Admin By Request (ABR) is a privilege management tool that allows users to request temporary local administrator rights in a controlled, auditable, and secure way.
It helps reduce risks from malware, accidental system changes, and unauthorised software installation, while still allowing users to perform legitimate admin tasks.
ABR works together with the following controls:
- Platform SSO – Revokes permanent local admin rights
- Admin By Request (ABR) – Handles day-to-day admin elevation requests, unless access is pre-approved
- Cloudflare Always-On – Enforces secure, always-on network connectivity
⚠️ Pilot notice
Admin By Request (ABR) is currently in a pilot phase.
- This implementation applies only to selected users
- Not all users will have Admin By Request enabled
- Platform SSO and admin elevation workflows described in this guide apply only to pilot users
- Users not in the pilot group will not see Admin By Request prompts or functionality
Before using Admin By Request, ensure the following requirements are met.
Platform SSO must be configured on your device before Admin By Request can be installed automatically and function correctly.
Refer to the Platform SSO setup guide.
Turn on Full Disk Access in Privacy & Security for the following:
- Admin By Request System Extension
- Admin By Request
Allow Admin By Request ApS under Login Items & Extensions.
Allow the security extension for Admin By Request:
- Go to Login Items & Extensions.
- Select Extensions.
- Select By App.
- Locate Admin By Request.
- Select the ⓘ (info) button.
- Turn on Security Extension, then select Done.
- Select the Admin By Request icon in the menu bar.
- Select About Admin By Request.
- Confirm that the following statuses are OK:
- Operational Status
- Cloud Connectivity
If an error is shown, follow the steps in What if Admin By Request is showing error?.
Ensure Cloudflare Always-On is enabled and connected before requesting admin access.
- Right-click the application you want to run, or double-click the
.pkgfile. - The Admin By Request prompt appears.
Note
On Windows devices, right-click the application and select Run as administrator.
- Enter the following details:
- Phone number
- Email address
- Reason for the request
(The reason must be more than 5 characters.)
- Complete MFA using your tech.gov.sg account.
- Your request is sent to ABR portal approvers.
- The approver receives a notification by email or via the dashboard.
- Once approved, a temporary admin session is granted.
- Complete MFA using your TechPass account.
If you are in pre-approved mode, your request is automatically approved.
- Select the Admin By Request icon in the menu bar.
- Select Request administrator access.
- Enter:
- Phone number
- Email address
- Reason for the request
- Complete MFA using your tech.gov.sg account.
When approved:
- A timer starts counting down the allowed admin duration.
- An ABR icon with the remaining time appears in the menu bar.
- Temporary local administrator rights are granted.
- Install software
- Update applications
- Run scripts or tools that require admin rights
- Disable Admin By Request
- Extend the session beyond the policy limit
- Gain permanent administrator rights
The admin session ends when:
- The 15-minute timer expires, or
- You select Finish from the Admin By Request menu
After the session ends:
- Temporary admin rights are removed
- All elevated actions are logged in the ABR portal
Uninstallation requires a PIN.
Please approach the SEED team for assistance.
Is this permanent admin access?
No. Admin By Request only grants temporary, audited administrator rights.
Admin access is removed automatically when the session ends.
Does Admin By Request work offline?
No. Admin By Request requires an active internet connection because MFA must be completed online.
Can users bypass Admin By Request?
No. Users cannot bypass Admin By Request if device permissions and allowed applications are configured correctly.
Can admins review what was done during an admin session?
Yes. Administrators can review elevated activities via the Audit Log, if command logging is enabled.
What if Admin By Request is showing error?
If Cloud Connectivity is shown as Red and Active Directory Domain is empty, Admin By Request is unable to communicate with Entra ID.
Check the following:
- Company Portal.app for device registration errors
- Device Management Profile in macOS Settings
Ensure that ABR-FDA and ABR-System-Extension profiles exist
If there is an Intune enrolment issue, required profiles may not be pushed to the device.















