One agent. Three layers of control.
Software installs. Windows settings access. USB devices. ElevateIQ puts IT in control of all three, with MFA, AI risk scoring, rules, and a full audit trail, without adding a second product or a shared admin password.
Everything privilege-related. One place.
ElevateIQ is an Endpoint Privilege Management (EPM) platform for Windows: it gives IT three distinct controls, each with its own rules, approval queue, and audit trail, all managed from a single console.
Elevation Requests
Standard users request elevated access, IT approves, ElevateIQ runs it. MFA-verified, AI-scored, and executed in exactly the right context.
-
User elevationTemporary admin rights, user identity preserved. Profile, drives, and licenses stay intact.
-
Admin elevationDedicated managed account, no shared credentials. Safe default for installs and updates.
-
System elevationSYSTEM-level access for drivers and services. Gated, logged, reserved for cases that need it.
Access Requests
Admin-gated Windows settings, network, printers, display, power. Pre-approve them once, users unlock on demand without calling IT.
-
Network and VPNAdapter settings, proxy config, and VPN client changes. Pre-approved, policy-gated.
-
Devices and printersPrinter installs and peripheral setup. Users self-serve, IT stays in control.
-
Power, display, and timeDate/time, power plans, and display settings, all policy-gated.
USB Requests
Every USB device goes through policy. Storage blocked by default, users request access, IT approves. Fully logged.
-
Storage controlFlash drives and external SSDs require approval before they enable.
-
BadUSB defenseHID devices plugged in mid-session go through the rule engine. Rubber Ducky blocked.
-
Standard / Strict / CustomStandard allows peripherals, Strict gates every class, Custom lets you pick per device type.
Software installs, your rules. Three ways to run them.
Every elevation is MFA-verified, AI-scored, and run in exactly the right context, not just "as admin." IT picks the mode per rule; users just click request.
User
Runs as the requesting user with temporary admin rights. HKCU profile loads, network drives stay mapped, licensed apps see the right identity. Best for apps that write to the user profile.
Admin
DEFAULTRuns via a dedicated managed admin account, no shared passwords, no user credentials exposed. The safe, audited default for the vast majority of software installs and updates.
System
ADVANCEDRuns as the Windows SYSTEM account. For kernel-level tools, Windows services, and machine-wide configuration that Admin mode cannot reach. Gated, logged, reserved for cases that need it.
Block the bad USB. Approve the good one in a click.
Same agent. Same admin queue. No second SKU. Standard posture allows peripherals; flip to Strict and every USB class goes through policy.
BadUSB defense by default
A Rubber Ducky plugged in mid-session goes through the same approval flow as any other USB. Defender, CrowdStrike, and Symantec leave keyboard-class devices outside policy.
One agent. One queue.
USB approvals and software elevation share the same tray, the same admin console, and the same audit log. No second product to install, license, or train your team on.
Safe by design
ElevateIQ runs entirely in user-mode using Windows’ own SetupAPI. Updates roll out smoothly across your fleet with zero risk to system stability.
User side: the moment a blocked USB plugs in.
A risk score on every request. Smarter every week.
AI Analysis
AI Suggestion: ApproveVerdict: The executable is a validly signed installer from Mozilla Corporation, a well-known and trusted software vendor. The product is identified as Firefox, a legitimate web browser.
This executable is an installer for the Mozilla Firefox web browser. It is used by end-users to install or update the Firefox application on their systems, providing internet browsing capabilities.
Approve from anywhere. Every decision on record.
Push-notified the moment a request comes in, admins review the app, publisher, machine and user, then approve or deny with Face ID, without opening a laptop. Every outcome lands in a searchable history: elevation, access, and USB decisions, tagged by org and requester.
- Face ID / passkey sign-in, secure by default
- Instant push on new requests
- Full decision history, searchable by app or user
Rules from everywhere. Deny always wins.
Build your allowlist five different ways. When an allow and a deny rule conflict, deny wins, always, with no exceptions.
- Manual
- From a pending request
- Drag-drop a binary
- Curated rule library
- Learned from your team
- Deny always wins
Simple, per-endpoint, no surprises.
Up to 10 endpoints
More than 10 endpoints