A remote access audit tells you exactly who can still get into your computers.
We go machine by machine and list every remote access tool installed, every account that can sign in, and every person outside the business who holds a credential. You get the inventory, a removal list you tick, and a second short session where the stale access actually comes off. From $90 per office up to 10 machines.
Why offices end up not knowing
Nobody sets out to leave six remote tools on a reception PC. It accumulates. The printer company installed one in 2021 to configure the copier. A contractor used another for a week. Someone's nephew put TeamViewer on to help with a spreadsheet. The accounts package vendor has a support agent that starts with Windows. Four years later the office has changed suppliers twice and every one of those still connects.
The audit is boring and that is the point. We open Programs and Features, the services list, the startup entries, the scheduled tasks and the installed browser extensions on each machine, and we write down what we find with the version and the install date. Then we look at accounts: local administrators, Microsoft 365 or Google Workspace admins, and anything with a shared password.
The most common finding, by a distance, is an RMM agent from a supplier the business stopped using. Second is a local admin account named after someone who left. Third is one password shared by four people, written on a sticky note that is now in a drawer.
| Row type | What we record | Verdict options |
|---|---|---|
| Remote access tool | Name, version, install date, machine, whether it starts with Windows | Keep / remove / ask supplier |
| Local account | Username, admin or standard, last sign-in | Keep / disable / delete |
| Cloud admin | Who holds global or billing admin in 365 or Workspace | Keep / reduce role |
| External credential holder | Supplier name, what they can reach, when it was granted | Keep / revoke |
| Shared password | What it opens and roughly how many people know it | Rotate / split |
| Router and Wi-Fi | Admin password still at default, guest network on or off | Change / leave |
Verdicts are yours. We recommend, you decide, and nothing is removed until you have ticked the row.
The removal list, and who pulls the trigger
The inventory comes back as a printed-style table, one row per finding, with a recommendation in plain words: remove, keep, or ask the supplier what it is for. You go down it and tick. We will not remove a tool because it looks unfamiliar, because the unfamiliar one is sometimes the thing that lets the copier scan to email.
Removal runs as a second short session, usually 30 to 60 minutes for an office of ten. Agents uninstalled, local accounts disabled rather than deleted first so anything that breaks can be put back, admin roles reduced, router admin password changed and handed to you in whatever password manager you use. We do not keep a copy.
Where a supplier holds access you still need, we do not revoke it behind their back. You get a line of text you can send them asking what the agent does and when it was last used. Several offices have found out that way that a supplier had not used the connection since 2022.
- Accounts disabled before deletion, so a mistake is a two-minute fix rather than a rebuild.
- New router admin password handed to you, never retained by us.
- A dated copy of the finished list, so next year's audit has a starting point.
- Our own access, if you keep any, appears on the same list as everyone else's.
How the audit runs
-
Scope call, ten minutes
How many machines, whether there is a server or a NAS, which cloud suite, and who has ever done IT work for you. Free, and it decides the price.
-
Machine sweep
Roughly 15 minutes per machine with someone watching. We read, we do not change. Anything we are not sure about is noted rather than guessed.
-
Accounts and cloud
Local admins, 365 or Workspace roles, router admin. This part is read-only too, and needs a sign-in from whoever currently holds it.
-
Inventory and recommendations to you
Usually the next working day. One row per finding, with the install date where we could read it, and a recommendation on each.
-
Removal session, once you have ticked
Only what you approved. At the end you get the same list again with the removed rows struck through and the date against each.
If you decide afterwards that you want us connected for routine work, that is unattended access setup and it gets its own named list. Our access is never a by-product of an audit.
When a remote access audit is worth the ninety dollars
Right after a staff member with admin rights leaves. When you change IT suppliers. When a business is bought or merged and nobody can say what the other side's contractor still reaches. Before an insurer or a client asks you to describe your access controls in writing. And when a technician inherits a client's office and has no documentation at all, which is the reason most of these are booked by the shops we work with.
Not worth it for a single home computer. One machine, one person, one answer: open Programs and Features and look. Book a 30-minute session instead and we will go through it with you for less.
We also do not run penetration tests, scan your network for vulnerabilities, or issue a compliance certificate. The audit is an inventory of access, not a security assessment, and we will not let it be described as one.
What people want to know before letting us look
Call +1 (899) 555-5520 during booking hours if yours is not here.
Asking a remote support company to audit remote access is a fair thing to be uneasy about. So our own access goes on the same list, with the same verdict column.
What we store, and for how longWe keep the inventory document so next year's audit has a baseline, and you can ask us to delete it. We never keep passwords, including the new router password, which goes straight to you.
A small file server or NAS, yes, as an extra line on the quote. A domain controller with group policy and a dozen service accounts is past what a remote sweep does honestly, and we will say so on the scope call.
Not during the audit, because nothing is changed. At removal we disable before deleting and we do the riskier rows first thing in a session, never at 17:45 on a Friday.
No. It is an inventory of who can reach your machines and a list of what you chose to remove. We hold no certifications, we do not issue any, and we will not let the document be presented as an audit report from an accredited body.
Unplug the network cable or turn off the Wi-Fi on that machine first, then call. An audit is the wrong order of operations when something is live. We will tell you the three things to do before we connect at all.
Find out what is still installed.
Machine count, cloud suite, and who has done IT work for you in the last five years. The scope call is ten minutes and costs nothing.
- Phone+1 (899) 555-5520
- Email[email protected]
- Address74 Cedar Court, Office 12
Austin, Texas 95088 - HoursMon to Fri 8:00 to 18:00 CT