For the complete documentation index, see llms.txt. This page is also available as Markdown.

Configure PEDM local elevation

This article explains how to configure Privilege Elevation and Delegation Management (PEDM) local elevation using Remote Desktop Manager and Devolutions Agent.

Agent PEDM allows a regular local user to temporarily elevate local administrator privileges from the Remote Desktop Manager workstation without giving that user a permanent local administrator account for normal sign-in.

In this article, Agent PEDM refers to the PEDM functionality provided by Devolutions Agent and surfaced through Remote Desktop Manager. It should not be confused with the broader PAM workflows configured through Devolutions Server.

This workflow is intended for local administrator elevation on the workstation where Remote Desktop Manager and Devolutions Agent are installed.

Install Devolutions Agent along with the PEDM components

  1. In Remote Desktop Manager, check the version number in the bottom right corner.

  2. Then, download the matching version (major and minor) of Devolutions Agent.

Contact our support team if you need a Devolutions Agent version matching an older version of Remote Desktop Manager.

  1. Launch the Devolutions installation wizard and make sure to install the PEDM component. The PEDM checkbox is not ticked by default and the Devolutions Agent options will not appear in Remote Desktop Manager if this isn't done.

Create and assign an Agent PEDM profile

The Agent PEDM profile must be created from Remote Desktop Manager while it is running as administrator.

  1. Close Remote Desktop Manager if it is already open, then relaunch it using "Run as administrator".

  2. In the Remote Desktop Manager Tools tab, open PEDM profile manager.

  3. Select Add to create a new profile and enter a name for it.

  4. Configure the profile settings as needed.

  5. Assign the profile to the intended local user.

  6. Save the profile and close Remote Desktop Manager.

After the profile is created and assigned, the regular user can launch Remote Desktop Manager normally and select the assigned profile when local elevation is required.

Select an Agent PEDM profile

After an Agent PEDM profile is created and assigned, the regular user can launch Remote Desktop Manager normally.

  1. Launch Remote Desktop Manager normally.

  2. In the Remote Desktop Manager Tools tab, select Select profile.

  3. Choose the assigned Agent PEDM profile.

  4. Perform the required local administrator action while the profile is active.

Last updated

Was this helpful?