Supporting Zero Standing Privilege with Privilege Manager for Endpoints
See how Delinea Privilege Manager enables approval-based privilege elevation for Windows applications, giving administrators control over privileged access requests without making users permanent local administrators.
In this demo, what we're going to be showing is elevation on a Windows system using the Privilege Manager agent.
Here, a user is required to ask for approval to elevate this application. So, they put in a reason, and the approvers have already been set up in the platform.
So, we're going to see the user submit his request here and then switch over.
When we switch to the other screen, it will be the admin.
So, you see the approval is pending, now, we log in as an admin to the tenant.
Once our page loads, we navigate to our requests.
I'm showing here that you can still see the agent is pending when there's a new request in the tenant.
We click it for details, and you can validate the path and the requested time.
We're going to go ahead and approve it.
Since this is a demo, we're going to change the duration.
You can do a one-time approval. So, that means that every single time the application is launched, they would have to approve it.
Here, we're going to switch back over to the agent and see that the request has been approved.
Once we click OK and the application launches, we can simulate a little test.
Now, the next application we're going to elevate is not one that requires approval to open.
If we open it here just by double-clicking, you'll see that it launches with no problem.
But in this demo, we're going to demonstrate that we want to elevate this application.
So when we right-click the application and launch Request Admin Privilege, you'll see that we get prompted again with our approval request.
We submit a reason.
We're going to click OK after we're done typing our reason.
As we switch over to the platform tenant again, we see the new request, this time for elevation.
So, we click it, check our details, and approve the request.
This time, we're going to actually change it from...
There we go. So now it's been approved.
We go ahead and elevate and run the commands that we need to.
Here, a user is required to ask for approval to elevate this application. So, they put in a reason, and the approvers have already been set up in the platform.
So, we're going to see the user submit his request here and then switch over.
When we switch to the other screen, it will be the admin.
So, you see the approval is pending, now, we log in as an admin to the tenant.
Once our page loads, we navigate to our requests.
I'm showing here that you can still see the agent is pending when there's a new request in the tenant.
We click it for details, and you can validate the path and the requested time.
We're going to go ahead and approve it.
Since this is a demo, we're going to change the duration.
You can do a one-time approval. So, that means that every single time the application is launched, they would have to approve it.
Here, we're going to switch back over to the agent and see that the request has been approved.
Once we click OK and the application launches, we can simulate a little test.
Now, the next application we're going to elevate is not one that requires approval to open.
If we open it here just by double-clicking, you'll see that it launches with no problem.
But in this demo, we're going to demonstrate that we want to elevate this application.
So when we right-click the application and launch Request Admin Privilege, you'll see that we get prompted again with our approval request.
We submit a reason.
We're going to click OK after we're done typing our reason.
As we switch over to the platform tenant again, we see the new request, this time for elevation.
So, we click it, check our details, and approve the request.
This time, we're going to actually change it from...
There we go. So now it's been approved.
We go ahead and elevate and run the commands that we need to.