Display Denial Reason to End User
complete
J
James Judd
AutoElevate currently provides a section where a technician can enter an explanation for why an elevation request was denied. However, this explanation is only visible within the portal or PSA integration and is not shown to the end user.
It would be helpful to have the ability to display this denial reason directly to the user when their request is rejected, rather than only presenting a generic denial message.
For example, a technician could specify that an application was denied because it modifies protected system files, is not approved for business use, is considered a security risk, or could negatively impact the stability of the system.
The end-user notification could display either the technician-entered explanation or a customizable message such as:
“This request has been blocked by your organization's security policy. Applications may be denied because they modify protected system components, are not approved for business use, or present a security risk that could compromise the stability or security of your system.
If you believe this application is required for business purposes, please contact IT for further review.”
Providing the actual denial reason would give users more context, reduce confusion, and potentially reduce unnecessary repeat requests or support tickets asking why an application was blocked.
D
Daniel Rivera
updated the status to
complete
D
Daniel Rivera
Hi James — good news on this one: it's already available.
When you deny an elevation request, the deny dialog includes a "Denial reason (shown to the end user, optional)" field, and whatever you enter there is displayed to the user in the denial pop-up on their machine. The same field is available in the mobile app and on the Partner API deny endpoint.
If you're not seeing it, a couple of things to check:
Agent version — this arrived in Windows agent v2.11.1432.0 (GA, Aug 26). If your endpoints are still on a 2.10.x build, the phased rollout likely hasn't reached them yet. You can pull it forward by switching to the beta channel under Settings → Agent Customizations & Behavior → Agent Update Channel, or per-machine via the Actions dropdown in the Computers grid.
macOS — end-user display of the denial reason isn't in the Mac agent yet; it's Windows today. The reason is still stored and visible to your techs.
If you're on a current agent and it's still not showing, please reach out to support@cyberfox.com and we'll dig into it with you.