Skip to main content
The BeyondTrust EPM API tool gives Neo agents access to the BeyondTrust Endpoint Privilege Management for Windows and Mac (EPM-WM) Management API. The common use is the elevation email: BeyondTrust emails your PSA when a user asks to run an application with admin rights, and the ticket lands on the wrong client. The agent finds the request, its computer and the computer’s group, and moves the ticket to the client the computer belongs to.
Automatically enabled when you configure BeyondTrust EPM permissions in your agent workflow.

What It Does

  • Find the JIT application access request from the ticket number in the email title (EPM000123)
  • Read the request’s user, computer, application, publisher, reason and decision
  • Read the computer’s group, domain, policy and last connection
  • Find the client: from the group’s company mapping, from the RMM device with the same name, or from the computer’s domain
  • Read JIT admin access requests, policies and their application groups, console users and roles, activity audits and endpoint events
  • Authorise, reject, archive and move computers, request their logs, and manage groups and policies

How the agent handles an elevation email

The email names the user and the application, but not the computer or the group. The agent reads the request by its ticket number, then the computer named on the request, then the computer’s group. It moves the ticket to the client that group or computer maps to, and adds an internal note with the computer, the group, the user, the product, the publisher and the reason. It never picks a client from the user name alone. If it cannot find exactly one client, it leaves the ticket where it is and writes what it found in an internal note.

Permission Groups

Access Profiles

Safety Controls

How to Configure

1

Connect BeyondTrust EPM

Save your EPM API account in the Neo Dashboard under the Security integrations category. See Connecting BeyondTrust EPM to Neo.
2

Configure permissions

In your agent workflow’s Integrations tab, choose an access profile or set each permission group by hand.
Start with Read Only. Moving an elevation ticket to the right client needs only reads in BeyondTrust; the ticket change is made with the PSA tools.