The Discovery policy contains Workstyles, Application Groups, and messages to allow the discovery of applications that need administrative privileges to execute. This must be applied to administrator users and includes a preconfigured exclusion group (false positives) maintained by BeyondTrust.

This template policy contains the following configurations:


  • Discovery Workstyle

Application Groups

  • (Default Rule) Any Application
  • (Default Rule) Any UAC Prompts
  • Approved Standard User Apps
  • Passive - All Users & Apps


  • Allow Message (Yes / No)