Getting Started

Keeper Endpoint Privilege Manager (EPM) gives you control without friction: secure privilege elevation, file access, and application control on every endpoint, with a focus on letting users do their jobs while you enforce policy.
This guide walks you through everything you need to stand up Keeper EPM in your organization — from activating your license to deploying agents, building your first policies, and operating the system at scale. Each page in the Getting Started section is written so you can read it on its own or follow it in order.
What Keeper EPM Does
Keeper EPM is Keeper Security's Privilege Elevation and Delegation Management solution that lets you:
Control When and How users run as administrator or access sensitive files and commands.
Require MFA, Approval, or Justification before sensitive actions complete — so security and compliance stay in your hands.
Reduce Standing Privilege so users don't need local administrator rights by default.
Redirect Risky Actions (like opening network settings) to a controlled substitute experience — so you say "yes" in a secure way instead of "no."
Keeper EPM uses policies to govern endpoint activity — File Access, Privilege Elevation, Command Line execution, Least Privilege enforcement, and Agentic AI governance (including Agentic Access and Agentic Privilege Elevation). Each policy type targets a specific class of action and can require MFA, justification, or approval before it completes.
Policies are defined in the Keeper Admin Console and enforced by an agent on each endpoint. The goal is to enable the right actions in a secure, auditable way — not to block productivity.
A User-First Approach
Keeper EPM is designed so users don't have to be security experts:
User-First: Users get their work done without needing to understand privilege or policy.
Enable, then Secure: The product prefers approved, controlled flows over blanket denials. When policy allows an action, the user gets a clear path to complete it.
Policy-Controlled: You define what's allowed and how. Users see a consistent experience; you keep control.
Features like redirects (substitute applications for sensitive actions), approval workflows, justification prompts, and ephemeral elevation support a "yes, you can" approach wherever your policy permits.
Zero-Standing Privilege
With Keeper EPM, you can move toward zero-standing privilege: users are not local administrators by default. When they need elevation, they request it; your policies decide whether to allow it, require MFA, require approval, or deny it. Elevation can be time-limited and fully audited. The result is stronger security and a smaller attack surface — without sacrificing the ability to get work done.
Granular, Application-Aware Enforcement
Enforcement is granular and application-aware. Keeper EPM supports several policy types that you can combine:
Privilege Elevation — Target specific applications, command lines, users, and machines. Choose Allow, Deny, MFA, Justification, or Approval per policy.
File Access — Allow, deny, or gate access to specific files or folders with justification or approval.
Command Line — Control which commands or patterns can run.
Least Privilege — Remove standing administrator rights where appropriate while keeping exceptions where you need them.
Agentic AI, Agentic Access, and Agentic Privilege Elevation — Govern Agentic AI and the actions they take on the endpoint.

Variables and Wildcards let one policy apply across many paths, users, or machines without maintaining long lists.
An Event-Driven, Extensible System
Keeper EPM is built to be powerful as well as secure. The system is event-driven: actions — a user requesting elevation, a policy returning pending, an approval granted — trigger workflows and jobs automatically. You can orchestrate MFA, approval, justification, launch, and custom logic without manual steps.
The system is also extensible. You can add custom jobs that run scripts or call APIs, configuration policies that push settings to endpoints, and redirects to substitute applications — all under the same policy and audit model. This power is designed without compromising security: the agent's control plane stays local, only trusted components can drive it, and every sensitive action remains policy-gated and auditable.
Audit & Visibility
You get full visibility into what's happening on your endpoints:
Audit Events for privilege elevation, file access, policy evaluations, and related actions.
Logging you can tune for troubleshooting or compliance.
Clear View of which policies matched, what was allowed or denied, and how approvers and users interacted.
Events are sent to the Keeper backend and can be used for reporting and integration with your existing security and audit tools.

Platform Resilience & Reliability
Keeper EPM is built to be reliable across your environment:
Multi-Platform: Windows, Linux, and macOS with consistent concepts and configuration.
Service-Based: A local service and plugins handle policy evaluation, backend sync, and logging.
Health Checks: Built-in health and status endpoints so you can monitor and automate.
Operational Control: Plugins and configuration can be updated and tuned so you can adapt without reinstalling.
Operational Flexibility
You have room to roll out and tune Keeper EPM without risk:
Policy Status — Use Off, Enforce, Monitor, or Monitor & Notify so you can test policies without blocking users. See Phased Policy Rollout Planning for the recommended progression.

Airgapped options — Offline registration and deployment are supported for locked-down environments.
The Keeper Admin Console
Your Keeper Admin Console is the control center for Keeper EPM. From there you:
Activate EPM and manage licensing.

Create and assign approvers, collections, policies, and deployment groups.
Build deployment packages and monitor agents.

View requests, approvals, and audit data.

The agent on each endpoint enforces what you configure in the console — so you manage once and enforce everywhere.
Last updated
Was this helpful?

