IAM

Endpoint Privilege Management

Endpoint Privilege Management evaluates device posture signals before granting access to privileged resources. The EPM agent (or integration with CrowdStrike / SentinelOne) reports OS patch level, full-disk encryption status, EDR agent presence, and certificate trust chain integrity. Posture results are cached with a configurable TTL and evaluated at session initiation and secret access.

Policies define minimum posture requirements per workspace or session target. Non-compliant devices receive a remediation prompt with specific instructions rather than a generic denial.

Endpoint Privilege Management screenshot

Key Configuration

  • Posture check TTL (minutes)
  • Required OS patch age (days)
  • EDR vendor allowlist (CrowdStrike, SentinelOne)
  • Remediation redirect URL
All documentation Question about this? Talk to us