Policy overhaul
Policies rebuilt around the applications and admin tasks the IT team manages, with an application allowlist and blocklist in place.
Most laptops still let the person using them install anything and change anything, because taking admin rights away usually means a help desk buried in requests. A US specialty retailer asked our engineers to remove those rights without that happening. This is how it was done: policies rebuilt around real tasks, every elevation raised and approved in ServiceNow, and every event sent to the team that watches.
Five pieces of work, delivered together.
Before the project, users held standing administrator rights on their endpoints. Software could be installed outside the IT team's control, and any malware a user ran inherited full administrative privilege along with it. The endpoint privilege policies that did exist were broad catch-all rules, not rules written for the applications and tasks people actually needed.
The brief was to take those rights away without leaving people stuck, which is why it became five pieces of work, delivered together.
Policies rebuilt around the applications and admin tasks the IT team manages, with an application allowlist and blocklist in place.
Elevation requests raised, approved and logged as ServiceNow tickets.
EPM alerts routed into the detection pipeline the security team already runs.
Standing administrator rights withdrawn from endpoints.
EPM moved onto CyberArk's shared Identity Security Platform tenant.
Anything a policy does not already cover goes through one route, and it is the route the IT team already works in.
Privilege lasts only as long as the approved request, so no account carries elevation between tasks. Every grant leaves a ticket record for audit.
EPM elevation, block and threat events now flow into the retailer's existing log pipeline, which routes, filters and enriches them before they reach the security operations tooling for detection and review.
The alerts leave EPM in a format that pipeline already consumes, so nobody has a separate console to watch. Elevation and block events are correlated with the rest of the security telemetry, and the event history is kept outside EPM for investigation and reporting.
Users held standing administrator rights on their endpoints.
Users operate as standard accounts.
Endpoint privilege moved off its standalone console and onto the Identity Security Platform tenant, where it shares identity and audit services with the rest of the platform.
Ongoing operation of the platform has transferred to the retailer.
Policy sets, elevation rules and endpoint group membership.
Elevation request intake, approval routing and closure.
Alert forwarding and the downstream detection rules.
Configuration records and operating procedures, delivered.
Replace the IT-wide policy set with policies written per department: profile elevation demand by department, draft and pilot departmental policy sets, then roll out while keeping the shared allowlist.
Keep EPM agents current without manual intervention: define upgrade rings and a schedule, automate distribution and reporting, and track version compliance centrally.
Let downloaded software run only when it comes from a known publisher: baseline the publishers already in use, block unsigned and unknown-publisher installers, and route exceptions through the ticketed request flow.
Anywhere users still hold local admin because taking it away felt too disruptive. The pattern is the one used here: policies written for real tasks, a ticketed route for everything else, and events sent to the people who watch. The same engineers delivered the PAM platform work for this retailer. For what EPM does on its own, see the CyberArk modules; for how an engagement runs, PAM implementation; and for the sector, identity security for retail.
A free audit is 30 minutes with a certified engineer on your own environment, with the findings in writing. No cost, no obligation.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.