Endpoint Privilege Management
Remove standing admin rights. Keep people moving.
Endpoint Privilege Management demotes standing local admins to standard users, then grants time-boxed elevation on demand. Admin rights exist only while they're needed, and every elevation is audited in Workshop.
The problem
Standing privilege is the attacker's favorite privilege
Most fleets pick one of two bad options: leave admin rights in place forever, or make every elevation a help-desk ticket. Endpoint Privilege Management removes the standing privilege without adding to the queue.
Standing admin rights
Users who only occasionally need admin access often hold it permanently. Standing administrator access is one of the most common and most abused sources of endpoint risk.
- Held around the clock, used a few minutes a month
- Privilege sits in place for malware or an attacker to abuse
- Anything that compromises the user inherits the admin rights
Ticket-driven elevation
The traditional fix is to strip admin rights and route every elevation through the help desk. Least privilege survives, but productivity pays for it.
- Every installer and system tweak becomes a ticket
- Users wait on another team for routine work
- IT burns time approving requests it almost always grants
How it works
Elevation on demand, revocation on schedule
Santa enforces the policy on the endpoint. Workshop sets the rules and keeps the record.
Standing admins are demoted
Santa demotes existing local administrators, any account with a UID of 500 or higher, to standard users. Standing privilege disappears from the host.
A user requests elevation
When admin access is actually needed, the user requests it from the Santa menu bar or with the santactl adminmode command.
Authenticate, then justify
Local authentication is always required before a user can elevate. Policy can also require a justification, captured for the record.
Time-boxed, then revoked
Admin rights are granted for a limited window, then revoked automatically when it expires, the screen locks, the session ends, or the machine reboots. Policy sets the ceiling, from 1 minute to 30 days.
Controls
Policy-driven, down to the minute
You decide how elevation works on your fleet. Every control is set per tag in Workshop's sync settings, where the feature appears as Temporary Admin Mode.
Duration limits
Set the maximum elevation window, from 1 minute to 30 days, and a default duration for requests that don't specify one. The maximum is a hard ceiling on every request.
Required justification
Require users to say why they're elevating. The justification is captured with the request and lands in the audit trail alongside the who and the when.
Per-tag targeting
Set policy per tag. Pilot with one team, keep tighter limits on sensitive groups, and roll out to the rest of the fleet as you build confidence.
Audit trail
Every elevation has a paper trail
Privileged access without a record is a liability. Santa records every elevation, expiry, and denial, then uploads it to Workshop, so the answer to 'who was admin, when, and why' is always one query away.
-
Who, when, and why
Every elevation, expiry, and denial is recorded with the user, the timestamp, and the justification they gave. Denials carry the reason they were refused.
-
Centralized in Workshop
Audit events upload to Workshop, so there's one complete record of privileged access across the fleet instead of logs scattered per host.
-
Live elevation visibility
See which user currently holds an elevation on any host, straight from the host view. No guessing who is admin right now.
Use cases
Least privilege people can live with
Endpoint Privilege Management is for teams that want admin rights gone, not just inventoried.
Least privilege and compliance
Enforce least privilege as standing policy, not an aspiration. The centralized audit trail gives SOC 2 and ISO 27001 reviewers a complete record of privileged access.
A smaller attack surface
Admin rights exist only inside short, deliberate windows. Malware that lands on a host inherits a standard user, not an administrator.
Developer-friendly elevation
Engineers get just-in-time admin access in seconds, from the menu bar they already use. No help-desk ticket, no waiting on another team.
Endpoint Privilege Management is part of Workshop
Pair EPM with the rest of the platform to cover execution, elevation, and everything in between.
Approval workflows
Self-service, manager, tag-based, and Slack-native approvals that keep lockdown usable.
Telemetry
Rich, queryable event data from every endpoint, including every elevation event EPM records.
Execution rules
Decide exactly what runs on your fleet with binary, certificate, Team ID, and Signing ID rules.