Admin by Request (Beta)
This document provides the steps required to configure the Admin by Request Inspector.
Quick DetailsRecommended Agent: On-Demand
Supported Agents: On-Demand or Self-Managed
Is Auto-Discovered By: N/A
Can Auto-Discover: Yes — one child launchpoint per managed computer in the tenant
Parent/Child Type Inspector: Yes
Inspected via: API
Default Frequency: Daily. (max every 8 hours)
Data Summary: Admin by Request Inspector Summary
Overview
The Admin by Request Inspector monitors a Customer's endpoint privilege management posture from the Admin by Request cloud. It inventories every managed computer, reports the local administrators on each, captures elevation requests and completed elevations (including the malware scan result of each elevated application), and records security events such as local-admin group changes and blocked executions. It runs daily by default and maps one Liongard Environment per managed computer.
Admin by Request is a privileged-access / endpoint privilege management (PEDM) product for Windows, macOS, and Linux. It removes day-to-day local-admin rights, lets users request just-in-time elevation with an approval workflow, scans every elevated application against VirusTotal, and maintains a per-device inventory of hardware, software, and security posture. It's sold per device and includes a read-only REST API on every plan, including the free plan.
Inspector Setup Preparation
Prerequisites: an Admin by Request tenant (any plan, including the free plan) and a portal login with access to Tenant Settings.
- Sign in to the Admin by Request portal.
- Go to Settings > Tenant Settings > Data > API KEYS.
- Click Add New. Leave the key type as General Purpose, save, then copy the generated API key.
- On the same page, note the API prefix shown under About API Keys — it identifies your data center (for example,
dc2api= US East). You'll select the matching region in Liongard.
Liongard Inspector Setup
Step 1: Parent Inspector Setup
Since Admin by Request isolates tenants completely, one Admin by Request Customer equals one tenant equals one Parent Inspector. You will set up a single "Parent" Inspector with that tenant's API key and region, which will then auto-discover a "Child" Inspector for each managed computer.
In Liongard, navigate to Admin > Inspectors > Inspector Types > Navigate to the Admin by Request Inspector > Select Add System.
Fill in the following information:
- Type of Inspector: Parent
- Environment: Select your MSP's Environment
- Friendly Name: Suggested Naming: Environment Name [Admin by Request] Parent
- Agent: Select an On-Demand or Self-Managed agent
- API Key: Paste the API key generated during Inspector Setup Preparation
- Data Center Region: Select the matching region (dc1–dc6) from the API prefix noted during setup preparation
- Inspector Version: Latest (Auto-Update)
- Scheduling: The Inspector will default to run once a day at the time the Inspector is set up. Here you can adjust the schedule.
Select Save. The Inspector will now be triggered to run within the minute.
Step 2: Child Inspector Setup
After the first run of the Parent Inspector, your tenant's managed computers will be Auto-Discovered and surfaced on the Discovered Systems page. Each maps one-to-one to a Liongard Environment.
Navigate to the Discovered Systems tab in your Inspectors > Admin by Request page.
- Activate your Discovered Systems by ensuring they're mapped to the correct Environment > Select the checkbox to the left of Inspector(s) > Select the Actions drop-down menu > Activate Launchpoints.
- Users may also Archive Discovered Systems by selecting the checkbox to the left of the Inspector(s) > Select the Actions drop-down menu > Archive Launchpoints.
Troubleshooting
- "Admin by Request rejected the API key" — verify the key (Settings > Tenant Settings > Data > API KEYS) and that the selected Region matches the tenant's data center; Admin by Request returns HTTP 500 (not 401) for a bad key.
- No child Environments — confirm the tenant has managed computers checking in (the inventory is populated) and that the parent run completed.
Updated about 7 hours ago

