Tip #80- Secure Connect: Add an Extra Layer Before You Connect – 'Insider Insights'

Tip #80- Secure Connect: Add an Extra Layer Before You Connect – 'Insider Insights'

Tip 80 – Secure Connect: Add an Extra Layer Before You Connect – 'Insider Insights'

Hello Zoho Assist Community!

Picture this: your support team relies on unattended access to keep the business running. Servers need overnight patches. Remote workstations need maintenance before the workday begins. A critical system goes down at 2 AM and someone needs to get in immediately, no end user available, no time to wait. Unattended access is what makes all of that possible, and for many IT and support teams, it's not a convenience. It's a backbone.

But think about what's sitting on those devices. Customer records. Financial data. Internal configurations. Proprietary software. The same machines your team needs fast access to are often the ones your organization can least afford to have accessed by the wrong person.

The challenge is that unattended access, by design, removes friction. Any technician in your organization with the right credentials can connect to a device, anytime, without anyone on the other end to accept the connection. That efficiency is exactly what you need, until it isn't. A compromised account, a shared password, or even an honest mistake can open the door to systems that should have stayed locked.

You don't want to slow your team down. But you also can't afford to leave sensitive devices with no second line of defense.

That's exactly the scenario Secure Connect is designed to prevent.

What is Secure Connect?

Secure Connect adds an extra layer of security to your unattended access sessions by requiring technicians to complete Multi-Factor Authentication (MFA) before connecting to any unattended device in the organization. It's not just about who has access, it's about verifying that the right person is connecting, every single time.

Note: Secure Connect is available exclusively in the Unattended Access – Professional edition, and settings can only be configured by Super Admins.

How to Enable Secure Connect

Navigate to Unattended Access  and select Settings and then choose Secure Connect. If MFA is already configured, enable the Authenticate before connecting to unattended devices checkbox. If MFA hasn't been set up yet, click Setup MFA, you'll be redirected to the Multi-Factor Authentication setup page to complete configuration. Once MFA is active, return to Secure Connect settings and enable the option.

That's it! From that point on, every technician in your organization will be prompted to verify their identity before connecting to an unattended device.



Reauthentication Time

Nobody wants to enter an MFA code every few minutes. Secure Connect includes a configurable reauthentication timeout, so technicians can reconnect to the same device within a set time window without being prompted again.

However, reauthentication is required when:

  • The configured time window expires.

  • The technician attempts to connect to a different device and then tries to connect to the earlier device.

This keeps security tight without creating unnecessary friction for your team's daily workflow.

Excluding Devices from Secure Connect

Some devices may not require the same level of verification, for example, low-risk or internal test machines. You can exclude specific devices from Secure Connect authentication without disabling the feature organization-wide.

To exclude a device you can go to Unattended Access followed by Settings and then select Secure Connect. Click Add an Exclusion and then select the devices to exclude,  they'll appear under the Excluded Devices section. Now you can remove a device from the exclusion list anytime using the delete icon.


Unattended access is one of the most powerful and sensitive capabilities in Zoho Assist. Secure Connect ensures it stays in the right hands.

Does your team already use MFA for Zoho Assist, or is Secure Connect something you're looking to set up? Drop your questions or experiences in the comments below, we'd love to hear how you approach security for unattended access!

For help or questions, reach out to us at support@zohoassist.com. We're always happy to help!