📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Multi-tenant remote support

Best multi-tenant remote support tools for MSPs

Lavawall® is a multi-tenant RMM and remote support platform for MSPs and IT teams, with patching, security monitoring, Microsoft 365 and Google Workspace breach detection, and compliance built into the same agent and console. Technicians get browser-based remote control, a background admin workspace, and a remote shell on Windows and Mac, scripting on Linux, and ad-hoc support for computers without the agent, with end-to-end encrypted sessions available. Lavawall can run on its own as your RMM, or be installed through Datto RMM, NinjaOne, ConnectWise, Kaseya, Intune, or any tool that runs a script, while you move over. Bomgar and BeyondTrust deliver enterprise-grade remote support at enterprise pricing. ConnectWise ScreenConnect, Splashtop, and TeamViewer cover the SMB tier. Datto RMM and NinjaOne are other RMMs with their own remote tools.

Start free, no credit card See what to look for

The short answer: the best remote-support tool for an MSP runs in the browser, isolates every client tenant, restricts access to approved countries by default, secures each session with TLS-in-TLS and mutual certificates, and logs every session for compliance. Lavawall® does all of this with nothing to install on the technician’s side, adds an Admin Workspace for work that doesn’t interrupt the user, and bundles remote support with patching, GRC, breach detection, helpdesk, and SaaS and shadow-AI discovery in one console.

Why remote support is a security decision

Remote support is critical infrastructure for a managed service provider. Most MSPs rely on ConnectWise ScreenConnect, Splashtop, TeamViewer, AnyDesk, or BeyondTrust and Bomgar. The trouble is that a remote-support session is exactly the high-value, lateral-movement target attackers look for, and security defaults vary from tool to tool.

The pattern worth adopting has four traits: it is browser-based, multi-tenant by default, country-restricted by default, and bundled with the rest of the platform so it is not one more standalone invoice.

What to look for in multi-tenant remote support

Seven criteria for MSP-grade remote support.

Browser-based operator workflow

Technicians should not need a heavy native client to start a session.

Multi-tenant by default

Per-client isolation, technician access limited to entitled tenants, and per-client branding.

Country-level access restrictions by default

An approved-country list as the default access control.

Mutual cert authentication and TLS-in-TLS tunnelling

Remote-support sessions are exactly the high-value lateral-movement target attackers look for.

An admin workspace that leaves the user alone

A shell and admin tools without disturbing the user. Lavawall's Admin Workspace gives the technician 19 Windows tools and three shells (PowerShell as system, PowerShell as the logged-in user, and Command Prompt as system), and a root zsh shell on Mac, while the user keeps working undisturbed. It extends the real built-in Windows admin apps (grouped Task Manager, per-process detail, an enriched file explorer, Services, Startup, and a classified Event Log).

Session logging and audit

Compliance frameworks increasingly expect a record of privileged sessions: who connected, when, and what they did.

Bundled with the rest of the MSP platform

Standalone remote support adds another invoice and another console.

Options to evaluate

Lavawall®: browser-based multi-tenant remote support bundled with the platform

A browser-based operator workflow with no operator agent to install. Multi-tenant by default. Country-level access restrictions on by default, with an approved-country list per tenant. TLS-in-TLS tunnelling with mutual certificate authentication. An Admin Workspace and remote shells without taking the screen, a consent prompt before a session, and session logging. Bundled with Lavawall® alongside patching, GRC, breach detection, helpdesk, and SaaS and shadow-AI discovery.

Best when: MSPs and IT teams that want browser-based, country-restricted remote support in the same RMM as their patching, security, and compliance.

Datto RMM: another RMM with its own remote tool

Datto RMM is an alternative to Lavawall as your RMM. Its Web Remote is “a browser-based HTML5 remote control, chat, and PowerShell tool.” According to Datto’s Web Remote documentation, only Windows and macOS devices with a Managed Agent installed can be controlled, up to four users can be on one Windows or macOS device at a time, and file uploads are limited to 1 GB per file.

Best when: MSPs already standardized on Datto RMM. Lavawall can be installed through Datto RMM, and both can run side by side while you move over.

NinjaOne: another RMM with its own remote tool

NinjaOne is an alternative to Lavawall as your RMM. NinjaOne’s remote access FAQ describes full remote control for Windows and macOS, Linux access “through secure remote command execution,” and IP allowlist configuration.

Best when: MSPs already standardized on NinjaOne. Lavawall can be installed through NinjaOne with a script, and both can run side by side while you move over.

BeyondTrust / Bomgar Remote Support: enterprise privileged remote support

Mature enterprise-grade remote support with deep audit and PAM integration. Strong if the customer is at enterprise scale, though pricing is enterprise-grade too.

Best when: Enterprises with dedicated PAM programs, or large MSPs serving regulated enterprise tenants.

ConnectWise ScreenConnect (Control): MSP remote-control

A long-established MSP remote-control product with a native client and strong session features. For its multi-tenant setup and country-restriction defaults, check ConnectWise’s documentation.

Best when: ConnectWise-stack MSPs.

Splashtop / TeamViewer / AnyDesk: generic remote-control

Generic remote-control products with MSP plans and reasonable feature sets at SMB pricing. For their security defaults and multi-tenant setup, check each vendor’s documentation.

Best when: Smaller MSPs with simple remote-control needs.

How Lavawall® fits

Lavawall® remote support runs in the browser, with no operator agent to install and no separate native client to maintain. The technician launches a session from the device-context view of the user's ticket.

Country-level restrictions are on by default. Each tenant has an approved-country list, and sessions from countries outside that list are blocked. Most credential-based remote-support attacks originate from outside the normal geography of the MSP and the tenant, so default-restricting closes the most common attack vector.

Session-level security uses TLS-in-TLS tunnelling with mutual certificate authentication. The Admin Workspace is a private workspace where a technician works with administrator rights while the user keeps working undisturbed: 19 Windows tools and three shells (PowerShell as system, PowerShell as the logged-in user, and Command Prompt as system) on Windows, and a root zsh shell on Mac. macOS asks the user to allow screen and audio access; our Mac setup guide shows what to click. In any session, 50 Windows admin tools are each one click away with administrator rights, from desktop or phone, without elevating the user. Because remote support is bundled with the rest of the platform, sessions launch from the same console as patching, GRC, ticketing, and breach detection.

Start free →Map session logging to a framework

Frequently asked

Why country-restriction by default?
Because credential-based remote-support attacks overwhelmingly originate from outside the normal geography of the MSP and the tenant. Default-restricting to approved countries closes the most common attack vector and forces a deliberate exception for legitimate travel.
Does Lavawall® replace BeyondTrust / Bomgar?
For most MSP scenarios, yes. For very large enterprises with dedicated PAM programs, BeyondTrust's depth at the privileged-access tier remains the gold standard; Lavawall® complements rather than replaces it in those cases.
Are sessions logged for compliance?
Yes. Session logging covers every connection and every command sent, screen captures can be attached to the ticket when the technician wants a record, and the log feeds Lavawall® GRC evidence for the relevant control families.

Datto and Datto RMM are trademarks of Kaseya. NinjaOne is a trademark of NinjaOne, LLC. Lavawall is not affiliated with either.