Skip to content

Releases: FrodeHus/elevate

Elevate 1.8.0

Choose a tag to compare

@github-actions github-actions released this 19 Sep 13:23
9b5cf03

Added

  • macOS, Windows and CLI: the Azure tab is a scope tree, and a subtree is one click. Azure
    resource eligibility does not scale in a flat list — a platform engineer eligible for Contributor
    on sixty subscriptions had sixty sibling rows to read and sixty clicks before the single
    activation Elevate promised. The Azure tab now groups its rows by the hierarchy the ARM scope
    string already describes: management group, subscription, resource group, resource, each header
    opening and closing and saying how many roles sit under it. A scope that only passes through — no
    eligibility of its own, one way down — is folded into the node below and named there ("Alpha /
    prod"), and a scope leading to a single role gets no header at all, so a narrow panel spends no
    row or indent on nothing. In select mode a scope header carries its own checkbox that takes every
    eligibility under it at once. The search box narrows the tree rather than sitting beside it, now
    reaches the whole ARM path, and keeps matches in their place in the tree even under a header you
    had closed. For scripts, elevate gains --under <scope> (everything at or below a resource
    group or subscription name, a subscription id, or a whole path, compared step by step so
    /subscriptions/abc never swallows /subscriptions/abcdef) and a glob form of --scope where a
    * crosses slashes (--scope "/subscriptions/*"); --scope without a * is the substring
    search it always was. elevate activate --all then takes every role the filters and names match
    instead of insisting each name picks exactly one, which is the scripted form of the subtree
    checkbox. Management groups sit beside the subscriptions rather than above them, in the panel and
    for --under: ARM writes a management group scope as its own flat path and never repeats it in a
    subscription's, so the eligibilities alone cannot say which subscriptions belong to which
    management group. (#186,
    #194)
  • macOS and Windows: the activation sheet no longer signs off with "Active", the word that means
    only that PIM wrote the assignment down. It holds for the first effective-access check and closes
    on Ready when the access is already there, on Activated when the check has not answered in
    a few seconds — it never holds you there for minutes, and the panel row carries the rest. A role
    that reaches its propagation deadline without coming into effect now also raises a notification
    naming the likely cause, rather than saying so only on a row nobody is looking at by then. Follows
    #181, which showed the propagating state on the
    row but left the sheet — the path most activations actually go through — saying what it always had.
  • macOS, Windows and CLI: the green light now means something. PIM reports an assignment active well
    before the access works, which is the most-repeated complaint about PIM. After an activation
    settles, Elevate probes the thing that would actually enforce the role — for an Entra directory
    role a token minted right then, looking for the role in its wids claim; for an Azure resource
    role Azure's own permission check at the activated scope, compared against what the role
    definition grants; for PIM for Groups a fresh token's groups claim, falling back to Graph's
    transitive membership check. elevate activate --wait, elevate profiles run --wait and
    elevate run now wait for that rather than for PIM's record, and report one of three outcomes
    per role: in effect, active but still not in effect (with the likely cause named — almost always
    a stale token in another tool), or active but not observable from here, which covers a
    directory-scoped Entra role, group ownership and sign-in methods whose tokens cannot be read.
    elevate run --settle 2m now bounds that check instead of being a blind pause; --settle 0
    turns the check off and keeps the old fixed 30-second pause for groups. In the panels a row that
    is active but not usable yet shows a hollow green dot and "propagating (~3 min)" beside its
    countdown, which keeps running because the clock started when PIM recorded the activation; the
    dot fills and a notification arrives the moment the access is really in effect, so switching away
    and coming back at the right time now works. A role that never confirms says "not in effect yet"
    and names the likely cause on hover. See
    Activated, but nothing happened.
    (#181)
  • CLI: elevate token --resource arm|graph|<resource uri> prints an access token on stdout and
    nothing else, so a command that authenticates itself — a curl against ARM, in-house tooling —
    can make one authenticated call with what is active now. A command rather than an exported
    variable because it refreshes, is not inherited by every descendant process and works outside
    run: elevate run --role Contributor -- sh -c 'curl -H "Authorization: Bearer $(elevate token --resource arm)" https://management.azure.com/...'. --format json adds the resource, account,
    tenant and expiry, and --format kubectl prints an ExecCredential, so kubectl can call
    elevate token as an exec credential plugin and get a fresh token whenever the old one expires.
    For a command that cannot call back out — a compiled binary, a container entrypoint —
    elevate run --export-token arm -- ./my-tool puts the token in ELEVATE_ARM_TOKEN for that
    command only, never in your shell. Tokens are minted after the activation is active rather than
    taken from the cache, so what was just activated is in them, and are never logged. token
    activates nothing itself. --resource graph is refused without --i-know, and warns when given
    it: Elevate's Graph token carries only the four permissions its registration is consented for, so
    a Graph call outside them is refused however privileged the role that was just activated. ARM has
    no such ceiling.
  • macOS, Windows and CLI: organization co-branding. Four managed-configuration keys —
    OrganizationName (1–32 characters, which gates the other three), OrganizationTitleStyle
    (by, managedBy or none), OrganizationSupportUrl (https:// only) and
    OrganizationSupportEmail — add your organization's name beside Elevate's own and point users
    at your help desk. The name appears as a caption under the title in the panel, on the first-run
    screen and in Settings, and the support contact becomes a "Get help from IT" link there
    and is appended to CLI sign-in and activation failures. Elevate's own name and icon are never
    replaced. Diagnostics names the organization. The Windows ADMX template and the macOS and Intune
    templates carry all four.
  • Windows: an account can now use its own Entra app registration instead of the one in Settings,
    matching macOS. Choose Use a different registration under Entra app registration in Add
    account, or Change app registration… / Upgrade to Entra app registration… from an
    existing account's menu. Each pinned client ID gets its own MSAL (WAM) public client, so its
    tokens stay separate; its admin consent links use that client ID. Both options are hidden when
    the organization manages the client ID, and such an account can then only move to the managed
    registration.
  • CLI: an account can now use its own Entra app registration instead of the configured one, the
    last platform to gain it. elevate login --method own --client-id <application id> adds one,
    elevate accounts set-client-id <account> <application id|--from-settings> moves an account
    between registrations later — and upgrades an Azure CLI, Azure PowerShell or other-app account to
    an Entra app registration — keeping its tenants, roles and profiles. The change is saved only
    after the same account signs in with the new registration. elevate accounts names the
    registration each account uses. Under a managed client ID only the managed registration may be
    chosen.
  • macOS: an account can now use its own Entra app registration instead of the one in Settings.
    Choose Use a different registration in Add account, or Change app registration… from an
    existing account's menu to switch later; both keep the account's tenants, roles and profiles.
    When the organization manages the client ID, such an account can only move to the managed
    registration. See
    Using a second registration for some accounts.
  • macOS: an account added with the Azure CLI app, the Azure PowerShell app or Other app
    (browser sign-in)
    can be upgraded to an Entra app registration from its account menu
    (Upgrade to Entra app registration…), so Elevate can also read and activate Entra roles and
    PIM for Groups for it — keeping its tenants, roles and profiles. The change commits only after
    the same account signs in with the new registration.

Changed

  • Renamed the "Company app (client ID)" sign-in method to Other app (browser sign-in) on
    macOS and Windows. The stored value (custom:<id>) and the managed-configuration key
    (custom) are unchanged.

  • Changing the client ID no longer removes accounts, on any platform. Accounts that use the
    configured registration keep their tenants, roles and profiles and sign in again — in the apps
    they show Sign in, and the CLI (elevate config set client-id) asks them to sign in on next
    use instead of signing them out; it still confirms first unless --yes is given. Accounts with
    their own registration, and Azure CLI and Azure PowerShell accounts, are unaffected.

  • Windows: every release now opens the microsoft/winget-pkgs pull requests for Reothor.Elevate
    and `...

Read more

Elevate Audit 1.1.0

Choose a tag to compare

@github-actions github-actions released this 19 Sep 14:10

Added

  • Three rules for eligibilities nobody uses, driven by PIM activation history: ELIGIBLE-ORPHANED
    (High — the eligibility is held by a disabled account, a blocked guest, or a principal that no
    longer resolves), ELIGIBLE-NEVER-ACTIVATED and ELIGIBLE-DORMANT (Medium for privileged roles,
    Low otherwise). All three cover Entra directory roles, PIM for Groups and Azure resource roles,
    and each finding carries the last activation date and the age of the eligibility. The HTML report
    gains an "Unused eligibility" area.
  • --dormant-after <days> (default 90) sets the dormancy threshold; the activation history is read
    over twice that, so a dormant eligibility can be seen at all.
  • An optional seventh Graph scope, AuditLog.Read.All, for the PIM entries of the directory audit
    log. If consent for it is refused the sign-in is retried without it, activation-history is
    listed as a skipped source, and only ELIGIBLE-ORPHANED runs. Azure activations come from ARM's
    own request history and need no extra scope. The report states the window it examined, because
    directory audit logs are retained for 30 days by default and the tenant may hold less than was
    asked for.

Fixed

  • winget manifest: the release-notes link points at the audit-v tag, not the app's v tag.

Install

The read-only companion that lists standing privileged access to move to PIM. One self-contained elevate-audit binary per platform, no runtime to install.

macOS and Linux with Homebrew (the fully qualified name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install frodehus/elevate/elevate-audit

Windows: winget install Reothor.Elevate.Audit (the manifest goes to winget-pkgs with each release and is published once Microsoft's checks pass, usually within a day or two), or download elevate-audit-1.1.0-win-x64.zip (or -win-arm64.zip) below and put elevate-audit.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-audit-1.1.0-checksums.txt. See docs/audit.md.

The Elevate app and CLI are released separately, under the v tags; this release carries the audit tool only.

Elevate 1.7.0

Choose a tag to compare

@github-actions github-actions released this 15 Sep 11:27
b7dc794

Changed

  • Windows: the release workflow signs the MSIs, the app's executable and assemblies, elevate.exe
    and elevate-audit.exe with a Certum code-signing certificate (SimplySign) instead of Azure
    Artifact Signing, which is not offered to individuals outside the USA and Canada. The publisher shows as "Open Source
    Developer Frode Hus"; SmartScreen may still warn on a new release until reputation builds.

macOS

Signed with Developer ID and notarized.

Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate

The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.

Or download Elevate-1.7.0.dmg below and drag Elevate to Applications. SHA-256: e7dbc7e2e5b0f5a760d4ee6ebdcabb2af53dcadb58b86db062f0316b4561ceef The DMG is the app alone.

Windows

Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.

Code-signed (Certum). SmartScreen can still show "Windows protected your PC" for a new release until the publisher has built reputation; choose More info, then Run anyway.

SHA-256:

  • x64: d15a3f029b985840b676c37349069e1a01986129696b0c54928758efcaf8faf9
  • arm64: d3ceba88728c1c7044800127039d4df2c9d912169290cf73d6d5f8c84a9e3111

CLI (Linux, macOS, Windows)

One self-contained elevate binary per platform, no runtime to install.

macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.7.0.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:

brew install frodehus/elevate/elevate-cli

Windows: Elevate-1.7.0-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.7.0-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.7.0-checksums.txt. See cli/README.md.

elevate-audit

The read-only companion that lists standing privileged access to move to PIM is versioned and released on its own, under the audit-v tags: brew install frodehus/elevate/elevate-audit, winget install Reothor.Elevate.Audit once the manifest is submitted, or the archives of the latest audit release. See docs/audit.md.

Enterprise

Elevate-1.7.0.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.7.0.pkg -target /. SHA-256: 73826cebcb4d011064584f30641d249a2b97e74dc635029d47eb228e9d8e4978

Elevate-enterprise-kit-1.7.0.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 4061275aeea05ad826b8de0834eda41046977db41f08a7f056870f2068c4fdab

Deploying Elevate to a fleet starts at docs/enterprise/README.md.

Elevate Audit 1.0.1

Choose a tag to compare

@github-actions github-actions released this 15 Sep 10:33

Changed

  • Windows: elevate-audit.exe is code-signed with the project's Certum certificate (publisher
    "Open Source Developer Frode Hus"), like the app and the CLI.

Install

The read-only companion that lists standing privileged access to move to PIM. One self-contained elevate-audit binary per platform, no runtime to install.

macOS and Linux with Homebrew (the fully qualified name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install frodehus/elevate/elevate-audit

Windows: winget install Reothor.Elevate.Audit once the manifest is submitted; until then download elevate-audit-1.0.1-win-x64.zip (or -win-arm64.zip) below and put elevate-audit.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-audit-1.0.1-checksums.txt. See docs/audit.md.

The Elevate app and CLI are released separately, under the v tags; this release carries the audit tool only.

Elevate 1.6.7

Choose a tag to compare

@github-actions github-actions released this 14 Sep 07:24

Changed

  • elevate-audit: the HTML report opens with an executive summary — a one-sentence verdict and one
    tile per area (Entra roles, PIM for Groups, Azure RBAC, Guests, Workload identities, Hygiene,
    Coverage) that links to its section — instead of four severity counts. Sections are collapsible,
    group findings roll up into one card per group with a membership outline, a nesting diagram and
    the people reached, and a small inline script adds search, severity filters, expand/collapse and
    50-row caps. The page is complete with JavaScript off and still loads nothing from the network.
  • elevate-audit: every "Start here" item now carries a pill naming its area, so "User Access
    Administrator on Production" reads as Azure RBAC rather than an Entra role, and the pill links to
    that section.

macOS

Signed with Developer ID and notarized.

Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate

The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.

Or download Elevate-1.6.7.dmg below and drag Elevate to Applications. SHA-256: 59ab438bf17463ab51dbabeeee8353698cec5d3bf87a347a5d9459ec5c7594ae The DMG is the app alone.

Windows

Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.

This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.7-x64.msi).Hash.

SHA-256:

  • x64: a861b744f5b4f0b1bb800174fe495d3a280b18ac659cc428bf0e9333e4c9a111
  • arm64: 47028696238161434f5fe8705d0d481791fbe51f35e27170665b199e38aacd27

CLI (Linux, macOS, Windows)

One self-contained elevate binary per platform, no runtime to install.

macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.7.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:

brew install frodehus/elevate/elevate-cli

Windows: Elevate-1.6.7-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.7-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.7-checksums.txt. See cli/README.md.

elevate-audit (Linux, macOS, Windows)

The read-only companion that lists standing privileged access to move to PIM: brew install frodehus/elevate/elevate-audit, or winget install Reothor.Elevate.Audit once the manifest is submitted, or download elevate-audit-1.6.7-<platform> below and put elevate-audit on your PATH. Verify with sha256sum -c elevate-audit-1.6.7-checksums.txt. See docs/audit.md.

Enterprise

Elevate-1.6.7.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.7.pkg -target /. SHA-256: bdc58333b86673375491bdef039bc7ff25fc5279c888bf9b99498656a3cce287

Elevate-enterprise-kit-1.6.7.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 568fd424403ac400eff174806559de46bd3130b9330ff5aa8c4a263edbce9408

Deploying Elevate to a fleet starts at docs/enterprise/README.md.

Elevate 1.6.6

Choose a tag to compare

@github-actions github-actions released this 14 Sep 06:33

Fixed

  • macOS: the "Active now" section was missing from the panel since 1.6.3. The bulk profile
    deactivation change kept a copy of the rows in the view and filled it from a task that never ran
    inside the panel's lazy list, so the section stayed hidden even with roles active. The rows now
    come straight from the model, which also holds a just-deactivated row for the moment its icon
    confirms.
  • Windows: signing an account out, or changing the client id, now also clears its remembered
    deactivation errors and in-progress phases, so a stale "deactivation refused" message cannot
    reappear on a row after the same account is signed in again.

macOS

Signed with Developer ID and notarized.

Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate

The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.

Or download Elevate-1.6.6.dmg below and drag Elevate to Applications. SHA-256: 021d66fcf390366895cd027d225be0b67710f3a6492c04a4f96e90c1fd18f265 The DMG is the app alone.

Windows

Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.

This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.6-x64.msi).Hash.

SHA-256:

  • x64: 8b4c7a96a935a4c49b5432dd99ea77a23a73a98e117a362b7a7be50a53b4d825
  • arm64: 833f4465d0d10fae74110376136c7d663ce11ea9dacd28f276b9ec4b3bc0804c

CLI (Linux, macOS, Windows)

One self-contained elevate binary per platform, no runtime to install.

macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.6.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:

brew install frodehus/elevate/elevate-cli

Windows: Elevate-1.6.6-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.6-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.6-checksums.txt. See cli/README.md.

elevate-audit (Linux, macOS, Windows)

The read-only companion that lists standing privileged access to move to PIM: brew install frodehus/elevate/elevate-audit, or winget install Reothor.Elevate.Audit once the manifest is submitted, or download elevate-audit-1.6.6-<platform> below and put elevate-audit on your PATH. Verify with sha256sum -c elevate-audit-1.6.6-checksums.txt. See docs/audit.md.

Enterprise

Elevate-1.6.6.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.6.pkg -target /. SHA-256: 9920cc27e4cf2d528b019f021fd8c452ab1c9858295d373ff0003ac5ab73ac00

Elevate-enterprise-kit-1.6.6.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 9e8cae2708c7ba8d1ffb167cc7c9e0dc789eccfee1952111cdec533a1ec86b6f

Deploying Elevate to a fleet starts at docs/enterprise/README.md.

Elevate Audit 1.0.0

Choose a tag to compare

@github-actions github-actions released this 14 Sep 10:00

Changed

  • Released on its own: elevate-audit now has its own version number, tag (audit-v<x.y.z>),
    GitHub Release ("Elevate Audit x.y.z") and changelog, so a change to the audit tool no longer
    rebuilds and re-signs the apps and the CLI, and an app release no longer republishes the audit
    tool. The download URLs move to the audit-v release; the Homebrew formula and the winget
    manifest follow.
  • elevate-audit update looks for audit-v releases only, so the app releases that used to carry
    an audit archive are never offered as an upgrade.

Shipped with Elevate 1.6.7 - 2026-09-14

The last audit build inside an app release, before the tool's own numbering began at 1.0.0.

Changed

  • The HTML report opens with an executive summary — a one-sentence verdict and one tile per area
    (Entra roles, PIM for Groups, Azure RBAC, Guests, Workload identities, Hygiene, Coverage) that
    links to its section — instead of four severity counts. Sections are collapsible, group
    findings roll up into one card per group with a membership outline, a nesting diagram and the
    people reached, and a small inline script adds search, severity filters, expand/collapse and
    50-row caps. The page is complete with JavaScript off and still loads nothing from the network.
  • Every "Start here" item now carries a pill naming its area, so "User Access Administrator on
    Production" reads as Azure RBAC rather than an Entra role, and the pill links to that section.

Install

The read-only companion that lists standing privileged access to move to PIM. One self-contained elevate-audit binary per platform, no runtime to install.

macOS and Linux with Homebrew (the fully qualified name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install frodehus/elevate/elevate-audit

Windows: winget install Reothor.Elevate.Audit once the manifest is submitted; until then download elevate-audit-1.0.0-win-x64.zip (or -win-arm64.zip) below and put elevate-audit.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-audit-1.0.0-checksums.txt. See docs/audit.md.

The Elevate app and CLI are released separately, under the v tags; this release carries the audit tool only.

Elevate 1.6.5

Choose a tag to compare

@github-actions github-actions released this 13 Sep 12:54

Added

  • Windows: a startup failure now shows in the flyout as an error bar ("Elevate cannot start") with
    the message and an Open Settings… button, in place of the role list, as the macOS panel does.
    Settings repeats the message next to Copy diagnostics. Before, the flyout stayed empty and the
    reason was only in elevate.log.

Changed

  • Windows: expiry notifications are now scheduled with Windows instead of being timed inside the app,
    so the "expires in 5 minutes" and "expired" toasts still appear after Elevate is quit or crashes, as
    they do on macOS. Extend and Activate again launch Elevate when it is not running. The
    in-app timer remains as a fallback when the system schedule is unavailable.
  • macOS, Windows and CLI: the "Cached tokens may be stale" hint after an Azure or group activation
    now appears only for accounts signed in with the Azure CLI or Azure PowerShell app, where Elevate
    shares the tool's token cache. For an account signed in through an app registration Elevate cannot
    tell whether the Azure CLI, Azure PowerShell or kubelogin were ever used as that account, so the
    hint no longer asserts that their cached tokens exist.
  • Windows: the deactivation review uses the same pre-flight verdicts as macOS. A role whose
    assignment has not been confirmed active shows "Awaiting active assignment confirmation", one
    without a verifiable identity or original activation interval says so, a replaced or expired
    assignment reads "Assignment replaced" or "Already inactive or expired", and the minimum period
    line becomes "Can be deactivated in N s (minimum activation period)". The Deactivate button
    is disabled while every remaining role is blocked instead of only when offline.
  • Windows: the tenant menu's "Open admin consent link…" is now offered for every account signed in
    with the Entra app registration method, not only after discovery fell back to manual roles or
    groups became unavailable, so an administrator can re-consent after a scope is added before
    anything fails, as on macOS since 1.6.1.
  • Windows: an account whose saved sign-in is gone at launch (a cleared MSAL or Azure CLI cache, a
    revoked session) is kept with its tenants, configured roles and profile entries instead of being
    signed out. The account row shows a Sign in button and its menu a Sign in again item
    that re-run the account's own sign-in method; refreshes skip the account until then. A read
    failure of the token caches keeps every account as it was. Matches macOS.

Fixed

  • Windows: the Profiles window says "No roles resolved yet. They appear once the tenants they
    name have loaded." for a managed profile whose tenants have not loaded, as on macOS, instead of
    the "Add roles…" hint for a control that is not there.
  • Windows: in the run review, rows that are already active, pending or not eligible reserve the
    checkbox width, so their names line up with the rows that have one.

macOS

Signed with Developer ID and notarized.

Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate

The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.

Or download Elevate-1.6.5.dmg below and drag Elevate to Applications. SHA-256: c2ecf7fc306c7d9b80a0deedae51fe7a2d18d11fe69909f8fbb2cd2d46a446e2 The DMG is the app alone.

Windows

Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.

This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.5-x64.msi).Hash.

SHA-256:

  • x64: 7906c8ecc8b88d9bab303d21a690347879b31df148f2cd5de4ff36184bbce5fa
  • arm64: 87db15f15afaa4ddb4a8db963fc59a1946d866151ff8476596fa0643790deac5

CLI (Linux, macOS, Windows)

One self-contained elevate binary per platform, no runtime to install.

macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.5.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:

brew install frodehus/elevate/elevate-cli

Windows: Elevate-1.6.5-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.5-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.5-checksums.txt. See cli/README.md.

Enterprise

Elevate-1.6.5.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.5.pkg -target /. SHA-256: 8da0e4d0919c6846b828f4e1f75f2fa093b014eceeeccfd287359c422a7c80a7

Elevate-enterprise-kit-1.6.5.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 12bc1279fbdc0c5e5046c56d120c3037decc5b0a0807a7da71efbbbf68cc6bec

Deploying Elevate to a fleet starts at docs/enterprise/README.md.

Elevate 1.6.4

Choose a tag to compare

@github-actions github-actions released this 12 Sep 16:24

Added

  • macOS and Windows: the run and deactivate reviews for a profile show a checkbox next to each
    role, checked by default. Unchecking a role omits it from that one run or deactivation pass;
    nothing is remembered onto the profile, and an omitted role stays available to a later pass.

Fixed

  • macOS, Windows and CLI: deactivating a role no longer fails with "Revoked". Microsoft Graph and
    Azure Resource Manager report a completed self-deactivation with that status, and the
    confirmation check added for profile deactivation only accepted "Provisioned".

macOS

Signed with Developer ID and notarized.

Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate

The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.

Or download Elevate-1.6.4.dmg below and drag Elevate to Applications. SHA-256: b3cc548ed91cdccb48a89797f290f8caf398c61366a49c9c10ba1f1adb792c1e The DMG is the app alone.

Windows

Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.

This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.4-x64.msi).Hash.

SHA-256:

  • x64: 28f2b408dba5d2dcd8a3dca6ea8c2fc9fbe34b25b29cd56a2c7ea78be97bcd5c
  • arm64: 8e64f430ea231ed1e0bd6c13256a380c8f598b5db7eb5905aafc14c1d41b2fb1

CLI (Linux, macOS, Windows)

One self-contained elevate binary per platform, no runtime to install.

macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.4.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:

brew install frodehus/elevate/elevate-cli

Windows: Elevate-1.6.4-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.4-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.4-checksums.txt. See cli/README.md.

Enterprise

Elevate-1.6.4.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.4.pkg -target /. SHA-256: 4d94ef6c5e01d81795005f7a98f682433a081e9e67710f74f0837b39ffcd87af

Elevate-enterprise-kit-1.6.4.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: c249029ae46957f5e659d15024f0c37ef37c38b7dd60b0f72e1a9a6c9300781c

Deploying Elevate to a fleet starts at docs/enterprise/README.md.

Elevate 1.6.3

Choose a tag to compare

@github-actions github-actions released this 12 Sep 15:11

Added

  • macOS and Windows: the tenant menu gains an Open… submenu that opens the Azure Portal, the
    Entra and Intune admin centers, and the Defender and Purview portals directly in that tenant.
    The browser session picks the account; Microsoft's sign-in page prompts with the tenant already
    fixed when it has none.

Changed

  • macOS and Windows: profile runs can now deactivate only the exact role assignments they
    activated. Per-role eligibility and results survive restarts, partial failures can be retried,
    and confirmed deactivation uses Elevate's chevrons pulsing downward before showing success.
  • macOS and Windows: per-role progress in activation dialogs and profile runs now uses Elevate's
    chevrons pulsing upward. Confirmed activation morphs them into a green circle and check mark;
    pending approval, scheduled requests and failures keep their distinct statuses. The animation
    respects reduced-motion settings, and activation dialogs briefly hold the success result before closing.

macOS

Signed with Developer ID and notarized.

Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate

The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.

Or download Elevate-1.6.3.dmg below and drag Elevate to Applications. SHA-256: 74d64707db33e2be3c876aea8abab3f089f6cba3b1f6dd19d08a79c37004a35d The DMG is the app alone.

Windows

Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.

This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.3-x64.msi).Hash.

SHA-256:

  • x64: 9ea2c44de5566e5e0f1a1074cc4a59002d0f72cc822f1a194a31f9656806d265
  • arm64: c065e202f5dbcc4ad64595ada732f7125ed60a3b4cb85349ba12c5911c93e382

CLI (Linux, macOS, Windows)

One self-contained elevate binary per platform, no runtime to install.

macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.3.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:

brew install frodehus/elevate/elevate-cli

Windows: Elevate-1.6.3-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.3-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.3-checksums.txt. See cli/README.md.

Enterprise

Elevate-1.6.3.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.3.pkg -target /. SHA-256: 4fe6ac790d817df9a8c78390733675b6667667cff06c72245363ced794c87134

Elevate-enterprise-kit-1.6.3.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: d429fb0387c2b9aef8ce33a38810fc4a06b6add57d1bce936ffb8a4b9b2ee9cc

Deploying Elevate to a fleet starts at docs/enterprise/README.md.