NetBlade
Windows Step 11 of 12 ~30 min Advanced

Remote actions, safely: fix Windows PCs from your desk

Use remote actions, the Remote and Manage menus, RDP, Shadow and remote uninstall on Windows PCs, with previews, confirmations and clear safety rules.

NetBlade can do more than look. From a device card you can run about 150 PowerShell actions on a Windows PC, open Windows’ own management tools already pointed at it, take over the user’s session with their consent, and uninstall programs without a window popping up on their screen. All of it runs as administrator on real machines, often in production. This article shows how to set it up, how to use it, and the habits that keep you out of trouble.

Before you start

  • The PC read successfully, with a Windows administrator credential filed for it (Prepare your Windows PCs).
  • A way in to the PC: WinRM on port 5985, or PsExec through port 445 and the ADMIN$ share.
  • For RDP and Shadow: Remote Desktop enabled on the target, and permissions to use it.

1. Check the way in

  1. Open the device’s card and press Remote actions.
  2. At the top, the window checks how to reach the machine, for example «From here: WinRM open · port 445 open · PsExec absent · account: …».
  3. If it says «No action can run like this», expand What the remote machine needs. It lists what to set up, in the order it is usually missing: an administrator account, WinRM on, a private or domain network, TrustedHosts on this PC outside a domain, LocalAccountTokenFilterPolicy for local accounts outside a domain, and PsExec. The commands are the same as in Prepare your Windows PCs, step 8.

How NetBlade chooses: it uses WinRM when it can. If WinRM does not answer, it falls back to PsExec, if present. If the NetBlade PC is not in a domain and the target is not in its TrustedHosts, Windows refuses WinRM, and NetBlade goes straight to PsExec without trying WinRM first.

Getting PsExec

PsExec is a free Microsoft tool (Sysinternals). Its licence does not allow it to be bundled with NetBlade, so you download it yourself and accept its licence:

  1. In the Remote actions window, press Download PsExec from Microsoft. It is fetched from live.sysinternals.com only when you press the button.
  2. If the download fails, get it by hand from learn.microsoft.com/sysinternals and put it in a folder on the PATH.

Note: PsExec cannot use a user name or password containing double quotes. For those accounts, turn WinRM on on the target.

2. Run an action

  1. In Remote actions, pick the Category: Diagnostics, Network, Remote management, Firewall, Services, Windows features, Software, Local accounts, Security, System, Printers or Custom command. Each category has a short description of what it touches.
  2. Search or pick the Action. Next to the name, ● marks an action that changes a setting and ▲ a critical one; no mark means it only reads.
  3. Fill in the parameter if there is one: a port, a service name, a winget package ID. The field shows an example and a hint.
  4. Read Command that will run on the host: the exact PowerShell script.
  5. For critical actions (▲), tick I confirm this change on the host. The action will not run without it.
  6. Press Run. The output appears in the window, with the transport used, the exit code and whether it succeeded.

Useful actions to know:

  • Diagnostics: «System summary», «Disk space», «Pending reboot?», «Logged-on users», «Installed updates (last 25)», «System errors (last 3 days)».
  • Software: «Available updates (winget)», «Search the winget catalog», «Update one package (winget)», «Missing Windows updates».
  • Security: «Defender status», «Update Defender signatures», «Start a quick scan», «BitLocker status», «Disable SMBv1 (recommended)» (in Windows features).
  • Printers: «Restart the print spooler» (in Services), «Clear the print queue».
  • Remote management: «Enable WinRM (remote management)», «Open the firewall for WMI», «Restore UAC remote restrictions».

Tip: Once even one way in works, the Remote management category can fix the rest from NetBlade. For example, reach a PC through PsExec and use «Enable WinRM (remote management)».

3. Use the Remote and Manage menus

The card’s header opens Windows tools already pointed at that machine:

  • Remote: PsExec (cmd), PsExec (PowerShell), Remote PowerShell (WinRM), SSH, WinBox (MikroTik), VNC, Telnet, FTP.
  • Manage: Computer Management, Event Viewer, Open C$, Open ADMIN$, HTTP, HTTPS, Restart…, Shut down…, Wake-on-LAN.

External tools (PsExec, WinBox, a VNC viewer) must be installed on the NetBlade PC; if one is missing, the app says so. SSH opens the Windows SSH client in a command window: NetBlade has no built-in SSH session. Restart… and Shut down… ask for confirmation before sending the command, because signed-in users lose unsaved work.

4. Help the user with RDP or Shadow

  • RDP opens Remote Desktop Connection to the machine.
  • Shadow finds the signed-in user’s session and opens it with remote control. It always asks the user at the other end for consent. If several sessions are connected, NetBlade asks which one to control.

Shadow needs a Windows PC with a signed-in user and Remote Desktop permissions. If nobody is signed in, there is no session to control, and the app says so.

5. Uninstall a program remotely

  1. Open the device’s card, then the Software tab.
  2. Next to the program, press Uninstall.
  3. Read the confirmation. It shows the command, and warns that whoever uses that PC may lose work open in the program.
  4. Confirm. The program is removed without any window on the PC.
  5. Wait for the check. NetBlade reads the PC again and says whether the program is gone, whether a restart is needed, or whether it is still installed. It trusts the re-read, not the uninstaller’s exit code.

Programs installed by their own .exe without a silent removal are marked Manual removal only. Their uninstaller opens a window and waits for a click; started remotely, it would sit on a window nobody sees. For those, the app offers Open Remote Desktop and Shadow the user’s session, so someone can remove it from Settings, Apps.

Note: If no program shows as removable, the PC was probably read before 23/09/2026. Read it again with Deep scan: this information was not collected before.

6. Know what never to do

These habits come from the warnings the app itself gives, and from the ways remote work goes wrong:

  • Never run a critical action without reading the preview. The script is right there; read it, every time.
  • Never disable the network adapter, reset the network stack or change DNS on the connection you are using to reach the PC. «Disable a network adapter» on that adapter cuts you off, and nobody will be at the desk to plug it back.
  • Never turn the firewall off to make something work. «Turn firewall off (all profiles)» exists for diagnosis. Open the one port you need with «Allow inbound TCP port», and remove the rule when done.
  • Never leave real-time protection off. If you use «Turn real-time protection off» to test something, turn it back on in the same session.
  • Never restart or shut down during working hours without telling the user. «Restart the host (60s)» gives 60 seconds; shutdown /a on the host cancels it, and «Cancel a pending shutdown» does the same from NetBlade.
  • Never paste a script you do not fully understand into «Run my own PowerShell». It runs as administrator on the remote machine.
  • Never add yourself to Administrators “just for now”. «Add a user to Administrators» lasts until someone removes it, and it will break the «At most three local administrators» rule.
  • Tell the user first for anything marked ● that they could notice.

Check that it worked

  • The output shows the transport, an exit code and «succeeded».
  • For changes that show up in the inventory (a program updated or removed, SMBv1 off, a defence back on), press Deep scan and check the card, then Check now on To fix.

If something goes wrong

  • «No Windows credential applies to this machine». Add one in Credentials for the device, the site or everywhere.
  • «There is no way in: WinRM is closed, and PsExec needs port 445 open and PsExec on this PC». Follow What the remote machine needs.
  • «This PC is not in a domain and the target is not in its TrustedHosts, so Windows refuses WinRM». Download PsExec, or add the target to TrustedHosts on the NetBlade PC.
  • «PsExec is not on this PC». Press Download PsExec from Microsoft.
  • An action took over half a minute. The target’s firewall blocks remote service management and PsExec waits before falling back. Download the enable script again and run it on that PC.
  • «winget not found on this host». App Installer is missing or not available to that account. Use the program’s own updater, or your usual deployment tool.
  • «The command finished but … is still installed». Its uninstaller removed nothing. Remove it by hand on the PC.

Next

Put it all together into a routine: Everything under control.

← All how-to guides Feature guide → The product: NetBlade Windows →