# Outsourced help desk support for remote teams: devices, identity and SLAs

> How an outsourced help desk supports remote and hybrid staff: cloud device management, safe remote sessions, verified resets, the agreement and the metrics.

- URL: https://computese.com/optimizing-remote-work-through-outsourced-it-help-desk-support/
- Author: Duong Quan Nguyen, CEO, Computese
- Published: 2023-12-03
- Updated: 2026-09-25
- Topics: IT support, Security

## In short
- An outsourced help desk gives remote staff one point of contact for IT, but its engineers can only reach them through the cloud: device management, identity and a remote support tool have to be in place before the desk can do its job.
- Manage every laptop from the cloud. Windows Autopilot and Apple Automated Device Enrollment let you ship devices straight to employees, and Intune compliance with Conditional Access grants access by device health, not by network location.
- Help desks are a target. A joint CISA, FBI and CCCS advisory describes Scattered Spider calling contracted help desks as employees to get passwords and MFA reset. Verify callers through a channel you already trust before any reset.
- Write the provider's access into the agreement: named accounts in your tenant with MFA, least-privilege and time-bound roles, consented and logged sessions, and every account disabled when the contract ends.
- Measure what remote staff feel: time to a first human reply and to resolution by priority, reopened tickets, onboarding lead time, offboarding speed and device compliance.

Outsourced help desk support for a remote team means an external provider runs your help desk: staff reach it by phone, chat or portal, and engineers fix problems through cloud device management and remote sessions the user accepts, under an agreement on hours, priorities and targets. It works when devices and identities are managed from the cloud first.

This guide covers what an outsourced desk does in ITIL terms, what remote and hybrid work adds to its job (device management, remote sessions, identity checks, laptops for people you never meet, time zones), how to outsource support for remote employees step by step, what to ask a provider, what to write into the agreement, and how to tell whether it is working.

## What an outsourced help desk does for a remote team

ITIL, the IT service management framework, describes the [service desk](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil4-practices-service-desk-3706) as the central point of contact between a service provider and its users. An outsourced help desk is that practice run by another company: your staff contact it, and every contact becomes a ticket with an owner, a priority and a history.

Two kinds of ticket reach the desk, and they are handled differently:

- **Incidents** are things that stopped working or got worse: a laptop that will not start, Outlook that will not sync, a VPN that drops. [Incident management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil4-practices-incident-management-3684) is about restoring normal service quickly, even with a workaround, and finding the cause later.
- **Service requests** are things people ask for that the desk already knows how to deliver: a laptop for a new starter, access to a shared mailbox, a software licence. [Service request management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil4-practices-service-request-management-3690) handles these predefined, user-initiated requests as a routine.

Providers usually work in tiers, from first line (taking the contact, triage, simple fixes) to third line (engineering work and escalations to vendors such as Microsoft). Some teams outsource every tier; others keep an internal IT lead and hand the provider the first lines, overflow and projects. For how these arrangements compare, see our guide to [IT support service models](https://computese.com/understanding-it-support-a-vital-role-in-the-digital-era/).

Each ticket gets a priority from two questions: how much of the business is affected (impact) and how soon it starts to hurt (urgency). The priority decides the target in the service level agreement. ITIL's [service level management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil-4-practitioner-service-level-management-3867) practice is about setting clear targets from business needs, which for a remote team means from when and where people actually work.

For a remote employee, the desk is the whole of IT. There is no one to walk over to, no spare laptop in a cupboard and no colleague who "knows the printer". That raises the bar on everything that follows.

## What remote and hybrid work changes for the desk

An office desk can fall back on physical access: a technician takes the laptop, plugs it into the network, re-images it. A remote desk cannot. NIST's telework guide, [SP 800-46 Rev. 2](https://csrc.nist.gov/pubs/sp/800/46/r2/final) (July 2016), tells organizations to plan on the assumption that external environments contain hostile threats: home and public networks are outside your control, and laptops that travel get lost and stolen. The [eavesdropping risks of shared Wi-Fi](https://computese.com/understanding-eavesdropping-attacks-how-they-work/) are one example.

| What changes when staff work remotely         | What the desk needs in place                                             |
| --------------------------------------------- | ------------------------------------------------------------------------ |
| Nobody can bring a laptop to IT               | Cloud device management and zero-touch enrolment                         |
| Home and public networks you do not control   | Access decided by identity and device health, not by network location    |
| Sign-in is the front door to everything       | MFA for everyone, phishing-resistant where possible, and verified resets |
| Every fix happens over the internet           | One approved remote support tool, with consent and logging               |
| Starters and leavers you never meet in person | Shipping, enrolment and revocation written as runbooks                   |
| People spread across time zones and countries | Coverage hours, languages and hardware logistics agreed per region       |

Hybrid work adds one more twist: the same laptop moves between the office network and a kitchen table. Rules tied to the office network (a firewall that trusts the internal range, a file share reachable only on site) stop protecting the device the moment it leaves. The rules have to follow the device and the person instead.

## Manage every laptop and phone from the cloud

Microsoft describes [Intune](https://learn.microsoft.com/en-us/intune/fundamentals/what-is-intune) as a cloud-based endpoint management service that runs with no on-premises infrastructure and covers Android, iOS/iPadOS, Linux, macOS and Windows, among others. It works in two modes, and a remote team usually needs both:

- **Mobile device management (MDM)** for company-owned devices. The device is enrolled, and Intune manages its settings, security and apps; if it is lost or stolen, it can be wiped.
- **Mobile application management (MAM)** for personal phones. Intune protects only the work apps and the data inside them, such as Outlook and Teams. When the person leaves, the organization's data can be removed without touching their personal content.

Enrolment alone does not stop a neglected laptop from reaching company data. That is the job of **compliance policies** combined with **Conditional Access**. A [compliance policy](https://learn.microsoft.com/en-us/intune/device-security/compliance/overview) sets rules such as a minimum operating system version or no jailbroken phones; Conditional Access in Microsoft Entra ID then blocks access to company resources from devices that fail them. Microsoft's own summary of the model is that access decisions rest on the device's current posture, not on whether it sits on the corporate network, which is exactly what a hybrid team needs.

Two tenant-wide settings deserve a look before the provider starts:

1. **Devices with no compliance policy assigned** are marked compliant by default. If you use Conditional Access, change this to "Not compliant", so that only devices confirmed healthy get in.
2. **Compliance status validity period** is 30 days by default (configurable from 1 to 120). A device that has not reported its compliance within that period is treated as noncompliant. For remote staff that is useful: a laptop left in a drawer for two months loses access until it checks in and catches up.

With this in place, the desk can check a device's compliance state before it calls the user, and can change a setting for one laptop or the whole company through group-assigned policies, without anyone visiting an office. Macs can be managed in Intune as well, or with a Mac-specific platform such as Jamf; what matters is that every company device is enrolled somewhere the desk can see it.

## Remote desktop support without handing out the keys

Outsourced remote desktop support means an engineer views or controls an employee's screen over the internet. The tool you allow for that is a security decision, not a convenience.

Windows ships with [Quick Assist](https://learn.microsoft.com/en-us/windows/client-management/client-tools/quick-assist). It is simple: the helper signs in and shares a time-limited code with the user, who allows screen sharing and, separately, control. But no roles, permissions or policies are involved, the person sharing the screen does not authenticate, and no logs are created on either device. Microsoft's own page recommends that organizations working within a single Microsoft Entra tenant consider Intune Remote Help instead, and warns users to accept a helper only when they started the contact themselves.

[Remote Help](https://learn.microsoft.com/en-us/intune/remote-help/) closes those gaps:

- Both the helper and the user sign in with a Microsoft Entra account from **your** organization. For an outsourced desk, that means its engineers work from named accounts in your tenant, under your MFA and Conditional Access rules.
- Role-based access control decides who can help whom, who can only view, and who may take full control or elevate.
- The Intune admin center reports who helped whom, on which device and for how long, and the helper sees a warning if the device is not compliant.
- Unattended remote sign-in, where no user is present, is limited to physical, company-owned, Intune-managed Windows devices.

Remote Help is one of Intune's [advanced capabilities](https://learn.microsoft.com/en-us/intune/fundamentals/advanced-capabilities), licensed through Intune Plan 2, the Intune Suite or selected Microsoft 365 bundles, so check your licences before assuming you have it. Many providers bring their own remote monitoring and management (RMM) platform instead; the same requirements apply to it.

Why so strict? In a January 2023 [advisory](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a), CISA described criminals sending help desk-themed phishing emails that led to legitimate remote access software being downloaded onto staff computers as portable executables, which run without administrator rights and slip past controls that only watch installations. So agree on one remote support tool with the provider, block the others with application control (including portable versions), and tell staff plainly: the desk will never ask you to download a remote access tool from a link.

## Identity: the help desk can reset its way into any account

A help desk that can reset passwords can, in effect, become anyone it resets. Microsoft marks its Entra [Helpdesk Administrator](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference) role as privileged and warns that changing a user's password may mean taking on that user's identity and permissions.

Attackers know it. A joint advisory from CISA, the FBI, the Canadian Centre for Cyber Security and others on [Scattered Spider](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a) (first published November 16, 2023, updated July 29, 2025) describes a group that targets large companies and their contracted IT help desks. Its members call help desks posing as employees, over several calls, first to learn the reset procedure and then to have a password reset or the employee's MFA moved to a device they control. Details gathered from social media and data leaks make the calls convincing.

Remote staff make this harder to catch, because the desk never sees them. The defence is a written verification procedure that the provider follows every time:

1. **Never verify with facts an attacker can find**, such as a birthday, an employee number or a manager's name.
2. **Call back on the number in your HR system**, not the number the call came from.
3. **Confirm through something the person already has**, such as the phone already registered to their account, or through their manager on a separate channel.
4. **Replace MFA, do not remove it.** Instead of turning MFA off "just for today", issue a short-lived pass the person uses to register a new method.
5. **Never reset an administrator's credentials on a phone call.** Escalate to a named person on your side.

![A ringing phone reaches a help desk console. The path from the console to a key is blocked by an orange gate until a separate, already registered phone shows a check mark.](https://computese.com/images/blog/optimizing-remote-work-through-outsourced-it-help-desk-support/reset.d56c1337ab-1536.webp)

*The reset waits until the request is confirmed through a device or record you already trust, not through the voice on the line.*

The pass in step 4 exists in Microsoft Entra ID as the [Temporary Access Pass](https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass): a time-limited passcode, single-use or valid for several sign-ins, with a lifetime you set between 10 minutes and 30 days (one hour by default). The user signs in with it and registers a passkey or the Microsoft Authenticator app.

The method they register matters too. CISA's [phishing-resistant MFA fact sheet](https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf) (October 2022) explains that codes and push approvals can be phished, SIM-swapped or approved by a tired user after repeated prompts ("push bombing"), and names FIDO/WebAuthn as the only widely available phishing-resistant method. For remote teams that means passkeys or security keys, starting with administrators and the help desk's own accounts.

## Onboarding and offboarding people you never meet

### Starting: a laptop that sets itself up

A remote start should not involve anyone configuring a laptop by hand. For Windows, the device's hardware identity is registered with your tenant for [Windows Autopilot](https://learn.microsoft.com/en-us/autopilot/registration-overview), ideally by the manufacturer, reseller or distributor, so the laptop can ship straight to the employee's home. According to Microsoft's [Autopilot overview](https://learn.microsoft.com/en-us/autopilot/overview), the only steps left for the user are connecting to a network and signing in; Autopilot then joins the device to Microsoft Entra ID, enrols it in Intune (which needs a Microsoft Entra ID P1 or P2 subscription), applies settings and installs apps. Our guide to [setting up Windows on a new computer](https://computese.com/how-to-set-up-windows-for-a-new-computer/) covers that path from the user's side.

Apple devices use [Automated Device Enrollment](https://support.apple.com/guide/deployment/automated-device-enrollment-management-dep73069dd57/web) through Apple Business, the service Apple previously called [Apple Business Manager](https://support.apple.com/guide/apple-business-manager/welcome/web). The device is managed from the moment it is taken out of the box, the user can be prevented from removing management, and a Mac running macOS 14 or later can be required to turn on FileVault disk encryption before anyone uses it.

![A laptop in a shipping box travels from a warehouse shelf to a desk in a house. The laptop connects over home Wi-Fi to the cloud, which sends an orange bundle of settings, security and apps down to it.](https://computese.com/images/blog/optimizing-remote-work-through-outsourced-it-help-desk-support/enrol.d293be5e4a-1536.webp)

*The laptop never passes through the IT office: its configuration comes from the cloud the first time it connects at home.*

In practice, a remote start runs in this order:

1. HR raises a service request with the start date, role and delivery address, early enough for shipping.
2. The desk orders a device through a reseller that registers it to your tenant, and ships it to the employee.
3. The account is created and added to role-based groups, so licences, apps and shared mailboxes follow from the role.
4. On day one, the desk verifies the person (by video call, compared with HR records) and gives them a Temporary Access Pass through that verified channel.
5. The employee signs in, registers a passkey, and the device enrols and becomes compliant.
6. The desk confirms that mail, files and the main business apps open, and closes the request with notes.

### Leaving: access first, device second

Offboarding a remote employee has a trap: the laptop is somewhere you cannot reach. Microsoft's guide to [revoking user access](https://learn.microsoft.com/en-us/entra/identity/users/users-revoke-access) sets out the order for an Entra ID account: disable the account, revoke its sessions (which invalidates refresh tokens), and disable the user's registered devices. Access tokens already issued stay valid until they expire, one hour by default, and applications that keep their own session cookies must be deprovisioned or have their sessions revoked separately.

Then the device. An Intune [wipe](https://learn.microsoft.com/en-us/intune/device-management/actions/wipe) factory-resets a company-owned device; a [retire](https://learn.microsoft.com/en-us/intune/device-management/actions/retire) removes company apps, settings and data but keeps personal content, which suits personal devices. Both act only when the device next connects: Microsoft notes that an offline device still has access to the data stored on it. Cutting the account's access first is what protects you in the meantime, and disk encryption protects whatever is still on the laptop until it is wiped or returned.

![An ID card's links to mail, files and chat are cut and padlocked. Below, an orange wipe command waits in the cloud because the laptop it is meant for is offline.](https://computese.com/images/blog/optimizing-remote-work-through-outsourced-it-help-desk-support/offboard.3158129bc3-1536.webp)

*Cut the account first: a wipe command only lands when the missing laptop next goes online.*

Close the loop with the hardware: a prepaid return box sent with the leaving date, the device marked in the asset register, and its Autopilot or Apple Business record kept so it can be reissued.

## Covering time zones and after-hours work

A remote team rarely keeps one office's hours. Before choosing a provider, map where your people work and when, then decide which kinds of problems deserve a human outside business hours. A sales team that cannot sign in at 7:00 in its own time zone is a business problem; a request for a new monitor can wait.

"24/7" means different things in different contracts. It can mean a person answers every call at every hour, an on-call engineer is paged for the top priority only, or tickets are logged overnight and picked up in the morning. Some providers run a follow-the-sun model, handing open tickets between regional teams as their days end, which works only if ticket notes are good enough for a stranger to continue the work.

Two practical questions complete the picture: which languages the desk answers in, and how hardware reaches people in other countries (spare devices, warranty repairs and returns). A lost laptop in another country is a logistics problem as much as a technical one.

## How to outsource IT support for remote employees, step by step

1. **Take stock.** List people, locations, time zones and working hours; company and personal devices by platform; your identity provider (Microsoft Entra ID, Google or another); the business apps; and who holds admin rights today.
2. **Decide the arrangement.** Fully managed, where the provider is the help desk and the administrators, or alongside an internal IT person, who keeps ownership while the provider takes the first lines, overflow and projects.
3. **Fix the foundation, or make it the first project.** Every company device enrolled in management, MFA on every account, one remote support tool, and a written onboarding and offboarding runbook.
4. **Shortlist providers** with the questions in the next section, and ask to see real, anonymized examples of their runbooks and monthly reports.
5. **Write the agreement** with the clauses below, including how the provider's own access works.
6. **Grant access properly.** Named accounts for each engineer in your tenant, MFA on all of them, the narrowest roles that do the job and, for a Microsoft partner, [granular delegated admin privileges](https://learn.microsoft.com/en-us/partner-center/customers/gdap-introduction) (GDAP), which are least-privilege and time-bound and must be granted explicitly by you.
7. **Tell your staff** how to reach the desk, which remote tool it uses, and how it will verify them before a reset.
8. **Review monthly** for the first quarter, then quarterly: tickets, trends and what the provider proposes to fix at the root.

## Questions to ask an outsourced IT support company for remote teams

| Question                                                                      | Why it matters for a remote team                                                |
| ----------------------------------------------------------------------------- | ------------------------------------------------------------------------------- |
| Which platforms do you manage every day: Windows, macOS, iOS, Android, Linux? | Remote staff cannot swap to a supported device down the corridor                |
| How do your engineers access our tenant?                                      | You want named accounts with MFA and scoped roles, never a shared admin login   |
| Which remote support tool will you use, and can we read its logs?             | Every fix is a remote session; you should be able to see who connected and when |
| How do you verify a caller before a password or MFA reset?                    | Help desks are a known social engineering target                                |
| Which hours and time zones does a person answer, in which languages?          | Coverage has to match where your people actually work                           |
| How do you ship, swap and collect devices in other countries?                 | A broken laptop abroad is a logistics problem as much as a technical one        |
| What happens when the contract ends?                                          | Documentation, admin accounts and the asset register must come back to you      |

## What to put in the agreement

The Canadian Centre for Cyber Security's guidance for [consumers of managed services](https://www.cyber.gc.ca/en/guidance/cyber-security-considerations-consumers-managed-services-itsm50030) starts from a point worth repeating: your organization remains the data owner and is legally responsible for its security. It recommends that the service level agreement specify turnaround times, communication channels, escalation processes, performance metrics and penalties for missed turnaround times, and it lists exit strategies and data destruction among the topics to settle before signing. A joint [advisory on managed service providers](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a) from the cyber security agencies of the UK, Australia, Canada, New Zealand and the United States (May 2022) adds the access rules: MFA on every provider account, no admin credentials reused across customers, least privilege, incident notification written into the contract, the most important logs kept for at least six months, and provider accounts disabled when the contract ends.

For a remote team, the agreement should cover at least:

| Clause                  | What to write down                                                                                              |
| ----------------------- | --------------------------------------------------------------------------------------------------------------- |
| Scope and exclusions    | Which users, devices, apps and locations are covered; which projects are quoted separately                      |
| Coverage                | Hours per region, after-hours arrangements by priority, public holidays, languages                              |
| Priorities              | Definitions by impact and urgency, with examples from remote work (one person locked out, a whole team offline) |
| Targets                 | Response and resolution or workaround targets for each priority                                                 |
| Channels and escalation | Phone, chat, email or portal; named escalation contacts on both sides                                           |
| Provider access         | Named accounts, MFA, least-privilege and time-bound roles, no shared or reused admin credentials                |
| Remote sessions         | The approved tool, user consent for attended sessions, where unattended access is allowed, log access           |
| Identity verification   | The written procedure for password and MFA resets, and who approves exceptions                                  |
| Security incidents      | How and how quickly the provider tells you about an incident affecting your environment                         |
| Reporting and review    | Monthly metrics, trends and recurring causes, reviewed in a meeting                                             |
| Exit                    | Handover of documentation and the asset register, return of admin credentials, accounts disabled                |

> [!IMPORTANT]
> Define "response" as a reply from a person who has read the ticket, not an automatic acknowledgement. Otherwise every target in the agreement can be met by an email robot while your employee is still locked out.

## How to measure whether it is working

The numbers worth watching are the ones a remote employee feels. Track them by priority and by region, and look at the trend rather than a single month.

| Metric                       | What it tells you                                                             |
| ---------------------------- | ----------------------------------------------------------------------------- |
| Time to first human response | Whether people are left waiting, especially outside the provider's main hours |
| Time to resolution           | Whether the targets in the agreement are met, and for which priorities        |
| First contact resolution     | How often the first person who answers can fix the problem                    |
| Reopened tickets             | Whether fixes hold, or tickets are closed too early                           |
| Recurring causes             | Whether the provider fixes root causes or resets the same thing every week    |
| Onboarding lead time         | Days from HR request to a new starter working on a compliant device           |
| Offboarding completion       | Time from the leaving date to account disabled, sessions revoked, device back |
| Device compliance            | Share of devices compliant and checking in within the validity period         |
| User satisfaction            | A one-question survey at ticket close, with the comments read                 |

A good provider brings these numbers to the review with an explanation and a proposal: the three causes behind most tickets this quarter, and what would remove them.

If you want help setting this up or running it, our [IT support service](https://computese.com/services/it-support/) covers the help desk, device management with Intune or Jamf, Microsoft 365 or Google Workspace administration, MFA and onboarding. Remote sessions happen only with your consent, and admin access goes to named engineers with multi-factor authentication and is removed when the work ends. More guides on running IT for a small team are in the [IT support](https://computese.com/category/it-support/) topic.

## Key terms
- **Service desk**: The single point of contact between an IT provider and the people it supports, where incidents and requests are logged, prioritized and tracked. ITIL treats it as one of its management practices.
- **Incident and service request**: An incident is something that stopped working or got worse, such as a laptop that will not start. A service request is something asked for that the desk already knows how to deliver, such as access to a shared mailbox.
- **Service level agreement (SLA)**: The written agreement between a provider and its customer on what is covered, when, and to which targets, for example the time to a first reply and to a resolution for each priority.
- **MDM and MAM**: Mobile device management (MDM) manages a whole enrolled device: settings, security, apps and wipe. Mobile application management (MAM) protects only work apps and their data, the usual choice for personal phones.
- **Conditional Access**: The Microsoft Entra ID policy engine that allows or blocks a sign-in using signals such as the user, the app, the location and whether the device is compliant with its Intune policies.
- **Zero-touch enrolment**: Setting a new device up from the cloud the first time it is turned on: Windows Autopilot for PCs, and Automated Device Enrollment through Apple Business for Apple devices.
- **Temporary Access Pass (TAP)**: A time-limited passcode in Microsoft Entra ID, single-use or multi-use, that lets a user sign in to register a passkey or other strong method, or to recover after losing one.
- **Phishing-resistant MFA**: Multifactor authentication that a fake site or a persuasive caller cannot trick out of the user: in practice FIDO2/WebAuthn passkeys and security keys, or certificate-based (PKI) sign-in.
- **Attended and unattended access**: In an attended session the user is present and accepts the connection. In unattended access an engineer connects without a user, which should be limited to company-owned, managed devices and logged.
- **GDAP**: Granular delegated admin privileges: the way a Microsoft partner receives least-privilege, time-bound admin roles in a customer's tenant, granted explicitly by the customer.

## Common questions

### What does an outsourced help desk do for remote employees?

It is their single point of contact for IT. It takes calls, chats and tickets, fixes device, account and app problems remotely, and handles requests such as new laptops and access changes. For a remote team it also runs the cloud tools that make remote fixes possible: device management, identity and MFA, and the remote support tool.

### How do you outsource IT support for remote workers?

List your people, devices and time zones, and decide whether the provider replaces or supports your own IT staff. Put device management and MFA in place, or make them the provider's first project. Then choose a provider, sign an agreement with priorities, hours and access rules, give its engineers named accounts in your tenant, and tell staff how to reach the desk and how it will verify them.

### What is outsourced remote desktop support, and is it safe?

It means the provider's engineers view or control an employee's computer over the internet to fix a problem. It is safe when the tool signs engineers in through your own identity provider, the user accepts each attended session, sessions are logged, and unattended access is limited to company-owned, managed devices. Staff should only accept a session they started by contacting the desk.

### Which endpoint tools does a remote help desk need?

At minimum: a device management platform (Microsoft Intune, or a Mac-specific one such as Jamf), an identity provider with MFA and Conditional Access, one approved remote support tool, and a ticketing system. The desk should be able to check a device's compliance state before it contacts the user.

### Can an outsourced help desk cover staff in several time zones?

Yes, but check what the agreement means by 24/7: a person answering at every hour, an on-call engineer for urgent priorities only, or tickets logged overnight for the morning. Map where your staff work and write down which priorities get a human reply in which hours, and in which languages.

### What should an outsourced help desk agreement include?

Scope and exclusions, coverage hours, priority definitions with response and resolution targets, channels, escalation contacts and reporting. For a remote team, add the access rules, the remote session rules, the caller verification procedure, how security incidents are reported to you, and an exit plan.

## Sources
1. [ITIL 4 Practitioner: Service Desk](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil4-practices-service-desk-3706), PeopleCert
2. [ITIL 4 Practitioner: Incident Management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil4-practices-incident-management-3684), PeopleCert
3. [ITIL4 Practices: Service Request Management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil4-practices-service-request-management-3690), PeopleCert
4. [ITIL 4 Practitioner: Service Level Management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil-4-practitioner-service-level-management-3867), PeopleCert
5. [SP 800-46 Rev. 2: Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security](https://csrc.nist.gov/pubs/sp/800/46/r2/final), NIST
6. [What is Microsoft Intune?](https://learn.microsoft.com/en-us/intune/fundamentals/what-is-intune), Microsoft Learn
7. [Device compliance policies in Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/compliance/overview), Microsoft Learn
8. [Use Quick Assist to help users](https://learn.microsoft.com/en-us/windows/client-management/client-tools/quick-assist), Microsoft Learn
9. [Use Remote Help to assist users authenticated by your organization](https://learn.microsoft.com/en-us/intune/remote-help/), Microsoft Learn
10. [Microsoft Intune advanced capabilities](https://learn.microsoft.com/en-us/intune/fundamentals/advanced-capabilities), Microsoft Learn
11. [Protecting Against Malicious Use of Remote Monitoring and Management Software (AA23-025A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a), CISA
12. [Microsoft Entra built-in roles](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference), Microsoft Learn
13. [Scattered Spider (AA23-320A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a), CISA
14. [Configure a Temporary Access Pass in Microsoft Entra ID to register passwordless authentication methods](https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass), Microsoft Learn
15. [Implementing Phishing-Resistant MFA](https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf), CISA
16. [Windows Autopilot registration overview](https://learn.microsoft.com/en-us/autopilot/registration-overview), Microsoft Learn
17. [Overview of Windows Autopilot](https://learn.microsoft.com/en-us/autopilot/overview), Microsoft Learn
18. [Automated Device Enrollment and device management](https://support.apple.com/guide/deployment/automated-device-enrollment-management-dep73069dd57/web), Apple Platform Deployment
19. [Apple Business Manager User Guide](https://support.apple.com/guide/apple-business-manager/welcome/web), Apple Support
20. [Revoke user access in an emergency in Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/users/users-revoke-access), Microsoft Learn
21. [Wipe devices with Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-management/actions/wipe), Microsoft Learn
22. [Device action: Retire](https://learn.microsoft.com/en-us/intune/device-management/actions/retire), Microsoft Learn
23. [Granular delegated admin privileges (GDAP) introduction](https://learn.microsoft.com/en-us/partner-center/customers/gdap-introduction), Microsoft Learn
24. [Cyber security considerations for consumers of managed services (ITSM.50.030)](https://www.cyber.gc.ca/en/guidance/cyber-security-considerations-consumers-managed-services-itsm50030), Canadian Centre for Cyber Security
25. [Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a), CISA
