EPM deployment
Remove standing local administrator rights and grant privilege per application from a single, featherweight agent, managed through Group Policy and the EPM console.
- An Active Directory domain and the Group Policy Management Console to distribute the agent.
- Windows endpoints joined to that domain (domain controllers included).
- An EPM entitlement in your license, activated in Get started → License.
- Optional: PAM groups or AD distinguished names to scope elevation policies.
1 · Roll out the agent (GPO) ¶
The agent is small and quiet. It deploys transparently, runs invisibly, and does not compete with the workloads it protects, so it can sit on every endpoint, domain controllers included, without a capacity conversation. Distribute it through Group Policy:
- Stage the package on a share every target can read.
- Create a GPO in the Group Policy Management Console and assign the agent under software installation (or run the installer from a startup script), pointed at the appliance address from Get started.
- Link the GPO to the OUs whose machines you want protected and let them pick it up on the next policy refresh. Enrolled endpoints appear in the EPM console.
2 · Set elevation policies (Application Elevation) ¶
Now remove standing local-admin rights and grant privilege per application. Under Application Elevation, create a rule that decides how each application is handled:
- Auto-elevate trusted applications with no prompt.
- Require justification with approval before elevation.
- Audit: allow but record.
Scope each rule to everyone, a PAM group, an Active Directory distinguished name, or a specific set of executables (by path, publisher or hash). Elevated sessions are recorded with keystroke logs and video, so every use of privilege is reviewable.
3 · Block execution (App Blocks) ¶
App Blocks stops unwanted software through IFEO registry entries, Software Restriction Policy, process termination, or service disable. Build the list from the observed Application List, and turn on the hardening rules that cover common bypasses, including the virtual keyboard, accessibility autostart, and ease-of-access.
4 · Patch and distribute (Patch Management, P2P) ¶
Create patch tasks with deadlines under Patch Management, target by AD tree, tag, or device list, and track affected devices against CPE vendor and product identifiers by severity. To avoid saturating a WAN link, agents elect a subnet seeder and distribute patches and applications peer to peer, so a remote site pulls the package once and shares it locally.
