Unattended Access to Shop Computers: The Setup That's Convenient AND Defensible

How to set up always-on remote access to shop machines properly — agent as a service, named users, MFA, approval posture, audit — and the mistakes that turn convenience into exposure.
Unattended Access to Shop Computers: The Setup That's Convenient AND Defensible
TL;DR
Unattended access — always-on machines you can reach with nobody at the keyboard — is the single highest-value arrangement in shop remote work and the one most often secured like a garden shed. The value: the diagnostic station answers questions at 9 PM, the front-office PC gets fixed Sunday, the 3 AM Windows update doesn't cost a 7 AM drive. The risk: a standing door into machines that program keys and hold customer data. This guide is the setup that keeps both truths in view: agent as a service, a short deliberate machine list, named users with MFA, Admin Mode for lock screens, and records of everything. Skip the discipline and you have built exposure with a subscription.
Why unattended is the arrangement worth doing right
Attended remote help — someone at the machine clicks "allow" — is easy to secure because consent is built into the workflow. It is also barely worth the setup: if someone is standing there, half the value of remoteness is gone.
The real returns live unattended:
- The diagnostic station consulted from a kitchen table after hours;
- The front-office PC running shop management software, maintainable without closing the counter;
- The multi-location owner's ability to be functionally present at three stores;
- Update recovery — the machine that rebooted overnight and came back reachable on its own.
Every one of those requires standing access with no human gatekeeper — which is exactly why the controls have to be structural.
The setup, in order
1. Choose the machines deliberately
Unattended access is per-machine exposure, so the list is a decision, not a default. The usual right answer: diagnostic/programming stations, the front-office PC, maybe a utility box. The usual wrong answer: "install it everywhere, it's unlimited." (On IgniteRemote it is unlimited computers — no per-machine charge — which is precisely why the restraint has to come from you.) Write the list down; review it quarterly; shorten it when in doubt.
2. Install the agent as a service
Run-when-launched tools die at reboot and sign-out. A service-level agent starts at boot, before login, and survives updates — the difference between "unattended in theory" and reachable at 7 AM after patch night. This is also the foundation Admin Mode builds on: lock-screen sign-in and UAC handling need the elevated service context.
3. Named users, MFA, per-machine assignment
The rule that separates infrastructure from exposure: every connection is a person. Named accounts for each user; MFA on all of them; access assigned per machine and per role — the new tech gets the stations, not the office PC with payroll open. And the quiet superpower of accounts over shared secrets: offboarding is one click, not a password-rotation project. The security checklist formalizes all of this.
4. Decide the visibility posture
Attended machines can demand approval at the keyboard. For genuinely unattended ones, choose consciously how presence is signaled and what stands in for consent: connection notifications, on-screen indication during sessions, and — non-negotiable — complete records. IgniteRemote's default posture is approval at the machine where a human is present, with named-and-logged access carrying the weight where one isn't.
5. Records: the substitute for the human who isn't there
Unattended access without records is the unwinnable dispute: something changed overnight, and the answer to "who and what" is a shrug. The two-piece answer:
- Audit logging — who connected, to which machine, when;
- Session recording — what they did, replayable.
Both are included in the IgniteRemote plan, and on unattended machines they are not optional extras — they are the supervision.
The mistakes that turn convenience into exposure
| Mistake | Why it bites | The fix |
|---|---|---|
| Shared static password on a standing machine | Unrotated, widely known, unlogged | Named users + MFA, always |
| "Install it everywhere" | Every machine is standing exposure | Short deliberate list |
| Run-when-launched agent | Dies at reboot; access is theater | Service-level install |
| No records on unattended machines | Disputes become memory contests | Logging + recording on |
| Nobody owns offboarding | Ex-employees retain access | Accounts die the day people leave |
| Free personal-tier tools for standing business access | Detection interrupts you; no audit anyway | Pay someone, on purpose |
The one-afternoon rollout
- Write the machine list (aim for three or fewer to start).
- Install the agent as a service on each; confirm it survives a reboot before you need it to.
- Create named accounts for everyone who will connect; turn MFA on; assign per machine.
- Turn on recording and confirm the audit log shows your own test session.
- Do one real after-hours task from home — the update, the file fetch, the setting change — and let the convenience argue for itself.
On IgniteRemote the whole arrangement — service agent, named users, MFA, Admin Mode, recording, audit — ships in the one plan at $24.90/month or $249/year, unlimited computers and technicians (pricing), with sessions from any browser (architecture). The standing candor line: USB passthrough is in development and included when it launches; unattended access as described here ships today, and it is the foundation the rest of the remote workflow — diagnostics, training, multi-store management — stands on.
The closing test for any unattended setup, ours or anyone's: if the machine did something surprising last night, could you say who, when, and what by lunchtime? If yes, you built infrastructure. If no, you built a door.