If your users are receiving messages like "request denied due to company policy", check the following:
Device Owner - in the portal, check Settings > [OS] Settings > Lockdown > OWNER. Only the owner of the endpoint is able to use Run As Administrator or start an Administrator Session.
The device owner is first non-administrator that logs on to the endpoint. You can change the owner in the inventory.
macOS version - make sure your Mac endpoints are running the latest version of Admin By Request. There was a problem identified in versions prior to 4.2.1 where certain scenarios caused "request denied" messages to users.
Admin rights - in the portal, check the following under Settings > [OS] Settings > Lockdown:
ADMIN RIGHTS - If On, make sure accounts to be excluded are entered.
RUN AS ADMIN - Deny elevating system files prevents the user from starting any file from the System32 directory with administrative privileges, such as cmd.exe or regedit.exe. You can define exceptions under Settings > [OS] Settings > > App Control -> PRE-APPROVE.
ADMIN SESSION - The same as for RUN AS ADMIN.