Privileged User Management

Privileged User Management (PUM) is how Analog Informatics Corporation (AIC) kits give a person administrator rights only when the work needs them, only for as long as it needs them, and with a record of every step. The industry also calls this Privilege Elevation and Delegation Management (PEDM): endpoint elevation, delegation, least privilege, application and command control, just-in-time elevation, and auditing of privileged activity.

Elevation works on the local system through the AIC Agent, or by remote control from AIC Server with no agent installed. It works on systems that are always connected, on systems that connect now and then, and on fully air-gapped systems that never reach AIC Server.

Short answers

Does elevation need a network connection?

No. A one-time activation code or a signed grant is checked on the system itself. The Agent needs no connection to AIC Server at the moment of elevation.

Does elevation need an agent?

No. AIC Server can elevate a user on Windows over WinRM and on Linux and Unix over SSH with sudo, with no agent on the target.

How long does elevation last?

For the time the approver set. When the time ends, the kit removes the rights. If the system restarts during the grant, the Agent restores or removes the grant on boot so a restart does not leave rights behind.

Can a person be forced to sign out when elevation ends?

Yes, on Windows and Linux. Forced sign-out on Apple Mac is planned.

Is every elevation recorded?

Yes. Requests, approvals, activation, expiry, and removal are written to the audit trail, the Windows Event Log, and syslog when configured.

How it works

  1. Request - The user or an administrator asks for elevation.
    • From the console or from the Agent on the system
    • The request names the system, the person, the reason, and the length of time
  2. Approve - An approver says yes or no.
    • Approval gate with the reason shown
    • Optional start delay and a fixed duration
  3. Deliver - The grant reaches the system by the path that fits the site.
    • Pushed or polled signed grant on a connected system
    • One-time activation code or challenge and response on an air-gapped system
    • Remote job over WinRM or SSH with no agent on the target
  4. Activate - The system checks the grant and applies it.
    • Code or signature checked on the system itself
    • Rights applied for the approved time only
  5. Expire and remove - Rights end on time.
    • Automatic removal at the end of the grant
    • Restore or remove on boot after a restart
    • Optional forced sign-out on Windows and Linux
  6. Record - Every step is in the audit trail.

Methods of elevation

MethodHow it worksWhere it fits
One-time activation codeAIC Server mints a time-based code for one person, one system, and one time window. The Agent checks the code on the system, with clock drift tolerance, and can require the code to match the exact requestAir-gapped systems, help desk by phone
Challenge and responseThe system shows a challenge. The approver returns a response. The Agent checks the response on the systemAir-gapped systems where the approver must see the exact system
Signed grantAIC Server signs the grant with an elliptic curve digital signature algorithm (ECDSA) key. The Agent checks the signature before applying it. The grant is pushed to the Agent or picked up when the Agent pollsConnected systems and systems that connect now and then
Signed grant packageA signed package carries the grant across the air gap on approved media. The Agent refuses any package it cannot verifyFully air-gapped systems
Agent-local elevationThe Agent applies the grant on the system through a local, protected channelAny system with the Agent
Agentless Windows elevationAIC Server runs the elevation job over WinRM with PowerShell. No agent on the targetWindows systems where no agent is allowed
Agentless Linux and Unix elevationAIC Server runs the elevation job over SSH with sudo. No agent on the targetLinux and Unix systems where no agent is allowed
Agentless Windows file-share elevationAIC Server runs the job over the Windows file-sharing protocol. Turned off by defaultWindows sites that allow this path

Before a remote job runs, AIC Server can wake a powered-off target so the grant applies and the timer starts on a running system.

What can be granted

Grant

  • Membership in a privileged group, such as local Administrators, for a set time
  • Specific account rights on Windows
  • Durable grants that survive a restart and are restored or removed on boot
  • Forced sign-out when the grant ends, on Windows and Linux
  • Forced sign-out when the grant ends, on Apple Mac
  • A dry run that shows what a grant would change before it runs
  • A protected list of accounts and groups that a grant can never change

Application and command control

Capability

  • Command restriction in brokered sessions, blocking dangerous commands as they are typed. See Capabilities
  • Application broker: measure an application, generate an allow policy for Windows Defender Application Control on Windows, fapolicyd on Linux, and Endpoint Security on Apple Mac, and measure the application again before launch
  • Secure Application Launch: start an application with credentials the user never sees

Platforms

Platform

  • Windows
  • Linux and Unix
  • Apple Mac

The same elevation methods work when AIC Server runs on premises, in customer-controlled cloud infrastructure, or inside an air-gapped site. See Air-gapped systems.

Screenshots

Just-in-time elevation works with an agent, without an agent, and on air-gapped systems through one-time codes.

Platforms and integrations

Operating systems

  • Microsoft Windows
  • Linux
  • Red Hat Enterprise Linux
  • Ubuntu
  • Apple macOS

All logos and trademarks are the property of their respective owners. Their use does not imply endorsement.

See it on your use case

Request a demo