Admin by Request Inspector Summary

Summary
| Property | Value |
|---|---|
| Production Status | Preview |
| Category | Endpoint |
| Discovers | One child launchpoint (Liongard Environment) per managed computer in the tenant |
Description
Monitors Admin by Request endpoint privilege management (PEDM). The parent enumerates managed computers in an Admin by Request tenant; each child reports that endpoint's posture (OS, hardware, network, installed software, local administrators, BitLocker/TPM/compliance) plus its elevation audit log and security events. The parent also collects tenant-wide elevation requests, audit-log elevations with malware/VirusTotal scan results, and security events for privilege-creep and configuration-drift detection.
Data View Information
Parent Overview Table
- Tenant Overview
- Tenant
- Workstation Seats
- Workstation Seats in Use
- Server Seats
- Managed Computers
- Computers with local admins
- Users with Local Admin
- Pending Elevation Requests
- Elevations (30d)
- Malicious Elevations (30d)
- Blocked Executions (30d)
- Computers Without BitLocker
- Non-Compliant Computers
Parent Data Tab Headers
- Managed Computers — 10 columns: name, platform, OS, logged-in user, is-admin, local-admin count, BitLocker, TPM, compliant, last inventory
- Recent Elevations — 9 columns, covering application name, vendor, version, SHA-256, VirusTotal scan result and threat name, approver, and timing
- Pending Requests — 5 columns, covering request status, requesting user, target computer, application, and reason
- Security Events — 5 columns, covering event text and severity level, describing local-admin group changes, blocked executions, local-account creation, and other administrative events
Child Overview Table
- Computer Detail
- Name
- Platform
- Operating System
- OS Version
- Make
- Model
- Serial Number
- CPU
- Memory (GB)
- BitLocker Enabled
- TPM Enabled
- Compliant
- Domain Joined
- Azure Joined
- Public IP
- Logged-in User
- User Is Admin
- Local Admin Count
- ABR Client Version
Child Data Tab Headers
- Local Administrators (1 column) — local administrator account name.
- Installed Software (4 columns) — not broken out further in the brief beyond the software inventory itself.
- Computer Activity (6 columns) — this computer's elevation audit history; specific column names aren't broken out in the brief.
Metrics
| Metric | Description |
|---|---|
| Admin by Request: Managed Computers | Total managed computers in the tenant. |
| Admin by Request: Computers With Local Admins | Computers with one or more local administrators. |
| Admin by Request: Users With Admin | Computers whose logged-in user is a local administrator. |
| Admin by Request: Pending Elevation Requests | Elevation requests awaiting approval. |
| Admin by Request: Elevations (30d) | Completed elevations in the last 30 days. |
| Admin by Request: Malicious Elevations (30d) | Elevations whose application scanned as Malicious (30d). |
| Admin by Request: Blocked Executions (30d) | Executions blocked by policy in the last 30 days. |
| Admin by Request: Local Users Created (30d) | Local user accounts created in the last 30 days. |
| Admin by Request: Computers Without BitLocker | Computers reporting BitLocker disabled. |
| Admin by Request: Non-Compliant Computers | Computers reporting non-compliant. |
| Admin by Request: Workstation Seats In Use | Workstation seats consumed in the tenant. |
| Admin by Request: Computer Local Admin Count | Local administrators on this computer (child). |
| Admin by Request: Local Administrator Accounts | Distinct local administrator accounts across all managed computers. |
| Admin by Request: Malicious Elevation Applications | Names of applications that scanned Malicious in completed elevations (30d). |
Actionable Alerts
Admin by Request ships 12 change-detection rules, all disabled by default — Partners enable the ones relevant to them. Two closely related rules (More Computers Have Local Admins / More Logged-in Users Are Admins) are combined into a single row below, matching the brief's own Suggested Rules table.
| Rule | Trigger | Severity |
|---|---|---|
| New Local Administrator | The local administrator account set changes | High |
| User Granted Admin / More Logged-in Users Are Admins | The count of computers whose logged-in user is a local admin increases | High |
| Malicious Elevation Detected | Malicious elevations in the last 30 days increase | High |
| Malicious Application Set Changed | The set of applications flagged Malicious in completed elevations changes | High |
| BitLocker Coverage Dropped | The count of computers without BitLocker increases | High |
| Computer Local Admin Count Changed | A computer's local-admin count changes | High |
| Blocked Executions Increased | Blocked executions in the last 30 days increase | Medium |
| Local User Created | Local user accounts created in the last 30 days increase | Medium |
| More Computers Non-Compliant | The count of non-compliant computers increases | Medium |
| Pending Request Backlog Grew | Pending elevation requests increase | Low |
| Managed Computer Count Changed | The managed computer count changes | Low |
Updated about 7 hours ago

