Editions & Features
Introduction
This page compares the editions of Admin By Request, sets out which features are available on each supported platform, and explains what each feature does. Useful when you are deciding which client to deploy on a given machine, when you are checking whether a control you saw demonstrated on one platform exists on another, or when you are scoping a rollout across a mixed Windows, macOS and Linux estate.
Two concepts are described:
-
Edition means the licence class and the installer that goes with it. Endpoint Privilege Management has two: Workstation and Server. A Workstation licence is cross-platform, so one seat covers a Windows, macOS or Linux desktop. A Server licence covers Windows Server operating systems (but not Windows Core at the time of writing - the desktop experience version is required).
-
Platform means the operating system family the endpoint client runs on: Windows, macOS or Linux. Feature availability varies by platform, and it varies again between Windows Workstation and Windows Server, which is why the comparison tables below have four columns rather than three.
For how many seats each plan includes, how licences are consumed and released, and how virtual desktops are counted, see Licensing. This page is about capability, not entitlement: the Free Plan and the paid plans include the same feature set (with the exceptions noted under Free Plan and Paid Plan differences).
The three Admin By Request products
As of August 2026, Admin By Request comprises three products. They all share one endpoint agent, one management portal and one audit log, and each is licensed separately:
|
Product |
What it controls |
Windows |
macOS |
Linux |
|---|---|---|---|---|
|
Endpoint Privilege Management (EPM) |
Local administrator rights and privilege elevation on the endpoint |
Yes |
Yes |
Yes |
|
Secure Remote Access (SRA) |
Browser-based remote control of endpoints |
Yes |
Yes |
Not yet |
|
Web Access Management (WAM) |
Web browsing policy and executable download governance on the endpoint |
Yes |
Not yet |
Not yet |
The feature comparisons on this page cover Endpoint Privilege Management only. Secure Remote Access and Web Access Management have their own documentation sections, their own settings areas in the portal and their own licences.
Both Secure Remote Access and Web Access Management activate through the agent you already have, so there is no second client to deploy, no new infrastructure and no separate portal (although Web Access Management does require the Windows endpoint client at version 9.0 or later).
Editions
Endpoint Privilege Management editions
|
Edition |
Installer |
Supported operating systems |
Licence class |
|---|---|---|---|
|
Workstation, Windows |
Windows Workstation MSI |
Windows 10 or later, x86, x64 or ARM64 |
EPM workstation seat |
|
Workstation, macOS |
macOS package |
macOS 14 Sonoma, macOS 15 Sequoia, macOS 26 Tahoe |
EPM workstation seat |
|
Workstation, Linux |
Linux install script and package repository |
Ubuntu 20.04, 22.04 and 24.04 LTS; Red Hat Enterprise Linux 9; Rocky Linux 9.0 |
EPM workstation seat |
|
Server, Windows |
Windows Server MSI (a distinct installer, not the Workstation MSI) |
Windows Server 2008 R2 or later, Desktop Experience only |
EPM server seat |
Note the following about choosing a Windows installer:
-
The Windows Workstation MSI will not install on Windows Server, and vice-versa. They are separate builds with different operating models. If a Workstation install already exists on a machine that needs the Server edition, run the cleaner tool before installing the Server edition.
-
Multi-session Windows hosts need the Server edition even though they feel like workstations. Azure Virtual Desktop multi-session and Windows Enterprise multi-session report the same Windows product type as Windows Server, so the Workstation edition is not compatible with them. Install the Windows Server edition on multi-session hosts. Note that the Server edition is not tied to a Windows Server operating system; it is the right client wherever several users hold simultaneous interactive sessions on one machine.
-
Amazon WorkSpaces are the exception to rule 2. WorkSpaces run a Windows Server operating system, so the Server installer looks like the obvious choice, but the Workstation build is the correct one there. The Server build has been observed leaving local administrator rights unrevoked on WorkSpaces.
Current client versions
|
Platform |
Current shipping version |
|---|---|
|
Windows Workstation |
9.0 |
|
Windows Server |
9.0 |
|
macOS |
5.3 |
|
Linux |
4.0 |
Version tags used on this page, such as [Win 9.0+] or [Mac 5.3+], mean the feature requires that client version or later on that platform. The portal Downloads page shows the major version only; append ?fullversion=true to the download URL to see the exact build being served.
Free Plan and Paid Plan differences
Both plans give access to the full feature set on every platform. There is one functional difference: deleting a computer from the portal Inventory is a paid-plan action. On the Free Plan a licence is released only when the client is uninstalled, or automatically after 60 days without the endpoint contacting the portal.
Technical support is a paid-plan entitlement. The Free Plan carries no support commitment. Free Plan issues are handled on a best-effort basis when time allows, which is not a service level and should not be planned around. If you need a response you can rely on, you need a paid plan. This is a commercial difference rather than a functional one: nothing in the product behaves differently, and every feature on this page works the same way on both plans.
Note also that the Free Plan covers workstation seats and a smaller allowance of Windows Server seats; see Licensing for the current numbers.
Feature comparison
Yes means the feature is available on that edition. A dash means it is not available. A superscript number refers to a numbered note directly beneath the table it appears in.
Features are grouped by area:
Core privilege management
|
Feature |
Workstation Linux |
Workstation Mac |
Workstation Windows |
Server Windows |
|---|---|---|---|---|
|
Administrator Access Lockdown |
Yes |
Yes |
Yes |
Yes ¹ |
|
Run As Admin (per-application elevation) |
Yes |
Yes |
Yes |
Yes |
|
Admin Session (time-limited full elevation) |
Yes |
Yes |
Yes |
Yes ² |
|
Approval workflow for elevation requests |
Yes |
Yes |
Yes |
Yes |
|
Require a reason for elevation |
Yes |
Yes |
Yes |
Yes |
|
Email Approval Flow |
Yes |
Yes |
Yes |
Yes |
|
PIN Code Offline Elevation |
Yes |
Yes |
Yes |
Yes |
|
Configurable Admin Session time limit |
Yes |
Yes |
Yes |
Yes |
|
Extend Active Session Timer |
- |
- |
Yes |
- |
|
Remote termination of an elevated session |
- |
- |
Yes |
- |
|
Command-line interface for elevation |
Yes |
- |
- |
- |
|
Tampering Protection |
Yes |
Yes |
Yes |
Yes |
|
Local Admins Group Cleanup |
Yes |
Yes |
Yes |
Yes ¹ |
|
Local Admins Group Protection |
Yes |
Yes |
Yes |
Yes |
|
Excluded accounts (exempt from revocation) |
Yes |
Yes |
Yes |
Yes |
|
Lock device to owner |
Yes |
Yes |
Yes |
Yes |
-
Disabled by default on Windows Server. Enable it through Windows Server settings or policy.
-
Admin Sessions can be disallowed on servers entirely through a global Windows Server setting.
Authorization and identity
|
Feature |
Workstation Linux |
Workstation Mac |
Workstation Windows |
Server Windows |
|---|---|---|---|---|
|
Confirm mode (single confirmation prompt) |
Yes |
Yes |
Yes |
- ¹ |
|
Multi-factor authentication mode (SSO / SAML) |
Yes |
Yes |
Yes |
- ¹ |
|
Authenticate mode (enter credentials) |
- |
Yes |
Yes |
Yes ¹ |
|
Single sign-on for elevation |
Yes |
Yes |
Yes |
Yes |
|
Email-match identity matching |
Yes |
Yes |
Yes |
Yes |
|
Account Separation (separate privileged identity) |
Yes |
Yes |
Yes |
Yes |
|
Multi-factor authentication on pre-approved applications |
Yes |
Yes |
Yes |
Yes |
|
Global access scope by group or organisational unit |
- |
Yes |
Yes |
Yes ² |
|
Entra ID connector for group-based sub-settings |
- ³ |
Yes |
Yes |
Yes |
|
Okta connector for group-based sub-settings |
- |
- ⁴ |
Yes |
Yes |
|
Google Identity connector for group-based sub-settings |
- |
- |
Yes |
Yes |
|
JumpCloud connector for group-based sub-settings |
- |
- |
Yes |
Yes |
-
The Windows Server edition operates in Authenticate mode only. Standard users supply credentials at every elevation; there is no Confirm mode and no multi-factor authentication mode on servers.
-
On Windows Server the access scope is not optional. A non-administrator who is not inside the Global Server Scope group sees no Admin By Request icon at all.
-
Group-based sub-settings on Linux are driven by the local policy file rather than by a directory connector. Directory-sourced Entra ID group scoping on Linux is a different mechanism and is not currently available.
-
macOS group matching against Okta is delivered through Okta Platform SSO
[Mac 5.2+], not through the Okta connector. The two share a vendor name and are separate mechanisms.
Application control
|
Feature |
Workstation Linux |
Workstation Mac |
Workstation Windows |
Server Windows |
|---|---|---|---|---|
|
Application pre-approval |
Yes |
Yes |
Yes |
Yes ¹ |
|
Pre-approval by file name and checksum |
Yes |
Yes |
Yes |
Yes |
|
Pre-approval by folder or location |
Yes |
- |
Yes |
Yes |
|
Pre-approval by vendor certificate |
- |
Yes |
Yes |
Yes |
|
Pre-approval by Team ID or bundle ID |
- |
Yes |
- |
- |
|
Pre-approve directly from the audit log |
- |
Yes |
Yes |
Yes |
|
Require user confirmation on a pre-approved application |
Yes |
Yes |
Yes |
Yes |
|
Per-rule audit logging on a pre-approved application |
Yes ² |
Yes ² |
Yes ² |
Yes ² |
|
Block subprocesses of a pre-approved application |
Yes |
- |
Yes |
Yes |
|
Read-only-directory protection on a pre-approval |
Yes |
- |
Yes |
Yes |
|
Version-range matching on rules |
- |
- |
Yes |
Yes |
|
Command-line parameter matching on rules |
- |
- |
Yes |
Yes |
|
Block Applications |
Yes |
- ³ |
Yes |
Yes |
|
Custom message on a blocked application |
Yes |
- |
Yes |
Yes |
|
Deny elevation of Windows system files |
- |
- |
Yes |
Yes |
|
Machine Learning auto-approval |
- |
Yes |
Yes |
Yes |
|
AI Approval (application and vendor reputation scores) |
- |
- |
Yes |
Yes |
-
Pre-approvals for servers must be created under Windows Server settings. A pre-approval created under Windows Workstation settings does not apply to a server.
-
Per-rule audit logging currently requires the rule's user confirmation prompt to be enabled. With user confirmation turned off the elevation runs silently and no audit-log entry is written.
-
Block rules can be created for macOS in the portal, but enforcement in the macOS client is currently unavailable following a macOS operating-system change. On macOS, restrict applications through pre-approval scoping instead.
Malware detection and device compliance
|
Feature |
Workstation Linux |
Workstation Mac |
Workstation Windows |
Server Windows |
|---|---|---|---|---|
|
Malware Detection with OPSWAT MetaDefender |
- |
Yes |
Yes |
Yes |
|
Real-time reputation check before elevation |
- |
Yes |
Yes |
Yes |
|
Cloud scan of unknown files |
- |
Yes |
Yes |
Yes |
|
Quarantine or permanent block on detection |
- |
Yes |
Yes |
Yes |
|
Malware notification emails |
- |
Yes |
Yes |
Yes |
|
Intune compliance requirement for elevation |
- |
Yes |
Yes |
Yes |
|
User obfuscation (pseudonymised user identity) |
- |
- |
Yes |
Yes |
Emergency access and remote assistance
|
Feature |
Workstation Linux |
Workstation Mac |
Workstation Windows |
Server Windows |
|---|---|---|---|---|
|
Break Glass emergency local admin account |
Yes |
Yes |
Yes |
Yes |
|
Support Assist (help desk assistance without admin rights) |
- |
Yes |
Yes |
Yes |
|
Support Assist session timeout and force-close |
- |
Yes |
Yes |
Yes |
Auditing, inventory and reporting
|
Feature |
Workstation Linux |
Workstation Mac |
Workstation Windows |
Server Windows |
|---|---|---|---|---|
|
Elevated Session Cloud Auditing |
Yes |
Yes |
Yes |
Yes |
|
Administrator Logon Cloud Auditing |
- |
- |
- |
Yes |
|
Hardware and Software Cloud Inventory |
Yes |
Yes |
Yes |
Yes |
|
Administrators group Cloud Inventory |
Yes |
Yes |
Yes |
Yes |
|
Geo-tracking of device location |
Yes |
Yes |
Yes |
Yes |
|
Audit log and inventory export to PDF, XLSX and CSV |
Yes |
Yes |
Yes |
Yes |
|
Approve and audit from the mobile app |
Yes |
Yes |
Yes |
Yes |
Endpoint experience
|
Feature |
Workstation Linux |
Workstation Mac |
Workstation Windows |
Server Windows |
|---|---|---|---|---|
|
Multi-lingual support (automatic language detection) |
Yes |
Yes |
Yes |
Yes |
|
Forced language override |
Yes |
Yes |
Yes |
Yes |
|
Branding (company name and logo in dialogs) |
Yes |
Yes |
Yes |
Yes |
|
Look and Feel controls (skin, request-form fields) |
Yes |
Yes |
Yes |
Yes |
|
Instructions / Code of Conduct screen |
Yes |
Yes |
Yes |
Yes |
|
Desktop and Start menu elevation shortcuts |
- |
- |
Yes |
Yes |
|
Dock icon shortcut for elevation |
- |
Yes |
- |
- |
|
Tray Tools menu |
- |
- |
Yes |
Yes |
|
Browser download notification extension |
- |
- |
Yes |
- |
|
App Store lockdown |
- |
Yes |
- |
- |
|
System Settings pane lockdown |
- |
Yes |
- |
- |
|
Allow sudo terminal commands during an Admin Session |
Yes |
Yes |
- |
- |
|
Allow sudo for non-sudoers |
Yes |
- |
- |
- |
|
Allow root login and root password change |
Yes |
- |
- |
- |
Administration and policy
|
Feature |
Workstation Linux |
Workstation Mac |
Workstation Windows |
Server Windows |
|---|---|---|---|---|
|
Group Policy control (ADMX) |
- |
- |
Yes |
Yes |
|
Local policy file override of portal settings |
Yes |
Yes |
- |
- |
|
Registry-based policy override |
- |
- |
Yes |
Yes |
|
Sub-settings (different rules for different groups) |
Yes |
Yes |
Yes |
Yes |
|
Custom request and ticketing email templates |
Yes |
Yes |
Yes |
Yes |
|
Automatic client updates |
- |
Yes |
Yes |
Yes ¹ |
|
Support for Servers |
- |
- |
- |
Yes |
-
Automatic updates on the Windows Server edition are opt-in and are started by Admin By Request after confirming with you, at a deliberately low daily rate. Enabling the portal toggle alone does not begin a server rollout, because an unannounced agent update on production server infrastructure is not an acceptable default.
What Admin By Request does not do
Several capabilities are commonly assumed to be included, but are not:
-
It is not application allow-listing. Only pre-approved applications elevate, but applications that need no elevation still run. There is no deny-all-except-allowlist mode and no ringfencing of what an approved application may then do. For deny-by-default requirements, pair it with Windows Defender Application Control, AppLocker or your device-management platform.
-
It does not police non-elevated execution. Software that installs and runs in the user's own context is outside the product's field of view by design, which is also why it does not appear in the software inventory.
-
It is not a software-asset-management tool. It records the administrative side of elevation. It does not meter application usage, track last-used timestamps, or classify packaging types.
-
The endpoint agent runs on desktop and server operating systems only. There is no endpoint agent for iPadOS or Android; the mobile application is an approver and management tool.