Elevation Modes (Audit, Policy, Live)
Differences between audit, policy, and active elevation modes to enhance security and control in your systems.
Table of Contents
Overview
What Elevation Modes Are
Audit Mode
What Audit Mode Does
Key Characteristics
Examples
Best Practices
Troubleshooting
Security & Sync Behavior
Policy Mode
What Policy Mode Does
Key Characteristics
Examples
Best Practices
Troubleshooting
Security & Sync Behavior
Live Mode
What Active Mode Does
Key Characteristics
Examples
Best Practices
Troubleshooting
Security & Sync Behavior
Changing Elevation Mode
AutoElevate Portal
Set a Persistent Elevation Mode
Advanced Use Cases
Mixed-Mode Deployments
Conditional Least-Privilege Rollouts
Compliance Reporting
Troubleshooting
Frequent Denials in Policy or Live Mode
Too Many Approval Requests in Live Mode
Devices Not Updating Modes
Computer Keeps Returning to a Different Mode
Security & Sync Behavior
Related Articles
Overview
Elevation Modes define how AutoElevate handles UAC elevation events across managed Windows devices. These modes determine whether actions are logged, automatically elevated based on rules, or handled interactively with real‑time technician approvals. Understanding these modes is essential for implementing least‑privilege security, reducing user interruptions, and achieving predictable privilege management.
What Elevation Modes Are
AutoElevate evaluates every UAC elevation event (installers, updaters, system settings, privileged tools) and applies one of three handling modes:
- Audit Mode — Log all events without prompts or enforcement.
- Policy Mode — Apply elevation/block rules and allow UAC for unknown items.
- Live Mode — Apply elevation/block rules and prompt users for approval request on unknown items.
Each mode supports different operational maturity levels and deployment strategies.
You can set the mode for individual computers from the Actions menu, or set a persistent mode for all your companies, a single company, or a single location from the Settings screen. See Set a Persistent Elevation Mode.
Audit Mode
What Audit Mode Does
Audit Mode logs all UAC elevation events but does not intercept, block, or elevate anything. No users or technicians are prompted.
Key Characteristics
- No behavior changes for users
- No approvals required
- All events logged in portal
- Useful for baseline analysis and preparation before enforcement
Examples
- Initial onboarding of a new company or location
- Identifying frequently requested elevations to convert into policies
- Assessing security posture without disruption
Best Practices
- Keep new environments in Audit Mode for 30 – 60 days
- Review Events page daily and create rules
- Note applications frequently updated or launched by users
Troubleshooting
- No events recorded: confirm device is checking in and UAC is enabled.
- Unexpected behavior: verify device doesn’t have conflicting profile assignments.
Security & Sync Behavior
- No elevation or blocking enforced
- All UAC event logs sync to the portal immediately
Policy Mode
What Policy Mode Does
Policy Mode enforces existing elevation rules and blocks or allows based on those rules. Unknown actions default to Windows UAC prompts, not AutoElevate dialogs.
Key Characteristics
- Rules elevate or block automatically
- Unknown actions do NOT generate requests
- Ideal for mature deployments
Examples
- Trusted vendors: Microsoft, Adobe, Google
- Automatic elevation of standard business apps
- Transitional phase between Audit and Live
Best Practices
- Add Publisher Rules for mainstream vendors
- Add Hash Rules for static internal apps
- Review logs continuously to refine rules
Troubleshooting
- Rule not applying: verify rule scope (company/location/device).
- Application still prompting: may need updated hash due to version change.
Security & Sync Behavior
- Predictable rule‑driven enforcement
- Immediate propagation of new rules to devices
Live Mode
What Active Mode Does
Active Mode intercepts every UAC event. For known applications, existing rules apply. For unknown elevation events, the user is prompted with an AutoElevate dialog, and technicians are notified for real‑time approval.
Key Characteristics
- User receives prompt for unknown items
- Technician approval workflow
- Maximum control and visibility
Examples
- Organizations handling ad‑hoc elevations
- Environments with diverse application needs
Best Practices
- Enable technician Teams or Mobile App notifications
- Add several technician approvers to avoid delays
- Convert repeated approvals into rules
Troubleshooting
- User prompt not appearing: confirm device is in Live Mode.
- Technicians not notified: verify notification routing settings.
- Delayed Approvals: approvals can take up to 10 minutes at the agents next check-in.
Security & Sync Behavior
- Real‑time oversight of unrecognized elevation requests
- Logged technician approvals/denials for compliance
- Fast bidirectional syncing between agent and notification server
Changing Elevation Mode
AutoElevate Portal
- Go to Computers or Profiles.
- Select the device(s) or group.
- Open Actions → Elevation Mode.
- Choose Audit, Policy, or Live.
- Devices will update on next check‑in.
Set a Persistent Elevation Mode
Use a persistent setting when you want every computer in a scope to stay in the same mode, including new computers.
- Open the Settings screen and select the "+" icon at the top of the grid.
- Choose the level: Global, Whole Company, or Whole Location.
- Choose Persistent Elevation Mode, select Audit, Policy, or Live, and SAVE.
- The setting is not in your grid until you add it. Until then, the mode is Not Managed and computers keep whatever mode was set manually.
- The most specific level wins (Location, then Company, then Global). A mode chosen for a computer from the Actions menu is an override and takes precedence. Remove Mode Override returns the computer to its Level Setting.
- New computers move to the mode automatically, and computers that drift are moved back at the next status check-in, about every 2 hours.
- Technician Mode sessions are never interrupted.
- The Persistent Elevation Mode column in the Computers grid shows each computer's mode and its source, for example "Audit (Global)" or "Live (Override)".
For full details, including Persistent Blocker Mode, see System Overview – System Agent.
Advanced Use Cases
Mixed-Mode Deployments
Use Audit Mode for new users while keeping established teams in Policy or Live Mode.
Conditional Least-Privilege Rollouts
Use Audit Mode to collect real behavior, then convert into automated rules.
Compliance Reporting
Export event logs for SOC 2, ISO 27001, CMMC evidence.
Troubleshooting
Frequent Denials in Policy or Live Mode
Likely missing rules—review logs and add publisher or hash rules.
Too Many Approval Requests in Live Mode
Convert recurring approvals into rules to reduce technician load.
Devices Not Updating Modes
Check connectivity and confirm no conflicting profile assignments.
If a persistent Elevation Mode is set, check the Persistent Elevation Mode column. "(Override)" means the computer's own mode wins over the Level Setting. Persistent changes apply after the next status check-in (about every 2 hours) and wait until any Technician Mode session ends.
Computer Keeps Returning to a Different Mode
A persistent Elevation Mode or a computer override is moving it back. Check the Persistent Elevation Mode column to see where the mode comes from, then change that setting in Settings or select Remove Mode Override from the Actions menu.
Security & Sync Behavior
- Elevation modes sync instantly on agent check‑in
- Persistent Elevation Mode settings are checked at each agent status check-in (about every 2 hours), and computers that drift are moved back automatically
- Technician actions sync in real time via notification server
- Full audit trail for all approvals and denials
Related Articles
- https://support.cyberfox.com/360000239832-General-Troubleshooting/360030799571-Elevation-Types
- https://support.cyberfox.com/115000883892-New-to-AutoElevate-START-HERE/115003709732-System-Overview-System-Agent
- https://support.cyberfox.com/115000883892-New-to-AutoElevate-START-HERE/360000840432-Audit-Guide
- https://support.cyberfox.com/360030799631-Creating-Elevation-Rules
- https://support.cyberfox.com/360030799651-Understanding-Publisher-Rules
- https://support.cyberfox.com/settings/4405408196877-Settings-Overview