Offline Technician Mode and Just-in-Time Admin Login
Table of Contents
Overview
Offline elevation allows a technician to use Technician Mode or Just-in-Time (JIT) Admin Login when a Windows computer cannot communicate directly with AutoElevate.
The computer displays an offline challenge that the technician scans with the AutoElevate Notify mobile app. The app securely processes the challenge and returns a one-time response code. The technician enters that code on the computer to continue.
This provides controlled administrative access for isolated computers, restricted networks, and temporary connectivity failures without requiring the endpoint itself to be online.
Important: Offline elevation does not mean every component is offline. The technician’s mobile device must have internet access, the technician must be signed into the AutoElevate Notify app, and the AutoElevate service must be reachable.
Video Overview
Watch the following walkthrough for a demonstration of Offline Technician Mode and Offline JIT Admin Login.
What Offline Elevation Is
Offline elevation is a secure challenge-and-response process that allows an AutoElevate agent to authorize an action without communicating directly with the AutoElevate service during that action.
It supports two Windows elevation workflows:
Offline Technician Mode
Technician Mode temporarily allows an authorized technician to perform administrative work within an active Windows session.
Use this option when:
- A user or technician is already signed in to Windows.
- The computer cannot reach AutoElevate.
- The technician needs to respond to UAC prompts or perform administrative work.
- Technician Mode is enabled for the computer.
- The technician has permission to use Technician Mode.
Offline JIT Admin Login
JIT Admin Login provides authorized administrative access from the Windows sign-in screen.
Use this option when:
- Administrative access is required before signing in to Windows.
- The AutoElevate JIT credential tile is available.
- The computer cannot communicate directly with AutoElevate.
- The technician is authorized to use JIT Admin Login.
This is separate from JIT Domain Login. Offline JIT Admin Login applies to the local Windows administrative workflow described in this article.
Understanding “Offline”
AutoElevate determines whether to use the online or offline workflow based on whether the endpoint can reach the AutoElevate service.
A computer may be connected to a local network, or even have general internet access, while still being unable to communicate with AutoElevate. In that situation, the offline workflow may appear.
The following components are still required:
- The AutoElevate agent must be installed and support offline elevation (Version 2.11.1432.0 or later).
- The computer must have successfully checked in previously.
- The technician must have a supported mobile device with internet access.
- The technician must be signed in to the AutoElevate Notify app.
- The AutoElevate service must be available to the mobile app.
- The technician’s account must have access to the company and computer.
Offline elevation will not work during a complete AutoElevate service outage because the mobile app cannot process the offline challenge. Maintain an appropriate break-glass administrative account for emergency access.
How Offline Elevation Works
The same general workflow applies to Technician Mode and JIT Admin Login.
- The AutoElevate agent attempts to connect to the AutoElevate service.
- If the endpoint cannot establish that connection, the agent displays an offline challenge.
- The technician opens the AutoElevate Notify app on an internet-connected mobile device.
- The technician scans the challenge displayed on the computer.
- AutoElevate confirms that the signed-in technician is authorized to act on that computer.
- The mobile app displays a one-time response code.
- The technician enters the response code on the computer.
- The agent validates the code locally and grants the requested access.
The response code is displayed in uppercase. Code entry is not case-sensitive, and the agent automatically converts entered characters to uppercase.
Requirements
Before using offline elevation, verify the following requirements.
Endpoint Requirements
- A supported AutoElevate agent is installed (Version 2.11.1432.0 or later).
- The agent has successfully checked in with AutoElevate at least once.
- The computer was provisioned for offline elevation during a previous connection.
- The computer cannot currently reach the AutoElevate service.
- For Technician Mode, a user is signed in to Windows.
- For JIT Admin Login, the AutoElevate credential provider is installed and available on the Windows sign-in screen.
A newly installed computer that has never checked in cannot use offline elevation because the required configuration has not yet been delivered to the agent.
Technician Requirements
- The technician has an active AutoElevate account.
- The technician is signed in to the AutoElevate Notify app.
- The mobile device has internet access.
- The technician has access to the company containing the computer.
- The technician has the required role and feature permissions.
A technician associated with another MSP or without access to the computer’s company cannot complete the request.
Using Offline Technician Mode
Offline Technician Mode applies to supported Windows computers with an active user session.
- Sign in to Windows on the affected computer.
- Press Ctrl + Alt + A to open Technician Mode.
- Allow the agent time to attempt its normal online connection.
- When the offline challenge appears, open the AutoElevate Notify app.
- Select the QR code scanner.
- Scan the challenge displayed on the computer.
- Complete device authentication if prompted.
- Enter the response code displayed by the mobile app.
- Continue into Technician Mode.
If the endpoint successfully connects to AutoElevate, the normal online authentication workflow appears instead. This is expected behavior.
Using Offline JIT Admin Login
Offline JIT Admin Login is initiated from the Windows sign-in or lock screen.
- At the Windows sign-in screen, select the AutoElevate JIT credential tile.
- Begin the JIT Admin Login process.
- Allow the credential provider time to attempt its normal online connection.
- When the offline challenge appears, open the AutoElevate Notify app.
- Scan the challenge.
- Complete device authentication if prompted.
- Enter the response code displayed in the app.
- Continue with the JIT administrative login.
If the AutoElevate credential tile is missing, confirm that the JIT credential provider is installed and that no third-party authentication product is preventing it from loading.
AutoElevate Notify App
The mobile portion of the process is performed through the AutoElevate Notify app.
iOS
- Confirm the iPhone or iPad has internet access.
- Open AutoElevate Notify.
- Sign in or refresh the session if prompted.
- Select the QR scanner.
- Allow camera access if requested.
- Scan the offline challenge.
- Complete Face ID, Touch ID, or device-passcode verification if required by your organization.
- Enter the displayed response code on the Windows computer.
Android
- Confirm the Android device has internet access.
- Open AutoElevate Notify.
- Sign in or refresh the session if prompted.
- Select the QR scanner.
- Allow camera access if requested.
- Scan the offline challenge.
- Complete biometric or device-passcode verification if required.
- Enter the displayed response code on the Windows computer.
Device authentication requirements depend on the organization’s mobile app configuration.
Advanced Use Cases
Isolated and Restricted Networks
Offline elevation can be used when a computer is connected only to a local network, located in an isolated environment, or restricted from communicating with AutoElevate. The technician’s mobile device must still be able to reach AutoElevate using its own internet connection.
Temporary Endpoint Connectivity Failures
A technician can use offline elevation when a computer temporarily loses network access during maintenance or troubleshooting. This avoids reconnecting the endpoint solely to obtain controlled administrative access.
Existing Local Authorization Rules
AutoElevate rules stored locally on the endpoint can continue to apply when the computer is disconnected. Offline elevation is primarily needed when a technician must authorize a new action or start a new administrative session not already covered by a local rule.
Emergency Access Planning
Offline elevation reduces reliance on permanent administrative credentials during normal endpoint connectivity problems, but it does not replace a break-glass account.
A break-glass account remains necessary when:
- The AutoElevate service is unavailable.
- The technician cannot access the mobile app.
- The mobile device has no internet connection.
- The agent or credential provider cannot start.
- The computer has never completed the required initial check-in.
- A task requires signing in with an existing administrative account rather than elevating an action.
Best Practices
- Confirm that managed computers check in successfully after installation.
- Keep the AutoElevate agent, credential provider, and mobile app current.
- Limit Technician Mode and JIT permissions to authorized roles.
- Review company access when technicians join, change responsibilities, or leave.
- Require mobile-device authentication before processing offline challenges where appropriate.
- Do not send screenshots of offline challenges or response codes through email or messaging platforms.
- Generate a new challenge if the original request is interrupted or abandoned.
- Use JIT access for temporary administrative work instead of maintaining unnecessary permanent administrator accounts.
- Maintain and test a separately controlled break-glass account.
- Review successful privileged-access activity as part of regular security and operational audits.
Troubleshooting
Ctrl + Alt + A Does Not Open Technician Mode
Confirm that:
- A user is currently signed in to Windows.
- The AutoElevate agent UI is running.
- The Technician Mode hotkey is enabled for the applicable scope.
- The computer supports Technician Mode.
- The agent has received the latest settings from a previous check-in.
If the hotkey setting was recently changed while the computer was offline, the agent cannot receive the change until it reconnects.
The Offline Challenge Does Not Appear
The agent first attempts the normal online workflow. A brief delay is expected while that connection is tested.
If the online workflow appears, the computer can still reach AutoElevate.
If neither workflow appears:
- Confirm the installed agent supports offline elevation (Version 2.11.1432.0 or later).
- Confirm the computer previously checked in successfully.
- Restart the AutoElevate agent components or the computer if appropriate.
- For JIT, verify that the supported credential provider is installed.
- Reconnect the computer and confirm a successful check-in before testing again.
“Cannot Create Session” Appears
The computer may not have the required offline configuration cached locally. Reconnect the computer to a network that can reach AutoElevate, allow the agent to check in, and then retry the offline workflow. If the issue continues after a confirmed check-in and agent update, contact CyberFOX Support.
The Mobile App Cannot Scan the Challenge
- Clean the mobile device’s camera lens.
- Increase the brightness of the computer display.
- Hold the mobile device steady and include the entire QR code in the scanner.
- Confirm AutoElevate Notify has camera permission.
- Confirm the app is current.
- Generate a new challenge if the displayed challenge is damaged, incomplete, or no longer active.
The Technician Is Not Authorized
Confirm that the technician:
- Is signed in with the intended AutoElevate account.
- Belongs to the same MSP environment as the computer.
- Has access to the computer’s company.
- Has the required Technician Mode or JIT authorization.
- Has a current mobile app session.
Do not grant broader company access solely to work around an authorization error. Correct the assigned role or use another authorized technician.
The Response Code Is Rejected
Code entry is not case-sensitive. If the code is rejected:
- Compare each character carefully.
- Check for similar-looking letters and numbers.
- Confirm the code belongs to the challenge currently displayed.
- Do not reuse a code from a previous attempt.
- Generate and scan a new challenge.
- Verify that the mobile app and Windows agent are current.
The JIT Credential Tile Is Missing
Confirm that:
- The computer is at the Windows sign-in or lock screen.
- JIT Admin Login is enabled.
- The AutoElevate credential provider is installed.
- The device uses a supported Windows configuration.
- A third-party Windows authentication product is not blocking the credential provider.
JIT Admin Login has additional platform and environment limitations. Review the standard JIT Admin Login article before treating a missing tile as an offline-elevation problem.
The Scan Succeeds but JIT Login Does Not Continue
The credential provider may not support the offline workflow or may still be attempting the standard online login process. Update the AutoElevate components, restart the computer, and test again. If the problem continues, collect the computer name, company, approximate attempt time, agent version, and a screenshot of the displayed error before contacting CyberFOX Support.
Do not include the response code or an active QR challenge in the support request.
AutoElevate Is Unavailable
Offline elevation will not operate during a complete AutoElevate service outage because the mobile app must reach the service to process the challenge. Use the organization’s approved break-glass procedure. Existing locally stored rules may continue to apply, but new approvals cannot be completed through this workflow.
Security and Sync Behavior
Authorization
AutoElevate validates the technician’s identity, MSP association, company access, and required permissions before returning a response code. Possession of the displayed challenge alone does not grant administrative access.
One-Time Challenges
Each elevation attempt creates a new challenge and response. Do not reuse a response from an earlier attempt for a new challenge. Treat active challenges and response codes as sensitive information. Do not photograph, store, or send them unless CyberFOX Support specifically requests diagnostic evidence and provides a secure method.
Endpoint Communication
The endpoint creates and validates the challenge locally. It does not need to establish a direct connection to AutoElevate to complete the offline action. The technician’s mobile device provides the required network connection.
Mobile Device Authentication
Depending on the organization’s configuration, AutoElevate Notify may require biometric verification or the mobile device passcode before processing an offline challenge. This provides an additional verification step if an authenticated mobile device is accessed by someone other than its authorized user.
Audit and Reconnection
Successful privileged-access activity is associated with the authorized technician and computer. When the endpoint reconnects, locally held state can synchronize during a subsequent agent check-in.
Detailed logging for every failed offline attempt has not been confirmed as a dependable customer-facing troubleshooting source. Do not assume that a mistyped code or local connection failure will appear in the Admin Portal.
For administrative change auditing, use the dedicated AutoElevate Audit Log documentation. That audit log currently focuses on supported user and settings changes and should not be represented as a complete record of every endpoint elevation event.
Break-Glass Access
Offline elevation supplements, but does not replace, emergency administrative access.
Break-glass credentials should be:
- Unique and securely stored.
- Restricted to emergency use.
- Excluded from automatic removal or downgrade where required.
- Monitored and rotated according to the organization’s security policy.
- Tested periodically without exposing the credentials to normal users or technicians.