Remote monitoring and management (RMM) tools are essential for administration, but they can also be exploited for unauthorized access. When Microsoft Defender Experts documented phishing campaigns in July 2026 that used legitimate MSP360 and ConnectWise ScreenConnect installers, it highlighted a core issue: your approved administrative software can look identical to an attacker's command-and-control channel at the network layer.
This checklist helps you establish controls to distinguish authorized RMM deployments from unauthorized ones. Each item maps to detection opportunities, policy enforcement points, and audit evidence to ensure you're managing remote administration as a privileged access control, not just an IT convenience.
Prerequisites
Before implementing this checklist, ensure you have these foundational elements:
Endpoint Detection and Response (EDR) coverage. Detect anomalous RMM behavior with telemetry showing process execution, network connections, and service installations. EDR platforms provide the visibility needed to identify when RMM.Agent.exe spawns PowerShell or when a digitally signed installer creates firewall rules on port 48678.
Privileged Access Management (PAM) governance. RMM tools grant administrative control over endpoints. Treat RMM credentials and deployment authority as privileged access. Define who can deploy RMM software, which accounts can authenticate to RMM platforms, and how those credentials are protected.
Application control or allowlisting capability. Enforce through Group Policy, endpoint protection platforms, or dedicated application control solutions to prevent unauthorized software installation. User Account Control (UAC) alone isn't sufficient. The July 2026 campaigns succeeded when users approved UAC elevation prompts for what appeared to be legitimate meeting invitations or PDF readers.
RMM Security Control Checklist
1. Maintain an Authorized RMM Software Inventory
Requirement: Document every approved remote administration platform, including product name, version, authorized use cases, and business owner.
Implementation: Create a definitive list in your configuration management database or asset register. Include MSP360, ConnectWise ScreenConnect, TeamViewer, AnyDesk, and any other remote access software approved for use.
What good looks like: Your IT security team can quickly verify if "RMM.Agent.exe v2.5.0.67" is authorized by consulting a single authoritative source. The inventory includes SHA-256 hashes for approved installers and specifies which departments are authorized to deploy each tool.
2. Restrict RMM Installation to Authorized Deployment Mechanisms
Requirement: Prevent users from installing RMM software through downloaded executables, even if the software itself is legitimate.
Implementation: Configure application control policies to block RMM installer execution unless the binary is deployed through your approved software distribution platform (SCCM, Intune, or equivalent). Block execution from user Downloads directories, temporary folders, and email attachment locations.
What good looks like: When a user downloads a suspicious executable and attempts to run it, the endpoint protection platform blocks execution and generates an alert. Legitimate RMM deployments occur only through IT-initiated software distribution jobs.
3. Enforce Privileged Elevation for RMM Service Installation
Requirement: Configure UAC and endpoint protection to prevent silent or deceptive elevation of RMM installers.
Implementation: Set UAC to "Always notify" for administrative actions. Configure EDR platforms to alert on UAC elevation requests from executables launched from Downloads folders or with suspicious filenames. Train users to deny elevation prompts for unexpected software.
What good looks like: Your security operations center receives real-time alerts when suspicious files are dropped to temporary directories as part of an installation workflow. Failed installations (where users denied elevation) generate incident tickets for investigation.
4. Monitor RMM Service Registration and Persistence Mechanisms
Requirement: Detect when new Windows services associated with remote administration software are created outside of authorized change windows.
Implementation: Configure SIEM rules to alert on service creation events for RMM.Agent.exe, RMM.Agent.Launcher.exe, ScreenConnect.ClientService.exe, and similar binaries. Cross-reference service creation timestamps against approved change requests.
What good looks like: When RMM.Agent.exe registers as a Windows service without a corresponding change ticket, your SOC receives an alert within minutes. The alert includes the service name, installation path, and the user account that initiated installation.
5. Control Outbound Network Connections from RMM Agents
Requirement: Restrict RMM software to communicating only with authorized management servers.
Implementation: Define allowed destination IP addresses and domains for each approved RMM platform. Configure next-generation firewalls or endpoint protection to block outbound connections from RMM processes to unauthorized destinations. Monitor for firewall rule creation events that enable inbound UDP traffic on non-standard ports.
What good looks like: Your firewall logs show RMM.Agent.exe establishing connections only to your organization's authorized management console. Any attempt to connect to unauthorized infrastructure triggers immediate blocking and investigation.
6. Detect Remote Command Execution Through RMM Platforms
Requirement: Identify when RMM agents spawn PowerShell, cmd.exe, or other command interpreters to execute remote instructions.
Implementation: Configure EDR to alert when RMM.Agent.exe, ScreenConnect.ClientService.exe, or similar processes launch child processes. Pay particular attention to PowerShell executions that modify execution policy, invoke web requests, or install software silently.
What good looks like: Your EDR platform flags suspicious process chains, indicating remote command activity requiring investigation.
7. Audit File Transfers and Staging Locations
Requirement: Monitor directories where RMM platforms commonly stage transferred files for execution.
Implementation: Configure file integrity monitoring or EDR file creation alerts for common RMM staging directories. Alert on executables with suspicious names that mimic legitimate Windows components.
What good looks like: When suspicious files are transferred to a staging directory, your security tools generate an alert identifying the transferred file, its hash, and the RMM session that delivered it.
8. Validate Digital Signatures Against Authorized Publishers
Requirement: Verify that RMM software is signed by expected publishers and hasn't been tampered with.
Implementation: Configure application control to allow execution only from specific trusted publishers. Maintain a list of approved code-signing certificates for RMM vendors. Alert on execution of RMM-related binaries signed by unexpected certificates or with modified signatures.
What good looks like: Your application control policy permits installers signed by approved publishers but blocks executables signed by unrelated publishers even if the filename claims to be legitimate.
9. Restrict Cloud Storage as RMM Distribution Channels
Requirement: Prevent users from downloading and executing RMM installers hosted on public cloud services.
Implementation: Configure web filtering and download policies to block executable downloads from public cloud services unless the download occurs through an authorized software distribution workflow. Alert on downloads of executables with RMM-related filenames from these services.
What good looks like: When a user clicks a phishing link that redirects to a public cloud service hosting a suspicious executable, your web proxy blocks the download and notifies the security team.
10. Correlate RMM Activity with Change Management Records
Requirement: Ensure every RMM deployment, configuration change, or remote session corresponds to an approved change request or support ticket.
Implementation: Implement a workflow requiring IT staff to document RMM deployments in your change management system before installation. Configure automated checks that compare RMM service installation timestamps against change ticket windows.
What good looks like: Your compliance dashboard shows full correlation between RMM service registrations and approved change tickets. Any RMM installation without a corresponding ticket triggers an automatic incident investigation workflow.
Common Mistakes
Treating digitally signed software as inherently safe. The MSP360 installer used in July 2026 campaigns was legitimate software, properly signed, and functionally identical to authorized deployments. Digital signatures verify publisher identity and code integrity but don't validate installation intent.
Relying on User Account Control as a security boundary. UAC prompts are permission requests, not security controls. Users routinely approve elevation for executables with deceptive filenames because the prompt doesn't explain what the software actually does.
Monitoring only for malware without detecting dual-use tools. Your antivirus won't flag ConnectWise ScreenConnect because it's legitimate software. Detection requires behavioral analytics that identify unauthorized deployment patterns, not signature-based malware scanning.
Failing to distinguish between RMM platforms and their intended use. Just because you've approved TeamViewer for help desk support doesn't mean MSP360 is authorized for the same purpose. Each RMM platform requires explicit approval, defined use cases, and separate monitoring rules.
Next Steps
Start with items 1, 2, and 6. Establishing an authorized software inventory, blocking user-initiated RMM installations, and detecting remote command execution provide immediate risk reduction. These three controls would have prevented or detected every stage of the July 2026 attack chain.
Then layer in network controls (item 5) and file transfer monitoring (item 7) to detect post-compromise activity even if initial installation succeeds. Finally, implement change correlation (item 10) to create audit evidence demonstrating that your RMM deployments follow documented authorization workflows.
Your RMM security posture isn't measured by whether you use remote administration tools. It's measured by whether you can distinguish your tools from an attacker's.





