Anshula Raina ← Back to Portfolio
Administrator Guide

Sentinel Privilege Manager

Administrator Guide for configuring users, endpoints, privilege policies, application elevation, monitoring, and reporting.

1. Introduction

Sentinel Privilege Manager (SPM) is a fictional Endpoint Privilege Management platform designed to help organizations control elevated privileges across managed endpoints.

SPM enables administrators to define privilege policies, manage users and endpoints, control application elevation, monitor security activity, and generate operational reports from a centralized administration console.

Purpose This guide explains how administrators can configure and manage Sentinel Privilege Manager.

1.1 Intended Audience

This guide is intended for:

  • System Administrators
  • Security Administrators
  • IT Operations Teams
  • Endpoint Management Teams

1.2 Key Capabilities

User Management

Create and manage administrative users and assign appropriate roles.

Endpoint Management

Monitor and manage endpoints registered with the platform.

Privilege Policies

Define rules controlling application and user privileges.

Application Elevation

Provide controlled elevated access to approved applications.

Monitoring

Monitor privilege-related events and administrative activity.

Reporting

Generate reports for operational and security analysis.

2. Getting Started

Administrators can access SPM through the web-based administration console.

2.1 Access the Administration Console

What Access the SPM administration console using an administrator account. Why The administration console provides centralized management of users, endpoints, policies, and security activity. How Follow the steps below to sign in.
Open a supported browser. Launch your preferred supported web browser.
Open the SPM console. Enter the URL provided by your organization.
Enter your credentials. Provide your administrator username and password.
Sign in. Click Sign In.
Note: Access to administrative features depends on the role assigned to your account.

3. Dashboard

The SPM Dashboard provides administrators with an overview of endpoint privilege activity and system status.

3.1 Dashboard Widgets

Widget Description
Managed Endpoints Displays the number of endpoints currently managed by SPM.
Active Users Displays users associated with managed endpoints.
Elevation Requests Displays privilege elevation requests generated by endpoints.
Blocked Applications Displays applications blocked by configured policies.
Policy Violations Displays events that violate configured policy conditions.
Recent Activity Displays recent privilege-related activity.

4. User Management

Administrators can create and manage users who require access to the SPM administration console.

4.1 Create a User

What Create an administrative user account. Why User accounts allow organizations to provide controlled access to administration functions. How Create the account from the Users page.
Open Users. Navigate to Administration → Users.
Start user creation. Click Create User.
Enter user information. Enter the required user details.
Assign a role. Select the appropriate administrative role.
Save the user. Click Save.

4.2 User Fields

Field Description
First Name User's first name.
Last Name User's last name.
Email User's business email address.
Username Unique identifier used to sign in.
Role Administrative role assigned to the user.
Status Specifies whether the account is Active or Inactive.

5. Role Management

SPM uses role-based access control to restrict administrative capabilities.

5.1 Available Roles

Role Description
Super Administrator Provides access to all administrative capabilities.
Security Administrator Provides access to security policies, privilege management, and reports.
Endpoint Administrator Provides access to endpoint management and endpoint configuration.
Auditor Provides read-only access to audit information and reports.
Security Recommendation: Assign administrators only the permissions required to perform their responsibilities.

6. Endpoint Management

The Endpoints page allows administrators to view and manage endpoints registered with SPM.

6.1 Endpoint Information

  • Endpoint name
  • Operating system
  • IP address
  • Agent version
  • Last check-in time
  • Assigned policy
  • Endpoint status

6.2 View Endpoint Details

Open Endpoints. Navigate to Endpoints.
Search for an endpoint. Enter the endpoint name or other supported search criteria.
Open endpoint details. Click the endpoint name.
Review endpoint information. Review configuration, policy assignment, and activity information.

7. Groups

Groups allow administrators to organize users and endpoints based on business or operational requirements.

7.1 User Groups

User groups can be used to apply common policies to multiple users.

Example groups include:

  • Finance
  • Human Resources
  • Developers
  • IT Support
  • Contractors

7.2 Create a User Group

Navigate to Groups → User Groups.
Click Create Group.
Enter the group name and description.
Select the users to add to the group.
Click Save.

7.3 Endpoint Groups

Endpoint groups organize managed devices according to business units, environments, operating systems, or other organizational requirements.

8. Privilege Policies

Privilege policies determine which applications and actions require elevated permissions.

Why use privilege policies? Policies allow organizations to control administrative privileges without providing users with permanent local administrator rights.

8.1 Create a Privilege Policy

Navigate to Policies → Privilege Policies.
Click Create Policy.
Enter a unique policy name.
Select the target users or endpoint groups.
Define the application conditions.
Select the required privilege action.
Configure the policy schedule, if required.
Click Save.

9. Application Elevation

Application Elevation allows administrators to grant elevated privileges to approved applications without providing users with permanent administrator privileges.

9.1 Example Workflow

User launches approved application
            ↓
SPM identifies the application
            ↓
SPM evaluates the applicable policy
            ↓
Policy conditions are validated
            ↓
Application receives controlled elevation
            ↓
Activity is recorded for auditing
            
Example: A developer needs elevated privileges to install an approved development tool. Instead of assigning the developer permanent administrator rights, an elevation policy can provide controlled access to the approved application.

10. Policy Assignment

Policies can be assigned to individual users, user groups, endpoints, or endpoint groups.

10.1 Assign a Policy

Navigate to Policies.
Select the required policy.
Click Assign.
Select the required target.
Click Apply.

11. Audit & Activity

SPM records privilege-related activity to support monitoring, investigation, and auditing.

11.1 Recorded Activities

  • Application execution
  • Elevation requests
  • Policy violations
  • Blocked applications
  • Administrative actions
  • Endpoint events
What administrators can do Administrators can filter activity records and review events to understand privilege-related activity across managed endpoints.

12. Reports

The Reports section provides administrators with reporting capabilities for security and operational analysis.

12.1 Available Reports

Report Purpose
Privilege Activity Report Provides an overview of privilege-related endpoint activity.
Application Elevation Report Provides information about application elevation events.
Policy Violation Report Provides information about policy violations.
Endpoint Activity Report Provides activity information for managed endpoints.
Administrative Audit Report Provides a record of administrative actions.

13. Troubleshooting

Use the following troubleshooting information to identify and resolve common administration issues.

Issue Possible Cause Resolution
Endpoint is not visible Agent has not checked in with the management service. Verify endpoint connectivity and agent status.
Policy is not applied Incorrect policy assignment. Verify the policy target and assignment.
Application still requests administrator credentials Application is not included in the elevation policy. Add the application to the appropriate elevation policy.
User cannot access console Account may be inactive or assigned an incorrect role. Verify the user's status and role.
Dashboard data is outdated Endpoint has not communicated with the management service. Check endpoint connectivity and last check-in time.

14. Best Practices

Follow these practices when administering Sentinel Privilege Manager:

  1. Apply the principle of least privilege.
  2. Avoid assigning permanent administrator access unless required.
  3. Use groups for large-scale policy management.
  4. Review privilege activity regularly.
  5. Test policies before applying them to production environments.
  6. Maintain separate administrative accounts.
  7. Review inactive users periodically.
  8. Monitor policy violations.

15. Glossary

Term Definition
Endpoint A device managed by Sentinel Privilege Manager.
Privilege Permission required to perform a restricted operation.
Elevation Granting additional privileges to an application or process.
Policy A set of rules defining privilege behavior.
User Group A collection of users managed together.
Endpoint Group A collection of endpoints managed together.
Agent Software installed on an endpoint to communicate with SPM.
Audit Event A recorded activity generated by users, applications, or endpoints.

Document Information

Document Type Administrator Guide
Product Sentinel Privilege Manager
Version 3.2
Audience System and Security Administrators
Status Portfolio Sample
Author Anshula Raina
Portfolio Disclaimer: Sentinel Privilege Manager is a fictional product created for demonstration purposes. This document does not contain confidential or proprietary information from any organization.