---
title: "Endpoint Privilege Management"
description: "Remove standing admin rights on macOS. Santa grants time-boxed, audited elevation on demand, revokes it automatically, and logs every request in Workshop."
doc_version: "1"
last_updated: "2026-07-24"
canonical: "https://northpole.security/features/endpoint-privilege-management"
---
![](https://northpole.security/images/workshop/figma/hero-bg.png)

Endpoint Privilege Management

# Remove standing admin rights. Keep people moving.

Endpoint Privilege Management demotes standing local admins to standard users, then grants time-boxed elevation on demand. Admin rights exist only while they're needed, and every elevation is audited in Workshop.

[Book a demo](https://northpole.typeform.com/to/SG9jCi0v) [View documentation](https://northpole.security/docs/workshop)

Beta

![](https://northpole.security/images/workshop/figma/snow-corner-tr.png) ![](https://northpole.security/images/workshop/figma/snow-floor.png)

The problem

## Standing privilege is the attacker's favorite privilege

Most fleets pick one of two bad options: leave admin rights in place forever, or make every elevation a help-desk ticket. Endpoint Privilege Management removes the standing privilege without adding to the queue.

### Standing admin rights

Users who only occasionally need admin access often hold it permanently. Standing administrator access is one of the most common and most abused sources of endpoint risk.

-   Held around the clock, used a few minutes a month
-   Privilege sits in place for malware or an attacker to abuse
-   Anything that compromises the user inherits the admin rights

### Ticket-driven elevation

The traditional fix is to strip admin rights and route every elevation through the help desk. Least privilege survives, but productivity pays for it.

-   Every installer and system tweak becomes a ticket
-   Users wait on another team for routine work
-   IT burns time approving requests it almost always grants

How it works

## Elevation on demand, revocation on schedule

Santa enforces the policy on the endpoint. Workshop sets the rules and keeps the record.

1

Standing admins are demoted

Santa demotes existing local administrators, any account with a UID of 500 or higher, to standard users. Standing privilege disappears from the host.

2

A user requests elevation

When admin access is actually needed, the user requests it from the Santa menu bar or with the santactl adminmode command.

3

Authenticate, then justify

Local authentication is always required before a user can elevate. Policy can also require a justification, captured for the record.

4

Time-boxed, then revoked

Admin rights are granted for a limited window, then revoked automatically when it expires, the screen locks, the session ends, or the machine reboots. Policy sets the ceiling, from 1 minute to 30 days.

Controls

## Policy-driven, down to the minute

You decide how elevation works on your fleet. Every control is set per tag in Workshop's sync settings, where the feature appears as Temporary Admin Mode.

### Duration limits

Set the maximum elevation window, from 1 minute to 30 days, and a default duration for requests that don't specify one. The maximum is a hard ceiling on every request.

### Required justification

Require users to say why they're elevating. The justification is captured with the request and lands in the audit trail alongside the who and the when.

### Per-tag targeting

Set policy per tag. Pilot with one team, keep tighter limits on sensitive groups, and roll out to the rest of the fleet as you build confidence.

Audit trail

## Every elevation has a paper trail

Privileged access without a record is a liability. Santa records every elevation, expiry, and denial, then uploads it to Workshop, so the answer to 'who was admin, when, and why' is always one query away.

[Explore telemetry](https://northpole.security/features/telemetry)

-   ### Who, when, and why
    
    Every elevation, expiry, and denial is recorded with the user, the timestamp, and the justification they gave. Denials carry the reason they were refused.
    
-   ### Centralized in Workshop
    
    Audit events upload to Workshop, so there's one complete record of privileged access across the fleet instead of logs scattered per host.
    
-   ### Live elevation visibility
    
    See which user currently holds an elevation on any host, straight from the host view. No guessing who is admin right now.
    

Use cases

## Least privilege people can live with

Endpoint Privilege Management is for teams that want admin rights gone, not just inventoried.

### Least privilege and compliance

Enforce least privilege as standing policy, not an aspiration. The centralized audit trail gives SOC 2 and ISO 27001 reviewers a complete record of privileged access.

### A smaller attack surface

Admin rights exist only inside short, deliberate windows. Malware that lands on a host inherits a standard user, not an administrator.

### Developer-friendly elevation

Engineers get just-in-time admin access in seconds, from the menu bar they already use. No help-desk ticket, no waiting on another team.

Beta

Endpoint Privilege Management is in beta and requires Santa 2026.6 and Workshop 2026.6. It is enabled per tenant, so [contact us](https://northpole.typeform.com/to/SG9jCi0v) and we'll turn it on for your fleet.

## Endpoint Privilege Management is part of Workshop

Pair EPM with the rest of the platform to cover execution, elevation, and everything in between.

[Book a demo](https://northpole.typeform.com/to/SG9jCi0v)

[

### Approval workflows

Self-service, manager, tag-based, and Slack-native approvals that keep lockdown usable.

](https://northpole.security/features/approval-workflows)[

### Telemetry

Rich, queryable event data from every endpoint, including every elevation event EPM records.

](https://northpole.security/features/telemetry)[

### Execution rules

Decide exactly what runs on your fleet with binary, certificate, Team ID, and Signing ID rules.

](https://northpole.security/features/execution-rules)

## Sitemap

- [Home](https://northpole.security/index.md)
- [Workshop](https://northpole.security/workshop.md)
- [Santa](https://northpole.security/santa.md)
- [Features](https://northpole.security/features.md)
- [Cookbook](https://northpole.security/cookbook.md)
- [Docs](https://northpole.security/docs.md)
- [Blog](https://northpole.security/blog.md)
- [Glossary](https://northpole.security/glossary.md)
- [About](https://northpole.security/about.md)
- [Contact](https://northpole.security/contact.md)
