Skip to main content

How elevation events work

Elevation events are collected only when EPM is enabled, and the EPM control mode for the workstation is set to audit or rules.
  • Events are captured on Windows and macOS workstations when applications need to launch with administrative privileges or user needs to take a privileged action.
  • On windows idemeum agent intercepts and captures the UAC event. For macOS we rely on endpoint security API to capture the elevation event.
  • For audit mode elevation events are captured for both admin and standard users
  • Idemeum cloud retains 120 days of elevation events per tenant
  • Elevations events are uploaded to cloud in real time

Elevation event structure

To access elevation events navigate to your admin portal and access ActivityEvents. You will be presented with the high level view of all events for your tenant. You can click on each event to expand the metadata for the event. Clean Shot 2026 05 25 At 11 04 27@2x Now let’s look at what each attribute in the event means.