The Rules page
1
Open Privilege Elevation
Log in as a user with the Privilege Elevation administrative permission. In the left navigation, under Security, click Privilege Elevation.
2
Select the Rules tab
The Rules tab shows every configured rule in a grid. It is empty by default until you create one.

The Privilege Elevation Rules tab.
The rules grid
Click the ⋮ menu next to a rule for Edit, Enable/Disable, or Delete.
Filters: Status, Elevation Mode, Last Update Time (date range). Search matches Name and Description, full or partial text.
Bulk actions
Select multiple rules’ checkboxes to Enable, Disable, or Delete them together.- Bulk Enable/Disable shows a confirmation: “You are about to change the status of <N> selected rules. Are you sure you want to continue?”
- Bulk Delete shows: “You are about to permanently delete <N> rules. Are you sure you want to continue?” — deletion is permanent.
Create a rule
Click Add on the Rules page to open the rule wizard: Details → Elevation Mode → Targeting Criteria → Assign Endpoints → Assigned Users → Notifications → Summary. Back, Next, Cancel, and (on Summary) Save are available throughout; Cancel discards all changes and returns you to the Rules page.1. Details

The Details tab of the rule wizard.
2. Elevation Mode
Choose the rule’s core action.- Auto-elevate
- Require approval
- Deny
Launches the application with administrator rights immediately — no prompt, no approval.Optionally, enable Auto-elevate during work hours to restrict automatic elevation to a schedule:
- Allowed dates — defaults to a 2-week range starting from the rule’s creation date; edit it manually as needed.
- Allowed time — defaults to 08:00–17:00.
- Allowed days of the week — defaults to Monday–Friday.
- Action outside of work hours — choose Always deny, or Require approval (which requires selecting Users who can approve access).
If a rule’s configured Allowed dates range expires, the rule doesn’t stop working — it falls back to whatever Action outside of work hours specifies (deny, or require approval).
Session recording during elevation is available for Auto-elevate and Require approval (not Deny), off by default. When enabled, it captures screen, keyboard, and command input during the elevated session for audit and forensic purposes — see Events and monitoring for how this recording behaves depending on your license.

The Elevation Mode tab, with Auto-elevate scheduling expanded.
3. Targeting Criteria
Define what the rule matches against — manually, by uploading a file to extract its parameters, or both together (combined with AND logic between manual and uploaded parameters, OR logic between parameters of the same type).- Manual entry
- File upload
Choose a parameter type, a comparison operator, and a value:
Matching is case-insensitive. For Like/Not like, a wildcard mask (
* or *.exe) is supported. Enter multiple values separated by semicolons.Click +Or to add another condition of the same logical group, or +And to add a condition that must also be true. Conditions of the same parameter type combine with OR; different parameter types combine with AND.Extract parameters offline
For SaaS customers (or anyone who prefers not to upload files to the Management Tool), the Offline Parameters Extractor is a small, standalone Windows utility you run locally.1
Download and run the tool
Download the Offline Parameters Extractor and run it on any Windows computer — no installation, no server connection required.
2
Choose a file
Click Choose file and select a
.exe or .msi file.3
Copy the extracted values
The tool displays File hash (SHA-256), Executable name(s), Path prefix, and Digital signature, each with its own Copy button. A field that couldn’t be extracted shows Empty.
4
Paste into your rule
Paste the copied values into the corresponding manual-entry fields on the Targeting Criteria tab.
The tool never uploads or executes the file — it only reads it locally to extract metadata, and isn’t included in the standard server installation package.
4. Assign Endpoints
Select at least one endpoint or endpoint group — this is required to proceed.Domain Computer groups combines with Endpoints/Endpoint groups using AND logic — if you specify a domain group, you must also select at least one endpoint or endpoint group. Endpoints and Endpoint groups combine with each other using OR logic. The PAM Client group can’t be selected here.
5. Assigned Users
Choose whether the rule applies to everyone, or to specific users:
Add domain users, domain groups, or local Windows users the same way: pick a Domain (from LDAP) or a specific Endpoint, then type a username or group with autocomplete suggestions — or use
* as a wildcard (for example, *\Administrator matches that account on any domain or local computer).
Exceptions, configured the same way, always override the main selection — a user listed as an exception is excluded from the rule even if they’d otherwise match.
6. Notifications
- Send email to approvers — for Require approval rules, emails the users selected as approvers when a request comes in.
- Show warning message to user — for Deny rules, shown to the user when their launch is blocked (configured back on the Elevation Mode tab).
- Notify if elevation failed — Optional checkbox, off by default.
7. Summary
Review every section before saving — Elevation Mode, Targeting Criteria, Assigned Endpoints, Assigned Users (with exceptions), and Notifications. Each section has its own Edit link, which jumps directly to that tab. An Impact preview shows the total number of endpoints the rule will affect. Click Save to activate the rule and return to the Rules page, where it now appears in the grid.Edit a rule
Opening an existing rule for editing starts on the Summary tab, where you can jump to any section via the left navigation or that section’s Edit link. Changes save as you move between tabs; nothing is finalized until you click Save on the way out, and Cancel at any point discards changes made in that session.How conflicting rules resolve
If more than one enabled rule matches the same elevation attempt, Syteca doesn’t pick a rule arbitrarily — it applies the most restrictive matching decision, in this order:- Deny (most restrictive)
- Require approval
- Auto-elevate (least restrictive)
notepad.exe; Rule B denies notepad.exe. Both match the same launch attempt → the result is Deny.
What happens when the Client starts enforcing a rule
1
No changes until the first rule is saved
After installing the Syteca Client, nothing changes on the endpoint until you save an enabled Privilege Elevation rule targeting it.
2
UAC is intercepted, not removed
Once a rule is active, the Syteca Client enforces Windows UAC settings so that elevation always triggers a prompt — silent, unmanaged elevation isn’t possible — and intercepts that prompt before it completes, evaluating your rules against it.
3
Group membership is untouched
Privilege Elevation does not remove any user from the local Administrators group. It governs how elevation happens, not who’s technically capable of it.
Upgrading to a version with Privilege Elevation adds the new page and rules to the Management Tool but changes nothing by default — the native Windows UAC continues to work exactly as before until you create and enable your first rule.
Windows UAC policies that Privilege Elevation changes
To guarantee that every elevation attempt produces a prompt it can intercept, the Syteca Client sets four Windows UAC security policies on the endpoint:
These policies live under Security Settings → Local Policies → Security Options in Local Security Policy or Group Policy.
Related
Overview
What Privilege Elevation does and how it’s licensed.
Events and monitoring
Every elevation decision, logged and searchable.
End-user experience
What a user sees when a rule applies to them.
Add a secret
Create the Secret a Require approval or Auto-elevate rule uses.
