{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/",
        "slug": "dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/"
        },
        "title": "Check the explicit EPM report permission when a reader receives HTTP 403",
        "summary": "Why can an Intune reader lose access to EPM report data despite device-configuration read permission?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:27:28+00:00",
        "modified_at": "2026-09-10T01:23:48+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 221,
        "potentially_affected": "Use this diagnostic for an intended EPM report consumer, including an existing custom-role reader. Keep authorization failure separate from an authorized report that has no recent matching data.",
        "dse_recommendation": "Inspect the dedicated report permission before adding broad administration rights.",
        "primary_source": {
            "name": "Monitor your Endpoint Privilege Management policies for Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/epm/monitor-reports",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Access to Endpoint Privilege Management reports in the Intune portal or Microsoft Graph requires the EPM Policy Authoring View Reports permission, identified as EpmPolicy.ViewReports in Graph. Device configurations Read, which previously allowed access, is no longer sufficient. Without that permission, the privilegeManagementElevations endpoint returns HTTP 403. Separately, report content depends on each device&#8217;s configured reporting scope and is processed once every 24 hours. <a href=\"https://learn.microsoft.com/en-us/intune/epm/monitor-reports\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this diagnostic for an intended EPM report consumer, including an existing custom-role reader. Keep authorization failure separate from an authorized report that has no recent matching data.</p>\n<h2>DSE recommendation</h2>\n<p>Inspect the dedicated report permission before adding broad administration rights. Ask the Intune role owner to confirm the reader&#8217;s approved reporting responsibilities and effective role assignment. If a change is justified, grant the specific reporting capability through the organization&#8217;s scoped role process. Do not add policy creation, assignment, or elevation-approval authority merely to recover read access.</p>\n<h2>Verification</h2>\n<p>With the intended identity, compare the report request before and after the approved role adjustment. Confirm a report can be read and that unrelated management operations remain unavailable. Then evaluate reporting scope and processing delay if expected entries are missing. Save the endpoint, response status, and role evidence without exporting sensitive elevation details unnecessarily.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/epm/monitor-reports\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Monitor your Endpoint Privilege Management policies for Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nAccess to Endpoint Privilege Management reports in the Intune portal or Microsoft Graph requires the EPM Policy Authoring View Reports permission, identified as EpmPolicy.ViewReports in Graph. Device configurations Read, which previously allowed access, is no longer sufficient. Without that permission, the privilegeManagementElevations endpoint returns HTTP 403. Separately, report content depends on each device’s configured reporting scope and is processed once every 24 hours. Microsoft Learn.\nApplicability\nUse this diagnostic for an intended EPM report consumer, including an existing custom-role reader. Keep authorization failure separate from an authorized report that has no recent matching data.\nDSE recommendation\nInspect the dedicated report permission before adding broad administration rights. Ask the Intune role owner to confirm the reader’s approved reporting responsibilities and effective role assignment. If a change is justified, grant the specific reporting capability through the organization’s scoped role process. Do not add policy creation, assignment, or elevation-approval authority merely to recover read access.\nVerification\nWith the intended identity, compare the report request before and after the approved role adjustment. Confirm a report can be read and that unrelated management operations remain unavailable. Then evaluate reporting scope and processing delay if expected entries are missing. Save the endpoint, response status, and role evidence without exporting sensitive elevation details unnecessarily.\nOfficial references\nMicrosoft Learn: Monitor your Endpoint Privilege Management policies for Microsoft Intune.",
        "content_markdown": "## Source facts\n\nAccess to Endpoint Privilege Management reports in the Intune portal or Microsoft Graph requires the EPM Policy Authoring View Reports permission, identified as EpmPolicy.ViewReports in Graph. Device configurations Read, which previously allowed access, is no longer sufficient. Without that permission, the privilegeManagementElevations endpoint returns HTTP 403. Separately, report content depends on each device’s configured reporting scope and is processed once every 24 hours. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/epm/monitor-reports).\n\n## Applicability\n\nUse this diagnostic for an intended EPM report consumer, including an existing custom-role reader. Keep authorization failure separate from an authorized report that has no recent matching data.\n\n## DSE recommendation\n\nInspect the dedicated report permission before adding broad administration rights. Ask the Intune role owner to confirm the reader’s approved reporting responsibilities and effective role assignment. If a change is justified, grant the specific reporting capability through the organization’s scoped role process. Do not add policy creation, assignment, or elevation-approval authority merely to recover read access.\n\n## Verification\n\nWith the intended identity, compare the report request before and after the approved role adjustment. Confirm a report can be read and that unrelated management operations remain unavailable. Then evaluate reporting scope and processing delay if expected entries are missing. Save the endpoint, response status, and role evidence without exporting sensitive elevation details unnecessarily.\n\n## Official references\n\n[Microsoft Learn: Monitor your Endpoint Privilege Management policies for Microsoft Intune](https://learn.microsoft.com/en-us/intune/epm/monitor-reports)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check the explicit EPM report permission when a reader receives HTTP 403",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/",
                "headline": "Check the explicit EPM report permission when a reader receives HTTP 403",
                "description": "Why can an Intune reader lose access to EPM report data despite device-configuration read permission?",
                "abstract": "Why can an Intune reader lose access to EPM report data despite device-configuration read permission?",
                "articleBody": "Source facts\nAccess to Endpoint Privilege Management reports in the Intune portal or Microsoft Graph requires the EPM Policy Authoring View Reports permission, identified as EpmPolicy.ViewReports in Graph. Device configurations Read, which previously allowed access, is no longer sufficient. Without that permission, the privilegeManagementElevations endpoint returns HTTP 403. Separately, report content depends on each device’s configured reporting scope and is processed once every 24 hours. Microsoft Learn.\nApplicability\nUse this diagnostic for an intended EPM report consumer, including an existing custom-role reader. Keep authorization failure separate from an authorized report that has no recent matching data.\nDSE recommendation\nInspect the dedicated report permission before adding broad administration rights. Ask the Intune role owner to confirm the reader’s approved reporting responsibilities and effective role assignment. If a change is justified, grant the specific reporting capability through the organization’s scoped role process. Do not add policy creation, assignment, or elevation-approval authority merely to recover read access.\nVerification\nWith the intended identity, compare the report request before and after the approved role adjustment. Confirm a report can be read and that unrelated management operations remain unavailable. Then evaluate reporting scope and processing delay if expected entries are missing. Save the endpoint, response status, and role evidence without exporting sensitive elevation details unnecessarily.\nOfficial references\nMicrosoft Learn: Monitor your Endpoint Privilege Management policies for Microsoft Intune.",
                "datePublished": "2026-09-10T00:27:28+00:00",
                "dateModified": "2026-09-10T01:23:48+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-268-check-the-explicit-epm-report-permission-when-a-reader-receives-http-403/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check the explicit EPM report permission when a reader receives HTTP 403"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 221,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Monitor your Endpoint Privilege Management policies for Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/epm/monitor-reports"
                }
            }
        ]
    }
}