Elevation rules - Idemeum Docs

Elevation rules framework

In this case we are only looking at elevation rules, without allowlisting to control application execution. If you want to learn more about allowlisting and full cycle rules, please check here.

  1. What is the application?
    The first part of the rule is to catch or match the application you are trying to elevate. Before elevating something, we need to know what it is. You can match the target application using file attributes (hash, name. path, etc.), publisher thumbprint (the hash of the certificate that is used to sign the executable, or certificate elements (when application is signed you can use certificate elements of the signing certificate to match the app).

  2. Allow elevation?
    If an application requires admin privileges, and you maintain standard rights for all users, you can allow the application to automatically elevate.

  3. Can users request?
    When application elevation is blocked, your users can request the permission or elevate the application.

Elevation rules best practices

These are some of the best practices related to rule management:

Catalog rules

Idemeum comes pre-configured with allowlisting and elevation rules for most common applications. We constantly update applications to make sure the rules are current and do not create any disruptions. With a click of a button you can allow most used applications in your environment.

Catalog rules Create elevation or allowlisting rules with a single click.

Create elevation rule

If you want to create your own custom rules or elevate applications that are not listed in idemeum catalog, you can simply do that from the event. Launch the application you want to elevate, the event will be generated and sent to the cloud. Now you can create rule from the event.

Elevation rules Regex

Idemeum rule engine supports regular expressions when matching the applications using various attributes. We support regex for file name, file path, and certificate elements. We use case-insensitive match.