{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/",
        "slug": "dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/"
        },
        "title": "Staff the EPM approval queue before requiring support-approved elevation",
        "summary": "Can the helpdesk operate the EPM approval window and communicate both decisions?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:28:37+00:00",
        "modified_at": "2026-09-10T00:55:36+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 230,
        "potentially_affected": "Use this operating plan for support-approved Endpoint Privilege Management requests. Confirm who can review the relevant device population and who will communicate with the requester.",
        "dse_recommendation": "Assign queue coverage and a documented checking interval before making approval a dependency for routine work.",
        "primary_source": {
            "name": "Use EPM support approvals for file elevation requests with Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/epm/manage-support-approvals",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Intune does not notify administrators when a new EPM elevation request arrives. An approval permits the requesting user to elevate that file on that device for 24 hours from approval; administrators cannot customize or cancel that period early. Denied users are not automatically notified. Reviewing requests requires the EPM elevation-request permissions within the administrator’s configured scope. <a href=\"https://learn.microsoft.com/en-us/intune/epm/manage-support-approvals\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this operating plan for support-approved Endpoint Privilege Management requests. Confirm who can review the relevant device population and who will communicate with the requester.</p>\n<h2>DSE recommendation</h2>\n<p>Assign queue coverage and a documented checking interval before making approval a dependency for routine work. Review the requested file, user, device, and business reason together. Approve only when the owner accepts the complete elevation window; do not promise an early withdrawal that the documented workflow cannot provide. Require a decision reason in the team’s procedure and contact denied users directly with the approved explanation.</p>\n<h2>Verification</h2>\n<p>Submit an authorized test request and confirm that the assigned reviewer can find it without relying on an alert. Check the approval time and expiration, and verify the intended file’s behavior on the requesting device. Separately rehearse a denial and the helpdesk’s manual response. Retain the decision trail and any communication delay, then adjust staffing before expanding the workflow.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/epm/manage-support-approvals\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use EPM support approvals for file elevation requests with Intune</a>.</p>",
        "content_text": "Source facts\nIntune does not notify administrators when a new EPM elevation request arrives. An approval permits the requesting user to elevate that file on that device for 24 hours from approval; administrators cannot customize or cancel that period early. Denied users are not automatically notified. Reviewing requests requires the EPM elevation-request permissions within the administrator’s configured scope. Microsoft Learn.\nApplicability\nUse this operating plan for support-approved Endpoint Privilege Management requests. Confirm who can review the relevant device population and who will communicate with the requester.\nDSE recommendation\nAssign queue coverage and a documented checking interval before making approval a dependency for routine work. Review the requested file, user, device, and business reason together. Approve only when the owner accepts the complete elevation window; do not promise an early withdrawal that the documented workflow cannot provide. Require a decision reason in the team’s procedure and contact denied users directly with the approved explanation.\nVerification\nSubmit an authorized test request and confirm that the assigned reviewer can find it without relying on an alert. Check the approval time and expiration, and verify the intended file’s behavior on the requesting device. Separately rehearse a denial and the helpdesk’s manual response. Retain the decision trail and any communication delay, then adjust staffing before expanding the workflow.\nOfficial references\nMicrosoft Learn: Use EPM support approvals for file elevation requests with Intune.",
        "content_markdown": "## Source facts\n\nIntune does not notify administrators when a new EPM elevation request arrives. An approval permits the requesting user to elevate that file on that device for 24 hours from approval; administrators cannot customize or cancel that period early. Denied users are not automatically notified. Reviewing requests requires the EPM elevation-request permissions within the administrator’s configured scope. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/epm/manage-support-approvals).\n\n## Applicability\n\nUse this operating plan for support-approved Endpoint Privilege Management requests. Confirm who can review the relevant device population and who will communicate with the requester.\n\n## DSE recommendation\n\nAssign queue coverage and a documented checking interval before making approval a dependency for routine work. Review the requested file, user, device, and business reason together. Approve only when the owner accepts the complete elevation window; do not promise an early withdrawal that the documented workflow cannot provide. Require a decision reason in the team’s procedure and contact denied users directly with the approved explanation.\n\n## Verification\n\nSubmit an authorized test request and confirm that the assigned reviewer can find it without relying on an alert. Check the approval time and expiration, and verify the intended file’s behavior on the requesting device. Separately rehearse a denial and the helpdesk’s manual response. Retain the decision trail and any communication delay, then adjust staffing before expanding the workflow.\n\n## Official references\n\n[Microsoft Learn: Use EPM support approvals for file elevation requests with Intune](https://learn.microsoft.com/en-us/intune/epm/manage-support-approvals)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Staff the EPM approval queue before requiring support-approved elevation",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/",
                "headline": "Staff the EPM approval queue before requiring support-approved elevation",
                "description": "Can the helpdesk operate the EPM approval window and communicate both decisions?",
                "abstract": "Can the helpdesk operate the EPM approval window and communicate both decisions?",
                "articleBody": "Source facts\nIntune does not notify administrators when a new EPM elevation request arrives. An approval permits the requesting user to elevate that file on that device for 24 hours from approval; administrators cannot customize or cancel that period early. Denied users are not automatically notified. Reviewing requests requires the EPM elevation-request permissions within the administrator’s configured scope. Microsoft Learn.\nApplicability\nUse this operating plan for support-approved Endpoint Privilege Management requests. Confirm who can review the relevant device population and who will communicate with the requester.\nDSE recommendation\nAssign queue coverage and a documented checking interval before making approval a dependency for routine work. Review the requested file, user, device, and business reason together. Approve only when the owner accepts the complete elevation window; do not promise an early withdrawal that the documented workflow cannot provide. Require a decision reason in the team’s procedure and contact denied users directly with the approved explanation.\nVerification\nSubmit an authorized test request and confirm that the assigned reviewer can find it without relying on an alert. Check the approval time and expiration, and verify the intended file’s behavior on the requesting device. Separately rehearse a denial and the helpdesk’s manual response. Retain the decision trail and any communication delay, then adjust staffing before expanding the workflow.\nOfficial references\nMicrosoft Learn: Use EPM support approvals for file elevation requests with Intune.",
                "datePublished": "2026-09-10T00:28:37+00:00",
                "dateModified": "2026-09-10T00:55:36+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Staff the EPM approval queue before requiring support-approved elevation"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 230,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use EPM support approvals for file elevation requests with Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/epm/manage-support-approvals"
                }
            }
        ]
    }
}