IAM
Endpoint Privilege Management
Endpoint Privilege Management evaluates device posture signals before granting access to privileged resources. The EPM agent (or integration with CrowdStrike / SentinelOne) reports OS patch level, full-disk encryption status, EDR agent presence, and certificate trust chain integrity. Posture results are cached with a configurable TTL and evaluated at session initiation and secret access.
Policies define minimum posture requirements per workspace or session target. Non-compliant devices receive a remediation prompt with specific instructions rather than a generic denial.
Key Configuration
- Posture check TTL (minutes)
- Required OS patch age (days)
- EDR vendor allowlist (CrowdStrike, SentinelOne)
- Remediation redirect URL