Remove local admin. Keep the business running.
Fidwyn EPM removes standing admin rights from every endpoint and grants privilege per application instead. One agent, engineered from scratch by Fidwyn, does the work: built to stay small and silent. Light enough to run everywhere; quiet enough to go unnoticed.
A next-generation agent your fleet will never feel.
Endpoint privilege management has a reputation for heavy agents that tax boot time, memory and the helpdesk. Fidwyn's agent technology, engineered from scratch, was built to end that trade-off.
It delivers exceptionally high performance with a minimal footprint and negligible CPU and RAM use, so lightweight that its size is never a concern for your endpoints or your fleet at scale. It deploys transparently through Group Policy, runs invisibly, and never competes with the workloads it protects. Elevation feels instant; patches and applications distribute peer to peer so a single WAN link is never saturated.
Least privilege that users do not fight.
The core of Fidwyn EPM is privilege: applications that need admin rights do not run without EPM approval. Around that core sit four deliberately lightweight capabilities managed from the same console: vulnerability analysis, patch management, software and hardware inventory. Fidwyn does not aim to replace an ITSM suite; it gives privilege management the visibility it needs.
Auto-elevate trusted applications, require justification with approval, or run in audit mode. Scope by everyone, a PAM group, an AD distinguished name, or a set of executables.
Elevated sessions are recorded with keystroke logs and session video, so every use of granted privilege is reviewable, event by event.
Block execution through IFEO registry, Software Restriction Policy, process termination or service disable. Hardening rules cover virtual-keyboard, accessibility-autostart and ease-of-access bypasses.
Create patch tasks with deadlines, target by AD tree, tag or device list, and track affected devices against CPE vendor and product identifiers, ranked by severity.
Fleet-wide software inventory across Win32, Appx, winget and Microsoft Store sources, with hardware inventory per device. When a newer version exists on winget or the Store and a CVE record matches, the system raises an update-available, vulnerability-present finding. CSV export included.
Applications with critical CVEs, top vulnerable applications, devices not reporting, and per-device CVE severity, with executive and compliance views for leadership.
A self-service catalog offers users the applications they are allowed to install; requests pass through approval and install remotely with no user interaction. Deployment manifests carry canonical IDs, architecture, install arguments and expected exit codes; UAC bypass and every elevation stay authorization-bound and logged.
Agents elect one seeder per subnet: it downloads once, the install is verified, then patches and applications spread peer-to-peer over a private local tunnel. A thousand endpoints do not queue behind a single WAN link, and distant networks each seed themselves.
Turns elevation and patch state into an audit-ready posture rather than a pile of raw events.
Least privilege without the helpdesk revolt.
Watch a standard user elevate one application, justify it, and have it recorded, with local admin gone.
