EPM - Endpoint Privilege Management Policies
Overview
A core principle of safe computing is to never use more privileges than necessary for day-to-day computing tasks. Normal tasks like web browsing and email should happen on a standard account, and never with administrative privileges. However, all users eventually encounter a scenario that requires them to elevate their privileges to a higher level in order to accomplish a task. Our goal is to enable this elevation without undue burden to the user or their local IT support staff.
At Texas A&M, we believe that our users are capable of making rational and informed decisions about security risks when properly educated and treated with respect. This belief is reflected in our approach to providing administrative rights to their end user devices. We believe we can provide our users the flexibility to perform their tasks while maintaining a secure environment.
Technology Services has selected two primary tools to enable privilege elevation on end user devices: Admin By Request for Windows devices, and Privileges for macOS. These are flexible tools that allow for the management of privilege elevation via multiple approaches. We have adopted a primary model for most end user devices on campus, with additional models available where a business need exists.
Admin Session Model
The Admin Session model allows users to elevate their privileges with a click of a button, provides them administrative rights for a short period, then automatically drops back to an unprivileged level after a short time. This model is particularly suited for academic environments, where faculty and other knowledge workers often need administrative access for novel or unpredictable tasks.
Specialized Privilege Model
Specialized Privilege models deviate from the Admin Session model based on business needs. Examples include:
- Permitting the ability to elevate specific applications without an Admin Session.
- Restricting elevation to specific applications during international travel.
- Denying the ability to elevate without a dedicated administrative account.
- Disabling all elevation for a user or device during a security incident.