DocumentationAPI ReferenceRelease Notes
Log In
Documentation

What are analytics?

Analytics displays at-a-glance reporting metrics for all of your endpoints' events, applications, and user actions.

How are they useful?

Use your analytics pages to understand and take action on your security posture within EPM for Windows and Mac.

  • Dashboard page: View data charts of your top event actions, endpoint user logins, and application requests.
  • Events page: View all endpoint activity you chose to log using EPM for Windows and Mac.
  • Applications page: View how different applications (grouping of events with the same application type) are used and controlled across all your machines, by all your users, in a single row of data.
  • Users page: View detailed information about your users' logons.

📘

A standard user requires delegated access to this feature. For more information, see About user types and resources.

When you want policy administrators to see events only for the computer groups they manage, create a user and select Standard User. From the Computer Groups list, select Analyze Group.

The Dashboard page

  1. Left menu: Easy access to all pages in Endpoint Privilege Management, including the Home, Policies, Computers, Computer Groups, Management Rules, Analytics, Just-in-Time Access Management, Configuration, Auditing, and User Management pages.
  2. Filters: Select a filter to refine your results. Click Clear Filters to remove all filters from your results.
  3. Data charts: There are three data charts on the Dashboard page.
    • Top Event Actions chart: Your tracked event actions. For detailed information about the actions, click the linked number on the chart to open the Events page.
      • Tracked Windows actions: Allowed, Elevated, Cancelled, Self-Elevated, and Blocked
      • Tracked macOS actions: Allowed, Allowed Installable, Allowed Deletable, Blocked, Cancelled, and Passive
    • Endpoint User Logins chart: The total active Windows users who logged into your estate.
      • Tracked users: Local Administrator, Domain Standard, Local Standard, and Domain Administrator
    • Application Request chart: The total number of application requests, approvals, and denials.

Use cases

The use cases provide guidance on how to manage and interpret the results of the data gathered by Analytics.

Generate views

Additional Analytics features you can use when generating the data:

  • After setting the filters, save the view to load the same set of filters the next time you want to refresh the data.
  • Add the applications to policy using the Add to Policy option.
Windows
Use CaseFavorite Filters
Learn about recent events that require admin rights in your estate and add them to your Add Admin Application Groups.On the Events grid with these filters:
  • OS: Windows
  • Admin Required: Yes
  • Application Group Names:
    • (Default) Trusted & Signed UAC Prompt
    • (Default) Signed UAC Prompt
    • (Default) UAC Prompt
Learn about recent on-demand elevation events in your estate, and add them to Add Admin Application Groups.On the Events grid with these filters:
  • OS: Windows
  • On Demand: Yes
  • Admin Required: Yes
  • Application group names:
    • (Recommended) Restricted Functions (On-Demand)
    • (Default) Any Application
Learn about the most popular applications that require admin rights in your estate, and add them to your Add Admin Application Groups.On the Applications grid with these filters:
  • Operating System: Windows
  • Admin Required: Yes
  • Application Group Names:
    • (Default) Any Trusted & Signed UAC Prompt
    • (Default) Any Signed UAC Prompt
    • (Default) Any UAC Prompt
Learn about the most popular applications that are elevated on demand in your estate, and add them to your Add Admin Application Groups.On the Applications grid with these filters:
  • OS: Windows
  • On Demand: Yes
  • Admin Required: Yes
  • Application group names:
    • (Recommended) Restricted Functions (On-Demand)
    • (Default) Any Application
To see the most popular passive applications that would have been blocked if the Low Flexibility policy was enabled, and add those to the Low Flex - Passive list before enabling the active allow list.On the Applications grid with these filters:
  • OS: Windows
  • Application Group:
    • (Default) Any Application
macOS
Use CaseFavorite Filters
Learn about recent events that require authorization rights in your estate, and add them to Add Admin Application Groups.On the Events grid with these filters:
  • OS: Mac
  • Authorization Required: Yes
  • Application Group Names:
    • (Default) General - Any Applications Requiring Authorization
Learn about the most popular applications that require authorization in your estate, and add them to your Authorize Application Groups.On the Applications grid with these filters:
  • OS: macOS
  • Authorization Required: Yes
  • Application Group Names:
    • (Default) General - Any Applications Requiring Authorization
To see the most popular passive applications that would have been blocked if the Low Flexibility policy was enabled, and add those to the Low Flex - Passive list before enabling the active allow list.On the Applications grid with these filters:
  • OS: macOS
  • Event Action: Allowed + Passive
  • Application Group Names:
    • (Default) Passive - System Trusted

Š2003-2025 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.