Admin Rights.
Removed. Controlled.

Stop giving users persistent admin access. ElevateGuard lets users request elevation via right-click — IT approves or denies in real-time. Full audit trail, zero standing privileges.

Start 14-Day Free Trial See How It Works

How It Works

1

Deploy the Agent

Install the lightweight ElevateGuard agent on your Windows endpoints. Integrates with the credential provider for seamless UAC flow. Takes under a minute.

2

Remove Admin Rights

Demote users from local administrators. ElevateGuard handles the rest — users never need standing admin access again.

3

Users Request Elevation

When users need to run something as admin, they right-click and choose "Request Elevation." The request is sent to your IT team instantly via MQTT.

4

Approve, Deny, or Auto-Approve

IT admins approve or deny requests in real-time from the web console. Set up auto-approve rules by application hash, publisher, path, or name to skip the queue for trusted apps.

Everything You Need

Right-Click Elevation

Users request admin access from the Windows context menu. No calls to the help desk, no shared admin passwords, no waiting for remote sessions.

Real-Time Approval

Elevation requests appear instantly in the web console via MQTT. Approve or deny with one click — the user sees the result in seconds.

Auto-Approve Rules

Create rules based on application hash, publisher certificate, file path, or executable name. Trusted apps elevate silently without IT involvement.

Full Audit Trail

Every elevation request, approval, denial, and auto-approve event is logged. Who requested what, when, and who approved it. Export anytime.

Learning Mode

Deploy in learning mode first to capture all UAC events across your fleet. See what users actually need admin for before enforcing policies.

Credential Provider Integration

Hooks directly into the Windows UAC flow via a custom credential provider. Seamless experience — no workarounds, no hacks, no shell replacements.

Multi-Tenant / MSP Ready

Manage multiple companies from one console. Per-company policies, auto-approve rules, and audit logs. Built for MSPs from day one.

MQTT Real-Time Comms

All communication between agents and console happens over MQTT. Instant request delivery, instant response. No polling, no delays.

Simple, Transparent Pricing

Starter

$1/endpoint/mo
Up to 100 endpoints
  • Right-click elevation
  • Real-time approval
  • Auto-approve rules
  • 30-day audit log

Enterprise

$5/endpoint/mo
Unlimited endpoints
  • Everything in Pro
  • Unlimited audit history
  • API access
  • Custom policies
  • Dedicated support

Start with a 14-day free trial. No credit card required. Full access to all features.

Frequently Asked Questions

What operating systems are supported?

ElevateGuard currently supports Windows 10 and Windows 11. The agent runs as a lightweight service and integrates with the Windows UAC credential provider.

How does the right-click elevation work?

The agent adds a "Request Elevation" option to the Windows context menu. When a user selects it, the request (including the application name, hash, publisher, and path) is sent to the ElevateGuard console via MQTT. IT admins can approve or deny in real-time, and the application launches with elevated privileges.

What is learning mode?

Learning mode captures all UAC elevation events on your endpoints without blocking anything. This lets you see exactly what applications users are running as admin before you remove their admin rights. Use the data to build auto-approve rules so the transition is seamless.

How do auto-approve rules work?

You can create rules that automatically approve elevation requests based on the application's file hash, publisher certificate, file path, or executable name. When a request matches a rule, it's approved instantly — no IT intervention needed. Great for trusted installers, signed vendor tools, and known-good applications.

Can I use this as an MSP?

Absolutely. ElevateGuard supports multi-tenant management from a single console. Each company gets its own endpoints, policies, auto-approve rules, and audit logs.

Is there a free trial?

Yes, every plan includes a 14-day free trial with full access. No credit card required.

What happens if IT doesn't respond to a request?

Requests remain pending until approved or denied. You can configure a timeout policy to auto-deny requests that aren't acted on within a set time. Users can also cancel and resubmit requests.

Does this replace Microsoft LAPS?

No — ElevateGuard and LAPS solve different problems. LAPS rotates local admin passwords. ElevateGuard removes the need for users to have admin rights at all. They complement each other well. For local admin password management, check out CredGuard.