AI agents: see /llms.txt for a full index of this site, or /llms-full.txt for concatenated documentation.

Endpoint Privilege Management

Remove standing admin rights. Keep people moving.

Endpoint Privilege Management demotes standing local admins to standard users, then grants time-boxed elevation on demand. Admin rights exist only while they're needed, and every elevation is audited in Workshop.

Beta

The problem

Standing privilege is the attacker's favorite privilege

Most fleets pick one of two bad options: leave admin rights in place forever, or make every elevation a help-desk ticket. Endpoint Privilege Management removes the standing privilege without adding to the queue.

Standing admin rights

Users who only occasionally need admin access often hold it permanently. Standing administrator access is one of the most common and most abused sources of endpoint risk.

  • Held around the clock, used a few minutes a month
  • Privilege sits in place for malware or an attacker to abuse
  • Anything that compromises the user inherits the admin rights

Ticket-driven elevation

The traditional fix is to strip admin rights and route every elevation through the help desk. Least privilege survives, but productivity pays for it.

  • Every installer and system tweak becomes a ticket
  • Users wait on another team for routine work
  • IT burns time approving requests it almost always grants

How it works

Elevation on demand, revocation on schedule

Santa enforces the policy on the endpoint. Workshop sets the rules and keeps the record.

1

Standing admins are demoted

Santa demotes existing local administrators, any account with a UID of 500 or higher, to standard users. Standing privilege disappears from the host.

2

A user requests elevation

When admin access is actually needed, the user requests it from the Santa menu bar or with the santactl adminmode command.

3

Authenticate, then justify

Local authentication is always required before a user can elevate. Policy can also require a justification, captured for the record.

4

Time-boxed, then revoked

Admin rights are granted for a limited window, then revoked automatically when it expires, the screen locks, the session ends, or the machine reboots. Policy sets the ceiling, from 1 minute to 30 days.

Controls

Policy-driven, down to the minute

You decide how elevation works on your fleet. Every control is set per tag in Workshop's sync settings, where the feature appears as Temporary Admin Mode.

Duration limits

Set the maximum elevation window, from 1 minute to 30 days, and a default duration for requests that don't specify one. The maximum is a hard ceiling on every request.

Required justification

Require users to say why they're elevating. The justification is captured with the request and lands in the audit trail alongside the who and the when.

Per-tag targeting

Set policy per tag. Pilot with one team, keep tighter limits on sensitive groups, and roll out to the rest of the fleet as you build confidence.

Audit trail

Every elevation has a paper trail

Privileged access without a record is a liability. Santa records every elevation, expiry, and denial, then uploads it to Workshop, so the answer to 'who was admin, when, and why' is always one query away.

  • Who, when, and why

    Every elevation, expiry, and denial is recorded with the user, the timestamp, and the justification they gave. Denials carry the reason they were refused.

  • Centralized in Workshop

    Audit events upload to Workshop, so there's one complete record of privileged access across the fleet instead of logs scattered per host.

  • Live elevation visibility

    See which user currently holds an elevation on any host, straight from the host view. No guessing who is admin right now.

Use cases

Least privilege people can live with

Endpoint Privilege Management is for teams that want admin rights gone, not just inventoried.

Least privilege and compliance

Enforce least privilege as standing policy, not an aspiration. The centralized audit trail gives SOC 2 and ISO 27001 reviewers a complete record of privileged access.

A smaller attack surface

Admin rights exist only inside short, deliberate windows. Malware that lands on a host inherits a standard user, not an administrator.

Developer-friendly elevation

Engineers get just-in-time admin access in seconds, from the menu bar they already use. No help-desk ticket, no waiting on another team.

Beta
Endpoint Privilege Management is in beta and requires Santa 2026.6 and Workshop 2026.6. It is enabled per tenant, so contact us and we'll turn it on for your fleet.