EPM control mode - Idemeum Docs

EPM control modes

Assuming the EPM is enabled for your tenant, you can change the control mode for each device to define how the control agent will handle elevations.

The sections below show how Windows and macOS devices behave with idemeum control agent installed depending on certain parameters.

Windows

Mode User type Control agent User experience
offline admin no actions No experience change
offline standard no actions No experience change
audit admin capture events UAC set to always prompt
Native auth
Events captured in the cloud
audit standard capture events UAC set to always prompt
Native auth
Events captured in the cloud
rules admin no actions Native auth
No events in the cloud
No rules or auto elevations
rules standard enforce rules Rules and auto elevations
Events captured in the cloud

macOS

Mode User type Control agent User experience
offline admin no actions No experience change
offline standard no actions No experience change
audit admin capture events Native auth
Events captured in the cloud
audit standard capture events Native auth
Events captured in the cloud
rules admin no actions Native auth
No events in the cloud
No rules or auto elevations
rules standard enforce rules Rules and auto elevations
Events captured in the cloud

Change EPM control mode

Bulk EPM control mode change