Access report Permanent admin rights are out. Temporary, auditable privilege is in.Endpoint brief Windows + macOS + Linux, managed from one cloud console.Access report Permanent admin rights are out. Temporary, auditable privilege is in.Endpoint brief Windows + macOS + Linux, managed from one cloud console.
Company profile / Cybersecurity

The admin key that vanishes

Admin By Request is betting that the safest administrator account is the one that disappears when the work is done. Its lightweight platform turns permanent privilege into a temporary, logged and policy-checked event.

A software installer asks for administrator rights. It is a small, familiar interruption, the sort that teaches employees to click quickly and think later. Behind that prompt sits one of enterprise security's oldest compromises: give people permanent power over their machines and risk abuse, or remove it and turn the help desk into a permission counter. Admin By Request has built a company around a third answer. Let the user ask, inspect the request, grant only what is needed, and take the privilege back when the job is finished.

The idea is almost stubbornly literal. Admin By Request is both the company name and the workflow. Its endpoint agent intercepts attempts to run an application with elevated rights. A policy can approve the application automatically, send the request to an administrator, or allow a timed session. The event is recorded, the file can be screened for malware, and the employee returns to ordinary user status. There is no permanent local-admin credential left lounging on the machine like a spare key under a flowerpot.

This is endpoint privilege management, a branch of the broader privileged access management market. Traditional PAM grew up around vaulting powerful credentials and controlling access to servers. Admin By Request focuses much of its attention on the laptop, workstation and server directly in front of a user. Its agents cover Windows, macOS and Linux, with policy and audit data living in a common cloud portal.

<3MBClaimed endpoint agent size
25Free EPM workstation seats
3 OSWindows, macOS and Linux

Privilege with an expiration date

The problem is not that employees occasionally need admin power. Developers install tools. Finance teams update specialist software. Technicians change system settings. The problem is duration. A standing privilege remains useful to its owner and potentially useful to an attacker, long after the original task has ended. Stolen credentials, malicious software and a hurried click all become more consequential when the signed-in user already has the keys.

Admin By Request narrows that window. In single-application elevation, the chosen process receives additional rights while the rest of the session does not. For work that cannot be boxed into one process, a timed elevation can grant broader access and then end automatically. Organizations can require a reason, a ticket number, multifactor authentication or a human approval. They can pre-approve known software and denylisted applications never make it through.

The lifecycle of a privilege request A five-step flow from user request through policy, risk check, limited access and audit record. 01REQUEST 02POLICY 03CHECK 04ELEVATE 05EXPIRE
The disappearing act. Privilege enters for a reason, passes through policy and risk checks, then leaves behind a record instead of an open door.

The mechanics create a useful byproduct: evidence. The portal can show who elevated what, when and why. Security teams can export events to SIEM tools, while auditors get a record of controls actually being used. Optional recordings add context to remote sessions. The company maps its capabilities against frameworks and standards including ISO 27001, SOC 2, PCI DSS, NIST and Cyber Essentials. It announced its own ISO 27001 certification in 2022 and maintains a trust center with compliance and security documents.

“Zero Standing. Zero Learning Curve.”Admin By Request's compact product thesis

The help desk is part of the threat model

Security controls fail in mundane ways. If approval takes an afternoon, an employee searches for a workaround. If a developer must open five tickets a week, the organization eventually creates an exception. Admin By Request competes on the idea that usability is not decoration; it determines whether least privilege survives contact with a working company.

Routine requests can be handled by allow rules, machine-learning suggestions or what the company calls AI auto-approval, while unusual cases reach a person. Administrators can respond from a mobile device. Integrations put requests and audit data inside systems the team already watches: ServiceNow for workflows, Slack for notifications, Jira or Zendesk for tickets, and Microsoft Sentinel or Splunk for security monitoring. Identity providers support single sign-on and group-based policy.

One endpoint event, several jobs
Least privilege
User speed
Audit context
Tool fit

Those bars are an editorial map, not benchmark scores. They show the jobs Admin By Request tries to join in one motion. A security team gets less standing privilege. An employee gets a route to the tool they need. The help desk gets fewer repetitive requests. Compliance gets a receipt. The unusual product decision is to treat all four as the same design problem.

Two products, one control plane

Endpoint Privilege Management remains the flagship. It removes local administrators, elevates a single application or a timed user session, checks executables with more than three dozen anti-malware engines through OPSWAT's MetaDefender Cloud, and offers break-glass access for emergencies. The agent reports hardware and software inventory and applies granular settings to users, groups or organizational units.

Secure Remote Access extends the same logic to support work. IT staff can launch attended help sessions or connect to unattended machines. Vendor Access lets an outside technician reach an approved device through a browser without receiving the main Admin By Request portal. Connections are created just in time and torn down afterward. The company uses outbound Cloudflare tunnels, avoiding a permanent inbound path and reducing the firewall choreography associated with older remote-access stacks.

The pairing matters. Remote-support products and privilege tools are often separate purchases with separate agents, policies and records. Here, remote access sits beside endpoint inventory, approval flows and the audit log. Product enrollment lets a company assign EPM, SRA or both to selected machines. In 2026, Secure Remote Access reached macOS, and a new Web Access Management product added policy around browsing destinations and downloads.

What a customer can actually doRemove local admin accounts, let approved apps run without a ticket, route unusual requests to a phone, give a vendor temporary browser-based access, record a remote session, and export the resulting trail to an existing security or service-management system.

A free tier built for suspicious buyers

Security software is sold on trust, but the buyers are professionally skeptical. Admin By Request's commercial answer is a lifetime free plan with the core feature set. It covers up to 25 EPM workstation seats across Windows, Mac or Linux, 10 Windows Server seats, and a limited allotment for Secure Remote Access. That is enough for a small company to operate or for a large one to run a real proof of concept.

Above that threshold, the business is familiar enterprise SaaS. Pricing depends on endpoint count and contract duration. Business plans begin above the free allocation; enterprise packages target deployments of roughly 2,000 seats or more, with onboarding, support and optional professional services. The website promises the same features rather than a maze of paid modules. Exact rates arrive by quote.

This product-led wedge is one distinction in a market populated by CyberArk, BeyondTrust, Delinea, ThreatLocker, AutoElevate, JumpCloud and Microsoft's Intune Endpoint Privilege Management. Admin By Request does not claim to replace every vault or identity system. It positions itself as a lighter, cross-platform route to controlling endpoint privileges, then broadens the account with remote access, integrations and compliance tooling.

Danish roots, enterprise ambitions

Founder and CEO Lars Sneftrup Pedersen came to the product through a long career in software. The code traces back to FastTrack Software, an earlier Danish company. Admin By Request emerged as its own focus in 2017, built from Aalborg rather than a standard Silicon Valley origin story. The legal company, Admin By Request ApS, remains registered in Aalborg, while its team operates across offices in North America, Europe and Asia-Pacific. Public employment data puts the staff at roughly 150 to 160 people.

Its customer references cross industries and company sizes. The company and external profiles name Disney, McLaren, the Red Cross and the Bill & Melinda Gates Foundation; published case studies cover businesses such as Senacor and Nutreco. The users inside those organizations are usually less glamorous than the logos: system administrators, security analysts, help-desk teams and compliance managers trying to make everyday access boring and provable.

The culture presented publicly is practical, globally distributed and engineering-led. Pedersen's stated mission is to build security that does not sacrifice usability for protection. The marketing occasionally takes a louder turn. Admin By Request has sponsored racing drivers Kevin Magnussen and Nico Hulkenberg, placing its logo on helmets and race suits. Both partnerships were renewed for 2026. It is a high-speed billboard for a product whose best moments are meant to feel uneventful.

That contrast captures where the company fits. Privileged access management can be grand and architectural, full of vaults, identity graphs and transformation programs. Admin By Request begins with a smaller scene: a person needs to install something. The product tries to make the secure answer faster than the unsafe shortcut. From that one exchange, it builds policy, telemetry, remote support and proof.

The wager is sensible but demanding. Automatic decisions must be conservative enough for security and quick enough for work. Cross-platform behavior must feel consistent even when operating systems disagree. Remote access must add convenience without recreating permanent entry points. And the free plan must convert real use into paid scale. Admin By Request's advantage is not a magical new category. It is the discipline to make an old security principle usable, one temporary permission at a time.

Keep exploring
CybersecurityEnterprise SaaSZero TrustLeast PrivilegeRemote Access