{"id":3236,"date":"2026-06-18T14:56:39","date_gmt":"2026-06-18T14:56:39","guid":{"rendered":"https:\/\/zecurit.com\/help\/remote-access\/unattended-remote-access\/session-confirmation-settings\/"},"modified":"2026-06-18T17:26:31","modified_gmt":"2026-06-18T17:26:31","slug":"session-confirmation","status":"publish","type":"docs","link":"https:\/\/zecurit.com\/help\/remote-access\/unattended-remote-access\/session-confirmation\/","title":{"rendered":"Session Confirmation Settings"},"content":{"rendered":"\n<p>Session Confirmation Settings allow organizations to control how remote access requests are approved before a technician can connect to a device. This feature helps improve security, protect user privacy, and ensure compliance with organizational policies by requiring end-user consent before a remote session begins.<\/p>\n\n\n\n<p>Session Confirmation is particularly useful in environments where users handle sensitive information or where regulatory requirements mandate explicit approval before remote access is granted.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"513\" src=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/06\/User-Confirmation-Settings-1024x513.webp\" alt=\"Remote access user conformation prompt settings.\" class=\"wp-image-3238\" srcset=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/06\/User-Confirmation-Settings-1024x513.webp 1024w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/06\/User-Confirmation-Settings-300x150.webp 300w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/06\/User-Confirmation-Settings-768x385.webp 768w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/06\/User-Confirmation-Settings-1536x769.webp 1536w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/06\/User-Confirmation-Settings-2048x1026.webp 2048w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/06\/User-Confirmation-Settings-1000x500.webp 1000w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p>By default, unattended remote access allows authorized technicians to connect directly to managed devices. However, some organizations may prefer to notify users and request permission before a session starts.<\/p>\n\n\n\n<p>When Session Confirmation is enabled:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>A notification is displayed on the remote device.<\/li>\n\n\n\n<li>The user is informed that a technician is requesting access.<\/li>\n\n\n\n<li>The user can approve or deny the request.<\/li>\n\n\n\n<li>The remote session begins only after approval.<\/li>\n<\/ol>\n\n\n\n<p>This provides transparency and helps users understand when their devices are being accessed remotely.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Benefits of Session Confirmation<\/h2>\n\n\n\n<p>Session Confirmation provides several advantages:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Enhanced Security<\/h3>\n\n\n\n<p>Users are notified whenever a remote connection is requested, helping prevent unauthorized access.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Improved Privacy<\/h3>\n\n\n\n<p>Employees maintain visibility and control over remote access sessions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Regulatory Compliance<\/h3>\n\n\n\n<p>Many organizations use Session Confirmation to support compliance initiatives and internal security policies.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Increased User Trust<\/h3>\n\n\n\n<p>Users are more comfortable with remote support when they know access requires their approval.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Reduced Support Disputes<\/h3>\n\n\n\n<p>Approval records provide visibility into when remote sessions were requested and accepted.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Accessing Session Confirmation Settings<\/h2>\n\n\n\n<p>To configure Session Confirmation:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Navigate to <strong>Remote Tab<\/strong>.<\/li>\n\n\n\n<li>Click <strong>User Confirmation<\/strong>.<\/li>\n\n\n\n<li>Configure the required settings.<\/li>\n\n\n\n<li>Click <strong>Save Changes<\/strong>.<\/li>\n<\/ol>\n\n\n\n<p>All changes apply to future remote access requests.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Enable User Confirmation<\/h2>\n\n\n\n<p>The <strong>Enable User Confirmation<\/strong> option controls whether users must approve remote access requests.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Enabled<\/h3>\n\n\n\n<p>When enabled:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Users receive a confirmation prompt.<\/li>\n\n\n\n<li>The technician must wait for approval.<\/li>\n\n\n\n<li>Remote access begins only after consent is granted.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Disabled<\/h3>\n\n\n\n<p>When disabled:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Approved technicians can connect immediately.<\/li>\n\n\n\n<li>No confirmation prompt is displayed.<\/li>\n\n\n\n<li>Devices operate in unattended access mode.<\/li>\n<\/ul>\n\n\n\n<p>This option is commonly used for servers, kiosks, and other managed systems that require continuous administrative access.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Confirmation Timeout<\/h2>\n\n\n\n<p>The <strong>Timeout<\/strong> setting specifies how long the confirmation request remains active before it expires.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Example<\/h3>\n\n\n\n<p>If the timeout value is set to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>120 Seconds\n<\/code><\/pre>\n\n\n\n<p>The user has 120 seconds to respond.<\/p>\n\n\n\n<p>If no action is taken:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The request expires automatically.<\/li>\n\n\n\n<li>The connection attempt is cancelled.<\/li>\n\n\n\n<li>The technician must initiate a new request.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Customizing the Prompt Message<\/h2>\n\n\n\n<p>Administrators can customize the message displayed to users when a remote connection is requested.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Example Prompt<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>$username$ is requesting remote access to your device.\nWould you like to grant permission for this session?\n<\/code><\/pre>\n\n\n\n<p>The prompt should clearly explain:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Who is requesting access<\/li>\n\n\n\n<li>Why access is needed<\/li>\n\n\n\n<li>What action the user should take<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Dynamic Variables<\/h3>\n\n\n\n<p>Session Confirmation supports dynamic variables that are automatically replaced when the message is displayed.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">$username$<\/h4>\n\n\n\n<p>Displays the name of the technician requesting access.<\/p>\n\n\n\n<p>Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>John Smith is requesting remote access to your device.\nWould you like to grant permission for this session?\n<\/code><\/pre>\n\n\n\n<p>This provides users with clear information about who is attempting to connect.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Writing Effective Prompt Messages<\/h3>\n\n\n\n<p>Use clear and professional language.<\/p>\n\n\n\n<p>Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$username$ from the IT Support team is requesting remote access to your device to assist with troubleshooting. Do you want to allow this session?\n<\/code><\/pre>\n\n\n\n<p>This helps users make informed decisions and improves approval rates.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Excluding Devices and Device Groups<\/h2>\n\n\n\n<p>Some devices may require continuous unattended access and should not require user confirmation.<\/p>\n\n\n\n<p>The <strong>Exclude Computers<\/strong> section allows administrators to exempt selected device groups from Session Confirmation requirements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Common Exclusion Scenarios<\/h3>\n\n\n\n<p>Organizations often exclude:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Servers<\/li>\n\n\n\n<li>Kiosks<\/li>\n\n\n\n<li>Shared Devices<\/li>\n\n\n\n<li>Conference Room Systems<\/li>\n\n\n\n<li>Test Environments<\/li>\n\n\n\n<li>Digital Signage Devices<\/li>\n\n\n\n<li>IT Administration Workstations<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Excluding a Device Group<\/h3>\n\n\n\n<p>To exclude a group:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open <strong>User Confirmation Settings<\/strong>.<\/li>\n\n\n\n<li>Navigate to <strong>Exclude Computers<\/strong>.<\/li>\n\n\n\n<li>Click <strong>Exclude Group<\/strong>.<\/li>\n\n\n\n<li>Select the desired device group.<\/li>\n\n\n\n<li>Save the configuration.<\/li>\n<\/ol>\n\n\n\n<p>Devices within the selected group will bypass confirmation prompts.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Exclusion List Information<\/h3>\n\n\n\n<p>The exclusion table displays:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Field<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td>Group Name<\/td><td>Name of the excluded device group<\/td><\/tr><tr><td>Excluded By<\/td><td>Administrator who created the exclusion<\/td><\/tr><tr><td>Excluded Time<\/td><td>Date and time of exclusion<\/td><\/tr><tr><td>Action<\/td><td>Available management actions<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Administrators can review and modify exclusions at any time.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">When to Use Session Confirmation<\/h2>\n\n\n\n<p>Session Confirmation is recommended in the following environments:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Corporate Employee Devices<\/h3>\n\n\n\n<p>Employees should be aware when support staff access their systems.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Remote Workforce<\/h3>\n\n\n\n<p>Provides visibility and transparency for remote employees.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Privacy-Sensitive Environments<\/h3>\n\n\n\n<p>Useful when devices contain personal or confidential information.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Regulated Industries<\/h3>\n\n\n\n<p>Often required to support organizational security policies and audit requirements.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">When to Use Unattended Access Instead<\/h2>\n\n\n\n<p>Session Confirmation may not be appropriate for:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Servers<\/h3>\n\n\n\n<p>Servers typically require immediate administrative access.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Data Center Systems<\/h3>\n\n\n\n<p>Infrastructure devices often need continuous remote management.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Kiosks<\/h3>\n\n\n\n<p>Interactive kiosks usually operate without active users.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Shared Devices<\/h3>\n\n\n\n<p>Confirmation prompts may not be practical when multiple users share the same endpoint.<\/p>\n\n\n\n<p>For these scenarios, consider using device group exclusions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Best Practices<\/h2>\n\n\n\n<p>To maximize security and user experience:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Enable Confirmation for User Devices<\/h3>\n\n\n\n<p>Require approval on employee workstations whenever possible.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Use Clear Prompt Messages<\/h3>\n\n\n\n<p>Ensure users understand who is requesting access and why.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Configure Appropriate Timeouts<\/h3>\n\n\n\n<p>Avoid excessively long approval windows.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Review Excluded Groups Regularly<\/h3>\n\n\n\n<p>Periodically verify that exclusions remain necessary.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Limit Administrative Access<\/h3>\n\n\n\n<p>Use role-based access controls to ensure only authorized technicians can initiate remote sessions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Maintain Audit Records<\/h3>\n\n\n\n<p>Review remote access logs and approval activity regularly.<\/p>\n\n\n\n<p>As recommended by the National Institute of Standards and Technology (NIST), organizations should implement access controls, user consent mechanisms, and activity monitoring to help secure remote access environments.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What happens if the user does not respond?<\/h3>\n\n\n\n<p>The request expires when the configured timeout period is reached.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can users deny access?<\/h3>\n\n\n\n<p>Yes. Users can decline the request, preventing the session from starting.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can administrators bypass confirmation?<\/h3>\n\n\n\n<p>Yes. Devices or device groups can be excluded from Session Confirmation requirements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does Session Confirmation affect unattended access?<\/h3>\n\n\n\n<p>Only devices that are not excluded will require approval. Excluded devices continue to support unattended remote access.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Are approval requests logged?<\/h3>\n\n\n\n<p>Yes. Approval activity can be audited through remote access logs and reporting features.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related Articles<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/zecurit.com\/help\/remote-access\/unattended-remote-access\/overview\/\">Unattended Remote Access Overview<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/zecurit.com\/help\/remote-access\/unattended-remote-access\/managing-devices\/\">Managing Devices<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/zecurit.com\/help\/remote-access\/unattended-remote-access\/remote-connections\/\">Remote Connections<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/zecurit.com\/help\/remote-access\/unattended-remote-access\/session-features\/\">Session Features<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/zecurit.com\/help\/remote-access\/settings\/preferences\/\">Preferences<\/a><\/li>\n\n\n\n<li>Security and Permissions<\/li>\n\n\n\n<li>Remote Support Overview<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n","protected":false},"featured_media":0,"parent":3193,"menu_order":1,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-3236","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3236","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/comments?post=3236"}],"version-history":[{"count":2,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3236\/revisions"}],"predecessor-version":[{"id":3248,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3236\/revisions\/3248"}],"up":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3193"}],"prev":[{"title":"Unattended Remote Access Overview","link":"https:\/\/zecurit.com\/help\/remote-access\/unattended-remote-access\/overview\/","href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3197"}],"wp:attachment":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/media?parent=3236"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/doc_tag?post=3236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}