Permanent admin rights
Every standing local admin account is an open door for ransomware and lateral movement.
Privileged Access Management for Windows
ZKE lets your technicians elevate on any Windows endpoint using their corporate identity — no permanent admin accounts, no shared passwords. Every elevation is rotated, audited and cryptographically tamper-evident.
Every standing local admin account is an open door for ransomware and lateral movement.
A reused local admin password across the fleet means one leak compromises everything.
When elevation isn't tied to identity, you can't prove who did what, when — or detect tampering.
No new habits for your technicians. ZKE plugs into the native Windows UAC dialog.
The technician right-clicks "Run as administrator" — the same Windows flow they already know.
They pick the ZKE tile and sign in with their Entra ID credentials. The password is validated locally and never leaves the endpoint.
If policy allows, the ZKE agent rotates the local admin password, elevates, then re-seals the account. Every step is audited.
From the UAC tile to the audit trail — the whole flow in one place.
A lightweight agent, native UAC and per-tenant key isolation. No on-prem servers to run.
A lightweight Windows service on each device. Polls for policy; rotates and re-seals the local admin account.
A ZKE tile in the native UAC dialog. Verifies the technician's password locally with the OS and asserts only the identity.
Evaluates policy and issues a freshly rotated, single-use local admin credential. Every query is tenant-scoped.
Each customer's credentials are encrypted with their own key in a managed HSM. Keys never leave it.
The technician authenticates in the UAC tile. The Credential Provider validates the password locally — it never leaves the device.
Only the verified identity is sent to the backend, which checks policy and returns a one-time local admin credential.
The agent applies it, elevation proceeds, and the account is re-sealed with an unknown password. The whole flow is audited.
The technician's password is verified on the device and never transmitted to the backend. ZKE stores no primary credentials.
Each customer's admin credentials are encrypted with their own key in a managed HSM. Strict tenant isolation throughout.
Every action is recorded in a per-tenant HMAC hash chain — altering or deleting a record is cryptographically detectable.
No approval ping-pong, no second device. ZKE focuses on fast, policy-driven, fully audited elevation.
The security of removing local admin, without the operational pain.
| Capability | Standing admin | Password rotation (LAPS) | ZKE |
|---|---|---|---|
| No permanent local admin | ✕ | ✕ | ✓ |
| Tied to corporate identity | ✕ | ✕ | ✓ |
| Rotated on every use | ✕ | ~ | ✓ |
| Password never shared | ✕ | ✕ | ✓ |
| Tamper-evident audit | ✕ | ✕ | ✓ |
| Native UAC, lightweight footprint | ~ | ✓ | ✓ |
Authorized technicians elevate on any managed endpoint with their own identity.
Grant a user a single, time-boxed elevation from the portal — no technician on site.
Trusted users elevate on their own machine under a reviewed, audited standing grant.
Endpoint offline? Authorized technicians recover access under reinforced audit and notifications.
Give technicians per-endpoint elevation across many client tenants, each fully isolated and audited.
Remove standing local admin from the fleet without drowning the help desk in tickets.
Prove who elevated, where and when, with a cryptographically tamper-evident trail.
What we're building next, driven by what enterprises ask for.
A full record of the actions performed during each elevated session, for forensics and compliance.
Users request elevation on demand; an administrator approves it just-in-time, fully audited.
Instantly disable an endpoint from the portal — blocking elevation and re-enrollment in one click.
No. The Credential Provider validates it locally against the OS; only the verified identity is sent to the backend. ZKE stores no primary credentials.
Authorized technicians can recover access through Recovery Elevation, under reinforced audit and notifications. When the endpoint reconnects, the local admin password is rotated automatically.
LAPS rotates and stores a local admin password. ZKE ties each elevation to corporate identity, issues a single-use credential per elevation, never shares the password, and records everything in a tamper-evident audit chain.
Microsoft Entra ID. Technicians and users authenticate with the corporate identity you already manage.
Encrypted per tenant with the customer's own key in a managed HSM (Azure Key Vault Managed HSM). The key never leaves the HSM, and tenants are strictly isolated.
No. ZKE handles interactive privileged elevation, not mass software deployment. It complements your existing management tooling.
Yes. Every elevation and administrative action is recorded in a per-tenant HMAC hash chain, so altering or deleting a record is cryptographically detectable.
It's a lightweight Windows service that plugs into the native UAC dialog. No second device, no mobile app, no approval ping-pong.
Tell us about your environment and we'll set up a tailored demo. No commitment.
Request a demoOr email us at [email protected]