Elevate 1.6.5
Added
- Windows: a startup failure now shows in the flyout as an error bar ("Elevate cannot start") with
the message and an Open Settings… button, in place of the role list, as the macOS panel does.
Settings repeats the message next to Copy diagnostics. Before, the flyout stayed empty and the
reason was only inelevate.log.
Changed
- Windows: expiry notifications are now scheduled with Windows instead of being timed inside the app,
so the "expires in 5 minutes" and "expired" toasts still appear after Elevate is quit or crashes, as
they do on macOS. Extend and Activate again launch Elevate when it is not running. The
in-app timer remains as a fallback when the system schedule is unavailable. - macOS, Windows and CLI: the "Cached tokens may be stale" hint after an Azure or group activation
now appears only for accounts signed in with the Azure CLI or Azure PowerShell app, where Elevate
shares the tool's token cache. For an account signed in through an app registration Elevate cannot
tell whether the Azure CLI, Azure PowerShell or kubelogin were ever used as that account, so the
hint no longer asserts that their cached tokens exist. - Windows: the deactivation review uses the same pre-flight verdicts as macOS. A role whose
assignment has not been confirmed active shows "Awaiting active assignment confirmation", one
without a verifiable identity or original activation interval says so, a replaced or expired
assignment reads "Assignment replaced" or "Already inactive or expired", and the minimum period
line becomes "Can be deactivated in N s (minimum activation period)". The Deactivate button
is disabled while every remaining role is blocked instead of only when offline. - Windows: the tenant menu's "Open admin consent link…" is now offered for every account signed in
with the Entra app registration method, not only after discovery fell back to manual roles or
groups became unavailable, so an administrator can re-consent after a scope is added before
anything fails, as on macOS since 1.6.1. - Windows: an account whose saved sign-in is gone at launch (a cleared MSAL or Azure CLI cache, a
revoked session) is kept with its tenants, configured roles and profile entries instead of being
signed out. The account row shows a Sign in button and its menu a Sign in again item
that re-run the account's own sign-in method; refreshes skip the account until then. A read
failure of the token caches keeps every account as it was. Matches macOS.
Fixed
- Windows: the Profiles window says "No roles resolved yet. They appear once the tenants they
name have loaded." for a managed profile whose tenants have not loaded, as on macOS, instead of
the "Add roles…" hint for a control that is not there. - Windows: in the run review, rows that are already active, pending or not eligible reserve the
checkbox width, so their names line up with the rows that have one.
macOS
Signed with Developer ID and notarized.
Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):
brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate
The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.
Or download Elevate-1.6.5.dmg below and drag Elevate to Applications. SHA-256: c2ecf7fc306c7d9b80a0deedae51fe7a2d18d11fe69909f8fbb2cd2d46a446e2 The DMG is the app alone.
Windows
Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.
This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.5-x64.msi).Hash.
SHA-256:
- x64:
7906c8ecc8b88d9bab303d21a690347879b31df148f2cd5de4ff36184bbce5fa - arm64:
87db15f15afaa4ddb4a8db963fc59a1946d866151ff8476596fa0643790deac5
CLI (Linux, macOS, Windows)
One self-contained elevate binary per platform, no runtime to install.
macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.5.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:
brew install frodehus/elevate/elevate-cli
Windows: Elevate-1.6.5-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.5-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.
Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.5-checksums.txt. See cli/README.md.
Enterprise
Elevate-1.6.5.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.5.pkg -target /. SHA-256: 8da0e4d0919c6846b828f4e1f75f2fa093b014eceeeccfd287359c422a7c80a7
Elevate-enterprise-kit-1.6.5.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 12bc1279fbdc0c5e5046c56d120c3037decc5b0a0807a7da71efbbbf68cc6bec
Deploying Elevate to a fleet starts at docs/enterprise/README.md.