Endpoint Privilege Management Flashcards
(40 cards)
What is Endpoint Privilege Management (EPM) ?
solution to allow organization’s users to run as a standard user (without administrator rights) and complete tasks that require elevated privileges
On which 2 OS can you use EPM?
Windows 10
Windows 11
3
What are the EPM licensing prerequisites ?
- Intune Plan 1 minimum
- stand-alone license that adds only EPM,
- OR Microsoft Intune Suite
What are the EPM prerequisites ?
- Microsoft Entra joined or Microsoft Entra hybrid joined
- Microsoft Intune Enrollment or Microsoft Configuration Manager co-managed devices
- Supported Operating System
What are the 3 steps to complete the EPM configuration ?
- License Endpoint Privilege Management
- Deploy an elevation settings policy
- Deploy elevation rule policies
what is an elevation settings policy ?
activates EPM on the client device
what is an elevation rule policies ?
links an application or task to an elevation action.
policy to configure the elevation behavior for applications your organization allows when the applications run on the device
What is the purpose of the right-click context menu option when EPM is activated?
To check elevation rules policies for matching to determine file elevation to run in an administrative context
EPM stands for Enhanced Protected Mode.
Fill in the blank: When EPM is activated, the right-click context menu option checks the device’s _______ to determine file elevation.
[elevation rules policies]
What are the three types of elevation behavior in EPM?
- Automatic elevation rules
- User confirmed rules
- Support approved rules
How do automatic elevation rules function?
They automatically elevate applications without user input
These rules can significantly impact the security posture.
What is required for user confirmed rules to work?
End users must acknowledge the elevation through a context menu
This adds an extra layer of protection.
What must end users do for support approved rules?
Submit a request to approve an application
An administrator must approve the request before elevation can occur.
True or False: User confirmed rules do not require any additional user input.
False
User confirmed rules require users to acknowledge the elevation.
Fill in the blank: EPM allows users without administrative privileges to run processes in the _______ context.
administrative
What is the purpose of Windows elevation settings policy?
To enable Endpoint Privilege Management on devices.
What happens when EPM is disabled on a device?
The client components immediately disable, with a delay of seven days before complete removal.
What is the default elevation response for elevation requests of unmanaged files?
Deny all requests.
Under what condition does the default elevation response take effect?
No rule exists for the application AND the user explicitly requests elevation.
What happens if no setting is delivered for the default elevation response?
The EPM components fall back to their built-in default, which denies all requests.
What does requiring user confirmation entail in the context of elevation requests?
Validation options must be set when this response is defined.
What validation options are available when user confirmation is required?
- Business justification
- Windows authentication
Fill in the blank: The default elevation response is not configured by _______.
default
True or False: The option ‘Require support approval’ allows an administrator to approve elevation requests without a matching rule.
True