Lets people work day to day as standard users while still running approved files or tasks with admin rights. This Intune advanced capability uses elevation settings and elevation rules policies, and each elevation can be automatic, confirmed by the user, approved by support or denied.
Also called EPM.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Endpoint Privilege Management in context, with comparison tables and the common traps.
Terms in this definition
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Capability
Something that a person, organisation or system is able to do.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
Related terms
- Default elevation response
What Endpoint Privilege Management does when a user asks to run something elevated that no rule covers: it can deny, ask the user to confirm, or wait for support approval. Leaving it unset has the same effect as a denial.
- Elevation requests
Raised by users who want to run a file that Endpoint Privilege Management has set to need support approval. An admin approves or rejects each one from Admin tasks or the Elevation requests tab.
- Microsoft Intune Suite
Sits on top of Plan 1 and contains everything in Plan 2, plus Microsoft Cloud PKI, Enterprise Application Management and Endpoint Privilege Management. Microsoft 365 E7 and E5 have included the complete bundle since July 2026.
- Reusable settings groups
Defined once and referenced by many rules or policies, these hold common items such as EPM publisher certificates or Device Control entries so they aren't duplicated.
- Run with elevated access
Endpoint Privilege Management adds this to the right-click menu so users without local administrator rights can ask for a file to run elevated, subject to the elevation rules.
- User confirmed
The default elevation type for new Endpoint Privilege Management rules. People pick Run with elevated access and confirm, and can be asked for a reason or for Windows authentication.
- Virtual account
A separate account that Endpoint Privilege Management runs elevated processes under. It does not use the user's profile and is never made a member of Administrators.