DESKROOK — WINDOWS CLIENT v0.3.23

Update the VPS to v0.10.0 and the Windows client to v0.3.23. Apply the VPS package first.
This release adds the Monitor selector for viewing/control of each connected display.
Input pauses during a switch and resumes after the new monitor image appears.
Sign-in remains on the primary display; desktop handover enables the selector.
Display configuration changes end the session; reconnect to refresh the list.
Clipboard, file transfer and restart/reconnect remain available.
The existing connection statistics, streaming and reconnection remain available.
Saved Full HD settings and the working sign-in handover remain available.

In the web viewer, choose Connection stats to see frame rate, bandwidth, round
trips, capture/encode/send/decode time and Windows client CPU usage. An unchanged
screen sends a full refresh every two seconds, so low FPS while idle is normal.

Recovery lasts at most 30 seconds after detecting a lost connection and keeps
the same session, permissions, expiry and resolution. Sharing and input pause
during recovery. Stop, pause, revoke, lock, sign-out, changed display or an expired
session ends access. No retry after reboot, process exit, browser reload or relay
restart. Windows sign-in sessions retain their existing fail-closed behavior;
recovery becomes available after the normal desktop handover completes.

Extract the entire ZIP. Windows x64; .NET runtime included. Native Windows login
still needs an endpoint retry; local tests simulate the Windows session changes.

UPDATE AN ALREADY ENROLLED DEVICE

1. Apply DeskRook-Platform-Update-v0.10.0.zip on the VPS and confirm the
   v0.10.0 console badge.
2. End sessions and exit all installed Remote Support Companion / DeskRook Agent windows from their tray
   menus. Open PowerShell as administrator in this DeskRook.Agent folder:

   powershell.exe -NoProfile -ExecutionPolicy Bypass -File .\scripts\Update-Unattended.ps1

3. Open DeskRook Agent from Start. Confirm v0.3.23; resume if paused.
   Existing device identity and lock-screen access setting are retained.
4. Start the sign-in connection from Devices, sign in with Enter, and leave the
   viewer open while Windows and its normal Companion become ready. The viewer
   can now continue when Windows replaces an empty sign-in console with another
   user session. An empty replacement console does not become the destination.
5. If it still ends, run this in administrator PowerShell after the attempt:

   Get-Content "$env:ProgramData\RemoteSupport\sign-in-transition.log" -Tail 100

   Send the latest SignInAttempt through Completed, plus the viewer message.
   DesktopDestination entries record baseline/current numeric Windows states,
   the verified Companion session and selection result. No username, typed
   input, password, screenshot, session ticket or device credential is logged.

No re-enrolment is needed. Identity, server and pause settings are preserved.
The updater checks the EXE checksum, backs it up and restarts the Windows service.
If the update fails after changing the option, rollback also restores the prior
DPAPI-encrypted device configuration. Do not uninstall to update.

Existing devices default to lock/sign-in access OFF. Omitting both option
switches keeps the current setting. To opt in on another device, add
-EnableLockScreenAccess to the update command. To disable it, close companions and run:

   powershell.exe -NoProfile -ExecutionPolicy Bypass -File .\scripts\Update-Unattended.ps1 -DisableLockScreenAccess

CTRL+ALT+DELETE, IF REQUIRED

When the software SAS policy value is absent and the service can write it,
Send Ctrl+Alt+Delete is enabled in a sign-in Control session. Clicking it lets
the authorised service temporarily allow Services, send the secure attention
sequence to the selected Windows session, then remove its temporary value.
Existing policy allowing Services (1 or 3) is used without changes. Existing
policy blocking Services (0 or 2), or an unrecognised value, remains blocked.

A disabled button explains whether Windows policy blocks the service or the
service capability is unavailable. Explicit managed policy must be reviewed by
your administrator; this app will not override it. The installer/updater does
not set policy, and merely opening View or Control does not set policy.
If restoring the temporary policy fails, the session ends with a specific error.
Keep the Windows Ctrl+Alt+Delete requirement and UAC settings intact.
Microsoft: https://learn.microsoft.com/en-us/windows/win32/api/sas/nf-sas-sendsas

GET HELP ONCE (ATTENDED)

Open publish\windows\RemoteSupport.Agent.exe normally. Enter the technician's
server address and pairing code, then approve View or Control when prompted.
End session or close the window to stop sharing. Attended use does not grant
lock-screen access.

ENROL A NEW DEVICE

1. In the console, enable MFA under Account security, then choose Devices >
   Enrol device. Create an enrolment code and remain signed in.
2. Run Windows PowerShell as administrator from this extracted folder:

   powershell.exe -NoProfile -ExecutionPolicy Bypass -File .\scripts\Install-Unattended.ps1

3. Enter the server and DEVICE ENROLMENT code. Tick the authorisation checkbox;
   optionally tick Windows lock/sign-in access. Enrol, then close the form.
4. Open DeskRook Agent from Start in the signed-in account. It also
   starts at future sign-ins. The device becomes Ready for View or Control.

LOCAL CONTROL AND LIMITS

The ordinary companion shows active sharing. Its End session / Ctrl+Shift+F12
also pauses unattended access. Minimise to keep it in the tray; exiting ends
ordinary desktop sharing. A separately enabled sign-in helper can still run
when Windows is locked or signed out. Pause blocks both forms of access.
Ctrl+Shift+F11 on the sign-in screen stops the helper and persists pause.
Resume from the signed-in companion to allow another connection.

Normal desktop companions use the launching user's existing Standard or
Administrator permissions; they never run as SYSTEM. The service starts a
separate short-lived SYSTEM helper only for explicitly enabled sign-in access.
It cannot follow the user onto the unlocked desktop. Windows credentials are
checked normally, with no stored password or automatic password entry.

UAC prompts, disconnected RDP, headless capture and Server Core are unsupported.
An eligible interactive session and display are required. Multiple active users
need the verified companion to identify the target; the service does not choose
arbitrarily. Handover waits at most 30 seconds and retains the original access mode.
A signed-out console may hand over once to a verified newly active desktop;
locked user sessions remain bound to their original Windows session. Pause, stop, revoke, relock, sign-out, service
loss cancel sign-in access. Approved normal desktop sessions can recover from brief network interruptions as described above.
For ordinary administrator apps, launch the companion via normal Windows Run
as administrator approval if needed. UAC is not disabled or bypassed.

The stream targets up to 20 fps with two outstanding frames. Control uses the
local browser pointer; View includes the remote pointer. Updated desktop peers
can stream up to 1920 x 1080 with Balanced or Sharper image quality. Sign-in and
older relays retain the existing 1280 x 800 cap. Actual speed depends on CPU/network.
Keyboard layouts, DPI and application compatibility need native testing.

If sign-in access fails, unlock locally and copy the companion service status,
including any Windows error number. Record Windows build, console/RDP and whether
Ctrl+Alt+Delete is required. Never send your Windows password for troubleshooting.

REMOVE ACCESS

Revoke the device in the console, then run scripts\Uninstall-Unattended.ps1 as
administrator. This removes the service, startup entry and local device credential.

The EXE/scripts are unsigned pilot builds; follow your application-trust policy.
Downloading does not enrol a device or grant access. No account/enrolment secrets
are included. EXE checksum: publish\windows\SHA256SUMS.txt. Runtime notices:
publish\windows\notices.

RESOLUTION SETTINGS

Windows must advertise and accept the selected mode. This changes the shared
primary display, not a separate RDP desktop. No virtual display driver is added.
The previous mode is restored on normal session end; if the desktop is locked,
cleanup waits for unlock while Companion is running. A later local mode change
is preserved. Forced termination or shutdown can prevent cleanup. Settings can
be opened during a session without ending it; saved defaults apply next time.

TEXT CLIPBOARD (v0.3.21)
After updating the VPS and this client, an approved Control session can use the
viewer Clipboard panel to read and change plain text on the remote clipboard.
Sending does not type or execute it. View only and sign-in screens cannot use
clipboard sharing. Clipboard data is not logged or synchronised in the background.


FILE TRANSFER (v0.3.21)
In an active desktop Control session, open Files in the browser toolbar.
Send file saves into the remote user's Downloads\DeskRook folder.
Choose remote file opens a picker on the remote screen; select one file and
Open, then use Save received file in the browser after verification.
100 MiB maximum; one file at a time; progress and cancellation are available.
Existing files are preserved using a numbered suffix. Received files never
open automatically. Save browser downloads before ending the session.
Windows sign-in, View only and the Mac preview cannot transfer files.

Verified console updates (Windows Agent v0.3.22 or newer)
After installing/updating the agent, run scripts/Enable-VerifiedUpdates.ps1 as
administrator with -PublicKeyPath pointing to your organisation's RSA-3072
update PUBLIC key. The same key must be installed on the DeskRook relay.
This registers the protected recovery helper and Windows recovery task.
Never copy your private signing key to a device or relay.
See docs/AGENT-UPDATES.md in the full DeskRook build for the complete workflow.
