Skip to main content

BeyondTrust EPM: Flexibilities

  • September 16, 2024
  • 3 replies
  • 587 views

dan-snelson
Forum|alt.badge.img

Easily assign macOS computers to a BeyondTrust Endpoint Privilege Management High, Medium or Low Workstyle Flexibility via a Jamf Pro Script Parameter

Workstyle Filters

While BeyondTrust Endpoint Privilege Management for Windows policy Workstyles can be filtered based on Microsoft Entra ID groups — as of this writing — macOS policy Workstyles cannot.

For macOS, each users’ account must be added to an existing local group for every Mac in your fleet.

Continue reading …

3 replies

Forum|alt.badge.img
  • BeyondTrust Employee
  • September 18, 2024

I love your work, Dan. Pertinent and insightful information, as always.


  • BeyondTrust Employee
  • September 19, 2024

This was a great read as always Dan.


Forum|alt.badge.img+4
  • Veteran
  • September 23, 2024

Great work and article. I typically do not recommend managing Low Flex users as they are typically 90-95% of all users. leaving you just to manage the 5-10% of Medium and High Flex users, the rest default to Low flex as they are not a member of the Admin GroupID 80 or Builtin/Administrators. This ensure that if the client is install the least privileged policy will apply.