Outsourced help desk support for a remote team means an external provider runs your help desk: staff reach it by phone, chat or portal, and engineers fix problems through cloud device management and remote sessions the user accepts, under an agreement on hours, priorities and targets. It works when devices and identities are managed from the cloud first.

This guide covers what an outsourced desk does in ITIL terms, what remote and hybrid work adds to its job (device management, remote sessions, identity checks, laptops for people you never meet, time zones), how to outsource support for remote employees step by step, what to ask a provider, what to write into the agreement, and how to tell whether it is working.

What an outsourced help desk does for a remote team

ITIL, the IT service management framework, describes the service desk as the central point of contact between a service provider and its users. An outsourced help desk is that practice run by another company: your staff contact it, and every contact becomes a ticket with an owner, a priority and a history.

Two kinds of ticket reach the desk, and they are handled differently:

  • Incidents are things that stopped working or got worse: a laptop that will not start, Outlook that will not sync, a VPN that drops. Incident management is about restoring normal service quickly, even with a workaround, and finding the cause later.
  • Service requests are things people ask for that the desk already knows how to deliver: a laptop for a new starter, access to a shared mailbox, a software licence. Service request management handles these predefined, user-initiated requests as a routine.

Providers usually work in tiers, from first line (taking the contact, triage, simple fixes) to third line (engineering work and escalations to vendors such as Microsoft). Some teams outsource every tier; others keep an internal IT lead and hand the provider the first lines, overflow and projects. For how these arrangements compare, see our guide to IT support service models.

Each ticket gets a priority from two questions: how much of the business is affected (impact) and how soon it starts to hurt (urgency). The priority decides the target in the service level agreement. ITIL's service level management practice is about setting clear targets from business needs, which for a remote team means from when and where people actually work.

For a remote employee, the desk is the whole of IT. There is no one to walk over to, no spare laptop in a cupboard and no colleague who "knows the printer". That raises the bar on everything that follows.

What remote and hybrid work changes for the desk

An office desk can fall back on physical access: a technician takes the laptop, plugs it into the network, re-images it. A remote desk cannot. NIST's telework guide, SP 800-46 Rev. 2 (July 2016), tells organizations to plan on the assumption that external environments contain hostile threats: home and public networks are outside your control, and laptops that travel get lost and stolen. The eavesdropping risks of shared Wi-Fi are one example.

What changes when staff work remotelyWhat the desk needs in place
Nobody can bring a laptop to ITCloud device management and zero-touch enrolment
Home and public networks you do not controlAccess decided by identity and device health, not by network location
Sign-in is the front door to everythingMFA for everyone, phishing-resistant where possible, and verified resets
Every fix happens over the internetOne approved remote support tool, with consent and logging
Starters and leavers you never meet in personShipping, enrolment and revocation written as runbooks
People spread across time zones and countriesCoverage hours, languages and hardware logistics agreed per region

Hybrid work adds one more twist: the same laptop moves between the office network and a kitchen table. Rules tied to the office network (a firewall that trusts the internal range, a file share reachable only on site) stop protecting the device the moment it leaves. The rules have to follow the device and the person instead.

Manage every laptop and phone from the cloud

Microsoft describes Intune as a cloud-based endpoint management service that runs with no on-premises infrastructure and covers Android, iOS/iPadOS, Linux, macOS and Windows, among others. It works in two modes, and a remote team usually needs both:

  • Mobile device management (MDM) for company-owned devices. The device is enrolled, and Intune manages its settings, security and apps; if it is lost or stolen, it can be wiped.
  • Mobile application management (MAM) for personal phones. Intune protects only the work apps and the data inside them, such as Outlook and Teams. When the person leaves, the organization's data can be removed without touching their personal content.

Enrolment alone does not stop a neglected laptop from reaching company data. That is the job of compliance policies combined with Conditional Access. A compliance policy sets rules such as a minimum operating system version or no jailbroken phones; Conditional Access in Microsoft Entra ID then blocks access to company resources from devices that fail them. Microsoft's own summary of the model is that access decisions rest on the device's current posture, not on whether it sits on the corporate network, which is exactly what a hybrid team needs.

Two tenant-wide settings deserve a look before the provider starts:

  1. Devices with no compliance policy assigned are marked compliant by default. If you use Conditional Access, change this to "Not compliant", so that only devices confirmed healthy get in.
  2. Compliance status validity period is 30 days by default (configurable from 1 to 120). A device that has not reported its compliance within that period is treated as noncompliant. For remote staff that is useful: a laptop left in a drawer for two months loses access until it checks in and catches up.

With this in place, the desk can check a device's compliance state before it calls the user, and can change a setting for one laptop or the whole company through group-assigned policies, without anyone visiting an office. Macs can be managed in Intune as well, or with a Mac-specific platform such as Jamf; what matters is that every company device is enrolled somewhere the desk can see it.

Remote desktop support without handing out the keys

Outsourced remote desktop support means an engineer views or controls an employee's screen over the internet. The tool you allow for that is a security decision, not a convenience.

Windows ships with Quick Assist. It is simple: the helper signs in and shares a time-limited code with the user, who allows screen sharing and, separately, control. But no roles, permissions or policies are involved, the person sharing the screen does not authenticate, and no logs are created on either device. Microsoft's own page recommends that organizations working within a single Microsoft Entra tenant consider Intune Remote Help instead, and warns users to accept a helper only when they started the contact themselves.

Remote Help closes those gaps:

  • Both the helper and the user sign in with a Microsoft Entra account from your organization. For an outsourced desk, that means its engineers work from named accounts in your tenant, under your MFA and Conditional Access rules.
  • Role-based access control decides who can help whom, who can only view, and who may take full control or elevate.
  • The Intune admin center reports who helped whom, on which device and for how long, and the helper sees a warning if the device is not compliant.
  • Unattended remote sign-in, where no user is present, is limited to physical, company-owned, Intune-managed Windows devices.

Remote Help is one of Intune's advanced capabilities, licensed through Intune Plan 2, the Intune Suite or selected Microsoft 365 bundles, so check your licences before assuming you have it. Many providers bring their own remote monitoring and management (RMM) platform instead; the same requirements apply to it.

Why so strict? In a January 2023 advisory, CISA described criminals sending help desk-themed phishing emails that led to legitimate remote access software being downloaded onto staff computers as portable executables, which run without administrator rights and slip past controls that only watch installations. So agree on one remote support tool with the provider, block the others with application control (including portable versions), and tell staff plainly: the desk will never ask you to download a remote access tool from a link.

Identity: the help desk can reset its way into any account

A help desk that can reset passwords can, in effect, become anyone it resets. Microsoft marks its Entra Helpdesk Administrator role as privileged and warns that changing a user's password may mean taking on that user's identity and permissions.

Attackers know it. A joint advisory from CISA, the FBI, the Canadian Centre for Cyber Security and others on Scattered Spider (first published November 16, 2023, updated July 29, 2025) describes a group that targets large companies and their contracted IT help desks. Its members call help desks posing as employees, over several calls, first to learn the reset procedure and then to have a password reset or the employee's MFA moved to a device they control. Details gathered from social media and data leaks make the calls convincing.

Remote staff make this harder to catch, because the desk never sees them. The defence is a written verification procedure that the provider follows every time:

  1. Never verify with facts an attacker can find, such as a birthday, an employee number or a manager's name.
  2. Call back on the number in your HR system, not the number the call came from.
  3. Confirm through something the person already has, such as the phone already registered to their account, or through their manager on a separate channel.
  4. Replace MFA, do not remove it. Instead of turning MFA off "just for today", issue a short-lived pass the person uses to register a new method.
  5. Never reset an administrator's credentials on a phone call. Escalate to a named person on your side.
A ringing phone reaches a help desk console. The path from the console to a key is blocked by an orange gate until a separate, already registered phone shows a check mark.
Fig. 1 The reset waits until the request is confirmed through a device or record you already trust, not through the voice on the line.

The pass in step 4 exists in Microsoft Entra ID as the Temporary Access Pass: a time-limited passcode, single-use or valid for several sign-ins, with a lifetime you set between 10 minutes and 30 days (one hour by default). The user signs in with it and registers a passkey or the Microsoft Authenticator app.

The method they register matters too. CISA's phishing-resistant MFA fact sheet (October 2022) explains that codes and push approvals can be phished, SIM-swapped or approved by a tired user after repeated prompts ("push bombing"), and names FIDO/WebAuthn as the only widely available phishing-resistant method. For remote teams that means passkeys or security keys, starting with administrators and the help desk's own accounts.

Onboarding and offboarding people you never meet

Starting: a laptop that sets itself up

A remote start should not involve anyone configuring a laptop by hand. For Windows, the device's hardware identity is registered with your tenant for Windows Autopilot, ideally by the manufacturer, reseller or distributor, so the laptop can ship straight to the employee's home. According to Microsoft's Autopilot overview, the only steps left for the user are connecting to a network and signing in; Autopilot then joins the device to Microsoft Entra ID, enrols it in Intune (which needs a Microsoft Entra ID P1 or P2 subscription), applies settings and installs apps. Our guide to setting up Windows on a new computer covers that path from the user's side.

Apple devices use Automated Device Enrollment through Apple Business, the service Apple previously called Apple Business Manager. The device is managed from the moment it is taken out of the box, the user can be prevented from removing management, and a Mac running macOS 14 or later can be required to turn on FileVault disk encryption before anyone uses it.

A laptop in a shipping box travels from a warehouse shelf to a desk in a house. The laptop connects over home Wi-Fi to the cloud, which sends an orange bundle of settings, security and apps down to it.
Fig. 2 The laptop never passes through the IT office: its configuration comes from the cloud the first time it connects at home.

In practice, a remote start runs in this order:

  1. HR raises a service request with the start date, role and delivery address, early enough for shipping.
  2. The desk orders a device through a reseller that registers it to your tenant, and ships it to the employee.
  3. The account is created and added to role-based groups, so licences, apps and shared mailboxes follow from the role.
  4. On day one, the desk verifies the person (by video call, compared with HR records) and gives them a Temporary Access Pass through that verified channel.
  5. The employee signs in, registers a passkey, and the device enrols and becomes compliant.
  6. The desk confirms that mail, files and the main business apps open, and closes the request with notes.

Leaving: access first, device second

Offboarding a remote employee has a trap: the laptop is somewhere you cannot reach. Microsoft's guide to revoking user access sets out the order for an Entra ID account: disable the account, revoke its sessions (which invalidates refresh tokens), and disable the user's registered devices. Access tokens already issued stay valid until they expire, one hour by default, and applications that keep their own session cookies must be deprovisioned or have their sessions revoked separately.

Then the device. An Intune wipe factory-resets a company-owned device; a retire removes company apps, settings and data but keeps personal content, which suits personal devices. Both act only when the device next connects: Microsoft notes that an offline device still has access to the data stored on it. Cutting the account's access first is what protects you in the meantime, and disk encryption protects whatever is still on the laptop until it is wiped or returned.

An ID card's links to mail, files and chat are cut and padlocked. Below, an orange wipe command waits in the cloud because the laptop it is meant for is offline.
Fig. 3 Cut the account first: a wipe command only lands when the missing laptop next goes online.

Close the loop with the hardware: a prepaid return box sent with the leaving date, the device marked in the asset register, and its Autopilot or Apple Business record kept so it can be reissued.

Covering time zones and after-hours work

A remote team rarely keeps one office's hours. Before choosing a provider, map where your people work and when, then decide which kinds of problems deserve a human outside business hours. A sales team that cannot sign in at 7:00 in its own time zone is a business problem; a request for a new monitor can wait.

"24/7" means different things in different contracts. It can mean a person answers every call at every hour, an on-call engineer is paged for the top priority only, or tickets are logged overnight and picked up in the morning. Some providers run a follow-the-sun model, handing open tickets between regional teams as their days end, which works only if ticket notes are good enough for a stranger to continue the work.

Two practical questions complete the picture: which languages the desk answers in, and how hardware reaches people in other countries (spare devices, warranty repairs and returns). A lost laptop in another country is a logistics problem as much as a technical one.

How to outsource IT support for remote employees, step by step

  1. Take stock. List people, locations, time zones and working hours; company and personal devices by platform; your identity provider (Microsoft Entra ID, Google or another); the business apps; and who holds admin rights today.
  2. Decide the arrangement. Fully managed, where the provider is the help desk and the administrators, or alongside an internal IT person, who keeps ownership while the provider takes the first lines, overflow and projects.
  3. Fix the foundation, or make it the first project. Every company device enrolled in management, MFA on every account, one remote support tool, and a written onboarding and offboarding runbook.
  4. Shortlist providers with the questions in the next section, and ask to see real, anonymized examples of their runbooks and monthly reports.
  5. Write the agreement with the clauses below, including how the provider's own access works.
  6. Grant access properly. Named accounts for each engineer in your tenant, MFA on all of them, the narrowest roles that do the job and, for a Microsoft partner, granular delegated admin privileges (GDAP), which are least-privilege and time-bound and must be granted explicitly by you.
  7. Tell your staff how to reach the desk, which remote tool it uses, and how it will verify them before a reset.
  8. Review monthly for the first quarter, then quarterly: tickets, trends and what the provider proposes to fix at the root.

Questions to ask an outsourced IT support company for remote teams

QuestionWhy it matters for a remote team
Which platforms do you manage every day: Windows, macOS, iOS, Android, Linux?Remote staff cannot swap to a supported device down the corridor
How do your engineers access our tenant?You want named accounts with MFA and scoped roles, never a shared admin login
Which remote support tool will you use, and can we read its logs?Every fix is a remote session; you should be able to see who connected and when
How do you verify a caller before a password or MFA reset?Help desks are a known social engineering target
Which hours and time zones does a person answer, in which languages?Coverage has to match where your people actually work
How do you ship, swap and collect devices in other countries?A broken laptop abroad is a logistics problem as much as a technical one
What happens when the contract ends?Documentation, admin accounts and the asset register must come back to you

What to put in the agreement

The Canadian Centre for Cyber Security's guidance for consumers of managed services starts from a point worth repeating: your organization remains the data owner and is legally responsible for its security. It recommends that the service level agreement specify turnaround times, communication channels, escalation processes, performance metrics and penalties for missed turnaround times, and it lists exit strategies and data destruction among the topics to settle before signing. A joint advisory on managed service providers from the cyber security agencies of the UK, Australia, Canada, New Zealand and the United States (May 2022) adds the access rules: MFA on every provider account, no admin credentials reused across customers, least privilege, incident notification written into the contract, the most important logs kept for at least six months, and provider accounts disabled when the contract ends.

For a remote team, the agreement should cover at least:

ClauseWhat to write down
Scope and exclusionsWhich users, devices, apps and locations are covered; which projects are quoted separately
CoverageHours per region, after-hours arrangements by priority, public holidays, languages
PrioritiesDefinitions by impact and urgency, with examples from remote work (one person locked out, a whole team offline)
TargetsResponse and resolution or workaround targets for each priority
Channels and escalationPhone, chat, email or portal; named escalation contacts on both sides
Provider accessNamed accounts, MFA, least-privilege and time-bound roles, no shared or reused admin credentials
Remote sessionsThe approved tool, user consent for attended sessions, where unattended access is allowed, log access
Identity verificationThe written procedure for password and MFA resets, and who approves exceptions
Security incidentsHow and how quickly the provider tells you about an incident affecting your environment
Reporting and reviewMonthly metrics, trends and recurring causes, reviewed in a meeting
ExitHandover of documentation and the asset register, return of admin credentials, accounts disabled

Important

Define "response" as a reply from a person who has read the ticket, not an automatic acknowledgement. Otherwise every target in the agreement can be met by an email robot while your employee is still locked out.

How to measure whether it is working

The numbers worth watching are the ones a remote employee feels. Track them by priority and by region, and look at the trend rather than a single month.

MetricWhat it tells you
Time to first human responseWhether people are left waiting, especially outside the provider's main hours
Time to resolutionWhether the targets in the agreement are met, and for which priorities
First contact resolutionHow often the first person who answers can fix the problem
Reopened ticketsWhether fixes hold, or tickets are closed too early
Recurring causesWhether the provider fixes root causes or resets the same thing every week
Onboarding lead timeDays from HR request to a new starter working on a compliant device
Offboarding completionTime from the leaving date to account disabled, sessions revoked, device back
Device complianceShare of devices compliant and checking in within the validity period
User satisfactionA one-question survey at ticket close, with the comments read

A good provider brings these numbers to the review with an explanation and a proposal: the three causes behind most tickets this quarter, and what would remove them.

If you want help setting this up or running it, our IT support service covers the help desk, device management with Intune or Jamf, Microsoft 365 or Google Workspace administration, MFA and onboarding. Remote sessions happen only with your consent, and admin access goes to named engineers with multi-factor authentication and is removed when the work ends. More guides on running IT for a small team are in the IT support topic.