Skip to main content
BeyondTrust Endpoint Privilege Management for Windows and Mac (EPM-WM) controls which applications your end users may run with admin rights. Connect your EPM API account to Neo once, at the MSP level.

What Neo can do with BeyondTrust EPM

Elevation requests

Find the JIT request behind a BeyondTrust elevation email from its ticket number, with the user, computer, application, publisher and reason.

Computers and groups

Read the computer behind a request, its group, domain and policy, and move the ticket to the client the computer belongs to.

Policies and console users

Read policies, application groups, console users and roles. Manage computers, groups and policies when you allow it.

Activity and events

See who changed what in the console, and search a computer’s or user’s endpoint events.
Approving or denying a request, removing a computer, and clearing or deleting a policy always ask a technician first.

Your groups are mapped to clients

Neo matches your BeyondTrust EPM computer groups to the companies in your PSA and keeps the mapping on the BeyondTrust EPM card’s Organization Mapping tab, refreshed on each PSA metadata sync. Matching uses the group name: exact, then after stripping a legal-form suffix (Ltd, Inc, LLC). Last comes an AI match for the long tail. A name match, or one you confirm, is handed straight to your agents, so they find the computers of the ticket’s client. An AI match is not handed to your agents automatically. It shows on the Organization Mapping tab, where you can confirm or correct it. A group Neo could not match stays unmapped and visible on the same tab, where you can set the right company by hand. A mapping you set by hand survives every later sync. A group that is not a client, such as a policy tier like “Mac Workstations”, stays unmapped; you can ignore it.

Next steps

Connect BeyondTrust EPM

Create an API account in BeyondTrust EPM and save it in Neo.