Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The best way to turn an observed Endpoint Privilege Management (EPM) elevation request into a reusable Intune rule is to create it directly from the request or Elevation report. Intune copies the file metadata for you, reducing transcription errors. However, the generated rule is only a starting point: review its path, hash, certificate, arguments, child-process behavior, and assignment scope before deploying it.

What this workflow creates

Microsoft Intune EPM allows standard users to perform approved administrative tasks without making them permanent local administrators. It uses file identity, policy rules, elevation behavior, user validation, approval workflows, and assignment scope to control elevation. See Microsoft’s EPM overview.

Keep these objects separate:

  • Elevation request: a user-generated request or reporting record for a file that attempted to elevate.
  • Elevation-rules policy: contains rules defining which files are managed and how they elevate.
  • Elevation settings policy: enables EPM on devices and controls default handling for files that do not match a rule.

A rule will not work unless EPM is enabled through an elevation settings policy and the rules policy is assigned to the intended users or devices.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prerequisites

  • The endpoint is managed by Intune and the intended test user is a standard user.
  • An elevation settings policy enables EPM and reporting is enabled at an appropriate scope.
  • You have permission to manage EPM policies and elevation requests.
  • The required EPM license or qualifying Microsoft subscription is assigned.
  • The application has generated an elevation request or appears in the Elevation report.
  • The executable is signed if you plan to use publisher or certificate validation.

Microsoft documents EPM settings in Manage Endpoint Privilege Management settings.

Create the rule from an elevation request

  1. In the Microsoft Intune admin center, open Endpoint security > Endpoint Privilege Management.
  2. To start from reporting, open Reports, select the Elevation report tile, find the executable in the File column, and select its name. Alternatively, open Elevation requests, select the relevant request, and open the file details.
  3. Review the details, including the file name, path, publisher, certificate, hash, product, company, version, and command-line information.
  4. Select Create a rule with these file details.
  5. Choose Create a new policy or Add to an existing policy.
  6. Configure the elevation behavior and detection conditions.
  7. Save the policy, then assign it to a controlled Entra ID group.

Microsoft supports creating a rule from requests that are pending, approved, or denied. The request’s status does not by itself prove that recurring elevation is approved. Treat the captured metadata as evidence for a security and business decision, not as automatic authorization. The current workflow is documented in Create elevation rules for Endpoint Privilege Management.

New policy or existing policy?

Create a new policy when the rule needs a separate assignment scope, approval owner, rollback path, or pilot group. This is usually the clearest choice for a newly observed application.

Add the rule to an existing policy when the application belongs to an established approved-application collection and its assignments are appropriate. Review every existing rule and assignment before saving, because modifying the policy changes its deployed configuration. Intune elevation-rules policies support up to 100 rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure the rule securely

Choose the elevation type

Setting Appropriate use Trade-off
User confirmed Normal business applications and pilots Preserves user interaction and validation
Support approved Rare or sensitive administrative tasks Requires approval before elevation
Automatic Highly trusted, tightly identified applications Least friction but greatest impact if the rule is too broad
Deny Prohibited or dangerous utilities Prevents the file from elevating

For a newly observed application, User confirmed is generally the safer starting point. Use automatic elevation only after testing the application, its update process, and its child processes. A deny rule takes precedence over an applicable allow rule for the same file.

Review the file path

The automatic workflow can require the same path observed in the request. Do not select or clear this option mechanically.

Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.
  • A protected installation path, such as a controlled location under Program Files, can strengthen the rule.
  • A Downloads folder, user profile directory, or other user-writable location can allow a substituted or modified executable to match.
  • Leaving the path unrestricted may be appropriate for a tightly controlled signed application, but it broadens the rule.

Microsoft recommends using a path that standard users cannot modify. Verify both the path’s security permissions and whether the vendor’s updater changes the installation location.

Select identity conditions

Use the narrowest practical combination of file properties:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Scenario Useful approach
One fixed, high-risk executable File hash, optionally combined with a protected path
Trusted vendor with regular updates Publisher or certificate plus a protected path and other file properties
Internal application Organization certificate plus version or hash
User-downloaded installer Avoid broad publisher-only matching; use a controlled path and hash

Hash matching is the most precise, but every binary update can require a rule change. Certificate or publisher matching reduces maintenance but can trust more files from that signing authority than the single file shown in the request.

Restrict file arguments

Where the workflow supports it, define approved command-line arguments or switches. With arguments configured, elevation is allowed only when the request contains one of the defined command lines. This is valuable for installers, repair tools, configuration utilities, and script-driven workflows.

Do not elevate a trusted executable with unrestricted arguments if those arguments could launch another process, load arbitrary content, or modify protected system state.

Rank #3

Control child processes

Determine whether the elevated application needs to launch elevated helpers, installers, update components, or other child processes. Allowing all child processes is convenient but expands the privileged boundary. Restricting child processes improves least privilege but can break legitimate workflows.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test the actual application path before changing this setting. Identify the specific helper executable that fails rather than enabling every child process as a workaround. Microsoft notes that child-process settings do not apply to deny rules.

Name and document the rule

Use a predictable name such as:

EPM - <Application> - <ElevationType> - <Scope>

For example:

EPM - FinanceTool - SupportApproved - Finance

Record the business owner, application version, detection method, expected path, certificate or hash, child-process decision, approval date, review date, and change reference. This makes later rule cleanup and incident investigation much easier.

Assign, deploy, and test

Creating the policy does not deploy it. Assign it in stages:

  1. IT test group
  2. Small pilot of standard users
  3. Application-owning department
  4. Broader production population

Rules may be assigned to users or devices. A device-targeted rule applies to every user of the device; a user-targeted rule follows that user on applicable devices. User-targeted rules take precedence over device-targeted rules where applicable, so document overlapping assignments and exclusions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.

Test with a standard-user account, not a local administrator. An administrator may launch the application normally without EPM intervention, producing misleading results. Test the main executable, expected prompts, updates, plugins, file associations, helper processes, and any installer or repair workflow.

Example: a VLC-style rule

A video application such as VLC can illustrate the workflow, but its configuration should not be copied blindly into production. Confirm the binary’s signature and certificate chain, verify its installation path is protected, and start with user-confirmed elevation. Avoid allowing all child processes unless testing proves it is required. Assign the rule only to a pilot group, then review elevation reporting before widening scope.

Automatic creation versus manual creation

Method Strengths Risks
From an elevation request Fast, based on observed metadata, and less prone to transcription errors The request may represent an unsafe path, one-off file, or overly broad certificate
Manual rule creation Better for standardized application catalogs and deliberate detection design Requires more effort and accurate file information

Use request-based creation for speed, then perform the security review manually. Use manual creation when packaging, application governance, or argument restrictions require a design that is broader than one observed request.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting

EPM is enabled, but nothing happens

  • Confirm the elevation settings policy is assigned and enables EPM.
  • Confirm the rules policy is assigned to the correct user or device group.
  • Check the device’s recent Intune check-in and policy status.
  • Verify that the file matches the configured path, hash, certificate, publisher, version, and arguments.
  • Confirm the file type is supported; Microsoft lists examples including .exe, .msi, and .ps1.
  • Check for another user- or device-targeted rule, especially a deny rule.

The parent application works but its task fails

Identify whether the task launches a helper executable, updater, installer, shell extension, PowerShell component, or command-line process. That child process may need its own rule or a carefully chosen child-process setting. Do not automatically permit every child process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The application stopped matching after an update

This is expected when the rule uses a file hash. Create a rule for the new approved hash, or consider certificate and publisher matching if the vendor is trusted and the broader scope is acceptable. Tie EPM rule maintenance to the application’s release process.

Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop

The rule denies an apparently approved file

Inspect all assigned policies and group memberships. Deny rules take precedence over applicable allow rules, and user- and device-targeted policies can interact. Also verify that the request contains the expected command line and that the file has not moved or changed signature.

For broader troubleshooting, consult Microsoft’s EPM frequently asked questions.

Licensing note

Licensing and entitlements change by region, agreement, and Microsoft 365 plan. Microsoft pricing pages observed in August 2026 showed an EPM standalone add-on signal of $3 per user per month on annual billing, but readers should verify current tenant-specific eligibility and pricing. Some advanced endpoint capabilities may also be included in qualifying Microsoft 365 entitlements. Check Microsoft’s current Intune pricing page before purchasing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

EPM is a strong fit for organizations already using Intune, Entra ID, Windows endpoints, and Microsoft 365. A dedicated third-party product may be worth evaluating when the estate is not Intune-managed, includes many non-Windows platforms, or requires more complex help-desk approval, credential brokering, or cross-platform privilege workflows.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$309.00
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.