Introduction
This FAQ explains security for in-Band Remote Connect in HP Workforce Experience Platform (WXP). It covers access, consent, user control, encryption, device changes, cloud infrastructure, session history, and tenant-level control.
1. Who can start a Remote Connect session?
A Remote Connect session can be generated only through an authenticated WXP account.
The support provider must have the required entitlement in WXP. Role-based access controls help ensure that only authorized users can start a session.
2. How is consent established between the support provider and the support recipient?
Before the session starts, WXP uses a one-time session code to support consent. The support recipient shares the code with the support provider, and the support provider enters the code to start the session.
3. Does the support recipient have control over the device during the session?
Both the support provider and the support recipient can use the keyboard and mouse during the live session.
Either person can end the remote session at any time.
4. How is data protected during an active session?
All in-session communication is protected from end to end by AES-256 encryption standards over UDP.
5. Can the support provider make changes to the device and its files?
The support provider controls the device through the account of the support recipient. As a result, the support provider can make changes during the session on behalf of the support recipient.
The support provider can elevate to administrator permissions when required.
6. How secure is the cloud infrastructure that hosts this service?
Remote Connect uses a gateway service to connect across network boundaries without a VPN. The gateway infrastructure is hosted in the public cloud. Connections can be made only by endpoints that present signed connection tokens.
7. Is Remote Connect session history stored and available?
Remote Connect session data is not available directly in WXP at this time. HP plans to provide session history data in a later release. This data may include session timestamps and the users who were involved in each session.
8. Can the Remote Connect feature be disabled?
Yes. Remote Connect can be turned on or off for each tenant that hosts devices. This setting gives administrators control over whether the service is available for the tenant.
Contact Us
For help, create a support case or email support@wxp.hp.com.