# What the Idira (CyberArk) EPM agent control panel is

> The Idira EPM Control Panel is the desktop window where a standard Windows user runs approved admin tasks and asks for temporary privileges.

Source: https://fmcybersecurity.com/en/insights/identity/what-the-idira-epm-agent-control-panel-is/
Locale: English
Other locale: https://fmcybersecurity.com/insights/identity/hva-er-idira-epm-agent-control-panel/

## Metadata

- Date: 2026-08-05
- Author: robin-kvernevik
- Topic: identity
- Format: guide

The Idira (CyberArk) EPM Control Panel is a small window on your Windows desktop that lets a standard user run a short list of administrator tasks your IT department approved in advance. It is installed by the Idira EPM agent, which is the endpoint half of [Endpoint Privilege Manager](/en/products/cyberark/endpoint-privilege-manager/). If you found it on a work laptop and had no idea what it was, this page explains what it does, who put it there, and what it cannot do.

One naming note before the detail. Palo Alto Networks folded the CyberArk portfolio into a single brand called Idira on 12 May 2026 ([announcement](https://investors.paloaltonetworks.com/news-releases/news-release-details/palo-alto-networks-introduces-idira-next-generation-identity)), so the same window reads CyberArk EPM Control Panel on older agents and Idira EPM Control Panel on current ones. The [rename explainer](/en/insights/identity/cyberark-is-now-idira/) covers the rest.

I lead the [Idira (CyberArk)](/en/partners/cyberark/) work at FM CyberSecurity. In the rollouts I have run, this window produces more first-week helpdesk tickets than any other part of Endpoint Privilege Manager, and the reason is almost always the same: nobody told the user what the icon was for.

## Where the control panel comes from

The control panel belongs to the Idira EPM agent, not to Windows. On a default Windows install the agent sits in `C:\Program Files\CyberArk\Endpoint Privilege Manager\Agent`, runs as a Windows service named `vf_agent`, and keeps a separate self-protection service running beside it ([agent CLI reference](https://docs.cyberark.com/epm/latest/en/content/installation/windows-agentcommands.htm)). Seeing those on a managed machine means your IT department deployed Endpoint Privilege Manager.

The panel does not appear on every managed machine. Idira's documentation is narrow about this: it shows up when policies with the Elevate action are created for Windows administrative tasks such as Add/Remove Printer or Network Connections, or for scripts attached to a policy ([key concepts](https://docs.cyberark.com/epm/latest/en/content/intro/key%20concepts.htm)). No policy of that shape, no panel.

There are two ways in. Double-click the desktop icon, which your administrator names and can hide. Or click the Idira icon in the Windows notification area and pick "Open Idira EPM Control Panel..." from the agent menu ([agent menu](https://docs.cyberark.com/epm/latest/en/content/policies/cyberarkmenu.htm)). The second route still works after the desktop icon has been hidden or deleted, which is worth remembering before you file a ticket.

macOS has no control panel. There, the same agent menu on the menu bar carries the request option directly.

## What you can do in the panel as an end user

Three things, and every one of them has to be switched on by policy first.

1. **Run an approved administrative task.** Printer setup and network connection settings are the two the documentation names. Double-click the item and Windows opens it with the privileges the policy grants, while your account stays a standard user.
2. **Run a script your administrator attached to a policy.** Same mechanism, applied to whatever the admin packaged: a driver install, a settings fix, a repair routine.
3. **Ask for temporary administrator rights.** Double-click Request Administrative Privileges, write why you need them, click OK ([end user steps](https://docs.cyberark.com/epm/latest/en/content/enduser/adhocelevationuser.htm)).

That third item deserves a sentence more, because it is the one people click when they are stuck. Your request goes to the Idira administrator and lands in the Events Management page of their console. If they agree, they create a Just in Time policy that adds you to a local group for a fixed number of hours, between 1 and 120. The membership expires by itself when the clock runs out.

The panel does not hand out offline authorization codes. That is a separate flow: the administrator generates a code with the Offline Policy Authorization Generator, and you right-click the file in Explorer, choose to run it with an authorization code, and paste the code into the dialog that opens ([offline access](https://docs.cyberark.com/epm/latest/en/content/epm/server%20user%20guide/one-time%20run%20authorization%20tool.htm)). Useful when a laptop has no route back to the service, but it never appears inside the control panel.

## What an administrator configures, and where

The control panel is a display switch, set in the Idira EPM management console. Go to Configuration, then Agent configuration, open the configuration you want, choose More actions and Edit parameters, then scroll to the Endpoint UI section. The parameter is "Show Idira EPM Control Panel on desktop", and it also decides the icon and the name your users read ([interface settings](https://docs.cyberark.com/epm/latest/en/content/epm/server%20user%20guide/customizeinterfacesettings.htm)).

The parameters next to it govern how visible the rest of the agent is. "Show icon in task/menu bar" controls the notification-area menu. "Hide Windows Run As... menu items" strips the standard Windows escalation entries out of Explorer. "Shell elevate menu text" renames the right-click entry that ships as "Run with Elevated Privileges".

What sits inside the panel is not configured there. It comes from the policies you write. Contents also follow the set the endpoint belongs to, and Idira shares no policies, events or configuration between sets. That is the first thing I check when a user reports that a colleague has an option they do not: different set, different panel.

## What it is not

The Windows Control Panel is separate software that happens to share the name. Idira's panel only ever offers the handful of items your policies put there.

Administrators do not work here either. Their console runs in a browser and holds the policies, the sets and the event history. The desktop panel is the endpoint-side view, built for the person using the machine.

Nor does the panel hand out local administrator rights. Everything in it already exists in policy, and Request Administrative Privileges sends a request to a human instead of granting anything.

Finally, the panel is not the product. Elevation rules, application control, credential theft protection and the restrictions that keep ransomware away from files and network resources all run in the agent whether the window is visible or not. For the product-level view rather than the component view, read [what endpoint privilege management is](/en/insights/identity/what-endpoint-privilege-management-is/).

## FAQ

### What is the Idira agent control panel?

A desktop window installed by the Idira EPM agent on Windows. It lets a standard user run administrative tasks and scripts that an administrator elevated by policy, and it carries the Request Administrative Privileges option when that is enabled.

### Why is there an Idira EPM agent on my computer?

Because your employer deployed Idira Endpoint Privilege Manager to remove local administrator rights and hand back only the specific tasks people need. The agent enforces those policies on the endpoint. It is standard managed-device software, not something you picked up by accident.

### Is the Indira agent control panel the same thing?

Yes, that is a common misspelling of Idira. The product name has one letter d and no n in the middle: Idira, the brand Palo Alto Networks introduced for the CyberArk portfolio in May 2026.

### Can I remove the control panel icon from my desktop?

You can hide it from the agent menu in the notification area, and deleting the icon is possible too. Neither removes the underlying capability. Reopen it from the agent menu with "Open Idira EPM Control Panel...". Removing the agent itself is an administrator action, not a user one.

### What is the difference between the control panel and the EPM management console?

The control panel runs on the endpoint and serves the person at the keyboard. The management console runs in a browser and serves the administrator who writes policies, groups computers into sets, and reviews events. They show different things to different audiences.

### Nothing happens when I open it. Is it broken?

Usually not. The panel only lists items that a policy put there, so an empty or thin panel means no Elevate policy for an administrative task or script currently targets your machine. Ask your IT department which set your computer belongs to before you assume a fault.

If you are rolling out Endpoint Privilege Manager and want the control panel to cut tickets rather than create them, decide the first three tasks to elevate before you switch the icon on. Talk to FM CyberSecurity's [identity practice](/en/services/identity/) for a 30-minute view of your rollout, and I will walk you through the policy set we start with.

Drafted with AI assistance, reviewed and edited by Robin Kvernevik and the FM CyberSecurity editorial team.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
