Flags (or unflags) a credential as elevated, without touching its name, type, principal, or secret. IsElevated is what an elevated role scan reports findings against.
Having trouble reaching the API, or logging in from another machine? See Network Access & Authentication Security -- by default the Api only answers
localhost, and PowerShell needs an extra flag once it does answer elsewhere.
Order of Operations
- Authenticate to the API.
- Get the credential's id (from List Credentials).
- Send the new flag value.
The call
PATCH /api/credentials/{credentialId}/elevated
Permission needed: Credential.Manage.
C# example
var jsonOptions = new JsonSerializerOptions(JsonSerializerDefaults.Web);
// Step 1: Authenticate to the API.
using var handler = new HttpClientHandler { UseDefaultCredentials = true };
using var client = new HttpClient(handler) { BaseAddress = new Uri("http://your-minion-agent-server:5443") };
client.DefaultRequestHeaders.Add("X-App-Name", "MyIntegration");
// Step 2: You already have the credential's id (from List Credentials).
var credentialId = 12;
// Step 3: Send the new flag value.
var response = await client.PatchAsJsonAsync($"/api/credentials/{credentialId}/elevated", new SetCredentialElevatedRequest(IsElevated: true), jsonOptions);
response.EnsureSuccessStatusCode();
Console.WriteLine("Updated.");
record SetCredentialElevatedRequest(bool IsElevated);
Not on a domain machine? Swap in the app-account login from Calling the API From Your Own Code.
PowerShell example
# Step 1: Authenticate to the API.
$headers = @{ "X-App-Name" = "MyIntegration" }
# Step 2: You already have the credential's id (from List Credentials).
$credentialId = 12
# Step 3: Send the new flag value. (-AllowUnencryptedAuthentication: PowerShell requires this for Windows auth over plain http to anything but localhost -- see "Network Access & Authentication Security".)
$body = @{ IsElevated = $true } | ConvertTo-Json
Invoke-RestMethod -Uri "http://your-minion-agent-server:5443/api/credentials/$credentialId/elevated" `
-Method Patch -Body $body -ContentType "application/json" -UseDefaultCredentials -AllowUnencryptedAuthentication -Headers $headers
"Updated."
What you get back
204 No Content -- no body.
Codes this call can return
See API Response Codes for what each one means in general. For this specific call:
- 204 -- updated.
- 403 -- you don't have
Credential.Manage. - 404 -- no credential exists with that id.
What gets audited
Recorded as Credential / Alter Credential, with the new IsElevated value in the after-state.
See also: List Credentials, Update a Credential, Request an Elevated Role Scan.