Home » Create EPM Policy
 

Create EPM Policy

Introduction

Implementing privilege management in Endpoint Central starts with creating a robust Endpoint Privilege Management policy that governs how users can access and run applications with elevated rights. Administrators begin by defining a Privileged Application List, which includes applications that require administrative access. Once the list is curated, it is then associated with specific custom groups containing user devices that need this level of access. After association, the policy is deployed from the Endpoint Central console, allowing selected users to run approved applications with elevated privileges—while retaining standard user rights elsewhere. This structured approach ensures that privilege elevation is tightly controlled and contextually applied, reducing security risks and ensuring compliance across the enterprise.

Create Privileged Application List

The applications can be run with elevated privileges in the following ways:

  • Self elevation of applications: Administrators have the option to allow users to elevate their user privileges by providing a justification. The provided justification will be logged, and this capability can be configured for specific applications or all allowlisted applications.

    Self Elevation

  • Elevation to all allowed applications: The custom groups associated to the Privileged Application List during policy deployment will be allowed to self-elevate their privileges to all allowlisted applications.

    Elevation for Allowed Applications

  • Elevation to specific applications: The groups associated to the Privileged Application List during policy deployment will be allowed to self-elevate their privileges to all the applications selected.

    Elevation for Specific Applications

  • Auto Elevation: The associated groups will be allowed to automatically run applications with elevated privileges.

    Auto Elevation

Was this article helpful?

Thank you for your feedback!

Sorry about that!

By clicking "Submit", you agree to processing of personal data according to thePrivacy Policy.
Back to Top