Skip to content

Elevate 1.6.7

Choose a tag to compare

@github-actions github-actions released this 14 Sep 07:24
· 84 commits to main since this release

Changed

  • elevate-audit: the HTML report opens with an executive summary — a one-sentence verdict and one
    tile per area (Entra roles, PIM for Groups, Azure RBAC, Guests, Workload identities, Hygiene,
    Coverage) that links to its section — instead of four severity counts. Sections are collapsible,
    group findings roll up into one card per group with a membership outline, a nesting diagram and
    the people reached, and a small inline script adds search, severity filters, expand/collapse and
    50-row caps. The page is complete with JavaScript off and still loads nothing from the network.
  • elevate-audit: every "Start here" item now carries a pill naming its area, so "User Access
    Administrator on Production" reads as Azure RBAC rather than an Entra role, and the pill links to
    that section.

macOS

Signed with Developer ID and notarized.

Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate

The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.

Or download Elevate-1.6.7.dmg below and drag Elevate to Applications. SHA-256: 59ab438bf17463ab51dbabeeee8353698cec5d3bf87a347a5d9459ec5c7594ae The DMG is the app alone.

Windows

Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.

This build is not code-signed. Windows SmartScreen shows "Windows protected your PC" the first time you run the installer: choose More info, then Run anyway. Verify the download against the SHA-256 first with (Get-FileHash .\Elevate-1.6.7-x64.msi).Hash.

SHA-256:

  • x64: a861b744f5b4f0b1bb800174fe495d3a280b18ac659cc428bf0e9333e4c9a111
  • arm64: 47028696238161434f5fe8705d0d481791fbe51f35e27170665b199e38aacd27

CLI (Linux, macOS, Windows)

One self-contained elevate binary per platform, no runtime to install.

macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.6.7.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:

brew install frodehus/elevate/elevate-cli

Windows: Elevate-1.6.7-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.6.7-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.6.7-checksums.txt. See cli/README.md.

elevate-audit (Linux, macOS, Windows)

The read-only companion that lists standing privileged access to move to PIM: brew install frodehus/elevate/elevate-audit, or winget install Reothor.Elevate.Audit once the manifest is submitted, or download elevate-audit-1.6.7-<platform> below and put elevate-audit on your PATH. Verify with sha256sum -c elevate-audit-1.6.7-checksums.txt. See docs/audit.md.

Enterprise

Elevate-1.6.7.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.6.7.pkg -target /. SHA-256: bdc58333b86673375491bdef039bc7ff25fc5279c888bf9b99498656a3cce287

Elevate-enterprise-kit-1.6.7.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 568fd424403ac400eff174806559de46bd3130b9330ff5aa8c4a263edbce9408

Deploying Elevate to a fleet starts at docs/enterprise/README.md.