
Local admin rights on Windows workstations are one of the most abused attack vectors in ransomware and data breaches. Endpoint Privilege Management (EPM) in Intune resolves the dilemma: employees run as standard users but can perform specific tasks with elevation through a managed and fully audited process. From 1 July 2026, EPM is included in Microsoft 365 E5.
Local administrator. In many Windows environments, those two words are synonymous with both productivity and the largest attack surface on a workstation. Whoever holds local admin rights can install software, change system settings, disable security software, and move laterally through a network after an initial compromise. Yet many IT teams still grant employees local admin rights, simply because tasks like installing a driver, updating business software, or running certain diagnostics will not work otherwise.
With Endpoint Privilege Management (EPM) in Microsoft Intune, there is now an answer to this dilemma. Users run as standard users but can perform specific tasks with administrator rights through a managed and fully audited process. No permanent admin rights, no local administrators group, yet the operational freedom employees need. From 1 July 2026, EPM is included in Microsoft 365 E5, significantly lowering the barrier to adoption.
Most successful ransomware attacks begin at a compromised endpoint. Once an attacker gains access, what the account is permitted to do determines how much damage is caused. With local admin rights, the attacker can disable security software, extract password hashes from memory, establish persistence via registry keys and scheduled tasks, and encrypt or exfiltrate files without any central policy intervening.
The principle of least privilege states that every user should have only the rights needed for their specific task. In practice, that principle has chafed against productivity requirements for decades. Help-desk staff were made local administrators because they could not otherwise install software for users. Finance employees received rights because accounting packages needed to write to certain system paths. The result is that a large portion of the Windows estate has run with unnecessary privileges for years, and that risk has accumulated over time.
EPM moves the decision about elevated rights from the device to a central policy in Intune. IT administrators define elevation rules that specify which applications or processes may be elevated, through which mode, and who may submit a request. The EPM agent is automatically installed on Windows devices that receive an EPM policy from Intune, with no manual agent deployment required.
Every elevation is logged: which process, which account, on which device, at what time, and whether it was an automatic elevation or one requested by the user. That audit data is available in the Intune Endpoint Analytics dashboard and can be retained via Purview for compliance purposes. Organisations that must comply with ISO 27001, NEN 7510, or similar frameworks gain demonstrable control over privilege use.
EPM offers three ways to manage elevation, each suited to a different situation.
Automatic elevation is the most transparent mode for end users. You define an application or process in the elevation rule, and every time it is launched, it automatically receives elevated rights without the user doing anything. This is suited for known business software that always requires admin rights, such as certain network diagnostics or configuration scripts managed by the IT department. The user notices nothing; control lies entirely with the IT administrator.
User-requested elevation requires the employee to explicitly indicate that they want to run a task elevated. Via a right-click or through the Windows Security Center app, the user requests an elevation. If the request matches an existing policy rule, it is granted immediately without help-desk approval. The action is fully audited. This is the most commonly used mode for one-off or irregular tasks.
Support-approved elevation is the strictest variant, intended for tasks that fall outside the standard policy rules. The employee submits a request via the Windows Security Center app, describes why the elevation is needed, and a help-desk operator approves or denies the request in the Intune portal. Only after approval does the user receive a temporary elevated session. This creates a fully traceable approval process for exception scenarios.
In June 2026, two EPM features reached general availability that are specifically relevant for environments with shared Windows devices. First, support-approved elevation now works for non-primary users. In situations where multiple employees use the same device, such as in healthcare, logistics, or retail, previously only the primary user could submit an approval request. Now any signed-in user can send a request that follows the normal approval workflow.
Second, EPM now fully supports shared device configurations in Intune. Elevation rules are device-bound rather than user-bound, and the approval workflow attaches to the user currently signed in. Organisations managing a pool of Windows devices for rotating employees can now deploy EPM without building per-user policies.
Until 1 July 2026, EPM was part of the paid Intune Suite add-on, a supplement that had to be purchased separately on top of an existing Microsoft 365 subscription. From that date, EPM is part of Microsoft 365 E5 at no additional cost for existing E5 customers. E5 customers who have not yet deployed EPM can start immediately: no new licence assignment is required. EPM functionality is automatically available as soon as you create an EPM policy in the Intune portal.
For organisations on Microsoft 365 E3, EPM remains available through the Intune Suite add-on, which also includes Remote Help, Advanced Analytics, and Microsoft Tunnel for Mobile Application Management. Organisations that already have the full Suite need no additional action. Those who want only EPM without the other Suite features can take the add-on on a per-user basis.
An EPM implementation runs in four steps. First step: configure the Windows elevation settings policy in the Intune portal. This determines whether EPM is active for the selected device groups and whether default elevation requests are allowed or disabled. Assign the policy to the appropriate Entra device groups.
Second step: create elevation rules. An elevation rule links a specific executable to an elevation mode and contains authentication criteria such as the file hash or the certificate of the application. This ensures that only the approved version of a tool can be elevated, not any arbitrary executable.
Third step: assign policies to device groups. The EPM agent installs automatically on Windows devices that receive the policy. Verify via the Intune console that the agent has been successfully installed and the policy applied before proceeding.
Fourth step: monitor via the Endpoint Analytics dashboard which elevation requests have been submitted, approved, or denied. That data helps you refine the policy. Frequently requested tasks that are not yet covered by a rule can quickly be converted into an automatic elevation rule, reducing help-desk workload further.
It is advisable to start with a pilot group, preferably the IT team itself, to test the workflow and calibrate the rules before rolling out to the wider organisation. Want help designing an EPM implementation plan, setting up elevation rules, or migrating from local admin rights to a least-privilege model? Contact Zarioh for a practical conversation.
Zarioh Digital Solutions
IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Security

Security

Security