Skip to main content

Overview

The RealVNC integration enables ThreatAware to access your RealVNC platform data, providing visibility into remote access devices and management activities. This helps you maintain inventory of remote-accessed devices and validate remote access controls.
Connection Method: API Setup Time: 10 minutes Access Required: RealVNC Account Administrator

Data collected

The RealVNC integration provides:
  • Remote access device inventory
  • Device management information
  • Device connectivity status
  • Remote access device details

Use cases

Remote Device Inventory

Track and monitor all RealVNC-managed remote access devices

Access Management

Verify remote access controls and device authentication

Device Health

Monitor device connectivity and health status

Compliance Support

Generate reports on remote access device management

Setup instructions

1

Log in to ThreatAware

  • Navigate to the ThreatAware dashboard
  • Go to Settings and select Systems
  • Use the search bar to find RealVNC
  • Click Connect - a pop-up window will appear
2

Access RealVNC Management Portal

  • Visit RealVNC Manage Account
  • Sign in using your RealVNC platform credentials
  • Ensure you are logged in with an administrator account
3

Navigate to API Access Keys

  • In the RealVNC management portal, click Add-ons in the left menu
  • Select API ACCESS KEYS from the options
4

Create API Access Key

  • Click Create Access Key
  • Fill in the Label field with “ThreatAware” (or similar identifier)
  • Check the box for List Entries permission
    • This allows ThreatAware to retrieve device listings
  • Review other available permissions as needed for your requirements
  • Click Submit or Create to generate the key
5

Copy API Credentials

  • The system will display the Access Key and Access Key ID
  • Copy the Access Key ID
  • Copy the Access Key (the secret credential)
  • Store both credentials securely
6

Configure in ThreatAware

In the ThreatAware pop-up window, enter:
  • Access Key ID: The Access Key ID from RealVNC
  • Access Key: The Access Key from RealVNC
  • Click Authorize or Connect to establish the integration
7

Verify Connection

  • Check the integration status on the ThreatAware dashboard
  • Verify it shows as Active or Connected
  • Data collection will begin within 1 hour
  • Confirm RealVNC device data appears in ThreatAware

Required credentials

Field Name: RealVNC Access Key ID Type: String Description: The unique identifier for your RealVNC API access key
  • Generated when creating the API access key in RealVNC
  • Required for API authentication
  • Typically displayed as part of the key pair
Field Name: RealVNC Access Key Type: Password (encrypted) Description: The secret credential for authenticating to the RealVNC API
Store this credential securely in your organisation’s password manager. Keep track of your keys in case regeneration is needed.

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings → Integrations in ThreatAware
    • Confirm RealVNC shows Active or Connected status
    • Check the last sync timestamp
  2. Verify Device Data
    • Wait 60 minutes for the initial data poll
    • Search for a known RealVNC device in ThreatAware
    • Verify device details match the RealVNC management portal
  3. Test Device Queries
    • Create a test query to filter devices from RealVNC
    • Verify the device data is accurate and complete

Troubleshooting

Symptoms: Integration status shows authentication failureSolutions:
  • Verify the Access Key ID and Access Key are correct
  • Ensure credentials were copied completely without extra spaces
  • Check that the access key is active and has not been revoked
  • Confirm the “List Entries” permission is enabled for the key
  • If needed, create a new access key and update ThreatAware
Symptoms: Integration connects but no device data appearsSolutions:
  • Verify the access key has the List Entries permission enabled
  • Check that your RealVNC account has administrator privileges
  • Ensure the access key scope includes all devices you want to monitor
  • Review RealVNC API Documentation for permission requirements
  • Regenerate the access key with correct permissions if needed
Symptoms: Integration fails to connect or connection timeout occursSolutions:
  • Verify the RealVNC API service is accessible
  • Check your internet connection and firewall settings
  • Ensure outbound HTTPS (443) traffic is allowed to RealVNC servers
  • Test the RealVNC management portal in a browser to verify accessibility
  • Wait a few moments and retry the connection
Symptoms: Integration shows active but no RealVNC devices appearSolutions:
  • Verify you have devices registered and active in RealVNC
  • Check that devices are not in offline or excluded state
  • Confirm the access key has “List Entries” permission
  • Ensure your RealVNC account manages the devices you expect to see
  • Wait additional time - first sync may take longer than 1 hour
  • Review ThreatAware integration logs for error messages

Important notes

API Key Security
  • Store API access keys securely in your organisation’s password manager
  • Do not share keys with unauthorized users
  • If a key is compromised, revoke it immediately in RealVNC
  • Create dedicated keys for each integration rather than reusing keys
Permission Setup
  • Ensure the “List Entries” permission is enabled for the access key
  • You may enable additional permissions if needed for your use case
  • Review RealVNC’s API documentation for available permissions
  • Test with minimal permissions first, then expand as needed

Additional resources

RealVNC API Documentation

Official RealVNC documentation for API setup and permissions

ThreatAware Support

Contact ThreatAware support for integration assistance

Best practices

Access Key Management
  • Create a dedicated access key specifically for ThreatAware integration
  • Label keys descriptively (e.g., “ThreatAware Integration”)
  • Document your access keys and their purpose
  • Rotate access keys annually or per your security policy
  • Review and monitor access key usage in RealVNC audit logs
Integration Maintenance
  • Verify the integration status regularly
  • Monitor for any authentication or permission errors
  • Test the connection periodically to ensure uninterrupted data flow
  • Keep your RealVNC account settings and ThreatAware up to date
  • Document any changes to your RealVNC device inventory