Local Tech Fix (626) 655-0020
All articles

Setting Up Remote Access to Help a Parent With Their Computer

September 14, 2026

The tools are free and they work. The part nobody selling them mentions is that "install this, and read me the code" is also the scammer's script — so the routine you build around the software matters more than which software you pick.

Black remote control showing netflix, prime video, and disney+ buttons
Photo by Anthony Gomez on Unsplash

The call comes on a Sunday afternoon. Your mother is four hundred miles away, or two hours down the freeway in the Coachella Valley, and something on the computer has stopped working. You ask what the screen says. She reads you part of it. You ask her to click the thing in the top corner and she asks which corner. Twenty minutes later neither of you is any closer and you are both quietly annoyed. This is the point at which nearly everyone decides to install remote-access software, and it is the right decision — being able to see the screen turns a forty-minute phone call into a four-minute fix, and it is the single biggest quality-of-life improvement available to anyone who has become the family tech support department.

Before you install anything, though, there is one thing worth understanding, because the way this is normally set up quietly teaches an older relative the exact habit that the most expensive consumer scam in America depends on. The software is not the problem. Every tool named below is free, legitimate and made by a company you have heard of. The routine you build around it is what decides whether this ends well, and the routine is the part that no vendor writes about, because no vendor sells it.

The habit you are about to teach is the one the scam needs

Here is the ordinary version of remote help, the one described in every guide. You ring your parent. You tell them to download a program. You read them a code over the phone. They type it in, a box appears, they click Allow, and suddenly you are driving their computer and can actually see what is wrong.

Now here is the tech support scam. A stranger rings your parent. They tell them to download a program. They read them a code over the phone. Your parent types it in, a box appears, they click Allow, and suddenly someone is driving their computer.

Those two sequences are the same sequence. Every step is identical, and the only difference is who happens to be on the other end of the line — which is a judgement your parent has to make, under pressure, on the basis of a voice. Every time you use the first version, you are practising the second one with them. After the tenth time it stops feeling like a decision at all and starts feeling like a thing one does when a helpful person on the phone asks.

This is not a theoretical worry, and the sharpest evidence for it comes from Microsoft. In May 2024 Microsoft Threat Intelligence published a report on a financially motivated criminal group it tracks as Storm-1811, which since mid-April that year had been "misusing the client management tool Quick Assist to target users in social engineering attacks." Quick Assist is Microsoft's own free remote-help app — the one built into Windows 11. The pattern was: flood someone's inbox with junk by signing their address up to dozens of mailing lists, then telephone them impersonating IT support and offer to clear it up, walk them into a Quick Assist session, and from there deliver Qakbot, Cobalt Strike and finally Black Basta ransomware. By the end of that month the same group had added Microsoft Teams messages and calls as a second way to make first contact. Microsoft said it was "working on improving the transparency and trust between helpers and sharers, and incorporating warning messages in Quick Assist to alert users about possible tech support scams."

The lesson is not that Quick Assist is dangerous software. It is a perfectly good tool and we will come back to it. The lesson is that a criminal group with ransomware to deploy picked it, out of everything available, precisely because it is ordinary, free, already on the machine and completely unremarkable to see running. The weak point was never the program. It was a person who had learned that letting a helpful voice on the telephone into the computer is a normal Sunday afternoon activity.

The rule that fixes most of it: the call only ever goes one way

Microsoft's own instruction, on its own documentation page for its own tool, is worth quoting exactly: "Only allow a Helper to connect to your device if you initiated the interaction by contacting Microsoft Support or your IT support staff directly."

Read that forwards and it turns out not to be about Microsoft at all. It is a rule about the direction of the call. The thing that distinguishes a real remote-support session from a fraudulent one is not the software, not the code, not how professional anyone sounds — it is who dialled. A scam session always begins with an inbound approach: a pop-up with a number on it, a cold call, an alarming email, a text. A real one begins with the person who needs help deciding they need help.

So this is the rule to agree out loud with your parent before you install anything, and it costs nothing: they ring you. You never ring them and ask to be let in. Not once, not as a favour, not because you are between meetings and it would be quicker. If you are away and something needs checking, you phone and talk about it, and if it turns into a session you ask them to hang up and call you back. It feels faintly ridiculous for about a week and then it becomes automatic — and it is worth the ridiculousness because it converts an impossible judgement (is this person really who they claim to be?) into a fact that anyone can check without any technical knowledge at all: who made the call?

Write it on an index card and leave it by the machine, in whatever words your parent would actually use. Something like: nobody gets into this computer unless I picked up the phone and dialled the number myself. That card is doing more security work than any software on the list below.

One reason this matters more than it used to: a familiar voice is no longer evidence of anything. Cloned voices are cheap now, and the "grandchild in trouble" call is built on exactly that — we have written about those separately. Which is precisely why the test should be the direction of the call rather than the sound of the voice. A cloned voice can say anything at all. What it cannot do is make your mother's telephone be the one that placed the call.

Option one: the app already on the machine (Windows only, whatever else you have read)

If your parent is on Windows, there is a free remote-help tool already installed and you do not have to download anything: Quick Assist. On Windows 11 it is there by default; on Windows 10 it comes from the Microsoft Store. The quickest way to open it on either is the keyboard shortcut Ctrl + Windows key + Q, which is also a mercifully short thing to read down a phone line.

The flow, per Microsoft's documentation: you — the helper — open it and choose "Help someone," and you may be asked to sign in. Quick Assist generates a time-limited security code. You read that code to your parent, who types it into the "Security code from assistant" box under "Get help" and presses Submit. They then get a dialog asking permission to share their screen, and they choose Allow. At that point you can see the screen but you cannot touch it: taking over requires you to press "Request control," which produces a second, separate prompt they have to accept. Two deliberate consents, not one, which is a good design.

One structural detail is worth knowing because it explains everything above. In Microsoft's words: "The helper must have a Microsoft account. The sharer doesn't have to authenticate." The person being helped proves nothing and is identified as nobody. The entire security of the session rests on that one moment where they decide whether to type in the code they were just given. That is the whole system. It is also exactly why the direction-of-the-call rule is doing all the real work here.

A gotcha that catches people out, and it is not in most of the listicles: Quick Assist is not a way to help a parent with a Mac. Microsoft ships a macOS version, but its own documentation is explicit that "Quick Assist for macOS is available for interactions with Microsoft Support" and "is not available outside of Microsoft Support interactions." If your parent has a Mac, stop looking for it and read the next section.

Option two: the one that works when your parent has a Mac

Chrome Remote Desktop is free, made by Google, and works across Mac, Windows and Linux in any combination, which makes it the usual answer when the two households are not on the same platform. It has two quite different modes and choosing between them is the most consequential decision in this whole article.

The first mode is one-off support. Your parent goes to remotedesktop.google.com/support, downloads the small helper app under "Get Support," clicks Generate Code, and reads you the code. You go to the same address, enter the code under "Give support," and connect. Two things about that session are genuinely useful. The code, in Google's words, "will only work one time" — it is not a standing key. And when you connect, your parent does not just get a vague "someone wants in" box: they see a dialog showing your email address, and they have to press Share. That email address is the closest thing to a real identity check anywhere in consumer remote support, and it is worth making a point of it — teach your parent to read the address and confirm it is yours, character for character, before pressing anything. Google also builds in a nag: "you will be asked to confirm that you want to continue to share your computer every 30 minutes," so a forgotten session does not run all week.

Be honest with yourself about what the session grants, because Google is. Its own help page states it plainly: "You can give others remote access to your computer. They'll have full access to your apps, files, emails, documents, and history." That is not a warning aimed at families; it is a factual description of what you are asking someone to hand over, and it applies equally to you and to anybody impersonating you.

The drawback of this mode is the one we started with. It requires your parent to go to a web address, download a program and read a code aloud, in the moment, while something is already going wrong — which is the scammer's script, performed under exactly the conditions (something is broken, someone is helping) that make people compliant. If you use it, the index card is not optional.

While we are on Macs: Apple does include a Screen Sharing app, but read what Apple's own guide says it is for — viewing and controlling "the screen of another Mac on your network." It is a local-network tool, for the Mac in the next room, not a way to reach a house in another county. Do not spend an afternoon trying to make it work across the internet.

Option three, and the one we would usually pick: set it up once, in person, so nothing has to be accepted in the moment

Chrome Remote Desktop's second mode is standing remote access, and it inverts the whole problem. At remotedesktop.google.com/access you choose "Set up Remote Access," install the host component on the computer, and set a PIN. From then on that machine appears in the computer list for the Google account that set it up, and connecting is a matter of choosing it and entering the PIN. Nobody at the other end has to do anything. The machine simply has to be switched on.

Set that up while you are physically in the house, on a visit, when nothing is broken and nobody is stressed, and you have removed the dangerous step permanently. Your parent never learns the ritual. There is no program for them to download while a voice waits on the line, no code for them to read out, no Allow button for them to press. When something goes wrong, the entire procedure on their side is: pick up the phone and call you. Which means the day a stranger rings and starts talking them through installing something so he can help, the request is not familiar and reassuring — it is unlike anything their family has ever asked them to do. That unfamiliarity is the point, and it is a better defence than any amount of explaining.

Now the honest trade-off, because there is one. Standing access is a permanent door into that computer and you have to treat it like one. The PIN is the entire lock, so make it something that is not a birthday and not the same four digits as anything else. More importantly, whichever Google account you used during that setup is the account that can reach the machine from now on, so that account needs to be genuinely well defended — a strong unique password, two-factor authentication or a passkey, and recovery details that are current. If someone takes over your Google account, they have not just taken your email; they have taken your mother's computer. That is a fair price for removing the accept-a-stranger habit, but only if you actually pay it.

There is also an etiquette question that is not technical and matters anyway. Standing access means you can look whenever you like, and you should decide out loud, with them, that you will not. Say that you will tell them when you connect and what you did. A parent who suspects they are being watched will unplug the thing, and then you are back to describing corners over the telephone.

What to do while you are actually there

A visit is worth more than the software. Remote access only helps with problems that leave the computer switched on and online, so the point of the in-person hour is to reduce how often you get called about everything else.

Check the obvious physical dependency first: a computer that is asleep, shut down or unplugged cannot be reached, so if it lives on a desk that gets switched off at the wall each night, you will need them to turn it on before you can help. Decide together whether that is fine (usually it is) or whether the power settings should change.

Write down the internet details — the provider, the account holder's name, the Wi-Fi network name and password, where the router actually lives — and keep a copy. When the fault is the internet itself, remote access is useless by definition, and that is the moment you will want to know whether you are talking to a dead modem or a neighbourhood outage.

Check that the recovery email address and phone number on their Microsoft, Apple or Google account are ones they still control and can reach, and that you know what they are. This is the single most common cause of an unfixable remote session: something asks for a verification code, the code goes to an address nobody has opened since 2014, and there is nothing you can do from another city. It is a ten-minute job in person and an impossible one remotely.

Finally, deal with the printer while you are standing next to it. Printers are the most-called-about device in the house and one of the hardest to diagnose remotely, because the interesting information is a blinking light on a physical object nobody is looking at. Make sure it is on the right Wi-Fi network, that it has a static or reserved address if it keeps wandering off, and that the ink situation is understood.

When remote access is the wrong tool

Three situations where it will not help, so you do not waste an hour discovering that.

If the internet is down, nothing in this article works. That is the circular frustration of remote support: the fault you would most like to see is the one that blocks you from seeing it. Keep a fallback plan for that case — a phone that can act as a hotspot, or simply somebody local.

If the machine will not start, will not boot, makes a noise, smells hot, has been dropped or has had liquid on it, this is hardware and it needs hands. Same for a drive that is failing: every extra hour a dying disk spends powered on is an hour of data you might not get back, and the correct remote instruction is "switch it off and stop using it."

And if you have rung because a stranger has already been in the computer — a pop-up with a phone number, a call from "Microsoft," a session someone else started — do not begin by connecting remotely to look around. Get them to disconnect it from the internet first, which ends any live session immediately, and work the problem in the right order from there. We have a separate guide to precisely that situation, including what to do if money has already moved.

Take off what you are not going to use

Whichever option you settle on, remove the others. This is not tidiness; it is the same reasoning Microsoft gives its own corporate customers, which is to reduce risk "by blocking or uninstalling Quick Assist and other remote management tools if the tools are not in use in their environment." A remote-access program sitting unused on a computer is one more thing a convincing stranger can talk somebody into opening, and one fewer thing you will ever have to explain.

If you have settled on standing access and your parent will never use Quick Assist, it can go: Settings, then Apps, then Installed apps, find Quick Assist, uninstall. If you set up Chrome Remote Desktop for a one-off and do not want it left behind, the computer can be taken off the list — go to remotedesktop.google.com/access and choose "Disable remote connections" next to it — and the program itself removes through Add/Remove Programs on Windows, or the Chrome Remote Desktop Host Uninstaller on a Mac.

And if somebody else once had remote access — an old support contract, a company your parent paid after a pop-up, an ex-partner, a neighbour's helpful nephew — that counts too. Anything on that machine that can accept an incoming connection should be there because someone currently trusted put it there on purpose.

What we do, and how to check that it is really us

A lot of our work is the two ends of this: the adult child in Los Angeles, Orange County or the Bay Area whose parent is in Arcadia, Pasadena, Rancho Mirage or Palm Desert, and the parent at the other end who would rather ask someone local than be a burden. We are happy to be either the person who sets this up properly on a visit, or the ongoing answer so that one phone call does not always have to be to family.

We do not sell remote-access software and we take nothing from anyone who does. If you want to set it up yourself using the free tools above, that is the right answer for a lot of families and this article is the whole method — there is nothing held back.

The uncomfortable part of being in our trade is that we are one of the few kinds of business that legitimately asks people for remote access, which is the same thing the scammers ask for. So we hold ourselves to the rule in this article. We do not cold-call anyone about a virus, a problem detected on their computer, or an expiring subscription, because nobody legitimate does. Any session starts because you contacted us, on a number you looked up or already had, and if you are ever unsure whether the person asking is us, the correct move is to hang up and ring the number you know. We will not be offended; we will be pleased. And if what you actually need is somebody to tell you whether the alarming thing on the screen is real, that is a conversation, not a job, and it costs nothing to have it.

We work with households and small businesses across Southern California — the San Gabriel Valley, Orange County, the Inland Empire, the Coachella Valley, Ventura County and the coast — onsite or by remote support.

Keep reading

Free calculators

Service areas we cover

Want a second opinion before you buy?

We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.

Call (626) 655-0020

Gear we recommend

All gear →