# Privilege Management Policy Deployment Associate a Privileged Application List with device groups, deploy the policy, and monitor elevation events from the console. ## Configuring Privilege Management Link the Privileged Application List to the device groups that need controlled elevation access. ### Deploying the EPM policy Once the Privileged Application List is created, deploy it by associating it with the appropriate custom groups. This ensures that only authorized users gain elevated access to approved applications in a secure and controlled manner. 1. Navigate to **Application Control → Privilege Management**. 2. To allow [self-elevation](https://www.manageengine.com/application-control/help/endpoint-privilege-management/epm-policy-creation.html#self), enable the toggle for **Enable users to elevate applications manually**. 3. To configure elevated privileges for [all allowed applications](https://www.manageengine.com/application-control/help/endpoint-privilege-management/epm-policy-creation.html#allowedapps) or [specific ones](https://www.manageengine.com/application-control/help/endpoint-privilege-management/epm-policy-creation.html#specific), enable **Configure specific application to run with elevated privileges** and build the application list. 4. Optionally enable **[Auto Elevation](https://www.manageengine.com/application-control/help/endpoint-privilege-management/epm-policy-creation.html#auto)** to elevate applications automatically without user prompts. 5. Navigate to the **Policy Deployment** tab and select the Custom Group containing the user devices that need privileged access. 6. Click **Yes** to **Associate the Privileged Application List** with the chosen custom group. ![Associate Privileged Application List dialog showing custom group selection and confirmation](https://www.manageengine.com/products/desktop-central/help/images/ac-associate-pl.png) *Associating the Privileged Application List with a custom device group.* After association, users on the target devices can right-click an application's .exe and choose **Run as ManageEngine** to execute it with elevated privileges — without entering admin credentials. ![Context menu showing the Run as ManageEngine option on an executable](https://www.manageengine.com/products/desktop-central/help/images/epm-elevation-1.png) *Run as ManageEngine — the entry point for standard users to access elevated applications.* ## Revoking Application Privileges Remove elevated access when it's no longer needed and review the full audit trail. ### Deleting a policy Delete any policy after its requirements have been fulfilled to prevent misuse of elevated privileges. This removes the elevation association from the affected custom groups. ![Delete Application Group confirmation dialog](https://www.manageengine.com/products/desktop-central/help/images/ac-delete-policy.png) *Deleting a policy immediately revokes its associated elevation permissions.* ## Application Elevation Events The **Elevation Events** view provides a detailed audit trail of every application elevated by users on a managed endpoint. Use it to monitor privilege activity and verify that elevated access is being used appropriately. ### Viewing elevation events 1. Navigate to **Systems** and select the target machine. 2. Open the **Events** tab and select **Elevation Events** from the left panel. 3. Click **Update Now** in the top-right corner to fetch the latest events from the endpoint. Each event record includes the application name, the user who performed the elevation, event type, date and time, the justification provided (if required), remarks, and the associated elevation policy. ![Elevation Events log showing elevated application records with user, time, and policy details](https://www.manageengine.com/sites/meweb/images/desktop-central/help/application-control/epm-elevation-events.webp) *Elevation Events — per-machine audit log of all privilege elevation activity.* ## Related - [Create EPM policy](https://www.manageengine.com/application-control/help/endpoint-privilege-management/epm-policy-creation.html) - [Endpoint Privilege Management overview](https://www.manageengine.com/application-control/help/endpoint-privilege-management/epm-overview.html) - [Remove admin rights](https://www.manageengine.com/application-control/help/endpoint-privilege-management/remove-admin-rights.html) - [JIT access for privilege elevation](https://www.manageengine.com/application-control/help/endpoint-privilege-management/epm-jit-access.html)