Our company has an employee IT, who is necessary to connect to the computers of other users and help them. In this case the employee does not have the rights of a domain and local administrator on the users' computers. If the officer is trying to connect to the user - the user pops up a request for acceptance of connection.
Despite the fact that the user agrees to the connection, you can only view the remote computer, without the ability to manage the session.
Tell me, is it possible to manage users' computers without domain rights and local administrator?
UPDATED
After reading the article How to: Allow automatic Remote Control for non-admin users I realized that it is sufficient to remove the label from one of the items on the agent.
The question is how it's best to remove these marks made on all computers in the network?