Skip to content

Keeper Endpoint Privilege Manager

Keeper Endpoint Privilege Manager is a privilege elevation and delegation management (PEDM) solution for Windows, macOS and Linux workstations and servers, developed by Keeper Security, that removes standing local administrator rights and grants just-in-time elevation per application, with optional approval and MFA. It also governs AI agents on endpoints and is licensed per endpoint on an annual subscription, as an add-on to Keeper Business or Enterprise.

Learn more about Keeper Endpoint Privilege Manager

Request a Quote

What is Keeper Endpoint Privilege Manager?

Keeper Endpoint Privilege Manager is a privilege elevation and delegation management (PEDM) solution for Windows, macOS and Linux workstations and servers, developed by Keeper Security, that removes standing local administrator rights and grants just-in-time elevation only for the approved application, command or task. It controls privilege elevation, file access, application execution, command-line activity, AI agent activity and outbound DNS access, always through policies defined in the Keeper Admin Console.

Keeper Endpoint Privilege Manager works with a lightweight agent installed on each managed endpoint, which intercepts elevation requests and evaluates them against company policies. On Windows, users are removed the local Administrators group; on macOS, elevation goes through a system extension; on Linux and macOS, sudo usage is governed by keepersudo. The product replaces the practice of making every user an administrator of their own machine and solves the problem of malware, ransomware and unauthorized installs that exploit that standing privilege.

Key features of Keeper Endpoint Privilege Manager

Keeper Endpoint Privilege Manager combines central policy, temporary elevation and real-time visibility:

  • Just-in-time elevation: grants privilege at the process or machine level only for the approved task, through ephemeral accounts created and removed by Keeper.
  • Approval workflow with MFA: requests go to an administrator in the Admin Console, Keeper Commander or ServiceNow, Jira, Slack and Microsoft Teams, with optional MFA and justification.
  • File and command policies: restrict access to sensitive files, application execution and command-line arguments, including sudo on macOS and Linux.
  • AI agent governance: detects known agents such as GitHub Copilot, Cursor and Claude Code, flags unknown processes that behave like agents and keeps an agentic AI inventory.
  • DNS control: limits outbound name resolution per endpoint, reducing communication with unauthorized domains.
  • Collections: group applications, machines, users, DNS names, command arguments and AI agents to apply policies at scale.

Benefits of Keeper Endpoint Privilege Manager

Keeper Endpoint Privilege Manager reduces the attack surface because no user keeps standing administrator rights: malware running in the user's session does not inherit the privilege to install drivers, disable antivirus or spread across the network.

The help desk gets fewer tickets because routine elevations for approved applications, such as an approved installer or an engineering tool, are released automatically by policy, without a technician having to access the machine.

Compliance is documented because every elevation, approval and denial is logged in the Admin Console and can flow to SIEM tools, building the audit trail required by privileged access controls.

Who Keeper Endpoint Privilege Manager is for

Keeper Endpoint Privilege Manager serves IT managers, endpoint security teams and desktop administrators who need to apply least privilege without blocking users' work. Typical scenarios: a company where every employee is a local administrator and that must remove that right for an audit; an engineering team that installs tools often and needs approved elevation per application; and a development team that adopted AI agents in the editor and wants to control what they execute on the machine.

What sets Keeper Endpoint Privilege Manager apart

Keeper Endpoint Privilege Manager is administered in the same Admin Console as the password vault and KeeperPAM: while KeeperPAM controls how an administrator reaches a server, EPM controls which rights they exercise once connected. Data about devices, applications and access requests is encrypted on the endpoint itself and decrypted only by authorized administrators, following Keeper's zero-knowledge architecture. The platform uses open standards such as SPIFFE and MQTT, and according to Keeper, EPM works alongside Microsoft Windows LAPS: LAPS rotates the local administrator password, and EPM reduces the need to use that account.

System requirements

Keeper Endpoint Privilege Manager requires the Keeper agent on each Windows, macOS or Linux endpoint, a Keeper license with enough endpoint seats for the agents to be installed, and EPM activated in the Admin Console, with an administrative role that has the permission to manage privileged access. The agent is distributed through a deployment package with a registration token. Syncing user and group collections through Commander requires an Active Directory integration configured in the Admin Console.

Keeper Endpoint Privilege Manager editions and licenses

Keeper Endpoint Privilege Manager has a single edition and is purchased as an add-on to a Keeper Business or Enterprise license, in endpoint seats. It is also part of the KeeperPAM platform, which includes an allowance of workloads on endpoints governed by EPM; the number of endpoints covered in each case is defined in the quote.

How much does Keeper Endpoint Privilege Manager cost?

Keeper Endpoint Privilege Manager is licensed per endpoint, on an annual subscription: each workstation or server with the Keeper agent installed uses one seat, regardless of how many users share the machine. There is no single list price because the investment depends on sizing: number of Windows, macOS and Linux endpoints, the existing Keeper base license (Business, Enterprise or KeeperPAM), AI agent use on workstations and whether it is a new purchase, a renewal or an expansion.

To buy Keeper Endpoint Privilege Manager in Brazil, OSB Software scopes this with you, sends the commercial proposal, issues the invoice and delivers the licenses — request a quote to get the exact figure for your scenario.

Frequently asked questions

Does Keeper Endpoint Privilege Manager work with Windows LAPS? Yes. LAPS keeps rotating the local administrator password on domain-joined machines, and EPM reduces the use of that account by granting temporary elevation per task.

How does a user request elevation in Keeper Endpoint Privilege Manager? When the user attempts an action that requires privilege, the agent shows a prompt according to the policy: elevation is released automatically, asks for MFA and justification, or goes to an administrator for approval.

Does Keeper Endpoint Privilege Manager control sudo on Linux? Yes. On Linux and macOS, the user is removed sudo and use of the command is governed by keepersudo, with command-line policies.

Is Keeper Endpoint Privilege Manager licensed per user? No. The license is per endpoint with the agent installed; the administrators who manage policies use the Keeper base license.

Why buy Keeper Endpoint Privilege Manager OSB Software?

OSB Software is an official Keeper Security partner in Brazil and supplies 100% genuine Keeper Endpoint Privilege Manager licenses to companies, with Brazilian invoicing, local contracting in Portuguese and full legal compliance — the safe way to buy imported software under a Brazilian corporate entity, with no risk of irregular licensing.

When you buy Keeper Endpoint Privilege Manager OSB Software, you get:

  • Consultative, specialist support — specialists who size your per-endpoint licensing to your actual operation, avoiding over- or under-buying.
  • Fast, secure processes — purchase order to delivery of genuine licenses, traceable at every step.
  • Dedicated commercial follow-up — quote to delivery and renewal, with advance notice before your license expires.
  • Invoicing that fits your company — Brazilian invoicing and terms adapted to your corporate procurement process.
  • Proven track record — thousands of customers served across Brazil.

If you are looking for where to buy Keeper Endpoint Privilege Manager in Brazil with legal certainty and properly licensed imported software, request a quote: OSB Software delivers reliable technology, qualified support and a simple, transparent purchase.

We help you choose

Not sure which software
you need?

Tell us about your need and our team helps you choose the ideal solution — from over 10,000 options in our catalog.