Service — Endpoint Privilege Management
One clicked link shouldn't hand over the whole machine
EPM removes permanent local admin rights from users’ devices, controls what’s allowed to run, and elevates only the specific actions people actually need. Most malware needs local admin to do real damage. Take it away and a lot of attacks stall on the first device, delivered across Norway, Sweden and Denmark.
Start with an application inventory: see what your users actually run before you change anything.
- Most malware needs local admin to do real damage
- Standing admin lets one clicked link spread
- 85 to 90% of daily work runs fine without it
What is EPM?
Take away the rights malware depends on
Endpoint Privilege Management (EPM) is the practice of removing permanent local admin rights from users’ devices and granting elevated access only to specific, approved actions when they’re needed. Users work with standard rights, and EPM elevates individual applications or tasks under policy. It’s the single most effective endpoint hardening control there is, because local admin rights are exactly what ransomware and credential theft depend on.
Most malware needs one thing to do real damage: local admin rights. With them, it can install persistence, disable your security tools, and dump credentials to move to the next machine. Take those rights away, and a lot of attacks simply stall on the first device.
That’s the idea behind EPM. It removes standing local admin rights from users, so everyone works as a standard user, and then elevates access surgically: this application, this task, this once, under policy. The user still gets their job done. The malware doesn’t get the keys.
The worry is always the same: won’t taking away admin rights break everything and flood the helpdesk? In practice, the application inventory that starts an EPM project usually finds that 85 to 90% of what users actually do runs fine under standard rights. Just-in-time elevation handles the rest, mostly without anyone calling IT.
- User endpoints & laptops
- Standing local admin rights
- Application execution
- Just-in-time elevation
- Windows, macOS & Linux
Local admin vs least privilege
Local admin for everyone vs least privilege with EPM
The default state in a lot of organisations is that ordinary users are local administrators on their own machines. It’s convenient, and it’s exactly what attackers count on. Removing permanent local admin closes the single most exploited privilege escalation path in ransomware.
| Local admin for everyone | Least privilege with EPM | |
|---|---|---|
| Who has admin rights | Standing, on every device | Nobody by default; elevated per task |
| If malware runs | Installs, persists, dumps credentials | Blocked from system-level actions |
| Lateral movement | One stolen credential spreads | Contained on the first device |
| Helpdesk load | Constant admin requests | Most elevation handled by policy |
| Cyber insurance | Increasingly hard to get | Meets a common requirement |
The platform
The six capabilities of Endpoint Privilege Management
Removing local admin rights
The foundation. Standing local admin is stripped from users, so nobody carries permanent administrative access on their device. This one change removes the privilege most malware needs to function.
Application control & allowlisting
Known, trusted applications run. Unknown or blocked ones don’t. Policy decides what’s allowed to execute, which stops a malicious download before it ever runs, rather than trying to catch it afterwards.
Just-in-time elevation
When a user genuinely needs to run something with elevated rights, EPM grants it for that specific action, under policy, and takes it away again. No standing admin account, no helpdesk ticket for routine cases.
Ransomware & lateral movement defence
By removing the admin rights malware relies on and controlling what can execute, EPM stops the most common path from one clicked link to a spreading ransomware incident. The infection stays contained on the first machine.
Policy-based control across platforms
One consistent set of policies across the operating systems your workforce actually uses, Windows, macOS and Linux, including hybrid and remote devices, rather than a different approach for each platform.
Audit & compliance
Every elevation and every blocked action is logged. When an auditor or a cyber insurer asks whether local admin has been removed and how elevation is controlled, the answer is a report, not a promise.
Why now
Why EPM matters now
Endpoint privilege used to be a nice-to-have. Three shifts moved it to the top of the list.
Ransomware runs on local admin. Most ransomware and credential-theft techniques depend on the elevated rights standard users shouldn’t have. Removing them is, control for control, the most impactful thing you can do to an endpoint. It’s also where much of the credential misuse behind most breaches in the Verizon DBIR begins.
Hybrid work widened the gap. Laptops leave the building, connect from home, and blur the line between corporate and personal use. A device with standing local admin, off the network, running unknown software, is exactly the exposure hybrid work created. EPM closes it wherever the device is.
Insurers and regulators expect it. Cyber insurance questionnaires now routinely ask whether local admin rights have been removed. NIS2, implemented in Norway as the Digitalsikkerhetsloven, expects least privilege as a baseline. EPM produces both the control and the evidence.
of what users do runs fine under standard rights, no admin needed
local admin is the top privilege-escalation path in ransomware
of breaches involve credential misuse (Verizon DBIR)
By sector
EPM by sector
The exposure is universal, but the stakes differ where endpoints touch the most sensitive systems.
Financial services
DORA, audit pressure and a low tolerance for endpoint compromise make removing local admin a priority, not a project for later.
Public sector
Large, mixed device estates and NIS2 obligations meet years of standing admin rights. EPM brings least privilege in without replacing every device.
Healthcare
Clinical and administrative devices touch patient data under GDPR, often shared and always sensitive. Controlling what runs on them, and who can elevate, is part of protecting the data.
Energy & utilities
Endpoints span corporate IT and operational environments, where a compromised device can reach far beyond a spreadsheet.
Our approach
How Kommando delivers EPM
Application inventory
We map what users actually run before removing anything, so elevation policies fit real work. This is the step that determines whether an EPM rollout is smooth or painful.
Policy design
Elevation rules, application control and the exceptions that keep specialist teams productive, designed around how your organisation works.
Rollout
Local admin removed and policies deployed in controlled waves, starting where risk is highest and disruption is lowest, so trust builds as you go.
Managed services
We tune policies, handle new applications and keep the estate at least privilege as it changes, rather than letting admin rights creep back in.
The tool isn't the hard part. Knowing what to elevate, and what to leave standard, is what makes removing local admin succeed instead of drowning in exceptions.
A note on what EPM doesn't fix
EPM secures the endpoint; it doesn't govern who should have access in the first place, and it won't succeed if the application inventory is skipped. The failures we're called in to rescue almost always removed admin rights before understanding what people actually run, and then drowned in exceptions. The tool isn't the hard part. Knowing what to elevate, and what to leave standard, is.
Frequently asked questions
Questions we actually get
What is Endpoint Privilege Management (EPM)?
EPM is the practice of removing permanent local admin rights from users’ devices and granting elevated access only to specific, approved applications or tasks when needed. Users work with standard rights, and EPM elevates individual actions under policy. It’s the single most effective endpoint hardening control, because local admin rights are what ransomware and credential theft depend on.
Why is endpoint privilege management important in a hybrid work environment?
In hybrid work, laptops leave the corporate network, connect from home, and run software IT doesn’t always see. A device with standing local admin rights, off the network, is a prime target for ransomware and credential theft. EPM removes those rights and controls what can run wherever the device is, so the endpoint stays protected outside the office as well as in it.
How does endpoint privilege management work?
EPM removes standing local admin rights so users run as standard users. When elevated access is genuinely needed, it’s granted just-in-time for a specific application or task under policy, then removed. Application control decides what’s allowed to execute, and every elevation and blocked action is logged for audit.
Does removing local admin rights break things or flood the helpdesk?
Usually far less than people fear. The application inventory that starts an EPM project typically finds that 85 to 90% of what users do runs fine under standard rights, and just-in-time elevation handles the rest without a helpdesk ticket in most cases. The key is mapping real usage before removing anything, which is why the inventory phase matters so much.
What is the difference between EPM and PAM?
Privileged Access Management (PAM) secures the powerful accounts administrators and services use, such as domain admins and vaulted credentials. EPM applies least privilege to ordinary users’ endpoints, removing standing local admin and controlling elevation. EPM is where PAM’s least-privilege principle reaches everyday devices. Most organisations need both.
Which EPM platform should we use?
The right platform depends on your environment, but CyberArk is the platform we most often implement for enterprise EPM in the Nordics, and it fits alongside the PAM most organisations already run. More important than the product is the application inventory and policy design behind it, which is what determines whether the rollout is smooth.
Do you offer endpoint privilege management in the Nordics?
Yes. Kommando delivers EPM across Norway, Sweden and Denmark, with certified consultants in Oslo, Gothenburg, Stockholm and Copenhagen. You get local delivery, in your language and time zone, from people who have removed local admin at scale in regulated Nordic organisations.
Do you offer managed services for EPM?
Yes. Endpoints and applications change constantly, and policies drift if nobody maintains them. We run and extend the platform after rollout, handling new applications and keeping the estate at least privilege, which is often more realistic than staffing it in-house.
Next step
Find out how much local admin you're actually running
An application inventory shows what your users genuinely need elevated rights for, usually far less than they hold today, and where removing local admin will cut the most risk. If you want to talk through where you’re at, we’re happy to help.
- Inventory of what your users actually run
- A rollout plan that won’t flood the helpdesk
- Delivered locally in Norway, Sweden and Denmark
Oslo · Gothenburg · Stockholm · Copenhagen