Whether you’re a one-person operation or a growing business with a full team, we’re here to help. Get in touch and let’s talk about what we can do for you.
Running as a local administrator is one of the biggest hidden security risks in any business. ThreatLocker Elevation solves this elegantly — staff can run approved applications that need elevated permissions, without ever being granted full admin rights on their device.
ThreatLocker Elevation is the component of the ThreatLocker suite that allows standard (non-admin) users to run specific approved applications with the elevated rights they need — without being granted full administrator access to their device.
If your staff currently log in as local administrators, or if certain line-of-business applications require admin rights to run. It's included in both Core and Complete Device Security Packs.
Approved application elevation policies, learning mode deployment, admin console management, and audit logging of all elevation events.
Removes the risk of staff running as local admins, reduces the blast radius of malware that relies on admin rights to execute, and keeps business applications working normally — without the security exposure.
Step 1
Step 2
Step 3
Step 4
Step 5
When a user is a local admin, any malware they accidentally run also inherits admin rights — giving it the ability to install software, change system settings, and spread across the network. Removing admin rights cuts this attack path dramatically.
No. ThreatLocker Elevation learns which applications need elevated rights and approves them specifically — those apps continue to work normally. Only unapproved software is blocked from elevating.
Before any restrictions go live, ThreatLocker runs in learning mode across your estate — observing what applications your team uses and building a picture of normal. This means the rollout doesn’t disrupt legitimate workflows.
They raise a request through the normal IT support process. We approve and add the application to the allowed list, then it’s available. It’s a small change in process for a significant security gain.
It’s one component. The Core Device Security Pack includes Elevation only. The Complete pack adds the full ThreatLocker suite — Allowlisting, Ringfencing, Storage Control, Network Control, and Endpoint Detect.
Yes. Every elevation event is logged, giving you a full audit trail of which applications ran with elevated rights and when.
Yes. ThreatLocker has a request workflow where a user can flag that an application needs elevated rights — we review it and approve or deny.
ThreatLocker’s primary focus is Windows environments. Speak to us about your specific estate if you have a significant number of Macs.
It’s blocked. The user sees a notification, and the event is logged. If it’s a legitimate business application, they can request it through IT support.
No. UAC is Microsoft’s basic prompt that asks if you want to allow changes — but it can be bypassed and doesn’t give you the audit trail or policy control that ThreatLocker Elevation provides.
There is nothing more annoying than an IT glitch that stops you working efficiently. However, knowing you have access to immediate attention to the glitch and a solution to it, is very reassuring and that is provided by We Do Your IT. We have so appreciated the availability and response given by the team at We Do Your IT, enabling us to remain a productive firm.
Richard Sharp – Sharp Family Law
This website uses cookies to improve your experience. Choose what you're happy with.
Required for the site to function and can't be switched off.
Help us improve the website. Turn on if you agree.
Used for ads and personalisation. Turn on if you agree.