Releases: FrodeHus/elevate
Release list
Elevate 1.8.0
Added
- macOS, Windows and CLI: the Azure tab is a scope tree, and a subtree is one click. Azure
resource eligibility does not scale in a flat list — a platform engineer eligible for Contributor
on sixty subscriptions had sixty sibling rows to read and sixty clicks before the single
activation Elevate promised. The Azure tab now groups its rows by the hierarchy the ARM scope
string already describes: management group, subscription, resource group, resource, each header
opening and closing and saying how many roles sit under it. A scope that only passes through — no
eligibility of its own, one way down — is folded into the node below and named there ("Alpha /
prod"), and a scope leading to a single role gets no header at all, so a narrow panel spends no
row or indent on nothing. In select mode a scope header carries its own checkbox that takes every
eligibility under it at once. The search box narrows the tree rather than sitting beside it, now
reaches the whole ARM path, and keeps matches in their place in the tree even under a header you
had closed. For scripts,elevategains--under <scope>(everything at or below a resource
group or subscription name, a subscription id, or a whole path, compared step by step so
/subscriptions/abcnever swallows/subscriptions/abcdef) and a glob form of--scopewhere a
*crosses slashes (--scope "/subscriptions/*");--scopewithout a*is the substring
search it always was.elevate activate --allthen takes every role the filters and names match
instead of insisting each name picks exactly one, which is the scripted form of the subtree
checkbox. Management groups sit beside the subscriptions rather than above them, in the panel and
for--under: ARM writes a management group scope as its own flat path and never repeats it in a
subscription's, so the eligibilities alone cannot say which subscriptions belong to which
management group. (#186,
#194) - macOS and Windows: the activation sheet no longer signs off with "Active", the word that means
only that PIM wrote the assignment down. It holds for the first effective-access check and closes
on Ready when the access is already there, on Activated when the check has not answered in
a few seconds — it never holds you there for minutes, and the panel row carries the rest. A role
that reaches its propagation deadline without coming into effect now also raises a notification
naming the likely cause, rather than saying so only on a row nobody is looking at by then. Follows
#181, which showed the propagating state on the
row but left the sheet — the path most activations actually go through — saying what it always had. - macOS, Windows and CLI: the green light now means something. PIM reports an assignment active well
before the access works, which is the most-repeated complaint about PIM. After an activation
settles, Elevate probes the thing that would actually enforce the role — for an Entra directory
role a token minted right then, looking for the role in itswidsclaim; for an Azure resource
role Azure's own permission check at the activated scope, compared against what the role
definition grants; for PIM for Groups a fresh token'sgroupsclaim, falling back to Graph's
transitive membership check.elevate activate --wait,elevate profiles run --waitand
elevate runnow wait for that rather than for PIM's record, and report one of three outcomes
per role: in effect, active but still not in effect (with the likely cause named — almost always
a stale token in another tool), or active but not observable from here, which covers a
directory-scoped Entra role, group ownership and sign-in methods whose tokens cannot be read.
elevate run --settle 2mnow bounds that check instead of being a blind pause;--settle 0
turns the check off and keeps the old fixed 30-second pause for groups. In the panels a row that
is active but not usable yet shows a hollow green dot and "propagating (~3 min)" beside its
countdown, which keeps running because the clock started when PIM recorded the activation; the
dot fills and a notification arrives the moment the access is really in effect, so switching away
and coming back at the right time now works. A role that never confirms says "not in effect yet"
and names the likely cause on hover. See
Activated, but nothing happened.
(#181) - CLI:
elevate token --resource arm|graph|<resource uri>prints an access token on stdout and
nothing else, so a command that authenticates itself — acurlagainst ARM, in-house tooling —
can make one authenticated call with what is active now. A command rather than an exported
variable because it refreshes, is not inherited by every descendant process and works outside
run:elevate run --role Contributor -- sh -c 'curl -H "Authorization: Bearer $(elevate token --resource arm)" https://management.azure.com/...'.--format jsonadds the resource, account,
tenant and expiry, and--format kubectlprints anExecCredential, so kubectl can call
elevate tokenas an exec credential plugin and get a fresh token whenever the old one expires.
For a command that cannot call back out — a compiled binary, a container entrypoint —
elevate run --export-token arm -- ./my-toolputs the token inELEVATE_ARM_TOKENfor that
command only, never in your shell. Tokens are minted after the activation is active rather than
taken from the cache, so what was just activated is in them, and are never logged.token
activates nothing itself.--resource graphis refused without--i-know, and warns when given
it: Elevate's Graph token carries only the four permissions its registration is consented for, so
a Graph call outside them is refused however privileged the role that was just activated. ARM has
no such ceiling. - macOS, Windows and CLI: organization co-branding. Four managed-configuration keys —
OrganizationName(1–32 characters, which gates the other three),OrganizationTitleStyle
(by,managedByornone),OrganizationSupportUrl(https://only) and
OrganizationSupportEmail— add your organization's name beside Elevate's own and point users
at your help desk. The name appears as a caption under the title in the panel, on the first-run
screen and in Settings, and the support contact becomes a "Get help from IT" link there
and is appended to CLI sign-in and activation failures. Elevate's own name and icon are never
replaced. Diagnostics names the organization. The Windows ADMX template and the macOS and Intune
templates carry all four. - Windows: an account can now use its own Entra app registration instead of the one in Settings,
matching macOS. Choose Use a different registration under Entra app registration in Add
account, or Change app registration… / Upgrade to Entra app registration… from an
existing account's menu. Each pinned client ID gets its own MSAL (WAM) public client, so its
tokens stay separate; its admin consent links use that client ID. Both options are hidden when
the organization manages the client ID, and such an account can then only move to the managed
registration. - CLI: an account can now use its own Entra app registration instead of the configured one, the
last platform to gain it.elevate login --method own --client-id <application id>adds one,
elevate accounts set-client-id <account> <application id|--from-settings>moves an account
between registrations later — and upgrades an Azure CLI, Azure PowerShell or other-app account to
an Entra app registration — keeping its tenants, roles and profiles. The change is saved only
after the same account signs in with the new registration.elevate accountsnames the
registration each account uses. Under a managed client ID only the managed registration may be
chosen. - macOS: an account can now use its own Entra app registration instead of the one in Settings.
Choose Use a different registration in Add account, or Change app registration… from an
existing account's menu to switch later; both keep the account's tenants, roles and profiles.
When the organization manages the client ID, such an account can only move to the managed
registration. See
Using a second registration for some accounts. - macOS: an account added with the Azure CLI app, the Azure PowerShell app or Other app
(browser sign-in) can be upgraded to an Entra app registration from its account menu
(Upgrade to Entra app registration…), so Elevate can also read and activate Entra roles and
PIM for Groups for it — keeping its tenants, roles and profiles. The change commits only after
the same account signs in with the new registration.
Changed
-
Renamed the "Company app (client ID)" sign-in method to Other app (browser sign-in) on
macOS and Windows. The stored value (custom:<id>) and the managed-configuration key
(custom) are unchanged. -
Changing the client ID no longer removes accounts, on any platform. Accounts that use the
configured registration keep their tenants, roles and profiles and sign in again — in the apps
they show Sign in, and the CLI (elevate config set client-id) asks them to sign in on next
use instead of signing them out; it still confirms first unless--yesis given. Accounts with
their own registration, and Azure CLI and Azure PowerShell accounts, are unaffected. -
Windows: every release now opens the
microsoft/winget-pkgspull requests forReothor.Elevate
and `...
Elevate Audit 1.1.0
Added
- Three rules for eligibilities nobody uses, driven by PIM activation history:
ELIGIBLE-ORPHANED
(High — the eligibility is held by a disabled account, a blocked guest, or a principal that no
longer resolves),ELIGIBLE-NEVER-ACTIVATEDandELIGIBLE-DORMANT(Medium for privileged roles,
Low otherwise). All three cover Entra directory roles, PIM for Groups and Azure resource roles,
and each finding carries the last activation date and the age of the eligibility. The HTML report
gains an "Unused eligibility" area. --dormant-after <days>(default 90) sets the dormancy threshold; the activation history is read
over twice that, so a dormant eligibility can be seen at all.- An optional seventh Graph scope,
AuditLog.Read.All, for the PIM entries of the directory audit
log. If consent for it is refused the sign-in is retried without it,activation-historyis
listed as a skipped source, and onlyELIGIBLE-ORPHANEDruns. Azure activations come from ARM's
own request history and need no extra scope. The report states the window it examined, because
directory audit logs are retained for 30 days by default and the tenant may hold less than was
asked for.
Fixed
- winget manifest: the release-notes link points at the
audit-vtag, not the app'svtag.
Install
The read-only companion that lists standing privileged access to move to PIM. One self-contained elevate-audit binary per platform, no runtime to install.
macOS and Linux with Homebrew (the fully qualified name is required: this tap is not a homebrew- named repository):
brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install frodehus/elevate/elevate-audit
Windows: winget install Reothor.Elevate.Audit (the manifest goes to winget-pkgs with each release and is published once Microsoft's checks pass, usually within a day or two), or download elevate-audit-1.1.0-win-x64.zip (or -win-arm64.zip) below and put elevate-audit.exe on your PATH.
Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-audit-1.1.0-checksums.txt. See docs/audit.md.
The Elevate app and CLI are released separately, under the v tags; this release carries the audit tool only.
Elevate 1.7.0
Changed
- Windows: the release workflow signs the MSIs, the app's executable and assemblies,
elevate.exe
andelevate-audit.exewith a Certum code-signing certificate (SimplySign) instead of Azure
Artifact Signing, which is not offered to individuals outside the USA and Canada. The publisher shows as "Open Source
Developer Frode Hus"; SmartScreen may still warn on a new release until reputation builds.
macOS
Signed with Developer ID and notarized.
Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):
brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate
The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.
Or download Elevate-1.7.0.dmg below and drag Elevate to Applications. SHA-256: e7dbc7e2e5b0f5a760d4ee6ebdcabb2af53dcadb58b86db062f0316b4561ceef The DMG is the app alone.
Windows
Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.
Code-signed (Certum). SmartScreen can still show "Windows protected your PC" for a new release until the publisher has built reputation; choose More info, then Run anyway.
SHA-256:
- x64:
d15a3f029b985840b676c37349069e1a01986129696b0c54928758efcaf8faf9 - arm64:
d3ceba88728c1c7044800127039d4df2c9d912169290cf73d6d5f8c84a9e3111
CLI (Linux, macOS, Windows)
One self-contained elevate binary per platform, no runtime to install.
macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.7.0.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:
brew install frodehus/elevate/elevate-cli
Windows: Elevate-1.7.0-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.7.0-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.
Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.7.0-checksums.txt. See cli/README.md.
elevate-audit
The read-only companion that lists standing privileged access to move to PIM is versioned and released on its own, under the audit-v tags: brew install frodehus/elevate/elevate-audit, winget install Reothor.Elevate.Audit once the manifest is submitted, or the archives of the latest audit release. See docs/audit.md.
Enterprise
Elevate-1.7.0.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.7.0.pkg -target /. SHA-256: 73826cebcb4d011064584f30641d249a2b97e74dc635029d47eb228e9d8e4978
Elevate-enterprise-kit-1.7.0.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 4061275aeea05ad826b8de0834eda41046977db41f08a7f056870f2068c4fdab
Deploying Elevate to a fleet starts at docs/enterprise/README.md.
Elevate Audit 1.0.1
Changed
- Windows:
elevate-audit.exeis code-signed with the project's Certum certificate (publisher
"Open Source Developer Frode Hus"), like the app and the CLI.
Install
The read-only companion that lists standing privileged access to move to PIM. One self-contained elevate-audit binary per platform, no runtime to install.
macOS and Linux with Homebrew (the fully qualified name is required: this tap is not a homebrew- named repository):
brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install frodehus/elevate/elevate-audit
Windows: winget install Reothor.Elevate.Audit once the manifest is submitted; until then download elevate-audit-1.0.1-win-x64.zip (or -win-arm64.zip) below and put elevate-audit.exe on your PATH.
Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-audit-1.0.1-checksums.txt. See docs/audit.md.
The Elevate app and CLI are released separately, under the v tags; this release carries the audit tool only.
Elevate 1.6.7
Changed
- elevate-audit: the HTML report opens with an executive summary — a one-sentence verdict and one
tile per area (Entra roles, PIM for Groups, Azure RBAC, Guests, Workload identities, Hygiene,
Coverage) that links to its section — instead of four severity counts. Sections are collapsible,
group findings roll up into one card per group with a membership outline, a nesting diagram and
the people reached, and a small inline script adds search, severity filters, expand/collapse and
50-row caps. The page is complete with JavaScript off and still loads nothing from the network. - elevate-audit: every "Start here" item now carries a pill naming its area, so "User Access
Administrator on Production" reads as Azure RBAC rather than an Entra role, and the pill links to
that section.
macOS
Signed with Developer ID and notarized.
Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):
brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate
The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.
Or download Elevate-1.6.7.dmg below and drag Elevate to Applications. SHA-256: 59ab438bf17463ab51dbabeeee8353698cec5d3bf87a347a5d9459ec5c7594ae The DMG is the app alone.
Windows
Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.
This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.7-x64.msi).Hash.
SHA-256:
- x64:
a861b744f5b4f0b1bb800174fe495d3a280b18ac659cc428bf0e9333e4c9a111 - arm64:
47028696238161434f5fe8705d0d481791fbe51f35e27170665b199e38aacd27
CLI (Linux, macOS, Windows)
One self-contained elevate binary per platform, no runtime to install.
macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.7.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:
brew install frodehus/elevate/elevate-cli
Windows: Elevate-1.6.7-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.7-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.
Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.7-checksums.txt. See cli/README.md.
elevate-audit (Linux, macOS, Windows)
The read-only companion that lists standing privileged access to move to PIM: brew install frodehus/elevate/elevate-audit, or winget install Reothor.Elevate.Audit once the manifest is submitted, or download elevate-audit-1.6.7-<platform> below and put elevate-audit on your PATH. Verify with sha256sum -c elevate-audit-1.6.7-checksums.txt. See docs/audit.md.
Enterprise
Elevate-1.6.7.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.7.pkg -target /. SHA-256: bdc58333b86673375491bdef039bc7ff25fc5279c888bf9b99498656a3cce287
Elevate-enterprise-kit-1.6.7.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 568fd424403ac400eff174806559de46bd3130b9330ff5aa8c4a263edbce9408
Deploying Elevate to a fleet starts at docs/enterprise/README.md.
Elevate 1.6.6
Fixed
- macOS: the "Active now" section was missing from the panel since 1.6.3. The bulk profile
deactivation change kept a copy of the rows in the view and filled it from a task that never ran
inside the panel's lazy list, so the section stayed hidden even with roles active. The rows now
come straight from the model, which also holds a just-deactivated row for the moment its icon
confirms. - Windows: signing an account out, or changing the client id, now also clears its remembered
deactivation errors and in-progress phases, so a stale "deactivation refused" message cannot
reappear on a row after the same account is signed in again.
macOS
Signed with Developer ID and notarized.
Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):
brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate
The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.
Or download Elevate-1.6.6.dmg below and drag Elevate to Applications. SHA-256: 021d66fcf390366895cd027d225be0b67710f3a6492c04a4f96e90c1fd18f265 The DMG is the app alone.
Windows
Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.
This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.6-x64.msi).Hash.
SHA-256:
- x64:
8b4c7a96a935a4c49b5432dd99ea77a23a73a98e117a362b7a7be50a53b4d825 - arm64:
833f4465d0d10fae74110376136c7d663ce11ea9dacd28f276b9ec4b3bc0804c
CLI (Linux, macOS, Windows)
One self-contained elevate binary per platform, no runtime to install.
macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.6.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:
brew install frodehus/elevate/elevate-cli
Windows: Elevate-1.6.6-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.6-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.
Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.6-checksums.txt. See cli/README.md.
elevate-audit (Linux, macOS, Windows)
The read-only companion that lists standing privileged access to move to PIM: brew install frodehus/elevate/elevate-audit, or winget install Reothor.Elevate.Audit once the manifest is submitted, or download elevate-audit-1.6.6-<platform> below and put elevate-audit on your PATH. Verify with sha256sum -c elevate-audit-1.6.6-checksums.txt. See docs/audit.md.
Enterprise
Elevate-1.6.6.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.6.pkg -target /. SHA-256: 9920cc27e4cf2d528b019f021fd8c452ab1c9858295d373ff0003ac5ab73ac00
Elevate-enterprise-kit-1.6.6.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 9e8cae2708c7ba8d1ffb167cc7c9e0dc789eccfee1952111cdec533a1ec86b6f
Deploying Elevate to a fleet starts at docs/enterprise/README.md.
Elevate Audit 1.0.0
Changed
- Released on its own:
elevate-auditnow has its own version number, tag (audit-v<x.y.z>),
GitHub Release ("Elevate Audit x.y.z") and changelog, so a change to the audit tool no longer
rebuilds and re-signs the apps and the CLI, and an app release no longer republishes the audit
tool. The download URLs move to theaudit-vrelease; the Homebrew formula and the winget
manifest follow. elevate-audit updatelooks foraudit-vreleases only, so the app releases that used to carry
an audit archive are never offered as an upgrade.
Shipped with Elevate 1.6.7 - 2026-09-14
The last audit build inside an app release, before the tool's own numbering began at 1.0.0.
Changed
- The HTML report opens with an executive summary — a one-sentence verdict and one tile per area
(Entra roles, PIM for Groups, Azure RBAC, Guests, Workload identities, Hygiene, Coverage) that
links to its section — instead of four severity counts. Sections are collapsible, group
findings roll up into one card per group with a membership outline, a nesting diagram and the
people reached, and a small inline script adds search, severity filters, expand/collapse and
50-row caps. The page is complete with JavaScript off and still loads nothing from the network. - Every "Start here" item now carries a pill naming its area, so "User Access Administrator on
Production" reads as Azure RBAC rather than an Entra role, and the pill links to that section.
Install
The read-only companion that lists standing privileged access to move to PIM. One self-contained elevate-audit binary per platform, no runtime to install.
macOS and Linux with Homebrew (the fully qualified name is required: this tap is not a homebrew- named repository):
brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install frodehus/elevate/elevate-audit
Windows: winget install Reothor.Elevate.Audit once the manifest is submitted; until then download elevate-audit-1.0.0-win-x64.zip (or -win-arm64.zip) below and put elevate-audit.exe on your PATH.
Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-audit-1.0.0-checksums.txt. See docs/audit.md.
The Elevate app and CLI are released separately, under the v tags; this release carries the audit tool only.
Elevate 1.6.5
Added
- Windows: a startup failure now shows in the flyout as an error bar ("Elevate cannot start") with
the message and an Open Settings… button, in place of the role list, as the macOS panel does.
Settings repeats the message next to Copy diagnostics. Before, the flyout stayed empty and the
reason was only inelevate.log.
Changed
- Windows: expiry notifications are now scheduled with Windows instead of being timed inside the app,
so the "expires in 5 minutes" and "expired" toasts still appear after Elevate is quit or crashes, as
they do on macOS. Extend and Activate again launch Elevate when it is not running. The
in-app timer remains as a fallback when the system schedule is unavailable. - macOS, Windows and CLI: the "Cached tokens may be stale" hint after an Azure or group activation
now appears only for accounts signed in with the Azure CLI or Azure PowerShell app, where Elevate
shares the tool's token cache. For an account signed in through an app registration Elevate cannot
tell whether the Azure CLI, Azure PowerShell or kubelogin were ever used as that account, so the
hint no longer asserts that their cached tokens exist. - Windows: the deactivation review uses the same pre-flight verdicts as macOS. A role whose
assignment has not been confirmed active shows "Awaiting active assignment confirmation", one
without a verifiable identity or original activation interval says so, a replaced or expired
assignment reads "Assignment replaced" or "Already inactive or expired", and the minimum period
line becomes "Can be deactivated in N s (minimum activation period)". The Deactivate button
is disabled while every remaining role is blocked instead of only when offline. - Windows: the tenant menu's "Open admin consent link…" is now offered for every account signed in
with the Entra app registration method, not only after discovery fell back to manual roles or
groups became unavailable, so an administrator can re-consent after a scope is added before
anything fails, as on macOS since 1.6.1. - Windows: an account whose saved sign-in is gone at launch (a cleared MSAL or Azure CLI cache, a
revoked session) is kept with its tenants, configured roles and profile entries instead of being
signed out. The account row shows a Sign in button and its menu a Sign in again item
that re-run the account's own sign-in method; refreshes skip the account until then. A read
failure of the token caches keeps every account as it was. Matches macOS.
Fixed
- Windows: the Profiles window says "No roles resolved yet. They appear once the tenants they
name have loaded." for a managed profile whose tenants have not loaded, as on macOS, instead of
the "Add roles…" hint for a control that is not there. - Windows: in the run review, rows that are already active, pending or not eligible reserve the
checkbox width, so their names line up with the rows that have one.
macOS
Signed with Developer ID and notarized.
Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):
brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate
The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.
Or download Elevate-1.6.5.dmg below and drag Elevate to Applications. SHA-256: c2ecf7fc306c7d9b80a0deedae51fe7a2d18d11fe69909f8fbb2cd2d46a446e2 The DMG is the app alone.
Windows
Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.
This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.5-x64.msi).Hash.
SHA-256:
- x64:
7906c8ecc8b88d9bab303d21a690347879b31df148f2cd5de4ff36184bbce5fa - arm64:
87db15f15afaa4ddb4a8db963fc59a1946d866151ff8476596fa0643790deac5
CLI (Linux, macOS, Windows)
One self-contained elevate binary per platform, no runtime to install.
macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.5.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:
brew install frodehus/elevate/elevate-cli
Windows: Elevate-1.6.5-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.5-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.
Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.5-checksums.txt. See cli/README.md.
Enterprise
Elevate-1.6.5.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.5.pkg -target /. SHA-256: 8da0e4d0919c6846b828f4e1f75f2fa093b014eceeeccfd287359c422a7c80a7
Elevate-enterprise-kit-1.6.5.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 12bc1279fbdc0c5e5046c56d120c3037decc5b0a0807a7da71efbbbf68cc6bec
Deploying Elevate to a fleet starts at docs/enterprise/README.md.
Elevate 1.6.4
Added
- macOS and Windows: the run and deactivate reviews for a profile show a checkbox next to each
role, checked by default. Unchecking a role omits it from that one run or deactivation pass;
nothing is remembered onto the profile, and an omitted role stays available to a later pass.
Fixed
- macOS, Windows and CLI: deactivating a role no longer fails with "Revoked". Microsoft Graph and
Azure Resource Manager report a completed self-deactivation with that status, and the
confirmation check added for profile deactivation only accepted "Provisioned".
macOS
Signed with Developer ID and notarized.
Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):
brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate
The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.
Or download Elevate-1.6.4.dmg below and drag Elevate to Applications. SHA-256: b3cc548ed91cdccb48a89797f290f8caf398c61366a49c9c10ba1f1adb792c1e The DMG is the app alone.
Windows
Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.
This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.4-x64.msi).Hash.
SHA-256:
- x64:
28f2b408dba5d2dcd8a3dca6ea8c2fc9fbe34b25b29cd56a2c7ea78be97bcd5c - arm64:
8e64f430ea231ed1e0bd6c13256a380c8f598b5db7eb5905aafc14c1d41b2fb1
CLI (Linux, macOS, Windows)
One self-contained elevate binary per platform, no runtime to install.
macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.4.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:
brew install frodehus/elevate/elevate-cli
Windows: Elevate-1.6.4-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.4-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.
Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.4-checksums.txt. See cli/README.md.
Enterprise
Elevate-1.6.4.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.4.pkg -target /. SHA-256: 4d94ef6c5e01d81795005f7a98f682433a081e9e67710f74f0837b39ffcd87af
Elevate-enterprise-kit-1.6.4.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: c249029ae46957f5e659d15024f0c37ef37c38b7dd60b0f72e1a9a6c9300781c
Deploying Elevate to a fleet starts at docs/enterprise/README.md.
Elevate 1.6.3
Added
- macOS and Windows: the tenant menu gains an Open… submenu that opens the Azure Portal, the
Entra and Intune admin centers, and the Defender and Purview portals directly in that tenant.
The browser session picks the account; Microsoft's sign-in page prompts with the tenant already
fixed when it has none.
Changed
- macOS and Windows: profile runs can now deactivate only the exact role assignments they
activated. Per-role eligibility and results survive restarts, partial failures can be retried,
and confirmed deactivation uses Elevate's chevrons pulsing downward before showing success. - macOS and Windows: per-role progress in activation dialogs and profile runs now uses Elevate's
chevrons pulsing upward. Confirmed activation morphs them into a green circle and check mark;
pending approval, scheduled requests and failures keep their distinct statuses. The animation
respects reduced-motion settings, and activation dialogs briefly hold the success result before closing.
macOS
Signed with Developer ID and notarized.
Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):
brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate
The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.
Or download Elevate-1.6.3.dmg below and drag Elevate to Applications. SHA-256: 74d64707db33e2be3c876aea8abab3f089f6cba3b1f6dd19d08a79c37004a35d The DMG is the app alone.
Windows
Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.
This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.3-x64.msi).Hash.
SHA-256:
- x64:
9ea2c44de5566e5e0f1a1074cc4a59002d0f72cc822f1a194a31f9656806d265 - arm64:
c065e202f5dbcc4ad64595ada732f7125ed60a3b4cb85349ba12c5911c93e382
CLI (Linux, macOS, Windows)
One self-contained elevate binary per platform, no runtime to install.
macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.3.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:
brew install frodehus/elevate/elevate-cli
Windows: Elevate-1.6.3-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.3-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.
Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.3-checksums.txt. See cli/README.md.
Enterprise
Elevate-1.6.3.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.3.pkg -target /. SHA-256: 4fe6ac790d817df9a8c78390733675b6667667cff06c72245363ced794c87134
Elevate-enterprise-kit-1.6.3.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: d429fb0387c2b9aef8ce33a38810fc4a06b6add57d1bce936ffb8a4b9b2ee9cc
Deploying Elevate to a fleet starts at docs/enterprise/README.md.