NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • Contact Us
English (US)
NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish
  • Home
  • AutoElevate Knowledgebase
  • AutoElevate Features & Troubleshooting

Elevation Modes (Audit, Policy, Live)

Differences between audit, policy, and active elevation modes to enhance security and control in your systems.

Written by Owen Parry

Updated at August 20th, 2026

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • AutoElevate Knowledgebase
    New to AutoElevate? START HERE AutoElevate Features & Troubleshooting Managing Rules in AutoElevate Integrations for AutoElevate AutoElevate FAQ Selling AutoElevate
  • Password Boss Knowledgebase
    Using Password Boss Administrating Password Boss Legacy Password Boss
  • CyberFOX DNS Filtering
    Getting Started with DNS Filtering DNS Filtering Concepts Network Requirements for DNS Filtering DNS Filtering Company and Location Setup Managing your DNS Filtering Policies Using Roaming Clients for DNS Filtering DNS Filtering Reports & Logs DNS Filtering Troubleshooting
  • Marketing Toolkit
    MSP Marketing & Education Toolkit CyberFOX Brand Guidelines
  • Changelogs for Autoelevate and Password Boss
  • CyberFOX Product Roadmap
  • Current Status
+ More

Table of Contents

Overview What Elevation Modes Are Audit Mode What Audit Mode Does Key Characteristics Examples Best Practices Troubleshooting Security & Sync Behavior Policy Mode What Policy Mode Does Key Characteristics Examples Best Practices Troubleshooting Security & Sync Behavior Live Mode What Active Mode Does Key Characteristics Examples Best Practices Troubleshooting Security & Sync Behavior Changing Elevation Mode AutoElevate Portal Advanced Use Cases Mixed-Mode Deployments Conditional Least-Privilege Rollouts Compliance Reporting Troubleshooting Frequent Denials in Policy or Live Mode Too Many Approval Requests in Live Mode Devices Not Updating Modes Security & Sync Behavior Related Articles

Overview

Elevation Modes define how AutoElevate handles UAC elevation events across managed Windows devices. These modes determine whether actions are logged, automatically elevated based on rules, or handled interactively with real‑time technician approvals. Understanding these modes is essential for implementing least‑privilege security, reducing user interruptions, and achieving predictable privilege management.

What Elevation Modes Are

AutoElevate evaluates every UAC elevation event (installers, updaters, system settings, privileged tools) and applies one of three handling modes:
 
  • Audit Mode — Log all events without prompts or enforcement.
  • Policy Mode — Apply elevation/block rules and allow UAC for unknown items.
  • Live Mode — Apply elevation/block rules and prompt users for approval request on unknown items.
Each mode supports different operational maturity levels and deployment strategies.
 

Audit Mode


What Audit Mode Does

Audit Mode logs all UAC elevation events but does not intercept, block, or elevate anything. No users or technicians are prompted.

Key Characteristics

  • No behavior changes for users
  • No approvals required
  • All events logged in portal
  • Useful for baseline analysis and preparation before enforcement

Examples

  • Initial onboarding of a new company or location
  • Identifying frequently requested elevations to convert into policies
  • Assessing security posture without disruption

Best Practices

  • Keep new environments in Audit Mode for 30 – 60 days
  • Review Events page daily and create rules
  • Note applications frequently updated or launched by users

Troubleshooting

  • No events recorded: confirm device is checking in and UAC is enabled.
  • Unexpected behavior: verify device doesn’t have conflicting profile assignments.

Security & Sync Behavior

  • No elevation or blocking enforced
  • All UAC event logs sync to the portal immediately

 

Policy Mode


What Policy Mode Does

Policy Mode enforces existing elevation rules and blocks or allows based on those rules. Unknown actions default to Windows UAC prompts, not AutoElevate dialogs.

Key Characteristics

  • Rules elevate or block automatically
  • Unknown actions do NOT generate requests
  • Ideal for mature deployments

Examples

  • Trusted vendors: Microsoft, Adobe, Google
  • Automatic elevation of standard business apps
  • Transitional phase between Audit and Live

Best Practices

  • Add Publisher Rules for mainstream vendors
  • Add Hash Rules for static internal apps
  • Review logs continuously to refine rules

Troubleshooting

  • Rule not applying: verify rule scope (company/location/device).
  • Application still prompting: may need updated hash due to version change.

Security & Sync Behavior

  • Predictable rule‑driven enforcement
  • Immediate propagation of new rules to devices

 

Live Mode


What Active Mode Does

Active Mode intercepts every UAC event. For known applications, existing rules apply. For unknown elevation events, the user is prompted with an AutoElevate dialog, and technicians are notified for real‑time approval.

Key Characteristics

  • User receives prompt for unknown items
  • Technician approval workflow
  • Maximum control and visibility

Examples

  • MSPs handling ad‑hoc elevations
  • Environments with diverse application needs

Best Practices

  • Enable technician Teams or Mobile App notifications
  • Add several technician approvers to avoid delays
  • Convert repeated approvals into rules

Troubleshooting

  • User prompt not appearing: confirm device is in Live Mode.
  • Technicians not notified: verify notification routing settings.
  • Delayed Approvals: approvals can take up to 10 minutes at the agents next check-in.

Security & Sync Behavior

  • Real‑time oversight of unrecognized elevation requests
  • Logged technician approvals/denials for compliance
  • Fast bidirectional syncing between agent and notification server

 

Changing Elevation Mode


AutoElevate Portal

  1. Go to Computers or Profiles.
  2. Select the device(s) or group.
  3. Open Actions → Elevation Mode.
  4. Choose Audit, Policy, or Active.
  5. Devices will update on next check‑in.

 

Advanced Use Cases


Mixed-Mode Deployments

Use Audit Mode for new users while keeping established teams in Policy or Live Mode.

Conditional Least-Privilege Rollouts

Use Audit Mode to collect real behavior, then convert into automated rules.

Compliance Reporting

Export event logs for SOC 2, ISO 27001, CMMC evidence.
 

Troubleshooting


Frequent Denials in Policy or Live Mode

Likely missing rules—review logs and add publisher or hash rules.

Too Many Approval Requests in Live Mode

Convert recurring approvals into rules to reduce technician load.

Devices Not Updating Modes

Check connectivity and confirm no conflicting profile assignments.
 

Security & Sync Behavior


  • Elevation modes sync instantly on agent check‑in
  • Technician actions sync in real time via notification server
  • Full audit trail for all approvals and denials

 

Related Articles


  • https://support.cyberfox.com/360000239832-General-Troubleshooting/360030799571-Elevation-Types
  • https://support.cyberfox.com/115000883892-New-to-AutoElevate-START-HERE/115003709732-System-Overview-System-Agent
  • https://support.cyberfox.com/115000883892-New-to-AutoElevate-START-HERE/360000840432-Audit-Guide
  • https://support.cyberfox.com/360030799631-Creating-Elevation-Rules
  • https://support.cyberfox.com/360030799651-Understanding-Publisher-Rules
autoelevate elevation modes audit mode policy mode active mode least privilege uac control windows elevation approval workflow msi elevation exe elevation publisher rules hash rules command-line rules zero trust privilege management endpoint security audit logging access control cyberfox autoelevate msp operations technician approval portal configuration device profiles automated elevation security compliance modes audit policy active elevation

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • How can I deploy agents in "Live" mode?
  • How do I manually update the User password for User Elevations?
  • Does AutoElevate Enter My Admin Password for End Users?
CyberFOX

PRACTICAL CYBERSECURITY FOR LEAN IT TEAMS

Platforms
  • Privileged Access Management
  • Password Management
  • DNS Filtering
  • SASE
Industry
  • Higher Education
  • K-12 Education
  • State and Local Government
  • Manufacturing
Company
  • About
  • Awards
  • Partnerships
  • Trust & Legal
  • Contact
  • Login
  • FAQ
  • Referral Program
  • Support
© 2026 CYBERFOX LLC ALL RIGHTS RESERVED | Privacy Policy | Terms of Service | Sitemap
Expand