Remote Shell

Troubleshoot a managed Windows device from a persistent, recorded terminal in the portal: Windows PowerShell or the Command Prompt, as the system (even when nobody is signed in) or as the signed-in user.

Requirements and access

  • An Account Owner or tenant Admin must enable Remote Shell in Settings and click Save Changes. Technician and ReadOnly users cannot open shells.
  • The device needs a remote-shell-capable Windows agent, a successful check-in after upgrading, and Windows 10 or Windows Server 2019 build 17763 or newer. macOS is not supported.
  • Recording encryption must be configured by the service operator before connections are available.
  • The terminal itself travels over a direct WebRTC connection between your browser and the device, the same way remote desktop does, so the same STUN and TURN servers apply. A network that blocks UDP falls back to the TURN relay over TCP or TLS on port 443; the status line shows "via relay" when that happens.

Start and end a session

  1. Open a Windows device, choose Remote Shell, pick Windows PowerShell or Command Prompt and whether to run as the system or as the signed-in user, and select Connect. Running as the user needs someone signed in on the device; it gives you their profile, drives and settings with their ordinary (non-elevated) rights.
  2. If another desktop or shell session is active, review who started it before choosing Take over. Taking over stops the previous session and its running commands.
  3. Use the terminal for interactive commands. Closing its tab, ending the session, losing the connection, or restarting the agent stops the shell and its child processes. Reconnecting starts a new shell.

The tenant's Notify the signed-in user setting controls whether a notification is shown before connecting. It is off by default. There is no consent prompt, and no console window appears on the user's desktop.

The system context does not share the signed-in user's profile, mapped drives, or application settings; the user context does. Only run commands approved for this device.

Limits and troubleshooting

  • Five minutes without any input or output ends the session; a command that is still printing keeps it alive. There is also a one-hour absolute session limit.
  • The agent records every keystroke and every line of output as it happens and uploads the recording to Pckgr within about a second. If the device cannot upload for a minute, or a batch fails its integrity check, the session is ended rather than left running unrecorded. Reaching 16 MiB or 100,000 recorded frames ends the session with a recording-limit message.
  • At most 64 KiB of input can be queued in the browser. A paste that exceeds this is rejected in full; the shell remains connected. Wait for the queue to drain or paste less text.
  • If the device cannot consume input and its bounded queues fill, the session ends with an input-queue message. Commands are not silently truncated or dropped. If your browser stops taking output for 15 seconds the session ends too.
  • A "could not establish a direct connection" message means no WebRTC path opened within 45 seconds, not even through the relay. Check that the device and your browser can reach the STUN and TURN servers listed under Hardened Environments.
  • An upgrade-required message means the device has not reported shell support. Update the agent and wait for its next check-in. A pending connection expires after 90 seconds.

For application-control and endpoint-security policies, see Hardened Environments.

Recordings and audit history

All input, output and terminal size changes are recorded, including passwords or other secrets typed into the terminal. Recordings are encrypted and available for 30 days from the session's start. Expired recordings are removed by an hourly cleanup; lifecycle audit entries follow the normal audit policy.

Only the Account Owner can play recordings from the device's shell history. Playback access is audited, including reads that begin partway through a recording. Playback never sends commands back to the device. The input transcript can be expanded for inspection.