# Process Elevation Rules

> Control which applications and child processes validated users can run with elevated rights, and how CapaOne matches a process to a rule.

Source: https://docs.capaone.com/capaone/privilege-manager/process-elevation-rules/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

Process elevation rules decide which applications a validated user can run with
**Run with Admin Privileges**, and which child processes those applications can start. You manage
the rules under **Security → Process Elevation Rules** in a Privileges configuration.

Rules only apply to users who pass **Validation**. See
[Privilege Manager Configuration Settings](/capaone/privilege-manager/privilege-manager-configuration-settings/#validation).

## Rule fields

| Field | Description |
|---|---|
| **Name** | A unique name for the rule. Special characters aren't allowed. |
| **Enabled** | Turns the rule on or off. Disabled rules are ignored. |
| **Allow Elevation** | Whether a process that matches the rule may be elevated. Turn it off to block the process. A new rule starts with **Allow Elevation** turned off. |
| **Main Process Name** | The file name of the process, such as `cmd.exe` or `setup.msi`. The name must end with `.exe` or `.msi`, and must be unique across the rules in the configuration. |
| **Main Process Path** | Optional. The folder the process must run from, such as `C:\Windows\System32\`. Enter the folder only, without the file name. |
| **Child Processes** | The processes that the elevated main process may start. See [Child processes](#child-processes). |

Some special characters, including Asian, Arabic, and Cyrillic characters, aren't supported in
process names and paths.

### Paths, wildcards, and environment variables

- Without a wildcard, the path must match the folder exactly. `C:\Windows\System32\` matches
  processes in that folder, but not in its subfolders.
- Use `*` as a wildcard to include subfolders. `C:\Program Files\*` matches processes in any
  subfolder of `C:\Program Files`.
- You can use environment variables, such as `%WinDir%\System32\`.

## The Default rule

Every configuration has a rule named **Default**. It applies when no other enabled rule matches the
process. You can't delete or disable the Default rule, but you can decide whether it allows
elevation.

- **Default allows elevation**: validated users can elevate any `.exe` or `.msi` file, except the
  processes you block with other rules.
- **Default blocks elevation**: validated users can only elevate the processes that other rules
  allow.

A new configuration starts with a Default rule that allows elevation and allows all child
processes.

## How a process is matched

When a user selects **Run with Admin Privileges**, CapaOne checks the enabled rules in the order
they're listed:

1. A rule with only a **Main Process Name** matches when the file name is the same. Case doesn't
   matter.
2. A rule with a **Main Process Name** and a **Main Process Path** matches when both the file name
   and the folder match.
3. The first rule that matches decides whether the process is elevated.
4. If no rule matches, the **Default** rule decides.

If the matching rule blocks elevation, the user sees a message that the process is blocked by
your organization's elevation policy.

## Child processes

Many applications start other processes. For example, `cmd.exe` and `powershell.exe` start the
Console Window Host (`conhost.exe`). The **Child Processes** list controls what the elevated main
process may start:

| Child process | Result |
|---|---|
| Listed and **Allowed** | The child process runs. |
| Listed and not allowed | The child process is stopped. |
| Not listed | Follows the **Default** entry in the list. |

Each rule starts with a **Default** child process entry that is allowed, so all child processes can
run until you change it. To allow only specific child processes, turn off **Allowed** for the
**Default** entry and add the processes you want to allow. Child process names must end with
`.exe`.

You can only change child processes for a rule that allows elevation.

If you restrict child processes for `cmd.exe` or `powershell.exe`, allow `conhost.exe`. See
[Child processes](/capaone/privilege-manager/#child-processes) for why.

## Example: allow only one installer

To let users run one approved installer and nothing else:

1. In the rules list, turn off **Allow Elevation** for the **Default** rule.
2. Click **Add**, enter the rule name `Approved installer`, and confirm. The new rule is selected.
3. Set **Main Process Name** to the installer's file name, for example `setup.exe`.
4. Set **Main Process Path** to the folder the installer runs from.
5. Turn on **Allow Elevation** for the new rule.
6. Save the configuration.

Validated users can now elevate `setup.exe` from that folder. Every other process is blocked by the Default rule.

:::tip
Set a **Main Process Path** on rules that allow elevation. A rule with only a **Main Process Name** matches a file with that name in any folder.
:::

![Process Elevation Rules list with the Default rule and a custom rule named CMD selected, and its Main Process Name, Main Process Path, and Child Processes fields on the right](/attachments/capaone/privilege-manager-process-elevation-rules.png)

## Good to know

- Rule changes take effect on an endpoint after you save the configuration and the endpoint
  receives the updated configuration.
- Process elevation rules aren't active while a user has an elevated session. See
  [Session Elevation](/capaone/privilege-manager/privilege-manager-configuration-settings/#session-elevation).
- To see which processes users elevate, and which are rejected by a rule, use
  [Elevation Analytics](/capaone/privilege-manager/elevation-analytics/).
