Duplicate » admin by request

Admin By Request Web Access Management Is Now Live, Bringing Browser Control to the Endpoint

Man in a light blue button-down shirt sits on a blue sofa with teal and orange cushions in a bright living room by a window.

Admin By Request Web Access Management is available today. We introduced it a while back, walking through how it works and where it fits, and now it’s a live product you can put in front of your users.

For anyone new to it, our Web Access Management controls which browsers, websites, and executable downloads are allowed on managed endpoints. Policy is enforced on the device itself, and every decision is recorded for audit. It’s the third product on our Zero Trust Platform, joining our Endpoint Privilege Management and Secure Remote Access solutions.

Laptop on a white desk with neon data streams and security icons in a bright office environment, illustrating cybersecurity. » admin by request

Built on What Came Before

The idea behind all three products is the same one we started with: give people the access they need at the moment they need it, and keep a record of everything. Endpoint Privilege Management does this for local admin rights, removing standing access and granting just-in-time elevation with a full audit trail. Our Secure Remote Access solution does it for connectivity, replacing always-open VPNs and jump servers with scoped, logged sessions that close when the work is done.

Web Access Management points that same approach at the browser, which is where people spend most of their working day and where a large share of malware arrives. It runs on the agent our Endpoint Privilege Management customers already have, and it’s managed from the portal they already use, so switching it on doesn’t mean a fresh rollout.

“The browser is where most work happens today, and it deserves the same level of governance as the rest of the endpoint. With Web Access Management, security teams can set clear policy on which sites and downloads are permitted, and have a complete record of every decision.”

Lars Sneftrup Pedersen, Founder and CEO of Admin By Request

How It Works

Web Access Management sits in the agent on each managed device and checks browsing and download activity against the policy you’ve set. When someone visits a site, it’s allowed, blocked, or held for approval based on your rules. Browsers themselves are covered the same way, so you can decide which ones are permitted and keep users off outdated versions.

Downloads get a closer look. When a user pulls down an executable, the agent holds the file before it lands, runs it against your policy and a malware scan, and only then releases the original to the user. Trusted files clear automatically, so most downloads happen without anyone waiting, and only the ones worth a second look go to an administrator.

Every allow, block, and approval is written to the audit log, giving you a full record of what was requested and what happened. The next section covers what sets this apart from the web filtering most teams already know.

What It Does Differently

Most web security tools sit in the network path and inspect traffic on its way out to the internet. That assumes people connect through a point you control, which no longer holds for remote workers and contractors on networks you don’t own. We enforce policy on the endpoint itself, so protection travels with the device and needs no proxy, DNS filter, or firewall change.

That endpoint approach also means nothing depends on a cloud gateway staying online. The checks run locally in the agent, so a dropped connection doesn’t leave people unable to work or quietly bypass policy. From the portal, you decide how browsing and downloads are handled across your fleet. Administrators can set policy over:

  • Which browsers users can run, and at which minimum versions
  • Which websites are allowed, blocked, or subject to approval
  • Whether executable downloads are allowed, require approval, require a stated business reason, or are denied outright
  • Whether MFA or Intune compliance is required before a download is released
  • Whether downloads are restricted to the device owner

We designed it so trusted activity clears on its own, because controls that slow people down tend to get switched off. You can pre-approve downloads by source, checksum, or vendor certificate, and let AI and machine learning wave through well-established software without manual review. The malware scan runs through OPSWAT MetaDefender, so files are checked against a broad set of reputation data before release, and routine downloads still go through untouched.

Professional woman in a gray blazer working on a laptop at a bright office desk, with a phone and notebook nearby. » admin by request

One Agent, One Portal

Web Access Management uses the sub-settings model that runs through the rest of the platform, so a company-wide baseline policy can coexist with tighter rules for specific groups. Your finance team can be held to approval and MFA on every download while IT works from a broader pre-approved list, with no separate deployment or second tenant to manage.

You can try Web Access Management on up to 25 endpoints through our free plan, with no time limit and no features held back. It’s the easiest way to see how it works against your own browsers, sites, and downloads before rolling it out more widely. Alternatively, you can book a demo here and we’ll walk you through it.

About the Author:

Picture of Pocholo Legaspi

Pocholo Legaspi

Pocholo Legaspi is a content writer at Admin By Request, where he covers privileged access management, endpoint security, threat analysis, and the wider cybersecurity issues facing IT teams. With over a decade in content marketing and SEO and a master's in business informatics, he writes about complex security topics in a way that's clear and useful for the IT teams putting them into practice.

Share this blog to your channels:

Lifetime Free Plan for 25 Endpoints,
No Strings Attached.

Fill out the form to create your account and get started.

Book a Demo