doesn't validate, the update is refused.
- Apply the verified update to the control server.
- Let your connected agents update themselves. Once the server is on the new build, agents auto-update from your server, so you don't patch each machine by hand. Watch the dashboard's agent-version drift indicators until the fleet converges on the new version.
Everything stays inside your network throughout: the air-gapped edition also uses its own internal certificate authority for HTTPS and an offline license, so no step here requires internet access.
White-label your deployment with your company name, logo, and accent color
You can rebrand MyRemoting so it looks like your own product to your team and clients. The branding applies to the operator interface, the agent, and the installer. A small "powered by MyRemoting" attribution remains.
- Sign in to your control server as an admin and open your deployment's branding settings.
- Set your company name. This is the name your operators and clients see across the operator interface, the agent, and the installer.
- Upload your logo to replace the default product logo in the interface.
- Choose your accent color so the interface matches your company's look.
- Save the branding. The operator interface reflects your company name, logo, and accent color right away.
- Roll the branding out to endpoints by distributing the branded agent and installer. New installs made from your server's install link or MSI carry your branding, and connected agents pick up the branded look through your server. Confirm the result by opening a machine's page and connecting, and by checking the at-the-machine tray icon (Windows) or menu-bar icon (macOS) shows your branding.
Because the installer is branded too, machines you deploy at scale present your company's identity from first install onward.
At the machine: privacy & consent
Using the tray or menu-bar icon on your own machine
MyRemoting runs a small agent on your machine, shown as a tray icon on Windows or a menu-bar icon on macOS. From that icon you can confirm the agent is healthy and control a few things about remote access yourself, without needing to sign in to the admin console.
- Find the icon: on Windows it's in the system tray (near the clock, bottom-right); on macOS it's in the menu bar (top-right). Click it to open the menu.
- Confirm the agent is running and connected. The menu shows whether the agent is active and reaching your server, so you can verify it's online before you expect anyone to connect.
- Pause remote control. This temporarily stops operators from controlling your machine until you resume it, so you stay in charge of when access is allowed.
- Set a session time limit. Cap how long a remote session may last, so access ends automatically after the time you choose.
- Change the machine's access code. This is the code an operator must enter to unlock remote control of your machine (the per-machine credential gate that sits on top of their console sign-in). Update it whenever you want to rotate it.
- Share your own screen or a file. From the icon you can mint a share link to your screen or to a file, so you can hand someone a view or a download without them enrolling your machine.
Note: the icon reflects your local agent only. Windows and macOS show the full menu; on Linux the agent provides terminal, file, process, and power access rather than screen sharing.
Approving attended support and reading the "you're being controlled" banner
Attended (one-off) support is the kind where a technician helps you right now, using a code-and-link or a browser-only session rather than always-on access. It can't start until you approve it, and a clear banner stays on screen the entire time so you always know when someone is connected.
- When a technician starts an attended session, a request appears on your machine. Read who is asking before you do anything.
- Approve the session to let them connect, or decline to refuse it. Nothing happens on your machine until you approve.
- Once you approve, watch for the "you're being controlled" banner. It stays visible for the whole session so it's always obvious that someone is connected and active.
- If the banner is not showing, no attended session is running. Treat a visible banner as the signal that control is live.
- To stop early, open the tray or menu-bar icon and pause remote control (see the tray/menu-bar how-to). This hands control back to you.
- When the session ends, your workstation can lock automatically and any privacy toggles the operator turned on revert on their own, so you return to a normal, private state without extra steps.
How your privacy is protected while a technician works
During a remote session, an operator can turn on protections that keep your work private and prevent conflicting input. These are set by the operator during the session (not by you at the machine); this article explains what they do and how you can tell they're active. For turning them on, see the operator-side privacy how-tos.
- Blank screen. The operator can blank your physical monitor so anyone standing near you can't see what's on screen, while the operator still sees the desktop remotely. Your monitor going blank during a session is expected, not a fault.
- Lock input. The operator can temporarily block your local keyboard and mouse so your input doesn't fight with theirs while they work. Your keyboard and mouse return to normal when the session ends or the operator releases the lock.
- Lock on disconnect. When the session ends, your workstation can lock automatically so it isn't left signed in and unattended after the technician disconnects.
- Auto-revert. Privacy toggles the operator turned on during the session revert on their own when the session ends, so you're not left with a blanked screen or blocked input afterward.
- Stay oriented using the on-screen banner and the tray or menu-bar icon: the "you're being controlled" banner tells you a session is live, and the icon lets you pause remote control at any time (see the attended-support and tray/menu-bar how-tos).