This guide outlines the steps to request privileged execution in EPM macOS, using policies that require a justification and define either a mandatory or optional execution window.
Requirements
- Application associated with a policy configured for privilege elevation in EPM macOS
- Justification (mandatory or optional) enabled in the policy
- Execution window configured as mandatory or optional
Request privileged execution with mandatory justification
- Right-click the desired application and select Run with privileges from the context menu.
- In the window displayed by EPM macOS:
- Fill in the Justification field (mandatory field, indicated by a red icon).
- If configured in the policy, define an execution window:
- Start date/time: must be later than the current date/time.
- End date/time: must be later than the start date/time (maximum of 48 hours).
- Click Submit request.
- A confirmation message will be displayed: "The execution of this application has been requested from the administrator. Once approved, execution will be allowed."
Request privileged execution with optional justification and execution window
- Right-click the application and select Run with privileges.
- In the window displayed:
- Fill in the Justification field (if required).
- The execution window may appear as optional:
- If you need to restrict the execution, fill in the start and end date/time fields.
- If no restriction is needed, leave the fields empty.
- Click Submit request.
- A confirmation message will be displayed indicating that the request was sent to the administrator for approval.
Expected behavior after submitting the request
Once the request is submitted, the following behaviors may occur depending on the administrator’s response in the backend:
| Request status | EPM macOS behavior |
|---|---|
| Approved | Execution is allowed within the configured window. |
| Pending | A message is shown: "Your request is still pending review." |
| Rejected | A message is shown: "Your last request was rejected by the administrator." |
| Outside the execution window | A message is shown: "The execution time has expired. Please submit a new request." |
Info
The administrator may modify the requested execution window. The EPM agent will automatically apply the updated window.
All actions related to request submission, approval, and execution are logged locally.