Allowing Passwordless Run-As

Using HYPR Passwordless: Windows

This page describes how to use the HYPR Passwordless client with the HYPR Mobile App to escalate admin privileges for a domain user account. In this document we will show a multi-user, multi-device flow (Local Run-as / Helpdesk) and multi-user single device flow (Privilege escalation).

Localized Run As

Why is this important?
In enterprises, domain users can go to helpdesk admins to fix any problems associated with their workstation. Helpdesk administrators have to manually enter their admin username/password to get admin access to applications like Regedit, etc., to find the root cause of the problem. Now, any helpdesk admin can use HYPR to login without entering a username/password.

  1. Login as a domain user and pair a mobile device following the steps in Pairing with the HYPR Mobile App.
  2. Login as an administrator, and right-click HYPR HYPR Passwordless client to Run as administrator.
  3. Pair a separate mobile device following the steps in Pairing with the HYPR Mobile App.

At this point you have successfully paired on device 1 - account 1 (domain user) and device 2 - account 2 (domain admin). Now let's see how a domain admin can obtain escalated privilege without entering username/password.

Run As Administrator (Starting As a User)

  1. Login as a domain user.
  2. Right-click any application and choose Run as administrator.
  3. Choose the HYPR Mobile App option to login to an admin account.
  4. Complete HYPR Passwordless authentication using the method you chose earlier.
  5. The workstation will require administrator credentials; provided the workstation is configured to allow the admin passwordless access, no passwords will be required to access the chosen application as an administrator.

Multi-user, Single Device (Privilege Escalation)

A domain user can get elevated access of a local admin with a single mobile device. These are the steps.

Register a Domain User

Login with your domain user credentials and follow the instructions for Pairing with the HYPR Mobile App.

Register a Local Administrator

  1. Shift + right-click the HYPR Passwordless client icon and select Run as administrator.
  1. Enter the local admin credentials to open the HYPR Passwordless application.
  1. Register with the HYPR Passwordless client application using the same HYPR Mobile App. Once enrollment is finished, you will see a second user account added to the HYPR Mobile App.

Escalate User Privileges with the HYPR Mobile App.

  1. While logged in as a non-admin domain user, attempt to launch a program using Runs as administrator.
  1. Choose to authenticate with the HYPR Mobile App when a permissions escalation prompt is given.
1652
  1. Authenticate via HYPR using the method you chose for the local admin earlier. The application passwordlessly opens with administrator permissions.

🚧

Note

Run as... a different user can only be used to register/enroll with another account. If the user wants to log in, then please use Run as administrator.

Run as... functionality is demonstrated so that any user account (local admin, domain user, domain admin) can be used to register as the second account. But as explained, it cannot be used for login.