Admin By Request for Windows 9.0 introduces Web Access Management, an endpoint-based policy layer that gives IT teams control over which browsers, websites, and executable downloads are allowed on managed devices. This release also gives you more control over elevated sessions while they’re running, letting users extend an active Admin Session and letting portal administrators end one remotely.
Web Access Management
Web Access Management is a policy layer for how people browse the web and pull down software, enforced on the endpoint by the agent already running our Endpoint Privilege Management solution. There’s no new client to roll out; it’s activated from the same portal you use for everything else.
The idea is to control web-based risk without turning IT into a full-time approval desk. Trusted sites and downloads can be pre-approved so they flow without friction, while riskier activity is blocked, held for approval, or scanned before it’s allowed through, and every decision is written to the audit log. It breaks down into two sets of controls.
Browsing controls:
- Browser lockdown – set which browsers are allowed and at what minimum version, so outdated or unapproved ones are kept out
- Blocked sites – deny known unwanted or non-compliant sites by URL and path
- Pre-approved sites – let trusted destinations skip the approval step, with explicit blocks always taking priority
Download controls:
- Approval and gating – allow, block, or send executables for approval, with release conditional on MFA, a stated reason, Intune compliance, or device owner
- Pre-approved and blocked – clear trusted downloads automatically, or hard-deny by source, checksum, or vendor certificate
- Malware scanning – check files through OPSWAT MetaDefender before they reach the user
Because enforcement happens in the agent rather than in the network path, policy travels with the device wherever the user is, with no traffic routed out to a cloud proxy or appliance for inspection.
For the full rundown of how it works, our Web Access Management deep dive covers it in detail, and the Getting Started guide walks through setup.

Extend an Active Admin Session
A non-admin user can now add time to an Admin Session that’s already running, without waiting for it to expire and without completing MFA again. Elevated work sometimes runs longer than the original window, and this keeps people from getting cut off mid-task.
It’s policy-controlled through the Allow session extension setting under Windows Settings > Lockdown > Admin Session, so you decide whether it’s available, and you can cap how many times a session can be extended and by how much. Every extension is logged. The result is fewer repeated MFA prompts during ongoing work and a better balance between control and usability.
End an Elevated Session Remotely
From the other direction, an authorized portal user can now terminate an ongoing Admin Session remotely from the portal. This is for situations where elevated rights need to come down right away, whether the work is done or IT needs to end things for a security or operational reason.
Termination applies immediately and reuses the existing end-of-session logic, including force-closing elevated applications, so it’s a real stop rather than a soft revoke. There’s an optional blackout period to stop the user re-elevating straight after, access can be limited to specific portal roles, and every termination is logged with a record of who ended the session.
Under the Hood
This release includes a round of bug fixes and stability improvements. Many address specific customer reports and have been communicated directly to the customers affected, with the broader improvements carrying across the Windows product range.

Wrapping Up
Existing customers can grab 9.0 from the admin portal. For the finer details on Web Access Management, the documentation hub has our getting-started guide, spec sheet, FAQs, and more in one place.
If you’re new to Admin By Request and want to see Web Access Management or the session controls in your own environment, book a demo and we’ll walk you through it.
Useful Resources for this Release:

