Skip to content
End This At Any Time You can end a remote session at any time

All notes / Basics

Attended and Unattended: the Distinction That Matters

Whether somebody is present at the far end changes everything about the risk, and the two are routinely conflated.

Basics · Explainer

Attended access means somebody is at the machine, agreeing each time. Unattended means the connection can be made without anybody present. They are different propositions and the second is where most of the risk sits.

The practical lesson in “Attended and Unattended: the Distinction That Matters” is to make responsibility visible without confusing visibility with certainty. A team reviewing more details for attendance point system can add structured time and project context, provided the purpose is disclosed and the interpretation is checked with the people affected.

Attended

Somebody at the far end approves the connection.

For an independent reference related to “Attended and Unattended: the Distinction That Matters”, consult the ENISA cybersecurity resources; it provides a useful external check on security, privacy and operating assumptions before a process is adopted.

They can watch, and they can end it.

The session is bounded by their presence.

This is what most people picture when they think of remote support, and it is the safer arrangement by a wide margin.

Unattended

The connection can be made at any time, with no approval, to a machine with nobody in front of it.

Necessary for servers, for overnight work, for devices in cupboards and for estates managed at scale.

And it means a standing route into a machine, held by whoever holds the credentials.

Why unattended is where the risk is

No approval step means no moment where somebody could say no.

No presence means nobody notices.

And the access persists: it was granted once, for a reason that may have ended years ago.

Most remote-access incidents in organisations involve unattended access that nobody was reviewing.

The consumer version

Support tools installed on a family member's computer so you can help without them doing anything.

Convenient and genuinely useful.

And a standing connection into somebody's machine, which should be a deliberate choice rather than a side effect of one afternoon's troubleshooting.

Its own note covers setting this up safely.

The question to ask of any unattended access

Who can use it, how is that controlled, and when was it last reviewed?

If the answer to the last is never, the access has outlived whoever set it up.

Hybrid arrangements

Some tools permit unattended access with a notification, or with a prompt that times out into acceptance.

Better than silent, worse than attended.

And worth knowing which yours does, because the behaviour differs between products and between configurations.

What to prefer

Attended wherever a person is available.

Unattended only where it is necessary, with named holders, logging, and a review date.

The convenience of unattended is real and it is not free, which is the whole of this distinction.

What to check

How many machines do you have unattended access to?

Who else can use it?

When was that list last reviewed?

And does a family member's computer have a standing connection you set up and forgot?