> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/keeperpam/endpoint-privilege-manager/getting-started.md).

# Getting Started

<figure><img src="/files/GXfQe38VD6SYqqzC4Zgq" alt=""><figcaption></figcaption></figure>

Keeper Endpoint Privilege Manager (EPM) gives you **control without friction**: secure privilege elevation, file access, and application control on every endpoint, with a focus on letting users do their jobs while you enforce policy.

This guide walks you through everything you need to stand up Keeper EPM in your organization — from activating your license to deploying agents, building your first policies, and operating the system at scale. Each page in the Getting Started section is written so you can read it on its own or follow it in order.

***

#### What Keeper EPM Does

Keeper EPM is Keeper Security's Privilege Elevation and Delegation Management solution that lets you:

* **Control When and How** users run as administrator or access sensitive files and commands.
* **Require MFA, Approval, or Justification** before sensitive actions complete — so security and compliance stay in your hands.
* **Reduce Standing Privilege** so users don't need local administrator rights by default.
* **Redirect** R**isky Actions** (like opening network settings) to a controlled substitute experience — so you say "yes" in a secure way instead of "no."

Keeper EPM uses **policies** to govern endpoint activity — File Access, Privilege Elevation, Command Line execution, Least Privilege enforcement, and Agentic AI governance (including Agentic Access and Agentic Privilege Elevation). Each policy type targets a specific class of action and can require MFA, justification, or approval before it completes.

Policies are defined in the Keeper Admin Console and enforced by an agent on each endpoint. The goal is to enable the right actions in a secure, auditable way — not to block productivity.

#### A User-First Approach

Keeper EPM is designed so users don't have to be security experts:

* **User-First:** Users get their work done without needing to understand privilege or policy.
* **Enable, then Secure:** The product prefers approved, controlled flows over blanket denials. When policy allows an action, the user gets a clear path to complete it.
* **Policy-Controlled:** You define what's allowed and how. Users see a consistent experience; you keep control.

Features like [**redirects**](/keeperpam/endpoint-privilege-manager/policies/policy-types/advanced-policy-types/file-access-redirect.md) (substitute applications for sensitive actions), [**approval workflows**](/keeperpam/endpoint-privilege-manager/managing-requests.md), [**justification prompts**](/keeperpam/endpoint-privilege-manager/policies/policy-controls.md), and [**ephemeral elevation**](/keeperpam/endpoint-privilege-manager/policies/policy-types/privilege-elevation-policy-type.md) support a "yes, you can" approach wherever your policy permits.

#### Zero-Standing Privilege

With Keeper EPM, you can move toward zero-standing privilege: users are not local administrators by default. When they need elevation, they request it; your policies decide whether to allow it, require MFA, require approval, or deny it. Elevation can be time-limited and fully audited. The result is stronger security and a smaller attack surface — without sacrificing the ability to get work done.

#### Granular, Application-Aware Enforcement

Enforcement is granular and application-aware. Keeper EPM supports several policy types that you can combine:

* [**Privilege Elevation**](/keeperpam/endpoint-privilege-manager/policies/policy-types/privilege-elevation-policy-type.md) — Target specific applications, command lines, users, and machines. Choose Allow, Deny, MFA, Justification, or Approval per policy.
* [**File Access**](/keeperpam/endpoint-privilege-manager/policies/policy-types/file-access-policy-type.md) — Allow, deny, or gate access to specific files or folders with justification or approval.
* [**Command Line**](/keeperpam/endpoint-privilege-manager/policies/policy-types/command-line-policy-type.md) — Control which commands or patterns can run.
* [**Least Privilege**](/keeperpam/endpoint-privilege-manager/policies/policy-types/least-privilege-policy-type.md) — Remove standing administrator rights where appropriate while keeping exceptions where you need them.
* [**Agentic AI**](/keeperpam/endpoint-privilege-manager/policies/policy-types/agentic-ai-policy.md)**,** [**Agentic Access**](/keeperpam/endpoint-privilege-manager/policies/policy-types/agentic-ai-policy.md)**, and** [**Agentic Privilege Elevation**](/keeperpam/endpoint-privilege-manager/policies/policy-types/agentic-privilege-elevation-policy.md) — Govern Agentic AI and the actions they take on the endpoint.

<figure><img src="/files/RmQIiB6MFw7u8QzZhiji" alt="" width="375"><figcaption></figcaption></figure>

[**Variables**](/keeperpam/endpoint-privilege-manager/policies/policy-reference/path-variables.md) **and** [**Wildcards**](/keeperpam/endpoint-privilege-manager/policies/policy-reference/wildcards.md) let one policy apply across many paths, users, or machines without maintaining long lists.

#### An Event-Driven, Extensible System

Keeper EPM is built to be powerful as well as secure. The system is event-driven: actions — a user requesting elevation, a policy returning *pending*, an approval granted — trigger workflows and jobs automatically. You can orchestrate MFA, approval, justification, launch, and custom logic without manual steps.

The system is also extensible. You can add [custom jobs](/keeperpam/endpoint-privilege-manager/custom-tooling/jobs-and-plugins/custom-job-guide.md) that run scripts or call APIs, configuration policies that push settings to endpoints, and redirects to substitute applications — all under the same policy and audit model. This power is designed without compromising security: the agent's control plane stays local, only trusted components can drive it, and every sensitive action remains policy-gated and auditable.

#### Audit & Visibility

You get full visibility into what's happening on your endpoints:

* **Audit Events** for privilege elevation, file access, policy evaluations, and related actions.
* **Logging** you can tune for troubleshooting or compliance.
* **Clear View** of which policies matched, what was allowed or denied, and how approvers and users interacted.

Events are sent to the Keeper backend and can be used for reporting and integration with your existing security and audit tools.

<figure><img src="/files/K4SnzO5SlksS9IwAAR4h" alt="" width="563"><figcaption></figcaption></figure>

#### Platform Resilience & Reliability

Keeper EPM is built to be reliable across your environment:

* [**Multi-Platform**](/keeperpam/endpoint-privilege-manager/deployment.md)**:** Windows, Linux, and macOS with consistent concepts and configuration.
* [**Service-Based**](/keeperpam/endpoint-privilege-manager/architecture/technical-architecture.md)**:** A local service and plugins handle policy evaluation, backend sync, and logging.
* [**Health Checks**](/keeperpam/endpoint-privilege-manager/custom-tooling/http-reference-guide/health-and-status-endpoints.md)**:** Built-in health and status endpoints so you can monitor and automate.
* [**Operational Control**](/keeperpam/endpoint-privilege-manager/policies/policy-types/advanced-policy-types/keeper-updates.md)**:** Plugins and configuration can be updated and tuned so you can adapt without reinstalling.

#### Operational Flexibility

You have room to roll out and tune Keeper EPM without risk:

* [**Policy Status**](/keeperpam/endpoint-privilege-manager/policies/policy-status.md) — Use Off, Enforce, Monitor, or Monitor & Notify so you can test policies without blocking users. See *Phased Policy Rollout Planning* for the recommended progression.

<figure><img src="/files/2Hm9q19Tp1FAgt05waMW" alt="" width="337"><figcaption></figcaption></figure>

* **Configuration Policies** — Push [plugin](/keeperpam/endpoint-privilege-manager/policies/policy-types/advanced-policy-types/update-settings-policy-type.md) and [job](/keeperpam/endpoint-privilege-manager/policies/policy-types/advanced-policy-types/update-jobs-policy-type.md) settings from the dashboard so configuration stays consistent.
* [**Variables**](/keeperpam/endpoint-privilege-manager/policies/policy-reference/path-variables.md) **and** [**Wildcards**](/keeperpam/endpoint-privilege-manager/policies/policy-reference/wildcards.md) — Scale policies across many machines and users without duplicate rules.
* [**Airgapped options**](/keeperpam/endpoint-privilege-manager/deployment/deployment-reference/airgapped-support.md) — Offline registration and deployment are supported for locked-down environments.

#### The Keeper Admin Console

Your Keeper Admin Console is the control center for Keeper EPM. From there you:

* Activate EPM and manage licensing.

<figure><img src="/files/WeLaFwVrRCUZIO1ncinh" alt="" width="563"><figcaption></figcaption></figure>

* Create and assign approvers, collections, policies, and deployment groups.
* Build deployment packages and monitor agents.

<figure><img src="/files/KQ8gFRo4kGZOQgiRKC6Q" alt="" width="563"><figcaption></figcaption></figure>

* View requests, approvals, and audit data.

<figure><img src="/files/4HV4q8VcaDmCFCo48dtn" alt="" width="563"><figcaption></figcaption></figure>

The agent on each endpoint enforces what you configure in the console — so you manage once and enforce everywhere.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/keeperpam/endpoint-privilege-manager/getting-started.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
