Securden Privilege Manager Features

How to Enforce Least Privilege on Offline Endpoints?

Users on offline endpoints should not be granted administrator accounts. They should be granted just enough privileges to complete tasks and only when required. While many methds are available for managing user privileges on offline endpoints, using an endpoint privilege manager would solve the problem of controlling and monitoring the elevated access even when the endpoints are offline.

Securden Endpoint Privilege Manager provides offline access provisions that allow users to dynamically gain admin rights using offline access codes when they are using offline endpoints.

What are offline endpoints?

Offline endpoints are computers that are not connected to the corporate network in the context of business organizations. The IT administrator has challenges when managing such endpoints. They are difficult to manage because the latest changes cannot always be pushed to these devices.

When an EPM is deployed and admin rights are stripped from the users, offline endpoints will not allow the end users to dynamically gain admin rights by placing requests. Here, Securden EPM provides offline access provisions that help the end user to carry out their tasks seamlessly.

How are Endpoints and the Securden EPM Server Connected?

Securden EPM works according to the architecture explained below.

  • The EPM admin console is installed on a central server in on-premises deployments. The EPM server resides in the cloud in SaaS deployments.
  • The agents are deployed on the endpoints to handle privilege management operations in accordance with the policies dictated by the central server.
  • The agents communicate with the central server in short intervals to update the server on activities and fetch latest policy updates and approval status updates for privilege elevation requests.

The endpoints are typically confined to that network and are in constant contact with the servers according to the configurations set by the IT administrators.

How does Connectivity between the EPM Server and Endpoints Get Severed?

The privilege management agent can stop communicating with the central EPM server in many situations. Here are some examples:

  1. The central server is down for maintenance purposes.
  2. Loss of connectivity due to firewall misconfigurations.
  3. Loss of internet connectivity on the endpoint. (In SaaS deployments)
  4. The employee needs to work remotely. (In on-prem deployments)

Similarly, many other scenarios cause loss of communication between the Securden agent and the EPM server.

How to manage privileges on these offline endpoints?

To handle privilege management in such scenarios, Securden provides a code-based privilege elevation mechanism which the users can use to get permissions to run applications and elevate privileges.

Offline access codes can be used in two ways. The administrator can enable/disable each of the options if needed.

  1. Codes are generated by users for themselves.
  2. Codes are generated by Admins for users.

Users can make use of these codes to elevate applications or gain temporary full-local admin rights in accordance with the preferences set by the Securden EPM administrator.

How to configure offline access code?

The Administrator in Securden can configure the preferences to control how users can use offline access codes.

Each of the option below can be enabled/disabled to control how offline codes are used.

  1. Accessing applications that are not allowlisted
  2. Elevating individual applications
  3. Getting temporary full-admin rights

Every privilege elevation activity performed using offline access codes gets tracked by the Securden Agent. Once the connectivity between the agent and the server is restored, then all these activities are populated in the audit trails.

Securden EPM helps enforce accountability for actions even on offline endpoints.

Privilege Management on Offline Endpoints - Frequently Asked Questions?

plus icon minus icon
Can users generate offline access codes for themselves?

Yes, if the EPM administrator has enabled the provision, users can generate the offline access codes for themselves using the Securden Agent.

plus icon minus icon
How to check if the provision to generate offline access codes has been enabled for end users?

End users can check if the provision is enabled by clicking on the agent’s tray icon. If the option Generate Offline Access Codes is available, then the provision is enabled.

plus icon minus icon
How many times can one offline code be used?

Offline access codes are for one-time use only. If the code is used once, then the code becomes invalid.

plus icon minus icon
How can the administrator share the offline code generated from the EPM interface?

The EPM administrator can share the offline access code with the end user through any means possible. However, sending the code in a password protected format is advisable for security purposes.

See Securden EPM in action.

Book a personalized demo today

Book a Demo
Securden Help Assistant
What's next?
Request a Demo Get a Price Quote

Thanks for sharing your details.
We will be in touch with you shortly

Thanks for sharing your details.
We will be in touch with you shortly