> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# BeyondTrust EPM API

> Find the JIT request, computer and group behind a BeyondTrust EPM elevation email and move the ticket to the right client; read and manage computers, groups, policies and console users

The BeyondTrust EPM API tool gives Neo agents access to the BeyondTrust Endpoint Privilege Management for Windows and Mac (EPM-WM) Management API. The common use is the elevation email: BeyondTrust emails your PSA when a user asks to run an application with admin rights, and the ticket lands on the wrong client. The agent finds the request, its computer and the computer's group, and moves the ticket to the client the computer belongs to.

<Info>
  Automatically enabled when you configure BeyondTrust EPM permissions in your agent workflow.
</Info>

## What It Does

* Find the JIT application access request from the ticket number in the email title (`EPM000123`)
* Read the request's user, computer, application, publisher, reason and decision
* Read the computer's group, domain, policy and last connection
* Find the client: from the group's company mapping, from the RMM device with the same name, or from the computer's domain
* Read JIT admin access requests, policies and their application groups, console users and roles, activity audits and endpoint events
* Authorise, reject, archive and move computers, request their logs, and manage groups and policies

## How the agent handles an elevation email

The email names the user and the application, but not the computer or the group. The agent reads the request by its ticket number, then the computer named on the request, then the computer's group. It moves the ticket to the client that group or computer maps to, and adds an internal note with the computer, the group, the user, the product, the publisher and the reason. It never picks a client from the user name alone. If it cannot find exactly one client, it leaves the ticket where it is and writes what it found in an internal note.

## Permission Groups

| Group | Access levels | Covers |
| - | - | - |
| JIT Application Access | Disabled, Read Only, Read / Write | JIT application access requests and their audit trail; the write records an approve or deny decision |
| JIT Admin Access | Disabled, Read Only, Read / Write | JIT admin access requests; the writes create or decide one |
| Computers | Disabled, Read Only, Read / Write | Computers, their command log and logs; authorise, reject, archive, request logs or status, renew a certificate, deactivate or delete |
| Groups | Disabled, Read Only, Read / Write | Computer groups; create, change, move computers, assign or clear a policy, delete |
| Policies | Disabled, Read Only, Read / Write | Policies, revisions and Policy Editor application groups; change, discard a draft, add applications, delete |
| Console Users and Access | Disabled, Read Only, Read / Write | Console users, roles, accepted domains, the sign-in provider, API accounts and SCIM users |
| Activity and Events | Disabled, Read Only | Console activity audits, endpoint events and task status |

## Access Profiles

| Profile | What runs on its own | What asks a technician |
| - | - | - |
| **Read Only** | Every read | No write is allowed |
| **Helpdesk** | Every read | Every write |
| **IT Admin** | Computer and group changes | Policy and console-user changes |
| **Full Automation** | Every write below | Only the writes below |

## Safety Controls

| Control | Behavior |
| - | - |
| **JIT decisions** | Approving or denying a JIT application request, and creating or deciding an admin access request, always ask a technician. An approval runs the software with admin rights |
| **Computer removal** | Deleting or deactivating a computer always asks a technician, because the endpoint leaves protection |
| **Policy removal** | Clearing a group's policy, deleting a group and deleting a policy always ask a technician, because computers are left without a privilege policy |
| **Computers by id only** | A write that selects computers must name them by id. Neo does not send a selection of every computer (`allComputers`) |
| **Refused** | Neo does not download the binary agent-log archive, and does not call the console's internal product switcher |

## How to Configure

<Steps>
  <Step title="Connect BeyondTrust EPM">
    Save your EPM API account in the Neo Dashboard under the **Security** integrations category. See [Connecting BeyondTrust EPM to Neo](/integrations/beyondtrust-epm/connecting-to-neo).
  </Step>

  <Step title="Configure permissions">
    In your agent workflow's **Integrations** tab, choose an access profile or set each permission group by hand.
  </Step>
</Steps>

<Tip>
  Start with **Read Only**. Moving an elevation ticket to the right client needs only reads in BeyondTrust; the ticket change is made with the PSA tools.
</Tip>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.