Privilege
Manager
Privilege Manager removes standing local admin rights and replaces them with time-bound, policy-driven elevation. Users get access only for the exact task they need, for a defined window — with every event logged and exportable for audits.
Use it standalone. Or run it with your existing Microsoft setup.

Standing local admin was our biggest unresolved risk. CapaOne removed it fleet-wide in a single afternoon.
Least privilege — without stopping work
Privilege Manager removes standing local admin rights and replaces them with time-bound, auditable elevation. Users request (or receive) privileges only when needed, for the exact task or application, and only for a defined window of time — so work keeps moving while risk stays low.
- Eliminate permanent local admin privileges while keeping users productive
- Grant just-in-time elevation to users, apps, scripts, or commands — on a timer
- Pre-approve apps based on executable name or app path
- Enforce guardrails with allow/deny rules and evidence capture
- Audit everything with immutable logs and exportable reports for change boards and audits
Watch the Privilege Manager demo
See Privilege Manager in action in about a minute — no signup, no install.
Built to eliminate excess privilege
Time-Bound Elevation
Grant admin privileges for minutes, not days — auto-revoke on expiry with no manual cleanup needed.
Scope-by-Design
Elevate a specific executable, installer, command, or task — never the entire session.
Session Elevation
Quiet, in-context prompts with configurable notifications and minimal disruption to the user's workflow.
Policy Engine
Define who can elevate what, where, and under which constraints — per user, group, device, or application.
Guardrails
Fully customizable controls for high-risk tools and sensitive actions — allow/deny rules with evidence capture.
Break-Glass Controls
Tightly scoped emergency elevation for critical, time-sensitive situations — without handing out standing admin.
Logs & Evidence
Who/what/when, endpoint, binary details, time, duration, and outcome — all exportable to CSV for audits and change boards.
User Experience Controls
Pre-approve apps by name or path, configure self-service prompts, and keep users moving without IT bottlenecks.
Two ways to deploy — your choice
Run Privilege Manager as a complete standalone platform, or with Intune. Either way, Privilege Manager handles the granular privilege controls Intune alone does not provide.
See It LiveStandalone
Privilege Manager runs as a complete platform on its own — no Intune required. Remove standing local admin, define elevation policies, and target Entra ID groups directly.
- No Microsoft dependency
- Full privilege control from day one
- Policy engine + break-glass controls in one platform
With Intune
Add the granular privilege controls Intune alone does not provide, without disruption.
- Target Entra ID groups — respect your existing group structure and RBAC
- Adds least-privilege enforcement on top of your enrollment, compliance, and configuration baselines — no rip-and-replace
- Works alongside Defender and compliance signals to enforce elevation policies
Least privilege is the new baseline
Local admin rights on every device is one of the biggest privilege misconfigurations in most Windows environments. Privilege Manager closes it — for good.
- Reduce the attack surface: remove persistent admin rights and stop lateral movement via local admin.
- Prove control: show auditors standardized elevation workflows, logs, and short-lived access patterns.
- Support the principle of least privilege and separation of duties across IT and support functions.
- Align with NIS2 and CIS practices: strong access governance, traceability, and rapid revocation.
Outcomes your team will notice
Fewer tickets
Users complete routine tasks with self-service, within policy — no helpdesk call needed.
Faster fixes
Support can grant scoped elevation quickly without handing out full admin credentials.
Lower risk, less rework
Strong guardrails reduce misconfiguration and malware exposure from excess privilege.
Happier users
No more waiting hours for simple installs — done safely in minutes, within policy.
What "done" looks like
- 01Zero standing local admin privileges across all managed devices.
- 02Minutes-not-days elevation cycles with auto-approvals for known-good applications.
- 03Consistent, auditable elevation workflows that satisfy internal and external audits.
- 04Reduced malware and misconfiguration incidents tied to excess privilege.
Live in four steps
Most teams remove standing local admin the same day they start.
Baseline & Remove
Remove standing local admin from target groups and establish a clean privilege baseline across the fleet.
Define Policies
Set elevation policies for standard tasks — approved installers, printers, VPN clients, developer tools.
Pilot & Tune
Roll out with short durations and strict guardrails. Review logs, tweak policies, confirm user experience.
Operationalize
Scale to departments with scheduled policy reviews, periodic access recertification, and exportable evidence.
Related resources
Explore the rest of the lineup
How Does Elevation Work in Practice?
Users trigger elevation for a specific executable. Policies decide whether to auto-approve or deny. Admin privileges apply only to that scope and auto-expire.
Can We Block Risky Tools by Default?
Yes. Create deny rules for shells or unsigned installers and require explicit policy exceptions for controlled use.
Do We Need to Keep Some Users as Local Admins?
Best practice is no standing admin. Use policies for routine tasks and break-glass elevation for rare exceptions.
What's Captured for Audits?
User, endpoint, binary details (executable name, app path), time, duration, and outcome — all exportable.
How Do We Prevent Elevation from Lasting Too Long?
Set a short duration with auto-revoke.
Does This Work with Intune and Entra ID Groups?
Yes. Target policies via Entra ID groups, respect existing group structure, and run with your Intune compliance and configuration.
What Happens Offline?
Policies can allow cached decisions for low-risk tasks with strict durations, and queue logs for sync when the endpoint is back online.
Can Support Staff Grant Elevation Without Sharing Admin Creds?
Yes. Supporters can authorize a scoped, time-bound elevation without exposing local admin accounts.
How Quickly Can We Roll This Out?
Typically within minutes — it's a very simple configuration, executed in a phased approach: remove standing local admin privileges, apply standard policies to test endpoints, then scale to departments with measured guardrails and reporting.
Ready to get started?
Consolidate your endpoint privilege operations with CapaOne — standalone or with Intune.




