Before you start
Five answers decide which method fits:
- What is the computer? A Mac, a Windows PC or a Linux machine. For Windows, check whether it's Home or Pro: Home can't accept Windows Remote Desktop connections.
- Where will you connect from? The same office or home network, or somewhere else on the internet.
- Will someone be sitting at it? If not, you need unattended access, and the computer has to stay on and awake.
- Which account will you use? You'll sign in to the remote computer, so its account needs a strong password. Microsoft's guidance asks for one.
- Do you have permission? Only connect to computers you own or have been asked to help with.
Method 1: Remote-access software
A remote-access tool puts a small app on the computer you want to reach. That app connects out to the tool's service, and you connect through the service from your other device. Because the connection starts from the computer, you don't change anything on your router. Check that a tool supports every kind of computer you need to reach before you choose it.
-
Install the app on the computer you want to reach
On a Mac, the app will ask for two permissions in System Settings > Privacy & Security: Screen & System Audio Recording (to show the screen) and Accessibility (to let you use the mouse and keyboard).
-
Link it to your account
Sign in on that computer, or follow the tool's pairing step, so the computer appears in your list.
-
Connect from your other device
Sign in to the same account from the device you're using, choose the computer, and connect.
-
Test it before you need it
Try once from a different network, such as a phone's hotspot, so you know it works from outside the building.
Aile Insight is one of these tools, set up differently: we install it with you on a 20-minute call. The app on each Mac, Windows PC or Linux server makes an outbound, encrypted connection, and you open the machine in a web browser: Mac Screen Sharing for a Mac, Windows Remote Desktop for a PC, and a terminal for a server. Nothing is installed on the device you connect from.
Method 2: Windows Remote Desktop
Remote Desktop is built into Windows. The PC you connect to must run Windows Pro, Enterprise, Education or Server; Microsoft's documentation says Home editions can only connect out (Microsoft: allow access to your PC).
-
Turn on Remote Desktop on the PC you want to reach
Go to Start > Settings > System > Remote Desktop, switch Remote Desktop on, then select Confirm.
-
Choose who can connect
Administrator accounts can connect automatically. Add anyone else under Remote Desktop users on the same page.
-
Note the PC's name or network address
You'll type it on the computer you connect from.
-
Connect
From another Windows PC, open Remote Desktop Connection (mstsc), enter the PC's name and sign in with that PC's account. From a Mac, use Microsoft's Windows App: Windows from a Mac, step by step
Remote Desktop opens your own Windows session, and the person at the PC is signed out of the screen while you're connected. It suits working on a PC as yourself. It isn't a way to watch and help someone who's using it.
Microsoft says to turn Remote Desktop on only on trusted networks. It connects directly, so it works out of the box on the same network. From outside, see Same network vs the internet.
Method 3: Chrome Remote Desktop
Google's Chrome Remote Desktop installs a small host on a Mac, Windows PC or Linux computer (Linux uses a Debian package). You connect from a browser. Google says all sessions are fully encrypted (Google: access another computer with Chrome Remote Desktop).
-
On the computer you want to reach
Go to remotedesktop.google.com/access, select Download and install the host.
-
Name it and set a PIN
You'll enter this PIN each time you connect.
-
Connect from another device
Open the same address, choose the computer and enter the PIN.
It only needs outbound connections from the computer, so there's nothing to open on your router. On an iPhone or iPad, Google's help pages point to the same web address, which you can add to your Home Screen to use full screen.
Chrome Remote Desktop also has a support mode for helping someone: see Helping someone, with their consent. You set up, update and troubleshoot it yourself.
If the computer is a Mac
A Mac's built-in way to be reached is Screen Sharing. Turn it on in Apple menu > System Settings > General > Sharing: click the Info button next to Screen Sharing and switch it on. If Remote Management is on, turn it off first; Apple says the two can't be on together (Apple: turn Screen Sharing on or off).
Screen Sharing is VNC-compatible, so other computers can connect with a VNC viewer on the same network. Apple warns that VNC software from other companies may not encrypt keystrokes, so keep that kind of connection on a network you trust. Third-party tools on a Mac need the Screen Recording and Accessibility permissions described in Method 1.
Reaching your own computer
The usual case: the office PC from home, or the studio Mac from a client's site. Set it up while you're sitting at the computer, because some steps need a click on that screen.
- Install or turn on your chosen method and connect once while you're still in the building.
- Stop it sleeping. On Windows, set sleep to Never. On a Mac desktop, go to System Settings > Energy and turn on "Prevent automatic sleeping when the display is off" and "Wake for network access". On a Mac laptop, the same settings are under Battery > Options.
- Test from another network before you rely on it.
Helping someone, with their consent
When you're helping a colleague or a relative, the person should see the request and approve it. The built-in options are designed that way.
- Quick Assist (Windows). The helper gets a time-limited code and gives it to the person, who selects Allow, then allows again if the helper asks for control. The shortcut is Ctrl+Win+Q (Microsoft: Quick Assist).
- Chrome Remote Desktop support. The person goes to remotedesktop.google.com/support and generates a one-time code. The helper enters it, the person confirms Share, and they're asked to confirm again every 30 minutes.
- Mac Screen Sharing. The option "Anyone may request permission to control screen" lets the person at the Mac accept or decline.
With Aile Insight, you open a colleague's Mac and see their screen as it is, and take the mouse when they ask. For a Windows PC, we set up screen sharing during setup, because Windows Remote Desktop would sign them out of the screen.
Attended vs unattended access
Attended means someone is at the computer to accept the connection, as with Quick Assist. Unattended means you can connect without anyone there to accept it, which is what you need for your own office machine or a server.
Unattended access only works if the computer is switched on, awake and running whatever accepts the connection. Use it only on computers you own or are responsible for.
Same network vs the internet
On the same network, Windows Remote Desktop and Mac Screen Sharing connect straight to the computer. From outside, that direct connection has nowhere to go unless you change your network. Microsoft lists the options (Microsoft: access your PC from outside):
- Port forwarding on your router, usually with dynamic DNS and a fixed address for the PC. Microsoft calls it "not recommended" and says a VPN is preferable.
- A VPN into your network.
- Remote Desktop Gateway, a Windows Server role that gives encrypted access over the internet without a VPN.
Tools that connect out (Method 1 and Chrome Remote Desktop) need only outbound traffic, so they work from anywhere without those changes. Remote access without a VPN
Security
- Use strong, unique passwords on every account that can connect.
- Keep Network Level Authentication on for Windows Remote Desktop. Microsoft says to turn it off only temporarily, for old clients.
- Keep each computer updated. Remote-access flaws do get found and fixed.
- Give access only to the people who need it, and remove it when someone leaves.
- Never connect to someone's computer without them knowing.
Troubleshooting
Start with these checks from Microsoft's troubleshooting guide for Remote Desktop (Microsoft: Remote Desktop can't connect), and most apply to other tools too.
- The computer is off or asleep. You can't connect to a PC that's off, asleep or hibernating. Set sleep to Never.
- The firewall blocks it. Allow Remote Desktop in Windows Firewall, or allow port 3389 on any other firewall between you and the PC.
-
You're not sure the port is reachable.
In PowerShell, run
Test-NetConnection -ComputerName <host> -port 3389. - You see the sign-in screen but can't sign in. Usually the account isn't in the Remote Desktop Users group.
- The PC name isn't found. Try its IP address instead.
- It still won't connect. Check whether antivirus software is blocking the connection.
Which method is right for you?
| Criterion | Windows Remote Desktop | Chrome Remote Desktop | Aile Insight |
|---|---|---|---|
| Computers you can reach | Windows Pro, Enterprise, Education, Server | Mac, Windows, Linux | Mac, Windows PC (Remote Desktop needs Pro or higher), Linux server |
| From outside your network | Needs a VPN or Remote Desktop Gateway | Connects out; no router changes | Connects out; no router or firewall changes |
| Helping someone at their screen | No: signs them out of the screen | Yes, with a one-time support code | Yes: Mac Screen Sharing, or screen sharing we set up on a Windows PC |
| Who sets it up | You | You | We do it with you on a call |
- A Windows Pro PC on the same office network: Windows Remote Desktop.
- A one-off fix with someone at the computer: Quick Assist on Windows, or Chrome Remote Desktop's support mode.
- Your own computers, and you're happy to set them up yourself: Chrome Remote Desktop or another remote-access tool.
- A small team that wants Macs, PCs and servers set up for them, with someone to call: a set-up service such as Aile Insight.