Endpoint Privilege Management Flashcards

(40 cards)

1
Q

What is Endpoint Privilege Management (EPM) ?

A

solution to allow organization’s users to run as a standard user (without administrator rights) and complete tasks that require elevated privileges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

On which 2 OS can you use EPM?

A

Windows 10
Windows 11

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

3

What are the EPM licensing prerequisites ?

A
  • Intune Plan 1 minimum
  • stand-alone license that adds only EPM,
  • OR Microsoft Intune Suite
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the EPM prerequisites ?

A
  • Microsoft Entra joined or Microsoft Entra hybrid joined
  • Microsoft Intune Enrollment or Microsoft Configuration Manager co-managed devices
  • Supported Operating System
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 3 steps to complete the EPM configuration ?

A
  1. License Endpoint Privilege Management
  2. Deploy an elevation settings policy
  3. Deploy elevation rule policies
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what is an elevation settings policy ?

A

activates EPM on the client device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what is an elevation rule policies ?

A

links an application or task to an elevation action.
policy to configure the elevation behavior for applications your organization allows when the applications run on the device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the purpose of the right-click context menu option when EPM is activated?

A

To check elevation rules policies for matching to determine file elevation to run in an administrative context

EPM stands for Enhanced Protected Mode.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Fill in the blank: When EPM is activated, the right-click context menu option checks the device’s _______ to determine file elevation.

A

[elevation rules policies]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the three types of elevation behavior in EPM?

A
  • Automatic elevation rules
  • User confirmed rules
  • Support approved rules
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How do automatic elevation rules function?

A

They automatically elevate applications without user input

These rules can significantly impact the security posture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is required for user confirmed rules to work?

A

End users must acknowledge the elevation through a context menu

This adds an extra layer of protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What must end users do for support approved rules?

A

Submit a request to approve an application

An administrator must approve the request before elevation can occur.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or False: User confirmed rules do not require any additional user input.

A

False

User confirmed rules require users to acknowledge the elevation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Fill in the blank: EPM allows users without administrative privileges to run processes in the _______ context.

A

administrative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the purpose of Windows elevation settings policy?

A

To enable Endpoint Privilege Management on devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What happens when EPM is disabled on a device?

A

The client components immediately disable, with a delay of seven days before complete removal.

18
Q

What is the default elevation response for elevation requests of unmanaged files?

A

Deny all requests.

19
Q

Under what condition does the default elevation response take effect?

A

No rule exists for the application AND the user explicitly requests elevation.

20
Q

What happens if no setting is delivered for the default elevation response?

A

The EPM components fall back to their built-in default, which denies all requests.

21
Q

What does requiring user confirmation entail in the context of elevation requests?

A

Validation options must be set when this response is defined.

22
Q

What validation options are available when user confirmation is required?

A
  • Business justification
  • Windows authentication
23
Q

Fill in the blank: The default elevation response is not configured by _______.

24
Q

True or False: The option ‘Require support approval’ allows an administrator to approve elevation requests without a matching rule.

25
What is the purpose of profiles for Windows elevation rules policy?
To manage the identification of specific files and how elevation requests for those files are handled ## Footnote Elevation rules configure details about the file being managed and requirements for it to be elevated.
26
What types of files are supported by Windows elevation rules?
* Executable files with the .exe or .msi extension * PowerShell scripts with the .ps1 extension ## Footnote These file types can have specific elevation rules applied to them.
27
What is the first step in configuring an elevation rule?
Identify the file using its name, certificate, or optional conditions ## Footnote Optional conditions can include minimum build version, product name, or internal name.
28
What is the default elevation type set to in a Windows elevation rule?
User confirmed ## Footnote This option is recommended for elevations.
29
What happens during a user confirmed elevation?
The user must select a confirmation prompt to run the file ## Footnote Additional confirmations can include organizational credential authentication or entering a business justification.
30
What is an automatic elevation?
An elevation that occurs invisibly to the user without any prompt ## Footnote There is no indication that the file is running in an elevated context.
31
What is required for a support approved elevation request?
Administrator approval for requests without a matching rule ## Footnote This is necessary before the application can run with elevated privileges.
32
What can be configured regarding child processes in elevation rules?
The elevation behavior that applies to child processes created by the elevated process ## Footnote Options include requiring a rule, denying all, or allowing child processes to run elevated.
33
Fill in the blank: The elevation type that allows child processes to always run elevated is called _______.
Allow child processes to run elevated ## Footnote This setting enables child processes to inherit elevated privileges.
34
How to create a Windows elevation settings policy ( steps) ?
1. Go to **Endpoint security** > **Endpoint Privilege Management** > select the **Policies** tab > and then select **Create Policy** 2. Set the **Platform** to **Windows**, **Profile** to **Windows elevation settings policy**, and then select Create 3. Basics: name + description 4. **Configuration settings** : define default behaviors for elevation requests on a device 5. Scope 6. Assignments 7. Review + create
35
For **elevation settings policy**, in **Configuration settings**, what are the 4 categories you need to define default behaviors for elevation requests on a device
1. **Endpoint Privilege Management**: Set to Enabled (default) 2. **Default elevation response** Options - Not Configured - Deny all requests - Require support approval - Require user confirmation (Business justification/Windows authentication) 3.Send elevation data for reporting 4.Reporting scope
36
How to manually configure **elevation rules** for Windows elevation rules policy ( 8 steps) ?
1. Go to **Endpoint security **> **Endpoint Privilege Management** > select the **Policies** tab > and then select Create Policy. 2. Set the Platform to Windows, Profile to Windows elevation rules policy, and then select Create. 3. Basics: name + description 4. On **Configuration settings**, add a rule for each file that this policy manages. When you create a new policy, the policy starts includes a blank rule with an elevation type of User confirmed and no rule name. Start by configuring this rule, and later you can select Add to add more rules to this policy. 5. select Edit instance to open its Rule properties page 6. Scope 7. Assignments 8. review+create
37
On elevation rules policy, when you edit the rule properties page, what are the 2 categories you must configure ?
* Elevation conditions * File information
38
On elevation rules policy, when you edit the rule properties page, what are Elevation conditions ?
Elevation conditions are conditions that define **how a file runs**, and **user validations that must be met** before the file this rule applies to can be run.
39
What are the 2 options for Elevation conditions in an elevation rules policy ?
* **Elevation type** : By default, this option is set to User confirmed, which is the elevation type MS recommends for most files. * **Child process behavior**
40
On elevation rules policy, when you edit the rule properties page, what is File information?
where you specify the details that identify a file that this rule applies to. * File name * File path (optional) etc