Editions & Features

Introduction

This page compares the editions of Admin By Request, sets out which features are available on each supported platform, and explains what each feature does. Useful when you are deciding which client to deploy on a given machine, when you are checking whether a control you saw demonstrated on one platform exists on another, or when you are scoping a rollout across a mixed Windows, macOS and Linux estate.

Two concepts are described:

  1. Edition means the licence class and the installer that goes with it. Endpoint Privilege Management has two: Workstation and Server. A Workstation licence is cross-platform, so one seat covers a Windows, macOS or Linux desktop. A Server licence covers Windows Server operating systems (but not Windows Core at the time of writing - the desktop experience version is required).

  2. Platform means the operating system family the endpoint client runs on: Windows, macOS or Linux. Feature availability varies by platform, and it varies again between Windows Workstation and Windows Server, which is why the comparison tables below have four columns rather than three.

For how many seats each plan includes, how licences are consumed and released, and how virtual desktops are counted, see Licensing. This page is about capability, not entitlement: the Free Plan and the paid plans include the same feature set (with the exceptions noted under Free Plan and Paid Plan differences).

The three Admin By Request products

As of August 2026, Admin By Request comprises three products. They all share one endpoint agent, one management portal and one audit log, and each is licensed separately:


Product

What it controls

Windows

macOS

Linux

Endpoint Privilege Management (EPM)

Local administrator rights and privilege elevation on the endpoint

Yes

Yes

Yes

Secure Remote Access (SRA)

Browser-based remote control of endpoints

Yes

Yes

Not yet

Web Access Management (WAM)

Web browsing policy and executable download governance on the endpoint

Yes

Not yet

Not yet


The feature comparisons on this page cover Endpoint Privilege Management only. Secure Remote Access and Web Access Management have their own documentation sections, their own settings areas in the portal and their own licences.

Both Secure Remote Access and Web Access Management activate through the agent you already have, so there is no second client to deploy, no new infrastructure and no separate portal (although Web Access Management does require the Windows endpoint client at version 9.0 or later).

Editions

Endpoint Privilege Management editions

Edition

Installer

Supported operating systems

Licence class

Workstation, Windows

Windows Workstation MSI

Windows 10 or later, x86, x64 or ARM64

EPM workstation seat

Workstation, macOS

macOS package

macOS 14 Sonoma, macOS 15 Sequoia, macOS 26 Tahoe

EPM workstation seat

Workstation, Linux

Linux install script and package repository

Ubuntu 20.04, 22.04 and 24.04 LTS; Red Hat Enterprise Linux 9; Rocky Linux 9.0

EPM workstation seat

Server, Windows

Windows Server MSI (a distinct installer, not the Workstation MSI)

Windows Server 2008 R2 or later, Desktop Experience only

EPM server seat


Note the following about choosing a Windows installer:

  1. The Windows Workstation MSI will not install on Windows Server, and vice-versa. They are separate builds with different operating models. If a Workstation install already exists on a machine that needs the Server edition, run the cleaner tool before installing the Server edition.

  2. Multi-session Windows hosts need the Server edition even though they feel like workstations. Azure Virtual Desktop multi-session and Windows Enterprise multi-session report the same Windows product type as Windows Server, so the Workstation edition is not compatible with them. Install the Windows Server edition on multi-session hosts. Note that the Server edition is not tied to a Windows Server operating system; it is the right client wherever several users hold simultaneous interactive sessions on one machine.

  3. Amazon WorkSpaces are the exception to rule 2. WorkSpaces run a Windows Server operating system, so the Server installer looks like the obvious choice, but the Workstation build is the correct one there. The Server build has been observed leaving local administrator rights unrevoked on WorkSpaces.

Current client versions

Platform

Current shipping version

Windows Workstation

9.0

Windows Server

9.0

macOS

5.3

Linux

4.0


Version tags used on this page, such as [Win 9.0+] or [Mac 5.3+], mean the feature requires that client version or later on that platform. The portal Downloads page shows the major version only; append ?fullversion=true to the download URL to see the exact build being served.

Free Plan and Paid Plan differences

Both plans give access to the full feature set on every platform. There is one functional difference: deleting a computer from the portal Inventory is a paid-plan action. On the Free Plan a licence is released only when the client is uninstalled, or automatically after 60 days without the endpoint contacting the portal.

Technical support is a paid-plan entitlement. The Free Plan carries no support commitment. Free Plan issues are handled on a best-effort basis when time allows, which is not a service level and should not be planned around. If you need a response you can rely on, you need a paid plan. This is a commercial difference rather than a functional one: nothing in the product behaves differently, and every feature on this page works the same way on both plans.

Note also that the Free Plan covers workstation seats and a smaller allowance of Windows Server seats; see Licensing for the current numbers.

Feature comparison

Yes means the feature is available on that edition. A dash means it is not available. A superscript number refers to a numbered note directly beneath the table it appears in.

Features are grouped by area:


Core privilege management

Feature

Workstation Linux

Workstation Mac

Workstation Windows

Server Windows

Administrator Access Lockdown

Yes

Yes

Yes

Yes ¹

Run As Admin (per-application elevation)

Yes

Yes

Yes

Yes

Admin Session (time-limited full elevation)

Yes

Yes

Yes

Yes ²

Approval workflow for elevation requests

Yes

Yes

Yes

Yes

Require a reason for elevation

Yes

Yes

Yes

Yes

Email Approval Flow

Yes

Yes

Yes

Yes

PIN Code Offline Elevation

Yes

Yes

Yes

Yes

Configurable Admin Session time limit

Yes

Yes

Yes

Yes

Extend Active Session Timer

-

-

Yes [Win 9.0+]

-

Remote termination of an elevated session

-

-

Yes [Win 9.0+]

-

Command-line interface for elevation

Yes [Linux 3.1+]

-

-

-

Tampering Protection

Yes

Yes

Yes

Yes

Local Admins Group Cleanup

Yes

Yes

Yes

Yes ¹

Local Admins Group Protection

Yes

Yes

Yes

Yes

Excluded accounts (exempt from revocation)

Yes

Yes

Yes

Yes

Lock device to owner

Yes

Yes

Yes

Yes

  1. Disabled by default on Windows Server. Enable it through Windows Server settings or policy.

  2. Admin Sessions can be disallowed on servers entirely through a global Windows Server setting.


Authorization and identity

Feature

Workstation Linux

Workstation Mac

Workstation Windows

Server Windows

Confirm mode (single confirmation prompt)

Yes

Yes

Yes

- ¹

Multi-factor authentication mode (SSO / SAML)

Yes

Yes

Yes

- ¹

Authenticate mode (enter credentials)

-

Yes

Yes

Yes ¹

Single sign-on for elevation

Yes

Yes

Yes

Yes

Email-match identity matching

Yes

Yes

Yes

Yes

Account Separation (separate privileged identity)

Yes [Linux 4.0+]

Yes

Yes

Yes

Multi-factor authentication on pre-approved applications

Yes

Yes

Yes

Yes

Global access scope by group or organisational unit

-

Yes

Yes

Yes ²

Entra ID connector for group-based sub-settings

- ³

Yes

Yes

Yes

Okta connector for group-based sub-settings

-

- ⁴

Yes [Win 8.5+]

Yes [Win 8.5+]

Google Identity connector for group-based sub-settings

-

-

Yes [Win 8.5+]

Yes [Win 8.5+]

JumpCloud connector for group-based sub-settings

-

-

Yes [Win 8.5+]

Yes [Win 8.5+]

  1. The Windows Server edition operates in Authenticate mode only. Standard users supply credentials at every elevation; there is no Confirm mode and no multi-factor authentication mode on servers.

  2. On Windows Server the access scope is not optional. A non-administrator who is not inside the Global Server Scope group sees no Admin By Request icon at all.

  3. Group-based sub-settings on Linux are driven by the local policy file rather than by a directory connector. Directory-sourced Entra ID group scoping on Linux is a different mechanism and is not currently available.

  4. macOS group matching against Okta is delivered through Okta Platform SSO [Mac 5.2+], not through the Okta connector. The two share a vendor name and are separate mechanisms.


Application control

Feature

Workstation Linux

Workstation Mac

Workstation Windows

Server Windows

Application pre-approval

Yes

Yes

Yes

Yes ¹

Pre-approval by file name and checksum

Yes

Yes

Yes

Yes

Pre-approval by folder or location

Yes

-

Yes

Yes

Pre-approval by vendor certificate

-

Yes

Yes

Yes

Pre-approval by Team ID or bundle ID

-

Yes [Mac 5.3+]

-

-

Pre-approve directly from the audit log

-

Yes

Yes

Yes

Require user confirmation on a pre-approved application

Yes

Yes

Yes

Yes

Per-rule audit logging on a pre-approved application

Yes ²

Yes ²

Yes ²

Yes ²

Block subprocesses of a pre-approved application

Yes

-

Yes

Yes

Read-only-directory protection on a pre-approval

Yes

-

Yes

Yes

Version-range matching on rules

-

-

Yes

Yes

Command-line parameter matching on rules

-

-

Yes

Yes

Block Applications

Yes

- ³

Yes

Yes

Custom message on a blocked application

Yes

-

Yes

Yes

Deny elevation of Windows system files

-

-

Yes

Yes

Machine Learning auto-approval

-

Yes

Yes

Yes

AI Approval (application and vendor reputation scores)

-

-

Yes

Yes

  1. Pre-approvals for servers must be created under Windows Server settings. A pre-approval created under Windows Workstation settings does not apply to a server.

  2. Per-rule audit logging currently requires the rule's user confirmation prompt to be enabled. With user confirmation turned off the elevation runs silently and no audit-log entry is written.

  3. Block rules can be created for macOS in the portal, but enforcement in the macOS client is currently unavailable following a macOS operating-system change. On macOS, restrict applications through pre-approval scoping instead.


Malware detection and device compliance

Feature

Workstation Linux

Workstation Mac

Workstation Windows

Server Windows

Malware Detection with OPSWAT MetaDefender

-

Yes

Yes

Yes

Real-time reputation check before elevation

-

Yes

Yes

Yes

Cloud scan of unknown files

-

Yes

Yes

Yes

Quarantine or permanent block on detection

-

Yes

Yes

Yes

Malware notification emails

-

Yes

Yes

Yes

Intune compliance requirement for elevation

-

Yes

Yes

Yes

User obfuscation (pseudonymised user identity)

-

-

Yes

Yes


Emergency access and remote assistance

Feature

Workstation Linux

Workstation Mac

Workstation Windows

Server Windows

Break Glass emergency local admin account

Yes [Linux 4.0+]

Yes

Yes [Win 7.3+]

Yes [Win 8.2+]

Support Assist (help desk assistance without admin rights)

-

Yes [Mac 5.0+]

Yes

Yes

Support Assist session timeout and force-close

-

Yes

Yes [Win 8.5+]

Yes


Auditing, inventory and reporting

Feature

Workstation Linux

Workstation Mac

Workstation Windows

Server Windows

Elevated Session Cloud Auditing

Yes

Yes

Yes

Yes

Administrator Logon Cloud Auditing

-

-

-

Yes

Hardware and Software Cloud Inventory

Yes

Yes

Yes

Yes

Administrators group Cloud Inventory

Yes

Yes

Yes

Yes

Geo-tracking of device location

Yes

Yes

Yes

Yes

Audit log and inventory export to PDF, XLSX and CSV

Yes

Yes

Yes

Yes

Approve and audit from the mobile app

Yes

Yes

Yes

Yes


Endpoint experience

Feature

Workstation Linux

Workstation Mac

Workstation Windows

Server Windows

Multi-lingual support (automatic language detection)

Yes

Yes

Yes

Yes

Forced language override

Yes

Yes

Yes

Yes

Branding (company name and logo in dialogs)

Yes

Yes

Yes

Yes

Look and Feel controls (skin, request-form fields)

Yes

Yes

Yes

Yes

Instructions / Code of Conduct screen

Yes

Yes

Yes

Yes

Desktop and Start menu elevation shortcuts

-

-

Yes

Yes

Dock icon shortcut for elevation

-

Yes

-

-

Tray Tools menu

-

-

Yes

Yes

Browser download notification extension

-

-

Yes [Win 8.6+]

-

App Store lockdown

-

Yes

-

-

System Settings pane lockdown

-

Yes

-

-

Allow sudo terminal commands during an Admin Session

Yes

Yes

-

-

Allow sudo for non-sudoers

Yes

-

-

-

Allow root login and root password change

Yes

-

-

-


Administration and policy

Feature

Workstation Linux

Workstation Mac

Workstation Windows

Server Windows

Group Policy control (ADMX)

-

-

Yes

Yes

Local policy file override of portal settings

Yes

Yes

-

-

Registry-based policy override

-

-

Yes

Yes

Sub-settings (different rules for different groups)

Yes

Yes

Yes

Yes

Custom request and ticketing email templates

Yes

Yes

Yes

Yes

Automatic client updates

-

Yes

Yes

Yes ¹

Support for Servers

-

-

-

Yes

  1. Automatic updates on the Windows Server edition are opt-in and are started by Admin By Request after confirming with you, at a deliberately low daily rate. Enabling the portal toggle alone does not begin a server rollout, because an unannounced agent update on production server infrastructure is not an acceptable default.

What Admin By Request does not do

Several capabilities are commonly assumed to be included, but are not:

  1. It is not application allow-listing. Only pre-approved applications elevate, but applications that need no elevation still run. There is no deny-all-except-allowlist mode and no ringfencing of what an approved application may then do. For deny-by-default requirements, pair it with Windows Defender Application Control, AppLocker or your device-management platform.

  2. It does not police non-elevated execution. Software that installs and runs in the user's own context is outside the product's field of view by design, which is also why it does not appear in the software inventory.

  3. It is not a software-asset-management tool. It records the administrative side of elevation. It does not meter application usage, track last-used timestamps, or classify packaging types.

  4. The endpoint agent runs on desktop and server operating systems only. There is no endpoint agent for iPadOS or Android; the mobile application is an approver and management tool.