Native Endpoint Privilege Management (EPM), Just-in-Time Admin & Application Allowlisting
Atera would benefit greatly from a native Endpoint Control module similar to idemeum Endpoint Control.
The goal would be to combine Endpoint Privilege Management, Just-in-Time Admin Access and Application Allowlisting directly within the existing Atera Agent.
Key features could include:
Remove permanent local admin rights from users
Just-in-Time temporary admin access
Elevate individual applications without granting full admin rights
Technician approval/denial of elevation requests
Policy-based automatic elevation for trusted applications
Application Allowlisting / Default-Deny
Audit / learning mode before enforcement
Allow rules based on publisher, certificate, hash or path
User requests for blocked applications
Approval directly from the Atera console or mobile app
Management of local admin accounts and password rotation
Full audit trail for elevation and application events
Policies per customer, site, group or endpoint
Example workflow:
A user starts an application that requires administrator privileges.
Instead of sharing an admin password or starting a remote session, the Atera Agent can automatically:
allow and elevate a trusted application,
block an unapproved application, or
send an approval request to a technician.
The same policy engine could also control which applications are allowed to run at all.
There are already separate UserVoice requests around UAC approval workflows, application whitelisting and credential management. Combining these capabilities into one native Endpoint Control module would provide a much more complete least-privilege and application-control solution for MSPs.