PAM Covers Your Servers.
Does It Cover Everything Else?

Legacy PAM was designed for systems and servers, but most breaches begin at the endpoint. Admin By Request EPM closes that gap, while extending coverage to Windows servers too, without replacing what you already have.

How Does Our Product Compliment Your Current PAM?

Endpoint Privilege Management doesn’t replace PAM. It extends privilege management coverage to the endpoint layer that legacy PAM and Microsoft Intune EPM weren’t built to fully address.

Capability

Legacy PAM

Microsoft Intune EPM

Admin By Request EPM

Platform support 

Limited or out of scope 

Windows 10/11 only 

Windows, macOS, Linux (core use case) 

Server support 

Yes, core use case 

Not available 

Windows server support 

Agent size 

Varies by vendor 

20MB+ extension 

2MB 

Policy sync 

Varies by vendor 

20–30 minutes 

Instant 

Just-in-time elevation with approval workflow 

Typically out of scope 

Custom workflow via Power Automate 

Manual and AI-driven approval, with Teams, Slack, ServiceNow, and Jira integration 

Activity reporting / audit logs 

Yes, for server access 

Up to 24 hours 

Real-time, for all endpoint elevation 

Malware scanning 

Typically not included 

None 

OPSWAT MetaDefender, 37+ AV engines 

Admin sessions (time-limited, system-wide elevation) 

Typically out of scope 

Not available 

Yes 

Support assist (helpdesk escalation) 

Typically not included 

Not available 

Yes 

Break glass / emergency admin access 

Typically out of scope 

Not available 

Built-in 

Offline mode 

Typically not included 

Not available 

PIN code support 

Secure remote and vendor access 

Typically not included 

Not available 

Available  

Browser and download control  

Typically not included 

Not available 

Available  

Mobile app for approvals 

Typically not included 

Portal only  

Yes, free iOS/Android app with real-time push approvals 

Microsoft 365 required 

Varies by vendor 

Yes (Intune Plan 1 minimum, or E5) 

No

Free tier 

Varies by vendor 

Trial only

25 endpoints, no time limit 

FAQs

No. Admin By Request EPM is designed to complement your existing PAM investment, not replace it. Legacy PAM solutions are purpose-built for privileged access to servers, infrastructure, and systems — and they do that job well. EPM addresses the layer PAM was not designed for: the endpoints where your users work every day. Together, they provide complete privileged access coverage across your environment.

EPM focuses on controlling and auditing local admin rights at the endpoint level — the workstations and laptops that legacy PAM typically does not manage directly. This includes just-in-time application elevation, time-limited admin sessions, helpdesk support assist, break glass emergency access, offline PIN codes, and real-time malware scanning on every elevation request via OPSWAT MetaDefender. These are capabilities that most legacy PAM products do not include at the endpoint level.

Admin By Request EPM supports Windows, macOS, and Linux from a single platform, with consistent policies, approval workflows, and audit logs across all three. ARM-based devices are also supported. Organizations running mixed environments can manage all endpoints from one portal without needing separate tools or separate reporting for each operating system.

Every elevation request is scanned in real time by OPSWAT MetaDefender, which checks files against more than 20 antivirus engines simultaneously. Suspicious or malicious files are automatically blocked or quarantined before elevation occurs, regardless of the policy configuration in place. This happens at the moment of request — not after the fact — which closes a critical window that most legacy PAM endpoint approaches leave open.

Deployment is typically measured in weeks, and in some environments, hours. The EPM agent is 2MB, requires no additional infrastructure, and can be deployed silently through your existing tools — SCCM, Intune, Jamf, or similar. There are no infrastructure changes required and no waiting period for rollback. For a detailed walkthrough of the process from evaluation to implementation, see the Enterprise Deployment Guide.

Admin By Request uses a Sub-Settings architecture that lets you set global defaults at the tenant level and create unlimited override groups for specific departments, locations, or device types. Policies are layered and applied on a first-match basis, which means you can maintain granular control across large, diverse endpoint estates without the policy sprawl that group-based systems create at scale. Organizations with 100,000+ endpoints manage this from a single portal without additional administrative overhead.

Admin By Request EPM includes offline PIN support, which allows users to request a time-limited PIN code that enables elevation without a network connection. This is particularly useful for field teams, remote workers, or situations where a device has become disconnected from the corporate network. It is a feature that many built-in endpoint privilege tools do not offer.

Yes. Admin By Request integrates with SIEM tools, identity providers, and ticketing systems including ServiceNow. Audit logs and telemetry feed into your existing monitoring stack, so EPM activity is visible alongside the rest of your security data rather than siloed in a separate system. For a full overview of available integrations, visit the Integration Hub.

What’s Next?

We have a range of resources available for enterprise security teams. Continue exploring at your own pace, or speak to one of our experts if you’d prefer a conversation.