Guide

Configure and use Staff Assist

Let authorized Windows and macOS users request help from tenant response groups without distributing a different installer to every person.

Tenant administrators, endpoint administrators, responders, and authorized requesters10 min readUpdated July 26, 2026

Understand the identity boundary

  • Deploy one tenant-bound Windows or macOS package through the organization’s normal device-management system. The installer is not unique to a person.
  • The desktop app reads the signed-in OS principal, directory email when published, domain, and stable local directory identifier only to help start pairing.
  • An OS username or email hint never grants access. The user completes the tenant’s verified sign-in, and the resulting authorization is bound to that tenant, account, desktop registration, and OS credential store.
  • DMTG Alerts rechecks active account status and the Staff Assist Requester permission on every request. Removing access takes effect without rebuilding the application.

Prepare response teams

  1. Open Alerts → Staff Assist and create one or more response groups, such as Medical Response or Facilities.
  2. Choose the Staff Assist alert procedure, expiry, and responders. Directory-managed responders and manually selected responders remain separate.
  3. For OIDC, open Single sign-on → Directory group access and map the provider’s immutable group or app-role value to a Staff Assist response group.
  4. While Staff Assist is still disabled, ask each responder to open Request Staff Assist once and verify their organization account on every desktop where they should receive targeted requests.
  5. Confirm the paired-device count for the response group, then enable Staff Assist.

Grant requester access

  1. Assign the Staff Assist Requester role directly, or map a reviewed provider group to that role.
  2. Enable Staff Assist only after at least one response group has an active paired responder device.
  3. Pilot with a clearly labeled exercise and verify delivery, acknowledgement, expiry, and audit evidence.

Request help from the desktop app

  1. Choose Request Staff Assist from the Windows notification-area icon or macOS menu-bar icon.
  2. On first use, complete organization sign-in in the system browser and confirm the code shown by the application.
  3. Choose the response team, add only non-sensitive helpful details, and review the confirmation.
  4. Send the request. The application reports how many currently authorized responder devices were targeted.

Revoke and troubleshoot

  • Suspend the tenant account, remove the requester role, remove the responder from the response group, revoke the desktop registration, or remove the SSO mapping as appropriate. Runtime checks apply the change without a new installer.
  • If no responder device is available, pair a responder desktop and verify its location and device registration are active.
  • Provider group changes are reconciled at verified sign-in. Removing a DMTG group mapping revokes access created by that mapping immediately while preserving manual assignments.