Standard users often need to download, install, or update applications on their systems. Often, these applications they install or files they download may not be required for their work, and in some cases, they may contain malware depending on where they’ve come from.
To prevent users from having excessive and risky permissions on their systems, IT administrators remove permanent admin rights and grant limited admin access when they need it for a genuine business purpose. This is called Just-in-time local admin access.
Unified PAM is a tool that helps the IT administrator remove the local admin access that users generally have on their systems after assessing what applications are used on their systems regularly.
The admin can then define which applications users truly need by configuring allowlist or blocklist control policies.
For all other requests, they can grant temporary local admin access upon one or more layers of approval. Once the time period elapses, they will go back to being a standard user.
Unified PAM comes with lightweight privilege management agents that handle admin access provisioning.
The IT admin will define security policies for these agents specifically for the computers they are sitting on. Once deployed on user’s systems, the agents control what is being run, installed, or updated by them.