evosecurity

Product Information

Training Mode: Auto Enrollment

Overview

Auto Enrollment allows administrators to automatically enroll only users and computers that generate End User Elevation (EUE) activity into Training Mode. Unlike traditional Training Mode, which enrolls an entire tenant, group, or endpoint,Auto Enrollment detects elevation activity and enrolls members individually.

This approach enables administrators to review real elevation requests, create Elevation Rules based on actual usage, and remove users or computers from Training Mode independently as they complete the review process.


Prerequisites

Before configuring Auto Enrollment, verify the following:

  • End User Elevation is enabled for the tenant.
  • End User Elevation licenses have been assigned to participating endpoints.
  • The Evo Agent is installed and communicating.
  • Your account has permission to manage Elevation Training.

For General EUE setup and rule creating, also see: Getting Started: End User Elevation Usage Guide: End User Elevation


Configure Auto-Enrollment

  1. In the Evo Portal, select the desired Tenant.
  1. Navigate to Elevation → Training → Auto-Enrollment.
  1. Under Auto-enroll Applies To, choose the desired enrollment mode.
  1. Configure Retrain Known Users if required.
  1. Click Save Changes.
  1. Add a Tenant or Group enrollment source.
Notion image

Auto-Enrollment Modes

Mode
Description
Computers and Users
Automatically enrolls both computers and mapped Evo users.
Computers Only
Only computers are enrolled into Training Mode.
Users Only
Only mapped Evo users are enrolled into Training Mode.
Disabled
Stops future automatic detections. Existing detected members remain in Training Mode until manually completed or removed.
Note: Group enrollment sources detect Users only. To automatically detect computers, use a Tenant enrollment source.

Add an Enrollment Source

Enrollment Sources define where Evo monitors for elevation activity.

To add a source:

  1. Navigate to Elevation → Training.
  1. Select Add to Training.
  1. Choose a Tenant or Group.
  1. Enable the selected source.
  1. Save your changes.

Once activity is detected, the Training page displays:

  • The Enrollment Source
  • Detected Users
  • Detected Computers
  • Training progress (for example, 3 / 8 Trained)
Notion image

Review Training Activity

Navigate to:

Elevation → Training → Activity

The Activity tab displays elevation requests collected while members are in Training Mode, including:

  • Application
  • User
  • Computer
  • Elevation Result
  • Training member that approved the request

Review this activity to determine which applications require Elevation Rules before marking members as trained.

Notion image

Mark a Member as Trained

Users and computers maintain independent Training statuses.

To complete Training for a member:

  1. Select the User or Computer.
  1. Click Mark as Trained.
  1. Confirm the action.
Notion image
Notion image
Note: Marking a User as trained does not mark any associated computers as trained.

Return a Member to Training

If additional elevation activity needs to be collected:

  1. Select the trained User or Computer.
  1. Choose Return to Training.
  1. Confirm the action.
Notion image

The member returns to In Training and resumes collecting elevation activity.


Manage Enrollment Sources

Enrollment Sources include bulk actions for their detected members.

Available actions include:

  • Mark as Trained – Marks all currently active detected members under the source as trained.
    • Notion image
  • Return to Training – Returns previously completed members to Training Mode.
Notion image

These actions affect only detected members and do not disable or remove the Enrollment Source. Future detections continue while the source remains enabled.


Retrain Known Users

The Retrain Known Users setting determines whether a previously trained user should automatically enter Training Mode again after being detected on a different computer.

Disabled

  • Previously trained users remain trained regardless of which computer they use.
  • Newly detected computers can still be enrolled independently.

Enabled

  • A new Training context is created whenever a trained user is detected on a different computer.
  • Previous Training history remains available for review.

Disable Auto-Enrollment

Setting Auto-Enrollment to Disabled prevents future automatic detections.

Existing detected members are not automatically completed and remain in Training Mode until they are:

  • Marked as Trained
  • Removed
  • Completed by removing the Enrollment Source

Remove an Enrollment Source

When removing an Enrollment Source, choose how active detected members should be handled.

Keep Detected Members in Training

Removes the Enrollment Source while leaving all currently detected users and computers in their existing Training state.

Use this option when you want to stop discovering new members but continue reviewing existing ones individually.

Mark Current Members as Trained

Removes the Enrollment Source and immediately marks all currently detected members as trained.

Use this option after Training Mode review has been completed for all remaining members.

Notion image

Best Practices

For the most effective rollout:

  • Enable Auto-Enrollment before users begin working.
  • Choose the smallest practical Tenant or Group as the Enrollment Source.
  • Allow normal administrative work to generate elevation requests.
  • Review collected activity before creating Elevation Rules.
  • Mark users and computers as trained independently.
  • Disable Auto-Enrollment when new detections are no longer required.
  • Remove Enrollment Sources once Training Mode has been completed.

Troubleshooting

User Does Not Appear by Name

Verify the Windows username has been configured as an alias for the corresponding Evo user.

Unmapped accounts may still appear through Computer or Tenant Training but will not create mapped User members.


Computer Is Not Detected

Verify the following:

  • The endpoint has an End User Elevation license.
  • The Evo Agent is installed and communicating.
  • Auto-Enrollment is configured for Computers and Users or Computers Only.
  • The Enrollment Source is a Tenant, not a Group.

Members Remain in Training After Auto-Enrollment Is Disabled

This is expected behavior.

Disabling Auto-Enrollment only prevents future detections. Existing detected members remain active until they are manually completed or removed.


Training Continues After Auto-Enrollment Is Disabled

Verify that a Tenant or Group has not remained configured as a manual Training Source.

Removing the remaining Training Source ends broad Training Mode enrollment.

Did this answer your question?
😞
😐
🤩