Out-of-band (offline) Ability to Respond to Requests
under consideration
M
Matthew Buehlmann
+1 to Jasper's comment - without the ability to assume admin when the device is offline there is a massive gap in the AutoElevate solution.
I'd like to make a feature request to have AE create a breakglass account (or temporary override code) for these types of scenarios, with the password stored (and protected via granular access control) in the portal. This would greatly alleviate some of the challenges faced by forcing partners to manage break glass accounts including:
1) Needing to engineer and implement a separate solution for break glass accounts (e.g., Windows LAPS)
2) If using RMM scripting, needing to manually pass a plaintext password as a variable to the script
3) If running a custom RMM script per device, you will having hundreds of different local admin PWs to manage
4) If running a custom RMM script per client, there will be one breakglass PW per org which is not best practice
5) The need to manually add breakglass account passwords to a separate password management solution to ensure retention, accessibility, and security
6) The risk of Breakglass admin passwords growing stale without appropriate password rotation
A
Andrew Morrell
this shoud be an essential feature
Jasper Golze
At least Support Admins need a way to get Admin Privileges.
Dave Sibiski
marked this post as
under consideration