Prove Compliance
Without Slowing Down Your Team

A foundation of zero-trust principals at the endpoint, continuous control coverage, and audit-ready evidence makes compliance goals easier.

Reporting Capabilities

Our audit log and reporting tools allow you to extract anything in real-time, such as a graphical representation of the requests and elevations happening – as they happen. Admin By Request’s management tools put you in the front seat of the whole operation.

Device Location

See where all of your devices are on a scalable Google Map. Click for detailed info on each device.

Inventory

Get extensive details on hardware, software, local admins, events, and more for each endpoint

Activity

Tracked activity includes API, Login, SCIM activity, mobile app usage, and a settings changelog.

New devices

At a glance, see which devices have recently installed Admin By Request software.

Local Admins

Track and manage your local administrators from a central, birds-eye-view point.

ELevated apps

Use the Auditlog to see which apps have been elevated, by who, why, and when.

Compliance Mapping

An overview of how we can help you achieve some of the most common compliance controls. We have detailed control maps available for a range of compliance frameworks on our Documentation site.

Product

Control Area

How it Contributes

HIPAA Security Rule

Endpoint Privilege Management

§164.312(a)(1), §164.308(a)(4): Access control & information access management

Least privilege on systems holding ePHI, audit logs of every elevated session

Secure Remote Access 

§164.312(e): Transmission security 

Encrypted, recorded remote sessions for vendors and support staff accessing ePHI systems 

Web Access Management

§164.312(c), §164.312(e): Integrity & transmission security 

Blocks malicious downloads and enforces browser lockdown on endpoints handling ePHI 

SOC 2

Endpoint Privilege Management

CC6.1–6.3: Logical access controls

Full session audit trail evidences access restriction, authorization, and removal

Secure Remote Access 

CC6.6: Third-party access controls 

Time-limited vendor access with complete session recording as audit evidence 

Web Access Management

CC6 / CC7: System operations & monitoring

Download approval workflow and audit logs of browsing activity

NIST CSF 2.0 

Endpoint Privilege Management

Govern & protect: PR.AA identity management and access control 

Removes standing admin rights, grants scoped access on request, telemetry feeds Detect (DE) 

Secure Remote Access 

Protect: PR.AA remote access management

Brokered remote sessions without inbound firewall changes, full audit trail 

Web Access Management

Protect: PR.DS data security 

Download and browsing controls narrow data exfiltration paths, logs feed Detect (DE) 

NIST SP 800-53 

Endpoint Privilege Management

AC-2, AC-6, AU-2: account management, least privilege, event logging

Removes default privilege, grants only what’s needed for a task, generates AU-2 audit records 

Secure Remote Access 

AC-17: remote access 

Controlled, logged remote sessions without exposing RDP or VPN ports

Web Access Management

SI-3, CM-7: malicious code protection, software execution policies

Scans downloads and restricts what executes via browser lockdown

CISA Cybersecurity Performance Goals 

Endpoint Privilege Management

Governance & asset management goals

Executive dashboards and audit trails for accountability, session logging for visibility into privileged access

Secure Remote Access 

Supply chain goal

Time-limited, monitored remote access for third parties and vendors

Web Access Management

Vulnerability management goal

Malware scanning and download blocking during patching and remediation windows

CyFun (CCB CyberFundamentals, 2025 / NIST CSF 2.0 aligned) 

Endpoint Privilege Management

Govern & protect: PR.AA access permission management

Least privilege on systems holding ePHI, audit logs of every elevated session 

Secure Remote Access 

Protect & govern: Supply chain risk management

Brokered, fully audited third-party remote access supports supply chain risk controls

Web Access Management

Protect: PR.DS data security 

Browsing and download controls support data security and DE detection of anomalous activity 

Compliance Pack

We’ve made it easy to get your hands on all the necessary documentation needed for compliance checks at your organization. Our Compliance Pack contains all the docs that you’ve got access to on this page – download it below

You’ll only get the Public documents when you download the Compliance Pack. Visit our Trust Center for more.

Compliance by Design For Peace of Mind

Forward-thinking organizations build compliance into their IT infrastructure from day one, eliminating the costly scramble of retrofitting disconnected solutions last minute.

Admin By Request makes this practical with an endpoint-first approach to zero-trust principles. Just-in-time privilege elevation removes standing admin rights, so least privilege is a technical default. Every elevation is tied to a user, a reason, and a timestamp, generating the continuous audit trail that frameworks like DORA, ISO 27001, and SOC 2 require without additional effort. 

The result is security and audit-readiness as inherent qualities, which means less cost and less stress when auditors come knocking. 

FAQs

No. Admin By Request EPM is designed to complement your existing PAM investment, not replace it. Legacy PAM solutions are purpose-built for privileged access to servers, infrastructure, and systems — and they do that job well. EPM addresses the layer PAM was not designed for: the endpoints where your users work every day. Together, they provide complete privileged access coverage across your environment.

EPM focuses on controlling and auditing local admin rights at the endpoint level — the workstations and laptops that legacy PAM typically does not manage directly. This includes just-in-time application elevation, time-limited admin sessions, helpdesk support assist, break glass emergency access, offline PIN codes, and real-time malware scanning on every elevation request via OPSWAT MetaDefender. These are capabilities that most legacy PAM products do not include at the endpoint level.

Admin By Request EPM supports Windows, macOS, and Linux from a single platform, with consistent policies, approval workflows, and audit logs across all three. ARM-based devices are also supported. Organizations running mixed environments can manage all endpoints from one portal without needing separate tools or separate reporting for each operating system.

Every elevation request is scanned in real time by OPSWAT MetaDefender, which checks files against more than 20 antivirus engines simultaneously. Suspicious or malicious files are automatically blocked or quarantined before elevation occurs, regardless of the policy configuration in place. This happens at the moment of request — not after the fact — which closes a critical window that most legacy PAM endpoint approaches leave open.

Deployment is typically measured in weeks, and in some environments, hours. The EPM agent is 2MB, requires no additional infrastructure, and can be deployed silently through your existing tools — SCCM, Intune, Jamf, or similar. There are no infrastructure changes required and no waiting period for rollback. For a detailed walkthrough of the process from evaluation to implementation, see the Enterprise Deployment Guide.

Admin By Request uses a Sub-Settings architecture that lets you set global defaults at the tenant level and create unlimited override groups for specific departments, locations, or device types. Policies are layered and applied on a first-match basis, which means you can maintain granular control across large, diverse endpoint estates without the policy sprawl that group-based systems create at scale. Organizations with 100,000+ endpoints manage this from a single portal without additional administrative overhead.

Admin By Request EPM includes offline PIN support, which allows users to request a time-limited PIN code that enables elevation without a network connection. This is particularly useful for field teams, remote workers, or situations where a device has become disconnected from the corporate network. It is a feature that many built-in endpoint privilege tools do not offer.

Yes. Admin By Request integrates with SIEM tools, identity providers, and ticketing systems including ServiceNow. Audit logs and telemetry feed into your existing monitoring stack, so EPM activity is visible alongside the rest of your security data rather than siloed in a separate system. For a full overview of available integrations, visit the Integration Hub.

What’s Next?

We have a range of resources available for enterprise security teams. Continue exploring at your own pace, or speak to one of our experts if you’d prefer a conversation.