Privilege Manager

Elevate Privileges for essential apps

Privilege Manager

Privilege Manager is an installable solution that lets IT Admins elevate and manage user rights quickly and precisely with ScriptLogic's Validation Logic targeting technology.  Use privilege elevation rules from the Privilege Authority Community or create your own rules and allow access to just the applications, Windows processes and ActiveX controls you deem safe..

Privilege Manager features:

  • Elevate applications, Windows processes and Active X controls
  • Pre-defined elevation rules
  • Custom Rule creation
  • Validation Logic Technology
  • Comprehensive Reporting
 

Unlock the low-cost solution to elevating user rights

Now you can grant user accounts the least privileges necessary according to best practices, yet elevate specific applications and ActiveX controls as needed.  Set elevated execution privileges for just those applications, features, and controls you choose.

Elevate applications, Windows process and Active X controls

Grant users permission to install software, make desktop changes, and install Active X controls that you deem secure.

Digital certificate verification and support

Deploy custom or pre-defined elevation rules by leveraging Group Policy Objects.  Digital certificate support provides additional security for file elevation rules.  Automatically elevate all of the applications from a specific publisher.  That way, anything signed with that certificate will be elevated.  (e.g.  all Microsoft or Adobe programs).

Target rules specific to a user, computer, group, platform and organisation

Our Patented Validation Logic technology can target access rights to a specific user, user group, organisational unit, operating system, computer group, office or application.

Easily report on elevated privileges

Use Privilege Authority’s single-click reports to audit privilege activities across the domain.  These reports help organisations comply with internal policies and external mandates like USGCB/FDCC, PCI, SOX and HIPAA.  Single-click reports also allow organisations to manage privilege elevation policies with fewer resources.

Community Rules Exchange and technical support

Maximise your investment by sharing rules through the Rules Exchange, and tips among the Admin community at our Privilege Authority forum.  Also get a full year of support by phone, email, and web.

Elevate specific applications

Many applications require administrative permissions to run properly, either because they’re accessing admin functions or because they weren’t written with limited privileges in mind.  Privilege Authority allows you to create rules to elevate those applications to run with any of the elevated privileges you specify.  Optionally elevate automatically any child processes created by that application.

Elevate Windows processes

The Windows security model means that often limited privilege users can’t do even basic things like change the time or time zone on their computer.  This leads to running most travelling users as local admin.  With Privilege Authority, you can elevate the specific Windows processes you need, without running those users as local admin.

Elevate all files in a folder

Many applications can involve several exe files, making it hard to know how to pinpoint the right one.  With Privilege Authority, you can elevate every file in a specific folder, including subfolders.  This ensures that every feature of the application will run properly, even if that feature is in a different exe file.

Elevate Active X controls

Unfortunately, Internet Explorer security means that allowing Active X controls is an all or none proposition.  If you allow them because of essential controls, like Flash, you are also allowing them for any control a user may wish to install.  This reduces system stability and increases help desk calls.  With Privilege Authority, you can disallow Active X controls in IE, but elevate approved controls by specifying their URL.

Elevate application installers

One downside to running users under limited privileges is that installing even approved applications requires the help of an admin.  With Privilege Authority you can run approved installers (setup.exe and setup.msi files) under elevated credentials.

Verify approved installers

When you elevate an installer, you can have Privilege Authority create a secure SHA-1 hash of the file.  This digital “fingerprint” ensures that only the approved installer will run with elevated privileges and that users can’t bypass security by renaming other files to get them to run.

Verify files with digital certificates

You can be sure that only the files you want to elevate are being approved by specifying that file’s digital certificate when you create the rule.  Then, when the application launches, Privilege Authority will verify the digital certificate before it allows the program to run.

Elevate applications with a publisher’s certificate

It would be much easier to elevate applications if you could just specify a publisher’s certificate when you create a rule.  Now, if you want to automatically elevate all of the applications from a specific publisher, just create a publisher’s certificate rule.  That way anything signed with that certificate will be elevated automatically.

Target rules to workstations or servers

Do you have a rule that you only want to apply on workstation operating systems? Now you can target rules to workstations or certificates with a single checkbox.

Target rules to specific operating systems

To run properly, an application might need admin rights on XP, but not on Windows 7, for example.  Now you can target rules to specific desktop or server operating systems just by checking those operating systems when you create the rule.

Target rules using Validation Logic

ScriptLogic’s patented Validation Logic is a real-time targeting engine.  Using Validation Logic lets you target rules to specific users, user groups, organisational units, computers, computer groups, IP address ranges, or even if specific files or registry keys exist on the target machine.  Boolean logic lets you create very granular targeting for your elevation rules.

Report on usage of privilege elevation policies

Privilege Authority’s centralised reporting enables administrators to generate reports across their entire environment without having to manually pull data from each individual client machine.  With a single click, administrators can report on privilege elevation activities, frequency of privilege usage and policy configurations.  These reports can be filtered or sorted by multiple criteria and exported to HTML, PDF and RTF formats.  For more in-depth information, custom reports can be created using SQL based 3rd party reporting tools.

Access phone, email and web support

Have full access to ScriptLogic’s phone, email and web support, and get program updates as well.

Download rules from the Rules Exchange

Don’t start from scratch.  You can easily download rules created by the Privilege Authority community through the Rules Exchange.  Download the rule, test it, customise it and deploy it all from the Privilege Authority console.

Share rules with the Privilege Authority Community

Create a cool rule? Want the admiration and adoration of your fellow admins? Share your rule on the Rules Exchange for other users to try.  Then the community can rate your rule, comment on it, and generally give you the recognition you deserve.

 

Solutions
Latest Version
2.7.1.80
26-01-2012
Google Analytics Alternative