Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Privileged Access Management in ScreenConnect

Connectwise
05/11/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Glenn here with ScreenConnect, and today I want to talk to you about our Privileged Access Management tool. This is how we handle UAC elevations and pretty much allowing you to automate the entire process as well as, from a security standpoint, setting users up with an ephemeral local admin for just operating by the principle of least privilege access and really locking down your security environment. So I will dive right in here, and the first thing I will cover is the UAC elevations. So let me just hop in a session here. Okay so what this looks like from the end user's perspective is, I'll just use notepad because it's right on my desktop, but they would right click, run as administrator, and as you can see here, we inject ourselves into this dialog. You can also input a reason right here. So let's just say they would like to update this program, and they would click this little blue arrow, and as you can see, you get a notification to the session as well as this privileged access shield right here. So once you click into this thread, you will get more information about the prompt. So program name, publisher, certificate thumbprint, and you can take action on it from here. So if you know what it is, you can approve it, deny it, whatever you want to do. You also have the ability to do that from within the session, just another call out. If you need more information about the request, you can first click on this node, which is a virus total integration, and this will run it against, I believe it's about 80 antivirus, to see if there's any known threats. So in this case, notepad, looks like it's good to go. Then what I would do is come to this middle node, this is the awesome part. So you can click on this middle node, and then create a rule. So this is basically saying, if these conditions are met, then take this action. So for this case, we can auto approve it. I will create that rule, I will approve this one, and then the next time this is encountered, run as admin, update, and then boom, no action is needing to be taken on that. Rules are stored under admin, automations. So if you're looking for those, that's where they are stored. And as you can see, this is the one I just created today, which we don't need. So just for cleanup, I'm going to delete that one. Okay, the second part of privileged access management is the creation of a temporary local admin. And this looks very similar. We inject ourselves here on the lock screen. So you send your control, delete, and you will have an additional option at the bottom that is screen connect, passwordless administrative logon. So very similar workflow, you could just send this request, now this is your technician performing this function. And you can see it's waiting for an approval. So you would just navigate back to that specific machine, there's your notification, and approve or deny. Again, for this, I will just deny it. But it is great because what's happening here is it's creating a temporary, long tail password. It's like 256 character AES encrypted, so very secure. When that technician is done with that session, then you can basically remove those credentials. So just really, really locking down your environment tight. Okay, last thing I want to cover here is the dashboard. So you'll navigate to admin and then privileged access. I love, I'm a data guy, so I love these graphs here. So this is going to just give you some information about the end user access, how many of these elevation prompts were encountered, how many of these admin logons were encountered, how many endpoints do you have PAM assigned to, and then even rules versus manual approvals and top elevation responses by application. So for another example, let's say you see 100 requests for Adobe Creative Cloud, and they're mostly manual approvals, then it's like, okay, well, maybe it's time to set up a rule for that, save my team a bunch of time. If you click on settings up here, this is where you would actually make these things visible. So for UAC elevation, you click edit, you can make it visible in all session groups, or if you select a percentage of PAM, you can have it in a specific session group or with host connected. So making the reason field visible, all of this is configurable as well as the administrative logon. So visible on lock screen, that's where you would make this visible with host connected, session group, et cetera. So there you have it. That's our ScreenConnect privileged access management tool in a nutshell. I hope this video was helpful. Be sure to click the like button and shoot me a follow on my YouTube channel for more great ScreenConnect tips and tricks. Cheers.

TL;DR

  • ScreenConnect PAM intercepts Windows UAC prompts and allows remote approval/denial with VirusTotal scanning integration for security validation before elevation
  • Automated rule creation enables conditional auto-approval of trusted applications, reducing manual intervention while maintaining security controls and audit trails
  • Ephemeral local admin accounts use 256-character AES-encrypted passwords that are automatically removed after session completion, enforcing least privilege access
  • Administrative dashboard tracks elevation patterns and identifies automation opportunities, helping teams optimize approval workflows based on application usage data

UAC Elevation Automation and Control

This demonstration walks through ScreenConnect's Privileged Access Management (PAM) capabilities, focusing on User Account Control (UAC) elevation handling. The system injects itself into Windows UAC prompts, allowing technicians to approve or deny elevation requests remotely. A key feature is the VirusTotal integration that scans executables against approximately 80 antivirus engines before approval. The platform enables rule creation based on conditions, automating future approvals for trusted applications. This eliminates repetitive manual approvals while maintaining security oversight through detailed logging and notification systems.

Ephemeral Admin Access and Security Dashboard

The second component creates temporary local administrator accounts using 256-character AES-encrypted passwords for technician access. This passwordless administrative logon appears on the Windows lock screen and requires approval before granting access, adhering to least privilege principles. Credentials are automatically removed after session completion. The administrative dashboard provides analytics on elevation prompts, admin logons, PAM-enabled endpoints, and application-level approval patterns. This data helps identify opportunities for rule automation, such as creating auto-approval rules for frequently requested applications like Adobe Creative Cloud.

Chapters

0:00 - Introduction to PAM
0:42 - UAC Elevation Demo
2:16 - VirusTotal Integration
2:36 - Rule Creation Workflow
3:29 - Temporary Admin Access
4:43 - Analytics Dashboard Overview

Key Quotes

0:25 "... allowing you to automate the entire process as well as, from a security standpoint, setting users up with an ephemeral local admin for just operating by the principle of least privilege access and really locking down your security environment ..."
2:23 "... this will run it against, I believe it's about 80 antivirus, to see if there's any known threats ..."
4:24 "... it's creating a temporary, long tail password. It's like 256 character AES encrypted, so very secure ..."
5:29 "... let's say you see 100 requests for Adobe Creative Cloud, and they're mostly manual approvals, then it's like, okay, well, maybe it's time to set up a rule for that, save my team a bunch of time ..."

Categories:
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Endpoint Management
  • Security Operations
  • Demo
  • Technical Deep Dive
  • Privileged Access Management
  • UAC Elevation Control
  • Ephemeral Admin Accounts
  • Least Privilege Access
  • Remote Access Security
  • Automation Rules
  • VirusTotal Integration
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Privileged Access Management in ScreenConnect

              Upcoming Webinar Calendar

              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                Preventing Your AI from Turning Against You: Essential Strategies
                https://www.truthinit.com/index.php/channel/2021/preventing-your-ai-from-turning-against-you-essential-strategies/
              • 07/02/2026
                10:00 AM
                07/02/2026
                Resilience Insights from Hybrid Threats Amidst Cloud Challenges
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-amidst-cloud-challenges/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Manifesting Agentic Trust in Real Life
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-manifesting-agentic-trust-in-real-life/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Quality Security Team for Unmatched Defense
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-quality-security-team-for-unmatched-defense/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers During the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-during-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Insights and Strategies from the DPDP Webinar
                https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-from-the-dpdp-webinar/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 08/19/2026
                12:00 PM
                08/19/2026
                Witness Cyera Agent Security in Action: A Firsthand Experience
                https://www.truthinit.com/index.php/channel/2036/witness-cyera-agent-security-in-action-a-firsthand-experience/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                30

                Mastering Active Directory Certificate Services for Long-Term Success

                06/30/202601:00 PM ET
                • Jul
                  01

                  Integrating Security in AI: Automated Red Teaming Strategies for Private Models

                  07/01/202604:00 AM ET
                  • Jul
                    01

                    Schutz von KI in Anwendungen, Agenten und APIs.

                    07/01/202604:00 AM ET
                    • Jul
                      01

                      Preventing Your AI from Turning Against You: Essential Strategies

                      07/01/202601:00 PM ET
                      • Jul
                        02

                        Resilience Insights from Hybrid Threats Amidst Cloud Challenges

                        07/02/202610:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version