Skip to main content

EPM control modes

Assuming the EPM is enabled for your tenant, you can change the control mode for each device to define how the control agent will handle elevations.
  • offline - idemeum control agent is not doing anything
  • audit - idemeum control agent collects events, but does not enforce rules
  • rules - idemeum agent applies rules and performs auto elevation
The sections below show how Windows and macOS devices behave with idemeum control agent installed depending on certain parameters.

Windows

ModeUser typeControl agentUser experience
offlineadminno actionsNo experience change
offlinestandardno actionsNo experience change
auditadmincapture eventsUAC set to always prompt
Native auth
Events captured in the cloud
auditstandardcapture eventsUAC set to always prompt
Native auth
Events captured in the cloud
rulesadminno actionsNative auth
No events in the cloud
No rules or auto elevations
rulesstandardenforce rulesRules and auto elevations
Events captured in the cloud

macOS

ModeUser typeControl agentUser experience
offlineadminno actionsNo experience change
offlinestandardno actionsNo experience change
auditadmincapture eventsNative auth
Events captured in the cloud
auditstandardcapture eventsNative auth
Events captured in the cloud
rulesadminno actionsNative auth
No events in the cloud
No rules or auto elevations
rulesstandardenforce rulesRules and auto elevations
Events captured in the cloud

Change EPM control mode

  • Navigate to your idemeum admin portal
  • Select Devices and search for the device you want to change the app control mode for
  • Click on ... then choose Set app control mode
  • Choose the mode and save the configuration
Clean Shot 2026 05 22 At 00 08 03@2x

Bulk EPM control mode change

  • Navigate to your idemeum admin portal
  • Access Devices section and select multiple devices with checkboxes
  • Click on the bulk change button at the top and choose Set app control mode
  • Choose the mode and save the configuration