Elevation Modes (Audit, Policy, Live)
Differences between audit, policy, and active elevation modes to enhance security and control in your systems.
Table of Contents
Overview
What Elevation Modes Are
Audit Mode
What Audit Mode Does
Key Characteristics
Examples
Best Practices
Troubleshooting
Security & Sync Behavior
Policy Mode
What Policy Mode Does
Key Characteristics
Examples
Best Practices
Troubleshooting
Security & Sync Behavior
Live Mode
What Active Mode Does
Key Characteristics
Examples
Best Practices
Troubleshooting
Security & Sync Behavior
Changing Elevation Mode
AutoElevate Portal
Advanced Use Cases
Mixed-Mode Deployments
Conditional Least-Privilege Rollouts
Compliance Reporting
Troubleshooting
Frequent Denials in Policy or Live Mode
Too Many Approval Requests in Live Mode
Devices Not Updating Modes
Security & Sync Behavior
Related Articles
Overview
Elevation Modes define how AutoElevate handles UAC elevation events across managed Windows devices. These modes determine whether actions are logged, automatically elevated based on rules, or handled interactively with real‑time technician approvals. Understanding these modes is essential for implementing least‑privilege security, reducing user interruptions, and achieving predictable privilege management.
What Elevation Modes Are
AutoElevate evaluates every UAC elevation event (installers, updaters, system settings, privileged tools) and applies one of three handling modes:
- Audit Mode — Log all events without prompts or enforcement.
- Policy Mode — Apply elevation/block rules and allow UAC for unknown items.
- Live Mode — Apply elevation/block rules and prompt users for approval request on unknown items.
Each mode supports different operational maturity levels and deployment strategies.
Audit Mode
What Audit Mode Does
Audit Mode logs all UAC elevation events but does not intercept, block, or elevate anything. No users or technicians are prompted.
Key Characteristics
- No behavior changes for users
- No approvals required
- All events logged in portal
- Useful for baseline analysis and preparation before enforcement
Examples
- Initial onboarding of a new company or location
- Identifying frequently requested elevations to convert into policies
- Assessing security posture without disruption
Best Practices
- Keep new environments in Audit Mode for 30 – 60 days
- Review Events page daily and create rules
- Note applications frequently updated or launched by users
Troubleshooting
- No events recorded: confirm device is checking in and UAC is enabled.
- Unexpected behavior: verify device doesn’t have conflicting profile assignments.
Security & Sync Behavior
- No elevation or blocking enforced
- All UAC event logs sync to the portal immediately
Policy Mode
What Policy Mode Does
Policy Mode enforces existing elevation rules and blocks or allows based on those rules. Unknown actions default to Windows UAC prompts, not AutoElevate dialogs.
Key Characteristics
- Rules elevate or block automatically
- Unknown actions do NOT generate requests
- Ideal for mature deployments
Examples
- Trusted vendors: Microsoft, Adobe, Google
- Automatic elevation of standard business apps
- Transitional phase between Audit and Live
Best Practices
- Add Publisher Rules for mainstream vendors
- Add Hash Rules for static internal apps
- Review logs continuously to refine rules
Troubleshooting
- Rule not applying: verify rule scope (company/location/device).
- Application still prompting: may need updated hash due to version change.
Security & Sync Behavior
- Predictable rule‑driven enforcement
- Immediate propagation of new rules to devices
Live Mode
What Active Mode Does
Active Mode intercepts every UAC event. For known applications, existing rules apply. For unknown elevation events, the user is prompted with an AutoElevate dialog, and technicians are notified for real‑time approval.
Key Characteristics
- User receives prompt for unknown items
- Technician approval workflow
- Maximum control and visibility
Examples
- MSPs handling ad‑hoc elevations
- Environments with diverse application needs
Best Practices
- Enable technician Teams or Mobile App notifications
- Add several technician approvers to avoid delays
- Convert repeated approvals into rules
Troubleshooting
- User prompt not appearing: confirm device is in Live Mode.
- Technicians not notified: verify notification routing settings.
- Delayed Approvals: approvals can take up to 10 minutes at the agents next check-in.
Security & Sync Behavior
- Real‑time oversight of unrecognized elevation requests
- Logged technician approvals/denials for compliance
- Fast bidirectional syncing between agent and notification server
Changing Elevation Mode
AutoElevate Portal
- Go to Computers or Profiles.
- Select the device(s) or group.
- Open Actions → Elevation Mode.
- Choose Audit, Policy, or Active.
- Devices will update on next check‑in.
Advanced Use Cases
Mixed-Mode Deployments
Use Audit Mode for new users while keeping established teams in Policy or Live Mode.
Conditional Least-Privilege Rollouts
Use Audit Mode to collect real behavior, then convert into automated rules.
Compliance Reporting
Export event logs for SOC 2, ISO 27001, CMMC evidence.
Troubleshooting
Frequent Denials in Policy or Live Mode
Likely missing rules—review logs and add publisher or hash rules.
Too Many Approval Requests in Live Mode
Convert recurring approvals into rules to reduce technician load.
Devices Not Updating Modes
Check connectivity and confirm no conflicting profile assignments.
Security & Sync Behavior
- Elevation modes sync instantly on agent check‑in
- Technician actions sync in real time via notification server
- Full audit trail for all approvals and denials
Related Articles
- https://support.cyberfox.com/360000239832-General-Troubleshooting/360030799571-Elevation-Types
- https://support.cyberfox.com/115000883892-New-to-AutoElevate-START-HERE/115003709732-System-Overview-System-Agent
- https://support.cyberfox.com/115000883892-New-to-AutoElevate-START-HERE/360000840432-Audit-Guide
- https://support.cyberfox.com/360030799631-Creating-Elevation-Rules
- https://support.cyberfox.com/360030799651-Understanding-Publisher-Rules