๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Elevation Settings

Choose how Application Elevation runs for a company, how long approvals last, who is notified, and what users see.

Where to find it
Devices โ€บ Application Elevation โ€บ Settings
Who can use it
Users with the elevation Admin permission
Plan
Application Elevation (Application Control + PAM)
For
Everyone

What the page is for

Settings apply to one company at a time. At the top you choose the operating mode: Disabled, Audit, Enforce, or Enforce + Ringfence. Below that you set how decisions are made (audit period, default approval length, how long a computer waits for a decision, the technician session window, offline grace period and several safety switches), how notifications and tickets work, and what the elevation prompt says to your users.

If the module is included in your plan but not switched on for this company, the page offers Turn on Application Elevation. Turning it on does not enforce anything; you pick a mode next.

What you see

The Elevation Settings page, with the operating mode, decisions & risk, notifications & ux, when somebody asks for elevation, save changes and danger zone numbered 1 to 6.
The Elevation Settings page. Numbers match the list below.
  1. Operating mode: four cards: Disabled, Audit, Enforce and Enforce + Ringfence. Selecting a card changes the mode immediately.
  2. Decisions & risk: Audit period (days), Default approval TTL (minutes), Wait for a decision (minutes), Technician session window (minutes), UAC credential provider, Restrict the temporary account, Offline grace period (hours) and four switches.
  3. Notifications & UX: Notification email, User message branding, Hotkey (technician quick-prompt), Max CPU (%) and Max RAM (%).
  4. When somebody asks for elevation: Show a notification in the console, Notify the parent company too, Raise a ticket for each request, and Time to log when a request was allowed automatically.
  5. Save changes: saves everything except the mode.
  6. Danger zone: Deauthorize Application Elevation.

How to use Elevation Settings

How to move from Audit to Enforce

  1. Review the Audit Review page and allow the common items first.
  2. Select the Enforce card. The mode changes straight away.
  3. Alternatively, set Audit period (days) so Audit switches to Enforce by itself after that many days (0 means no automatic switch).

How to change approval timings

  1. Set Default approval TTL (minutes), used when an approver does not pick one. 0 means one-time only.
  2. Set Wait for a decision (minutes): how long the computer keeps a request open. The default is 1440 (24 hours).
  3. Set Technician session window (minutes): after a QR approval, how long the technician can re-elevate without another prompt.
  4. Select Save changes.

How to set the technician hotkey

  1. Under Hotkey (technician quick-prompt), tick at least one of Ctrl, Alt, Shift or Win.
  2. Choose one letter or digit as the key. A preview shows the combination, with a warning if Windows or browsers already use it.
  3. Select Save changes.

How to set up notifications and tickets

  1. Enter a Notification email for pending-request alerts, in addition to the in-app feed.
  2. Turn on Show a notification in the console so approvers see a pop-up and a count on the scanner button.
  3. For customers who manage their own elevation, turn off Notify the parent company too.
  4. Turn on Raise a ticket for each request and set the minutes to log for requests an allow rule approved automatically (0 closes the ticket without logging time).
  5. Select Save changes.

How to customise the prompt users see

  1. Type a short message in User message branding, for example "Need help? Call Example Co. IT on 555-0100."
  2. Select Save changes.

How to switch the module off

  1. Under Danger zone, select Deauthorize Application Elevation and confirm.
  2. Computers stop enforcing rules within the offline grace period. Your rules and audit logs are kept.

Tips

  • Start in Audit: it logs every request without blocking and shows you what Enforce would do.
  • Block elevation when parent is browser, mail, or script host stops a common attack path where a downloaded file or email attachment asks for admin rights.
  • Require 2FA for technician approvals adds a second factor for the person approving.
  • Max CPU (%) and Max RAM (%) cap how much the agent may use on each computer.
  • The UAC credential provider lets a computer answer an administrator-password prompt by itself while a technician session is open, using a temporary local account. Keep Restrict the temporary account on its recommended setting.
  • A Block on the credential provider, or a requirement to restrict the temporary account, applies to that company and every company below it and cannot be relaxed lower down. A customer can always be stricter than their MSP, never looser.

Troubleshooting

  • "Pick a company first.": Settings belong to one customer at a time. Choose one in the company selector.
  • "Application Elevation is included in your plan: turn it on for this customer.": Select Turn on Application Elevation (administrators only).
  • "You don't have permission to change elevation settings.": Ask for the elevation Admin permission.
  • "Failed to change mode.": The mode change was refused; the page reloads to show the current mode.
  • The credential provider option says "not available: โ€ฆ has blocked it".: A company above this one has blocked it, and that cannot be overridden here.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.