Skip to content

Elevate 1.6.3

Choose a tag to compare

@github-actions github-actions released this 12 Sep 15:11
· 203 commits to main since this release

Added

  • macOS and Windows: the tenant menu gains an Open… submenu that opens the Azure Portal, the
    Entra and Intune admin centers, and the Defender and Purview portals directly in that tenant.
    The browser session picks the account; Microsoft's sign-in page prompts with the tenant already
    fixed when it has none.

Changed

  • macOS and Windows: profile runs can now deactivate only the exact role assignments they
    activated. Per-role eligibility and results survive restarts, partial failures can be retried,
    and confirmed deactivation uses Elevate's chevrons pulsing downward before showing success.
  • macOS and Windows: per-role progress in activation dialogs and profile runs now uses Elevate's
    chevrons pulsing upward. Confirmed activation morphs them into a green circle and check mark;
    pending approval, scheduled requests and failures keep their distinct statuses. The animation
    respects reduced-motion settings, and activation dialogs briefly hold the success result before closing.

macOS

Signed with Developer ID and notarized.

Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate

The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.

Or download Elevate-1.6.3.dmg below and drag Elevate to Applications. SHA-256: 74d64707db33e2be3c876aea8abab3f089f6cba3b1f6dd19d08a79c37004a35d The DMG is the app alone.

Windows

Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.

This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.3-x64.msi).Hash.

SHA-256:

  • x64: 9ea2c44de5566e5e0f1a1074cc4a59002d0f72cc822f1a194a31f9656806d265
  • arm64: c065e202f5dbcc4ad64595ada732f7125ed60a3b4cb85349ba12c5911c93e382

CLI (Linux, macOS, Windows)

One self-contained elevate binary per platform, no runtime to install.

macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.3.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:

brew install frodehus/elevate/elevate-cli

Windows: Elevate-1.6.3-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.3-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.3-checksums.txt. See cli/README.md.

Enterprise

Elevate-1.6.3.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.3.pkg -target /. SHA-256: 4fe6ac790d817df9a8c78390733675b6667667cff06c72245363ced794c87134

Elevate-enterprise-kit-1.6.3.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: d429fb0387c2b9aef8ce33a38810fc4a06b6add57d1bce936ffb8a4b9b2ee9cc

Deploying Elevate to a fleet starts at docs/enterprise/README.md.