Use one remote support tool, deployed by policy, with named technician accounts and MFA (Multi-Factor Authentication) on the console. Ad-hoc consumer tools invited by email are exactly how attackers get in — and once staff are used to 'IT (Information Technology) asks me to install a remote tool', social engineering becomes trivial.
Always announce and consent: the user should see who connected, when, and be able to end the session. Unattended access should be limited to servers and clearly documented machines, not every laptop.
Keep a support script: confirm identity, confirm the symptom, take control, narrate what you are doing, verify with the user, disconnect, document. Narrating is not a courtesy — it teaches the user, reduces repeat tickets, and builds the trust that keeps you in the building.
Know your remote limits. Firmware, encryption recovery, hardware failure and a dead network need hands on site. Recognising that in the first five minutes is a skill, not a failure.