Remote Access
Set up remote access for Virbe kiosk machines so you can troubleshoot, update, and manage installations without being on-site.
Remote access is essential for managing kiosk installations – especially when they are in public locations that are difficult or costly to visit. A properly configured remote access solution lets you restart the kiosk app, update the Virbe application, adjust Windows settings, and diagnose issues without leaving the office.
Configure remote access before deploying the kiosk to its final location. It is significantly harder to set up remote access once the machine is in a publicly accessible location and you cannot easily sit at a keyboard.
Remote Access Options
TeamViewer
TeamViewer is the most widely used remote access solution for kiosk deployments. It works reliably across firewalls and network address translation (NAT) without requiring VPN or port forwarding.
Setup:
- Download and install TeamViewer Host (not the standard TeamViewer app) from teamviewer.com
- TeamViewer Host runs as a Windows service and starts automatically with the system – it is available even before Windows login, including during the boot sequence
- Assign the device to your TeamViewer account during setup
- Set an unattended access password (or use your TeamViewer account for authentication)
- Note the device ID and confirm remote access works before deploying the kiosk
Recommended settings:
- Enable Start TeamViewer with Windows
- Enable Unattended access
- Disable Show TeamViewer in tray if you are hardening the kiosk (prevents users from seeing the remote access icon)
AnyDesk
AnyDesk is a lightweight alternative to TeamViewer with a low-latency connection, which is useful for live monitoring of the kiosk display.
Setup:
- Download AnyDesk from anydesk.com
- Install it in service mode (run as a Windows service) so it is available before login
- Configure an unattended access password
- Note the device ID
Windows Remote Desktop (RDP)
Windows Remote Desktop Protocol (RDP) is built into Windows Pro and does not require a third-party account or subscription. However, it requires network-level access to the kiosk (either direct LAN access or a VPN/port-forward setup).
Requirements:
- The kiosk must have a static local IP address or a known hostname
- Your network must allow RDP connections (TCP port 3389) to the kiosk, or you must use a VPN
- Windows 10/11 Pro is required (Home edition does not support inbound RDP connections)
Setup:
- Settings → System → Remote Desktop → Enable Remote Desktop (Windows 11) or Control Panel → System → Remote settings (Windows 10)
- Add the user account that should be allowed to connect
- Note the machine's IP address or hostname
For cloud-hosted deployments where the kiosk connects outbound to the Virbe platform but is not directly reachable from the internet, use TeamViewer or AnyDesk instead of RDP.
Remote Restart and Recovery
Restarting the Kiosk App Remotely
If the Virbe Kiosk app crashes or becomes unresponsive, you can restart it remotely:
- Connect via your remote access tool
- Open Task Manager → find the Kiosk app process → End task
- The startup script or Task Scheduler task will relaunch the app automatically (if configured), or launch it manually
Restarting Windows Remotely
A full system restart often resolves issues that cannot be fixed by restarting the app alone:
- Via remote access tool: use the remote reboot/restart function
- Via Windows: Start → Power → Restart
- Via command line:
shutdown /r /t 0
After a restart, Windows auto-login and the startup task will return the kiosk to its running state automatically.
Network Considerations
The Virbe Kiosk application itself only needs outbound access (HTTPS, port 443, plus DNS resolution) to a single endpoint:
- Virbe-hosted: the Virbe servers (
*.virbe.ai) - Azure-hosted: your own custom deployment endpoint in your Azure tenant
The kiosk does not communicate directly with AI model, STT, or TTS providers – all third-party calls (OpenAI, Azure, Anthropic, Google, ElevenLabs) are made server-side by the Virbe Hub, never from the kiosk device. This keeps the kiosk's network footprint minimal.
Restricted networks and VPN: Because the kiosk's only dependency is the single Virbe (or your Azure deployment) endpoint, its traffic can be locked down tightly if your security policy requires it – place the kiosk on a dedicated, assigned secure network segment or route it through a VPN that permits only DNS and HTTPS to the deployment endpoint. This is a common pattern for corporate, retail, and banking installations; coordinate the exact allowlist with the site's IT team.
Additional outbound access is needed only for the remote access tool, if used:
*.teamviewer.com(for TeamViewer)*.anydesk.com(for AnyDesk)