PayloadKit

Elevate24

com.jigsaw24.Elevate24

macOS privilege access management tool from Jigsaw24

macOS

Configuration Keys (47)

KeyTypeTitle
PFC_SegmentedControl_0required
string
LicenseKey

Enter your Elevate24 license key. Mandatory key for Premium customers only.

stringLicense Key (Premium)
LicenseAPIKey

Enter your Elevate24 license api key. Mandatory key for Premium customers only.

stringLicense API Key (Premium)
newUI

Change Elevate24 to show to the new UI. Not required for Elevate24 2.3+ as this is now default.

Default: false

booleanNew UI
message

Change the standard application message in the application.

Default: "Use of admin accounts is recorded for security compliance. Select why you require admin privileges and select how long for."

stringMessage
iconPath

Prodvide the file path to a JPEG or PNG to use as the icon in the Elevate24 application.

Default: "Main Jigsaw24 Logo"

stringIcon (Premium)
heading

Change the standard header from Elevate24 in the application. Always displays in bold.

Default: "Elevate24"

stringHeading (Premium)
subheading

Change the standard text "Privilege Access Management" under the Elevate24 header. New UI V2.2.0+ Only.

Default: "Privilege Access Management"

stringSub Header (Premium)
mainbutton

Change the standard button text from Elevate in the application.

Default: "Elevate24"

stringMain Button Text (Premium)
HideLogo

Hide the “Powered by Jigsaw24” logo in the application.

Default: false

booleanHide Powered By Jigsaw24 Logo (Premium)
DisableUserElevation

Elevate24 2.5+ Only. When enabled, the Elevate24 menubar UI is hidden and cannot be launched manually from /Applications. End users will have no visible way to request elevation, view their session status, or interact with Elevate24 directly. The underlying agent continues to run in the background, enforcing session policies and authorisation rules as normal.

Default: false

booleanDisable User Elevation
AllowCliElevation

Elevate24 2.5+ Only. When enabled, allows user to elevate from the command-line.

Default: false

booleanAllow CLI Elevation
Enabletimelist

Enables the option for the application to display a choice of times. To be used in conjuction with Session Times list.

Default: false

booleanEnable Choice of Session Times
enableReason

Will replace reasons drop down list with a free text entry box.

Default: false

booleanEnable free text reason
blockExtend

Will disable the ability to extend the time of an active Elevate24 session.

Default: false

booleanBlock extending session
Sessiontime

Change the length of time (in seconds) the user will be elevated for. Do not use this key if you want to present a list of times to choose from.

Default: "3600"

stringSession Time
times

List of available times to chose from in the Application. Enter time below in seconds.

Default: ["1800","3600","7200"]

arraySession Times
reasons

The reasons to choose for needing elevated rights in dropbox within the application.

arrayReasons
sessionExpiryReminder

Set the number of minutes before the application notifies the user that the session is expiring

Default: 0

integerSet Session Expiry Notification (Premium)
AllowUserDefinedScripts

Elevate24 2.4+ Only. When enabled, allows users to specify their own elevation and demotion script paths in addition to any admin-defined scripts. If scripts are configured at both the admin and user level, all scripts will execute. When disabled, only admin-defined scripts (ElevateScriptPath and DemoteScriptPath) will be used.

Default: false

booleanAllow User Defined Scripts
ElevateScriptPath

Elevate24 2.4+ Only. Specify the full file path to a script that will be executed automatically when a user's session is elevated to admin. This can be used to perform actions such as logging, launching tools, or configuring the environment at the point of elevation.

stringElevate Script Path
ElevateScriptHash

Elevate24 2.4+ Only. Optionally provide the SHA256 hash of the elevation script specified in ElevateScriptPath. When configured, Elevate24 will verify the script's integrity before execution and refuse to run it if the hash does not match, protecting against unauthorised modification of the script.

stringElevate Script Hash
DemoteScriptPath

Elevate24 2.4+ Only. Specify the full file path to a script that will be executed automatically when a user's elevated session ends and they are demoted back to a standard user. This can be used to perform clean-up tasks, revoke temporary access, or audit the end of an elevated session.

stringDemote Script Path
DemoteScriptHash

Elevate24 2.4+ Only. Optionally provide the SHA256 hash of the demotion script specified in DemoteScriptPath. When configured, Elevate24 will verify the script's integrity before execution and refuse to run it if the hash does not match, protecting against unauthorised modification of the script.

stringDemote Script Hash
DisableDefaultLog

To disable sending of premium reporting data to Jigsaw24. If you are a basic customer, no data is sent from the device, it is all stored locally.

Default: false

booleanDisable Default Log (Premium)
siemURL
stringSIEM URL (Premium)
siemAuthHeader
stringSIEM Auth Header (Premium)
siemAuthToken
stringSIEM Auth Token (Premium)
microsoftsentinel
arrayMicrosoft Sentinel
EnableSessionMonitoring

To enable monitoring of administrator activities whilst in an elevated state.

Default: false

booleanEnable Session Monitoring (Premium)
enableAppleAuth

Prompts the user for their local Apple credentials or TouchID (if enabled on device) before allowing elevation.

Default: false

booleanApple Auth
GoogleAuth

Enables the use of authenticator applications such as Google Auth or Microsoft Auth, prompting for a valid session token before Elevating to admin.

Default: false

booleanOTP Auth (Premium)
standardAtLoad

Will remove admin rights when the application first launches.

Default: false

booleanStandard At Load
demoteAllAdmin

Enables all admin users being demoted to standard users when the current elevation period ends. If you have any accounts on the device you'd like to remain admin please configure Demote Exclusions.

Default: false

booleanDemote All Admin
demoteAllAdminQuit

Will demote all admin accounts from admin when the application quits or the laptop is restarted.

Default: false

booleanDemote All Admin Quit
demoteExclusions

Will exclude accounts on device from being demoted.

arrayDemote Exclusions
killterminalsessions

Will demote the current terminal session from sudo session to standard.

Default: false

booleanKill Terminal Sessions
UseSystemExtension

Elevate24 v2.3+ Only. To ensure the Application is protected by the on-device system extension, to prevent misuse and tampering.

Default: false

booleanSystem Extension
userElevateAdmin

Will create a temporary secondary account instead of Elevating the primary account. A temporary password will also be supplied upon elevation.

Default: false

booleanUser Elevate Admin (Premium)
useCurrentUserAsAdmin

If User Elevate Admin Key is enabled and this key is also enabled, the temporary account will use the current logged in users username as part of the account naming. For example, Joe.Bloggs-adm

Default: false

booleanUse Current User As Admin (Premium)
adminUserName

If ‘Use Current User As Admin’ is not enabled, this key allows the ability to create a temporary admin account with a standard name. Such as "Temp Admin"

stringAdmin User Name (Premium)
ComplexPassword

Enables the use of a custom complex password when 'User Elevate Admin' is enabled.

Default: false

booleanComplex Password (Premium)
PasswordUppercase

Enter the amount of uppercase Letters required for the password.

stringPassword Uppercase (Premium)
PasswordLowercase

Enter the amount of lowercase Letters required for the password.

stringPassword Lowercase (Premium)
PasswordNumbers

Enter the amount of numbers required for the password.

stringPassword Numbers (Premium)
PasswordSymbols

Enter the amount of symbols required for the password.

stringPassword Symbols (Premium)
showAdminPasswordGrace

Set the number of seconds after elevation or last showing the password that the password will be shown (Max 45 seconds). This only works if 'User Elevate Admin' is enabled.

Default: 0

Range: — – 45

integerShow Admin Password Grace (Premium)
string
string
microsoftsentinelItem
dict
SentinelClientId
stringClient ID
SentinelTennantId
stringTennant ID
SentinelClientsecret
stringClient Secret
SentinelUploadURL
stringUpload URL
string