Agent Reference Guide
Windows Agent
Local Administration Right
4 min
relogs end users need to have local administration rights on the endpoint at this point agent supports flexibility to manage this process on the endpoint, end user requests the local administration right over the agent’s tray application as shown below then the end user needs to choose a time limitation for being a local administrator at the end of this time local administrator right will be taken back and the session will be terminated in a configurable time to configure this session, the kill time below parameter should be set on the system configuration management page as second the default value is 30 seconds win agent local admin right expire session kill time = 30 when the time limitation is chosen, the request goes to kron pam, and the end user’s manager can observe it on the my approvals page the manager can approve or reject it the screen below shows that a user called demo user1 requested to be a local administrator for one hour if approved, a notification is shown to the end user to gain local administrator access, the end user needs to log out and then log in again when the end user relogs to the endpoint again, who has the local administrator right anymore till the time limitation is ended? when the time limitation is reached below kind of warning appears again and warns the end user to kill the session in a configurable time giving local admin rights is the online feature approval from the manager is required so, the agent and kron pam should communicate if the client is offline, this feature is not going to work