Skip to main content

EPM - Endpoint Privilege Management Policies

EPM Tool Deployment Policy

  • Endpoint Privilege Management (EPM) tools are authorized for use on individually-assigned end user devices, and may be permitted on shared devices on a case-by-case basis.
  • EPM tools are intended to support knowledge workers as outlined at EPM Overview, and must be available to knowledge workers.
  • Privilege elevation is only allowable on devices with the EDR agent installed and providing telemetry, and is subject to the Usage Policy.
  • Admin By Request and Privileges are the only allowable EPM tools on end user devices.
  • The default policy for devices is the Admin Session model.
    • Specialized Privilege models may be available as an alternative in situations where the Admin Session model is not appropriate, such as shared devices in a lab, devices travelling internationally, or devices used by some administrative staff.
    • In order to utilize a Specialized Privilege model, a documented business justification must be approved by the Office of the CISO (submit to endpoint-security@tamu.edu).
  • Some units may choose to operate without providing access to elevated privileges in specific circumstances.
    • In these cases, the EPM tools do not need to be installed.
    • Requests should be submitted in writing to the Endpoint Security team with an Axonius query identifying the exempted devices.
    • Final approval rests on agreement between the corresponding Associate Vice President within Technology Services over that unit and Office of the CISO, or their delegates.
  • Requests for exceptions to the above policies must be approved by the Office of the CISO.

Policy on Misuse of Elevated Privileges

As part of our Endpoint Privilege Management (EPM) strategy, faculty and staff may be granted the ability to temporarily elevate their device permissions using EPM tools; Admin By Request (Windows) or Privileges (macOS). This access is intended to support productivity and flexibility while maintaining a secure computing environment.

With elevated privileges comes added responsibility. Misuse of admin rights — even if unintentional — can put institutional systems, data, and users at risk. To ensure appropriate use of these tools, violations of this policy will be addressed through a three-strike process as outlined below.

What Constitutes a Violation?

A violation occurs when a user takes action using elevated permissions that violates institutional policies, security standards, or acceptable use expectations. Examples include (but are not limited to):

  • Installing prohibited or unauthorized software (see Prohibited Software documentation)
  • Disabling or circumventing security tools (e.g., antivirus, endpoint detection, device management platforms like Intune or Jamf)
  • Installing software in violation of its license terms (see control CM-11)
  • Making system configuration changes that impact security, networking, or device management
  • Creating unauthorized local accounts or attempts to make admin access persistent beyond the session time provided by EPM tools
  • Using admin privileges to support unauthorized users or activities
  • Using admin privileges to violate the university’s Acceptable Use Policy

Three-Strike Enforcement Process

  1. First Strike – Informal Warning & Reversal
    • The user receives a warning from their local IT support team.
    • The specific action taken with elevated permissions will be reversed or remediated as needed.
    • IT may offer education or clarification on proper use of ABR/Privileges to prevent future issues.
  2. Second Strike – Formal Warning from Information Security
    • Temporary suspension of admin privileges
    • Access to admin privileges will be reenabled after a formal discussion with the Office of the CISO
      • They will be informed that any further misuse will result in loss of elevated privilege access.
      • An email will be sent to the offending employee (CC: employee’s direct supervisor; ciso@tamu.edu) documenting the conversation and reiterating the expectations to maintain access to admin privileges
    • The specific action taken with elevated permissions will be reversed or remediated as needed.
    • Additional guidance or policy training may be provided.
  3. Third Strike – Revocation of Administrative Access
    • The user’s access to EPM tools will be permanently revoked.
    • Any future actions requiring admin privileges will be strictly limited to standard IT support channels.
      • This includes the restriction & removal of local administrative accounts, “-admin” accounts, alternate logins, etc.

Additional Notes

  • Local IT and Information Security will coordinate on detection, documentation, and enforcement of Usage Policy violations.
  • Strikes do not reset over time; they accrue cumulatively throughout a user’s employment. Appeals due to exceptional circumstances can be submitted to the Office of the CISO.

If you have questions about this policy or appropriate use of admin privileges, please contact your local IT team or the Endpoint Security Team.