Admin On-Demand

Overview


Admin On-Demand provides a quick, easy way for Mosyle Administrators to convert Admin user accounts on the Mac to Standard users, while also allowing user accounts on the Mac to request temporary user account escalation to complete any tasks that require Admin access.

Admin On-Demand is organized into four menu items: Overview, Devices, Settings, and Logs.

Overview

The Overview pane provides a quick summarized view of your user account status on devices. You can view the following in this area:

overview.png

Devices

The Devices tab will show all devices assigned to the Admin On-Demand configuration and the current user type logged in on the device - either Admin or Standard.

Use Filters available to filter and sort devices to show only those of interest. If needed, the data can be exported at any time using the button in the upper right “X devices match filters”.

Click a device tile to bring up additional details about the device and user. See any logs or actions taken on the device, export the data, or convert the user to Admin or Standard user.

devices.png

Settings

Configure the Admin On-Demand settings, including the conversion behavior, request settings, and/or customize the notification text for end users.

settings.png

Logs

View logs to see detailed info for when a user requested Admin access, when it was granted and removed, the justification for the access, and any corresponding logs. The date & time stamp, device name and serial number are also listed. To export the logs, click “Export” in the upper right corner. To export individual device action logs, click “View” under the Active Log column and click “Export”.

logs.png

 

 

Configuring Admin On-Demand


To configure Admin On-Demand

  1. Go to Security
  2. Admin On-Demand
  3. Click Settings > Add new profile
  4. Configure the settings in the three available tabs: Convert Current Admin, Request Settings, and Notification Pop-Up

Convert Current Admin

The Convert Current Admin settings will convert the current logged in Admin user to a Standard user. This option will not convert the additional Admin account created during Automated Device Enrollment (DEP Admin), however it will convert any other logged in Admin users if enrolled manually.

Using the dropdown menu, choose from the following:

Request Settings

The Request Settings tab allows configuration of whether or not users will have access to Admin On-Demand in the Manager application to request temporary Admin access. There are two options available:

When users have the option to temporarily escalate their privileges to Admin, they can request the escalation in the Manager application and because they have access to perform such escalation, it will be granted automatically to the end user. The following options are available to configure for this escalation period:

Notification Pop-Up

Customize the pop-up message users will see before their user account is escalated to have Admin privileges.

 

 

 

What to Expect


When users have access to Admin On-Demand, they can request the user privilege escalation from the Manager application.

request.png

After requesting Admin access, users will receive a notification indicating the account has been converted.

account-converted.png

At the end of the approved time period, the end user will receive a notification that their account has been converted back to Standard user access.

account-converted-back.png

Actions taken during the user privilege escalation can be viewed in the Admin On-Demand Logs.


Revision #1
Created 2025-10-08 00:47:07 UTC by joliveira
Updated 2025-10-08 00:47:58 UTC by joliveira