Skip to content

Process Elevation Rules

Process elevation rules decide which applications a validated user can run with Run with Admin Privileges, and which child processes those applications can start. You manage the rules under Security → Process Elevation Rules in a Privileges configuration.

Rules only apply to users who pass Validation. See Privilege Manager Configuration Settings.

Field Description
Name A unique name for the rule. Special characters aren’t allowed.
Enabled Turns the rule on or off. Disabled rules are ignored.
Allow Elevation Whether a process that matches the rule may be elevated. Turn it off to block the process. A new rule starts with Allow Elevation turned off.
Main Process Name The file name of the process, such as cmd.exe or setup.msi. The name must end with .exe or .msi, and must be unique across the rules in the configuration.
Main Process Path Optional. The folder the process must run from, such as C:\Windows\System32\. Enter the folder only, without the file name.
Child Processes The processes that the elevated main process may start. See Child processes.

Some special characters, including Asian, Arabic, and Cyrillic characters, aren’t supported in process names and paths.

Paths, wildcards, and environment variables

Section titled “Paths, wildcards, and environment variables”
  • Without a wildcard, the path must match the folder exactly. C:\Windows\System32\ matches processes in that folder, but not in its subfolders.
  • Use * as a wildcard to include subfolders. C:\Program Files\* matches processes in any subfolder of C:\Program Files.
  • You can use environment variables, such as %WinDir%\System32\.

Every configuration has a rule named Default. It applies when no other enabled rule matches the process. You can’t delete or disable the Default rule, but you can decide whether it allows elevation.

  • Default allows elevation: validated users can elevate any .exe or .msi file, except the processes you block with other rules.
  • Default blocks elevation: validated users can only elevate the processes that other rules allow.

A new configuration starts with a Default rule that allows elevation and allows all child processes.

When a user selects Run with Admin Privileges, CapaOne checks the enabled rules in the order they’re listed:

  1. A rule with only a Main Process Name matches when the file name is the same. Case doesn’t matter.
  2. A rule with a Main Process Name and a Main Process Path matches when both the file name and the folder match.
  3. The first rule that matches decides whether the process is elevated.
  4. If no rule matches, the Default rule decides.

If the matching rule blocks elevation, the user sees a message that the process is blocked by your organization’s elevation policy.

Many applications start other processes. For example, cmd.exe and powershell.exe start the Console Window Host (conhost.exe). The Child Processes list controls what the elevated main process may start:

Child process Result
Listed and Allowed The child process runs.
Listed and not allowed The child process is stopped.
Not listed Follows the Default entry in the list.

Each rule starts with a Default child process entry that is allowed, so all child processes can run until you change it. To allow only specific child processes, turn off Allowed for the Default entry and add the processes you want to allow. Child process names must end with .exe.

You can only change child processes for a rule that allows elevation.

If you restrict child processes for cmd.exe or powershell.exe, allow conhost.exe. See Child processes for why.

To let users run one approved installer and nothing else:

  1. In the rules list, turn off Allow Elevation for the Default rule.
  2. Click Add, enter the rule name Approved installer, and confirm. The new rule is selected.
  3. Set Main Process Name to the installer’s file name, for example setup.exe.
  4. Set Main Process Path to the folder the installer runs from.
  5. Turn on Allow Elevation for the new rule.
  6. Save the configuration.

Validated users can now elevate setup.exe from that folder. Every other process is blocked by the Default rule.

Process Elevation Rules list with the Default rule and a custom rule named CMD selected, and its Main Process Name, Main Process Path, and Child Processes fields on the right

  • Rule changes take effect on an endpoint after you save the configuration and the endpoint receives the updated configuration.
  • Process elevation rules aren’t active while a user has an elevated session. See Session Elevation.
  • To see which processes users elevate, and which are rejected by a rule, use Elevation Analytics.