Skip to main content
Once a Privilege Elevation rule is active on an endpoint, Syteca replaces the native Windows UAC prompt with its own experience, matching whatever elevation mode the applicable rule specifies.

What the user sees, per elevation mode

No pop-up, and no UAC window. The application starts immediately with administrator privileges.

When the endpoint is offline

Without a connection to the Application Server, Syteca can’t check for approval or confirm an Auto-elevate schedule — so it falls back to denying elevation, regardless of the rule’s configured mode:

Requesting and approving access

The approver’s side

A Require approval request appears on the Access Requests page in the Management Tool, visible to the users or groups selected as approvers on the rule. An email notification is also sent to them, including the request date/time, the requesting user and endpoint, their comment, the rule name, and the application’s path. Opening a request shows the same details, plus (once processed) who approved or denied it and when. Approving a request opens a follow-up pop-up where the approver sets how long the granted administrator access should last before it’s automatically revoked.
The Request Type filter on the Access Requests page includes Privilege Elevation as its own type, alongside your existing PAM access request types.

The user’s side, after a decision

Syteca Access Center

Once at least one Privilege Elevation request has been approved for an endpoint, a Syteca Access Center icon appears in that endpoint’s Windows notification area.
1

Open the Access Center

Right-click the Syteca Client tray icon and select the Access Center option.
2

Review your requests

See every Approved, Pending, Denied, and Expired access request available to you. Use Search to find one by application or file name.
3

Launch an approved application

Each approved entry shows how long it remains valid, with a Run button to launch it directly — no need to trigger a new elevation attempt.
Syteca Access Center window with a list of access requests

The Syteca Access Center, showing available access requests.

When elevation fails outright

Separate from a Deny decision, an elevation attempt can fail for operational reasons — for example, the account in the rule’s Secret no longer belongs to the local admin group, its password was changed outside Syteca, or the rule only has an Active Directory Secret but the endpoint isn’t domain-joined. In these cases, an error pop-up (“Elevation failed”) tells the user to contact their administrator, and — if configured — the failure notification is emailed to the recipients defined on the rule.

Overview

What Privilege Elevation does and how it’s licensed.

Creating and managing rules

Configure the elevation mode and approval settings referenced here.

Events and monitoring

Every request and decision, logged for audit.