How elevation events work
Elevation events are collected only when EPM is enabled, and the EPM control mode for the workstation is set to
audit or rules.- Events are captured on Windows and macOS workstations when applications need to launch with administrative privileges or user needs to take a privileged action.
- On windows idemeum agent intercepts and captures the UAC event. For macOS we rely on endpoint security API to capture the elevation event.
- For
auditmode elevation events are captured for bothadminandstandardusers - Idemeum cloud retains
120 daysof elevation events per tenant - Elevations events are uploaded to cloud in real time
Elevation event structure
To access elevation events navigate to your admin portal and accessActivity → Events. You will be presented with the high level view of all events for your tenant. You can click on each event to expand the metadata for the event.

