Removing local administrator rights looks simple until finance must update a token driver, a developer needs a signed installer and support has to repair a service. Microsoft Intune Endpoint Privilege Management (EPM) lets a standard user elevate a specific file rather than the whole session. The benefit does not come from merely enabling the agent. It depends on rule quality, the operating model for unknown applications and evidence that an approved executable does not launch unexpected child processes. A weak EPM design simply moves the queue from administrator passwords into a different console.

EPM elevates a process, not the user

When a rule matches, EPM runs the target in an administrative context. Except for Elevate as current user, it uses a virtual account that separates the elevated action from the user profile. The application nevertheless receives full administrative capability on the device. EPM is therefore not safe simply because the employee remains a Standard User. Every allowed EXE, MSI, script and descendant chain is a decision to trust that code with system change.

Four elevation modes serve different risks

Select mode by frequency and risk
ModeGood fitMain risk
AutomaticFrequent, stable and precisely verified binaryElevation without a conscious user action
User confirmedKnown tool launched from the context menuUsers may confirm by habit
Support approvedUnknown or exceptional file requiring reviewQueue delay and no native admin alert
Elevate as current userApplication dependent on user profile and identityMore exposure of the user profile and token

Microsoft warns that broad Automatic rules can materially affect security posture. User confirmed can require authentication, business justification or both. Support approved is useful for exceptions: a user submits the file and reason, then an administrator examines its metadata. Elevate as current user should be reserved for software that genuinely depends on the profile and fails under the virtual account; otherwise it gives up part of the isolation EPM is meant to provide.

Licensing changed on 1 July 2026

Since 1 July 2026, EPM is included with Microsoft 365 E5 and E7 alongside other advanced Intune capabilities. Microsoft 365 E3 receives a different subset and does not include EPM; other plans require Intune Suite or the relevant add-on. Any user or device directly or indirectly benefiting from Intune needs the appropriate entitlement under current terms. For an existing E5 estate, EPM is no longer mainly a purchase decision. It is an operating-model change for security and support.

Prove device and network readiness before the pilot

EPM supports 64-bit Windows including Arm64, requires Entra joined or hybrid joined devices and enrollment in Intune or Configuration Manager co-management. Windows 365 and single-session AVD are supported. Devices need clear line of sight to required endpoints without SSL inspection; otherwise policy and approval delivery can appear randomly delayed. Assigning an Elevation settings policy installs Microsoft EPM Agent Service under Program Files. Capture agent presence, version, network reachability and policy receipt in readiness evidence.

Build rules from the strongest evidence

A hash identifies one exact file but changes with every update. A publisher certificate tolerates new versions while trusting a broader family of code; narrow it with product name, internal name, file description and minimum version where possible. File name or path alone is weak identity. A practical hierarchy uses hashes for stable sensitive tools, tightly constrained publisher rules for managed products and Support approved for everything else.

Child processes explain both failures and over-broad trust

An installer can launch a second MSI, service helper, updater or shell. If only the parent is elevated, the next step may prompt for UAC again. If every descendant is allowed, a trusted bootstrapper may become a launch path for unrelated code. Observe each pilot package as a process tree. Record parent, child, publisher, hash and required context. Extend a rule only to descendants that belong to the verified installation flow, and repeat the measurement after application updates.

Rule conflicts follow a fixed precedence

Deny always wins. A user-targeted rule outranks a device rule, and a hash is considered most specific. Without a hash, the rule with more defined attributes wins; a remaining tie is resolved in the order User confirmed, Elevate as current user, Support approved, then Automatic. A client-settings conflict is also counterintuitive: if Enable EPM conflicts, the default is to enable it. Translate this logic into test cases because the assignment view alone does not reveal the effective decision.

Support approval needs an operating process around the portal

Requests are available to Intune administrators with View or Modify elevation requests RBAC permissions. Microsoft does not currently provide a native administrator notification for a new request. After approval, the device syncs and the user receives a toast; after denial, the user receives no notification and support must contact them. Approval lasts 24 hours, with no custom duration or early revocation. Without queue ownership, an SLA, backup approvers and a communication channel, users understandably conclude that the feature is broken.

Minimum approval record
FieldWhy it matters
File and hashIdentifies the exact artifact
Publisher and signatureEstablishes origin and integrity
User and deviceProvides request and policy context
Business justificationSeparates need from convenience
Process treeFinds secondary installers and shells
Decision and ownerSupports audit and conversion into a managed rule

Use telemetry to change the ruleset

During the first weeks, measure which files are elevated, where requests fail and approval lead time. A repeated legitimate request is a candidate for a narrow User confirmed rule; a one-off should remain an approval. An unsigned binary is not automatically malicious, but it needs deeper review. Also track the number of devices retaining standing local admin. Success is not more EPM rules; it is fewer permanent privileges without a growth in unresolved incidents.

Pilot real work, not only VIP users

  1. 01

    Inventory elevation demand

    Use logs, service-desk data and workshops to learn what truly needs admin

  2. 02

    Remove avoidable demands

    Fix packaging, installation or ACLs before creating an EPM rule

  3. 03

    Choose a representative cohort

    Include office work, specialists, development and remote devices

  4. 04

    Start with deny and approval

    Keep unknown files on support approval; automate only proven repetition

  5. 05

    Test updates and offline states

    Exercise new versions, descendants, restart, network loss and rollback

  6. 06

    Remove local admin after evidence

    Meet acceptance scenarios first, then monitor support impact

A decision framework for every new request

Ask first whether the application truly needs administrative rights; many internal tools can be corrected with a service, a narrower ACL or Intune packaging. If elevation remains necessary, verify origin, signature, reputation and process tree. Then assess frequency and blast radius. A common, tightly identified file may justify User confirmed; a stable machine operation may rarely justify Automatic; a profile dependency may justify Elevate as current user; uncertainty belongs in Support approved or Deny. Expire decisions regularly. A permanent ownerless rule is simply a new form of local admin.

What EPM does not replace

EPM does not replace patch management, application control, Defender, LAPS or Privileged Identity Management. It does not cover macOS and cannot prevent abuse of a legitimately allowed application when a rule is broad. Combine it with managed software delivery, Windows Defender Application Control or App Control for Business, security monitoring and a LAPS-protected local recovery account. EPM is a precise bridge between a standard user and one administrative task, not a universal privileged access platform.

Frequently asked questions

Is EPM included with Microsoft 365 E3?

From July 2026 EPM is included in Microsoft 365 E5 and E7. E3 has a different advanced Intune subset; verify the current plan or an Intune Suite add-on.

Does an administrator receive an email for a request?

Microsoft currently provides no native notification for a new support-approved request. Monitor the queue or build separate alerting.

How long does approval last?

A support approval lasts 24 hours. Its duration cannot currently be customized or revoked early.

Can EPM make the whole user an administrator?

No. It elevates a specific process under a rule, which is why its child processes matter.