TechIDManager Guide: TechIDElevate

 

TechIDElevate gives MSPs a controlled way to manage UAC elevation requests from end-user machines. Instead of giving users standing local admin rights, technicians can approve or deny elevation requests when users need to run an application, installer, command prompt, PowerShell, QuickBooks update, or another task as administrator. This feature is available in public beta with TechIDAgent version 6.680 and newer.

What TechIDElevate Does

TechIDElevate allows a technician to remotely control whether an end user’s UAC prompt should be approved or denied.

When an end user tries to run something as administrator, they are prompted to request permission through TechIDManager. A technician can then review the request, confirm the details, and approve or deny the action.

Once approved, TechIDElevate temporarily satisfies the UAC requirement using a just-in-time managed user. After the elevated task is complete, that temporary access is removed and the account is disabled.

This means users can get the elevation they need without being granted permanent local admin rights.

TechID Elevate also includes:

  • Desktop app notifications
  • Mobile app notifications
  • Portal-based request approval
  • Auto-approve and auto-deny rules
  • Elevate scopes for technician permissions
  • Elevate history and reporting
  • White labeling so users see your name and logo

Before You Begin

To use TechID Elevate, you need:

  • TechID Agent version 6.680 or newer
  • TechID Elevate enabled in your TechIDManager tenant – Contact Support@TechIDManager.com to request access
  • TechID Elevate enabled on the agent machines where you want to manage UAC prompts
  • Technicians or Managers who will approve Elevate requests

For partners joining the public beta, TechIDManager recommends scheduling a support meeting (support@techidmanager.com ) so the team can enable the feature in your tenant and walk through the initial setup.


Step 1: Enabling TechIDElevate on Agents

TechIDElevate can be enabled from the TechIDManager Portal or from the command line.

Enable from the Portal

In the portal, the agent screen includes icons that show what each agent is configured to do. Agents that are capable of using TechIDElevate will display the Elevate icon.

Agents that are capable of running TechIDElevate but do not have it enabled will appear grayed out.

You can enable TechIDElevate in two ways:

  1. Open an individual agent and enable or disable TechIDElevate.
  2. Multi-select multiple capable agents from the agent list and Enable TechIDElevate in bulk.

This allows you to roll out TechIDElevate to lots of machines at once.

Enable from the Command Line

TechIDElevate can also be enabled from the command line on the machine itself. This allows you to enable it using a batch file, script, or RMM tool.

To enable TechIDElevate, run the TechIDAgent executable with the TechIDElevate parameter:

    TechIDAgent.exe TechIDElevate

After TechIDElevate is enabled, you can run the agent’s show command to confirm the new Elevate options are visible.

You should see a new section showing TechID Elevate settings, including:

  • UAC Elevate management

  • Removal of local admin from users on the computer

  • Host information

  • Whether the Elevate provider is registered

These commands can be run locally, remotely, or in bulk across multiple machines.

To disable TechIDElevate, use:

    TechIDAgent.exe NoTechIDElevate

You can also review the current Elevate configuration by running the agent’s show command. The output includes the TechIDElevate options, such as whether UAC prompt management is enabled, whether local admin removal is enabled, and whether the Elevate providers are registered.


Step 2: Local Admin Removal

As part of enabling TechIDElevate, normal users can automatically lose local administrator rights on the machine.

This does not apply to the built-in administrator account or users managed by TechIDManager.

You can control this behavior with command-line options:

    TechIDAgent.exe RemoveLocalAdmin

This removes local admin rights from normal users.

    TechIDAgent.exe DoNotRemoveLocalAdmin

This stops TechIDManager from removing local admin rights. This does not add right back to user(s).

This setting can also be reviewed under the TechIDElevate options when running the show command.


Step 3: Have the End User Request Elevation

Once TechIDElevate is enabled, the end user can attempt to run something as administrator.

For example, they may try to run:

  • Command Prompt

  • PowerShell

  • An installer

  • A line-of-business application

  • Another executable that requires admin rights

Instead of receiving a normal UAC prompt, the user will see a TechIDElevate permission request.

The prompt asks why the application needs to run as administrator. The user can enter a reason and “Request Permission”.

Once submitted, the request waits for a technician response.


Step 4: Review the Elevate Request in TechIDManager

The technician will see the Elevate request in the TechIDClient, on Windows, macOS, iPhone, and Android.

The request includes details such as:

  • The user making the request

  • The machine where the request originated

  • The executable being run and its hash

  • The file path

  • The trusted certificate status

  • How long ago the request was submitted

The technician can review the request and decide whether to approve or deny it.

Before approving, the technician may choose to contact the user, confirm the reason for the request, or verify whether the application should be allowed to run as administrator.


Step 5: Approve or Deny the Request

If the request is legitimate, the technician can approve it.

Once approved, the UAC prompt is satisfied automatically and the requested application runs as administrator for the user.

TechIDElevate uses a Just-In-Time managed user to complete the elevation. That user is granted the permissions needed to run the approved task. Once the task is complete, the user is disabled and the rights are removed.

TechIDElevate does not elevate the user’s entire session. Instead, the requested item runs in a specialized controlled context as a special user.

This means only the approved application receives administrator permissions. The rest of the user’s processes remain unelevated.

If the request should not be allowed, the technician can deny it.

This gives the MSP control over elevation without giving the end user permanent (or even temporary) admin rights.


Step 6: Manage Requests from the TechIDPortal

Elevate requests also appear in the TechIDPortal under the Elevate Requests section.

From the portal, Managers can view request details all the same details and Techs can from TechIDClient.

Managers can approve requests from the portal. Once processed, approved or denied requests move into the processed request list.

If a user submitted a request but did not wait for a technician response, the request can still be reviewed and approved later.

When approval is granted after the user has stopped waiting, the user will receive a notification. The notification explains that their request has been approved and that the approval is valid for one elevation.

The user can then choose to run the application immediately or later. The approval is valid for one use for up to 7 days. 


Step 7: Understand One-Time Approval Behavior

TechIDElevate approvals are valid for one use.

If the user chooses “Run it now,” the approved application launches as administrator.

If the user chooses to run it later, the next time they attempt to run that same approved item, the elevation will proceed without requiring another technician response.

After that one-time use, the approval is consumed.

This helps keep elevation controlled, temporary, and auditable.


Step 8: Create Auto Responses for Trusted Requests

TechIDElevate also supports auto responses.

Auto responses allow specific elevation requests to be automatically approved based on criteria you define.

For example, you could create an auto response that allows a specific version of PowerShell or a trusted application to run as administrator from a specific machine.

Auto responses can be based on details such as:

  • File path

  • File hash

  • Certificate

  • Certificate trust status

  • Username

  • Machine name

  • IP address

  • Agent name

You can make rules as specific or as broad as needed.

For example, you could automatically approve:

  • A specific executable for a specific user

  • A specific application on a specific machine

  • Applications with trusted certificates from selected certificate providers

  • A known installer with a matching hash

The goal is to reduce repeated technician approvals for known-safe actions while still keeping elevation controlled.


Step 9: Convert History into Auto Responses

TechIDElevate keeps a history of past elevation activity.

From the Elevate History section, previously approved requests can be converted into auto responses.

This makes it easier to build rules from real-world usage.

For example, if technicians regularly approve the same trusted application for the same user or device, that historical request can be converted into an auto response and then edited as needed.

You can adjust the rule to apply to:

  • The same user

  • Any user

  • The same machine

  • Any machine

  • The same executable

  • A specific file hash

  • A trusted certificate

  • Other matching criteria

This allows MSPs to start with manual approval, observe real usage patterns, and then safely automate repeat requests.


Step 10: Configure Elevate Scopes

Elevate scopes determine which technicians can approve Elevate requests for which agents.

These scopes work similarly to TechIDManager triplets, which define which technicians receive which rights for which accounts on which agents.

An Elevate scope combines:

  • A technician group

  • An agent group

Scopes are additive, which means you can create multiple scopes to match your operational structure.

For example, you may allow:

  • All technicians to approve requests for all agents

  • A specific technician group to approve requests for a specific client

  • A co-managed technician to approve requests for only a few specific machines.

Managers can respond to any request from the portal.


Elevate Reports

TechIDManager includes reporting for TechIDElevate.

The Elevate Scope Report shows which technicians have permission to approve requests for which agents and groups.

This helps administrators review approval permissions and confirm that technicians have the correct scope.


Elevate History and Log Details

TechIDElevate also records elevation activity in the history and logs.

The Elevate History shows details such as:

  • Who elevated the request
  • What was elevated
  • Where it was elevated
  • Whether the request was approved or denied
  • Whether it was approved by a technician or manager
  • How long the request took to process

For example, the processing time shows how long it took from when the user clicked “request permission” to when the technician or manager approved or denied the request.

The logs also show details such as the technician name, manager email address, status, and Elevate request ID.


White Label TechIDElevate

TechIDElevate is brandable. In the TechIDManager portal, go to the client branding settings. From there, you can set your company name and Elevate icon.

The company name appears as part of the Elevate experience, and the icon appears anywhere an elevation icon is shown, including the UAC request prompt.

This allows MSPs to present the TechIDElevate workflow under their own brand and build on the trust they already have with their clients.


Best Practices for Using TechIDElevate

Use TechIDElevate to reduce standing local admin access while still allowing users to complete legitimate work.

Recommended practices include:

  • Remove local admin rights from end users where possible

  • Require users to provide a reason for elevation requests

  • Train technicians to verify unusual requests before approval

  • Use auto responses only for known, trusted, repeatable actions

  • Review Elevate History regularly

  • Keep auto response rules specific enough to avoid unnecessary risk

  • Use Elevate scopes to limit which technicians can approve requests for each environment

  • Treat one-time approvals as the default and automation as the exception


TechIDElevate gives MSPs a practical way to manage UAC elevation and remove permanent local admin rights at the same time.

End users can request elevation when needed. Technicians can review and approve or deny the request. Approved actions run through a temporary just-in-time managed user with highly scoped access that is removed when the task is complete.

With Elevate requests, history, auto responses, and technician scopes, TechIDElevate helps MSPs balance usability, security, and accountability.

To get started with TechIDElevate during the public beta, schedule a TechIDManager support meeting so the feature can be enabled for your tenant and configured correctly.


Support

Contact our team at support@techidmanager.com