Skip to main content

EPM Windows - Admin removal and reporting

  • July 17, 2026
  • 2 replies
  • 31 views

Forum|alt.badge.img+1

Hello! I see that EPM Windows does not have option to remove local admin users . There is an idea created 4 years ago. Also, available reporting is limited i.e. who has admin access - I believe this report is based on user login. We are working on removing admin rights from users who had exception requests and finding it difficult to provide reliable evidence which is easy to generate from within a console - currently relying on multiple tools such as scripts for VPN, internal network computers, SCCM and PRA for computers not currently connected to internal network etc. I see we can trigger powershell scripts using EPM  based on certain events e.g. Creating rule to launch the script when certain known application like MS edge update is run.
  Just want to check how others are handling such scenarios 

2 replies

  • BeyondTrust Employee
  • July 20, 2026

The local admin removal feature is on the road map (coming soon), some organization uses endpoint management tools to handle admin right removal such as 

  • Microsoft Intune (Account Protection / Local Users and Groups)
  • Group Policy Preferences (on-prem AD)
  • MECM / SCCM
  • Tanium
  • BigFix
  • Workspace ONE

 


Forum|alt.badge.img+4

@bt101  This is one function that I am usually torn on. It just a nice feature to have, but in some cases it’s just a conflict, I would still recommend using the MS Native tools to get people out of the admin group, reason being it just works!.