US-based RMM platform · Lancaster, Pennsylvania Support Mon–Fri, 8:00 AM – 8:00 PM ET
Architecture and rollout

How ITSupport RMM works, end to end

A signed agent on each endpoint, an outbound-only encrypted connection, and a browser console for your team. No on-premises servers to maintain, no inbound firewall rules, no VPN dependency.

Structured network cabling patched into a switch inside a communications rack

The three components

There are only three moving parts, which is deliberate. Fewer components means fewer failure modes and a shorter security review.

1. The endpoint agent

A code-signed service installed on each managed device. It collects performance and inventory data, evaluates the policies assigned to that device, executes approved scripts and patch jobs, and brokers remote sessions. It is visible in the installed-programs list and can be removed with a documented command.

2. The cloud platform

Hosted in United States data center regions for US accounts. It stores telemetry, inventory, policies, scripts and audit records; runs the alerting and automation engines; and serves the console API. Multi-tenant isolation is enforced at the data layer, not only in the interface.

3. The browser console

Works in current versions of Chrome, Edge, Firefox and Safari. No plug-in, no desktop client required. Technicians authenticate with MFA, see only the tenants their role allows, and can launch a remote session directly from an alert or asset record.

Connectivity: outbound only, port 443

Every agent initiates its own connection outbound to the platform over TCP port 443 using TLS 1.2 or higher. That single design decision removes most of the network work usually associated with deploying an RMM:

  • No inbound NAT rules or port forwarding on client firewalls
  • No site-to-site VPN required to support a remote worker
  • Works behind CGNAT, hotel Wi-Fi and cellular hotspots
  • HTTP/HTTPS proxy and PAC configurations are supported
  • Certificate pinning on the agent side to resist interception
  • A documented allow-list of platform hostnames for tightly filtered networks

If an endpoint loses connectivity, the agent continues evaluating local policies, queues results, and uploads them when the link returns, so a laptop that spent a week offline does not create a gap in your patch evidence.

Network equipment rack with patch panels and indicator lights

A rollout plan that fits four weeks

This is the plan our onboarding team walks through with new accounts. It is included with every plan; we do not charge implementation fees.

Week 1

Structure and pilot

  • Create the tenant tree: organization, clients or business units, sites, device groups
  • Invite technicians and set roles; enable MFA for everyone
  • Deploy agents to a 10–25 device pilot group covering each OS you support
  • Validate inventory accuracy and remote session performance
Week 2

Monitoring policies

  • Start from baseline templates for workstations, servers and domain controllers
  • Tune thresholds and durations against real data from the pilot
  • Configure escalation chains, on-call routing and maintenance windows
  • Connect alert delivery to email and your ticketing system
Week 3

Patching and automation

  • Define approval rings and reboot behavior per client
  • Enable third-party application patching where licensed
  • Attach automatic remediation to your five noisiest alert types
  • Review the script library and submit any custom scripts for approval
Week 4

Scale out and report

  • Push agents to the remaining fleet, tenant by tenant
  • Reconcile agent counts against your asset records and billing
  • Schedule client-facing and internal reports
  • Decommission the previous RMM agent where applicable

Deployment methods for the agent

Choose whatever already works in your environment. The installer is per tenant, so devices land in the correct client automatically.

Supported installation approaches. All installers are code-signed and support silent installation.
EnvironmentMethodNotes
Windows domainGroup Policy software installation or startup scriptMSI with silent switches and a tenant token
Microsoft Entra joinedIntune Win32 app deploymentAssign per device group; detection rule provided
Existing RMM in placePush the installer as a script from your current toolAgents can coexist during migration
macOSSigned PKG, MDM deployment, or a single terminal commandIncludes the profile guidance needed for screen recording and accessibility permissions
LinuxDEB and RPM packages, or a shell installerRuns as a systemd service
Unmanaged / walk-up devicesDirect download link from the tenantUseful for BYOD support and one-off servers

macOS remote control requires the user or your MDM to grant screen recording and accessibility permissions; this is an Apple platform requirement, and we document the exact configuration profile keys needed.

Team of IT specialists collaborating at workstations in an open office

What happens after go-live

Onboarding is not a hand-off into silence. Every account gets a documented escalation path and a review cadence.

  • Onboarding sessions. Guided configuration calls during your first 30 days, included on all plans.
  • Support channels. Email and in-console tickets on Core; phone plus a 24/7 emergency line on Professional and Enterprise. Response targets are published in the SLA.
  • Change communication. Platform release notes, advance notice of scheduled maintenance windows, and a public status page.
  • Quarterly reviews. Optional configuration reviews to retire alerts nobody acts on and tighten patch policies as your fleet changes.
  • Exit path. If you leave, you can export inventory, policies, scripts and audit history through the API or as CSV. We do not hold your operational data hostage.