# Create a Privilege Manager Configuration

> Create a Privileges configuration that decides who can elevate on which endpoints, then assign it to endpoints or groups.

Source: https://docs.capaone.com/capaone/privilege-manager/create-a-privilege-manager-configuration/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

A Privileges configuration controls who can run applications with elevated rights, which
applications they can elevate, and whether they can elevate their whole Windows session. This page
shows you how to create one and assign it to endpoints.

:::note[Before you start]
- The CapaOne agent is installed on the endpoints. See [Windows Enrollment](/capaone/enrollment/windows-enrollment/).
- User Account Control is enabled and configured on the endpoints. See the
  [Privilege Manager prerequisites](/capaone/privilege-manager/#prerequisites).
- To validate users against Entra ID groups, set up the Entra ID integration first. See
  [Integrate CapaOne with Entra ID](/capaone/integrations/integrate-capaone-with-entra-id/).
:::

## Create the configuration

1. Go to **Windows → Configurations**.
2. Select the **Privileges** tab.
3. Click **New**. If you're asked for a configuration type, select **Privileges**.
4. Enter a name for the configuration. The name must be unique and can't contain special
   characters.
5. Under **Validation**, add at least one way to identify the users who are allowed to elevate.
   You can combine several methods:
   - **Entra ID Groups**
   - **On-Prem AD Groups**
   - **Local Groups**
   - **Endpoint Admins**
   - **Global Admins**
6. Optional: under **Branding**, adjust the **Informational Text** and **Confirmation Text** that
   users see before a process is elevated.
7. Optional: under **Security**, add **Process Elevation Rules** to control which applications
   users can elevate.
8. Optional: under **Security → Session Elevation**, turn on session elevation or hide the
   built-in **Run as administrator** menu item.
9. Click **Create**.

The configuration appears in the list on the **Privileges** tab.

![New Privileges configuration page with the Name field, the Create and Cancel buttons, and a left menu grouped under Validation, Branding, and Security](/attachments/capaone/privilege-manager-new-configuration.png)

For a description of every setting, see
[Privilege Manager Configuration Settings](/capaone/privilege-manager/privilege-manager-configuration-settings/).

:::caution
A user must pass **Validation** before any process elevation rule applies. A configuration with
rules but no validation method lets no one elevate. See
[Missing Privileges](/capaone/troubleshooting/missing-privileges/).
:::

## Assign the configuration

A configuration has no effect until it's assigned.

1. On the **Privileges** tab, click the options menu (**⋮**) next to the configuration.
2. Select **Assignment**, and then choose one of the following:
   - **Direct** to assign the configuration to individual endpoints.
   - **Groups** to assign it to groups of endpoints.
3. Click **Assign**, and move the endpoints or groups from **Available** to **Assigned**. See
   [Assign a configuration](/capaone/windows-management/windows-configurations/#assign-a-configuration).

The endpoints receive the configuration the next time they communicate with CapaOne. Users on
those endpoints can now right-click an `.exe` or `.msi` file and select
**Run with Admin Privileges**.

If an endpoint is covered by more than one Privileges configuration, the configuration with the
highest priority applies. See [Configuration Priority](/capaone/reference/configuration-priority/).

## Edit the configuration

1. On the **Privileges** tab, click the options menu (**⋮**) next to the configuration.
2. Select **Edit**.
3. Make your changes, and then click **Save** to stay on the page or **Save and close** to return
   to the list.

If a user still can't elevate after a change, ask them to sign out of Windows and sign in again.

## Related

- [Privilege Manager Configuration Settings](/capaone/privilege-manager/privilege-manager-configuration-settings/)
- [Process Elevation Rules](/capaone/privilege-manager/process-elevation-rules/)
- [Elevation Analytics](/capaone/privilege-manager/elevation-analytics/)
