Skip to content

Elevate 1.6.5

Choose a tag to compare

@github-actions github-actions released this 13 Sep 12:54
· 162 commits to main since this release

Added

  • Windows: a startup failure now shows in the flyout as an error bar ("Elevate cannot start") with
    the message and an Open Settings… button, in place of the role list, as the macOS panel does.
    Settings repeats the message next to Copy diagnostics. Before, the flyout stayed empty and the
    reason was only in elevate.log.

Changed

  • Windows: expiry notifications are now scheduled with Windows instead of being timed inside the app,
    so the "expires in 5 minutes" and "expired" toasts still appear after Elevate is quit or crashes, as
    they do on macOS. Extend and Activate again launch Elevate when it is not running. The
    in-app timer remains as a fallback when the system schedule is unavailable.
  • macOS, Windows and CLI: the "Cached tokens may be stale" hint after an Azure or group activation
    now appears only for accounts signed in with the Azure CLI or Azure PowerShell app, where Elevate
    shares the tool's token cache. For an account signed in through an app registration Elevate cannot
    tell whether the Azure CLI, Azure PowerShell or kubelogin were ever used as that account, so the
    hint no longer asserts that their cached tokens exist.
  • Windows: the deactivation review uses the same pre-flight verdicts as macOS. A role whose
    assignment has not been confirmed active shows "Awaiting active assignment confirmation", one
    without a verifiable identity or original activation interval says so, a replaced or expired
    assignment reads "Assignment replaced" or "Already inactive or expired", and the minimum period
    line becomes "Can be deactivated in N s (minimum activation period)". The Deactivate button
    is disabled while every remaining role is blocked instead of only when offline.
  • Windows: the tenant menu's "Open admin consent link…" is now offered for every account signed in
    with the Entra app registration method, not only after discovery fell back to manual roles or
    groups became unavailable, so an administrator can re-consent after a scope is added before
    anything fails, as on macOS since 1.6.1.
  • Windows: an account whose saved sign-in is gone at launch (a cleared MSAL or Azure CLI cache, a
    revoked session) is kept with its tenants, configured roles and profile entries instead of being
    signed out. The account row shows a Sign in button and its menu a Sign in again item
    that re-run the account's own sign-in method; refreshes skip the account until then. A read
    failure of the token caches keeps every account as it was. Matches macOS.

Fixed

  • Windows: the Profiles window says "No roles resolved yet. They appear once the tenants they
    name have loaded." for a managed profile whose tenants have not loaded, as on macOS, instead of
    the "Add roles…" hint for a control that is not there.
  • Windows: in the run review, rows that are already active, pending or not eligible reserve the
    checkbox width, so their names line up with the rows that have one.

macOS

Signed with Developer ID and notarized.

Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate

The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.

Or download Elevate-1.6.5.dmg below and drag Elevate to Applications. SHA-256: c2ecf7fc306c7d9b80a0deedae51fe7a2d18d11fe69909f8fbb2cd2d46a446e2 The DMG is the app alone.

Windows

Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.

This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.5-x64.msi).Hash.

SHA-256:

  • x64: 7906c8ecc8b88d9bab303d21a690347879b31df148f2cd5de4ff36184bbce5fa
  • arm64: 87db15f15afaa4ddb4a8db963fc59a1946d866151ff8476596fa0643790deac5

CLI (Linux, macOS, Windows)

One self-contained elevate binary per platform, no runtime to install.

macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.5.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:

brew install frodehus/elevate/elevate-cli

Windows: Elevate-1.6.5-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.5-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.5-checksums.txt. See cli/README.md.

Enterprise

Elevate-1.6.5.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.5.pkg -target /. SHA-256: 8da0e4d0919c6846b828f4e1f75f2fa093b014eceeeccfd287359c422a7c80a7

Elevate-enterprise-kit-1.6.5.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 12bc1279fbdc0c5e5046c56d120c3037decc5b0a0807a7da71efbbbf68cc6bec

Deploying Elevate to a fleet starts at docs/enterprise/README.md.