GuideInformationBusiness ContinuityIT

Check EPM parent rules before relying on a child-process denial

Can an EPM child-process allowance bypass a separate deny rule for the child?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

Can an EPM child-process allowance bypass a separate deny rule for the child?

Potentially affected

Use this review when an approved EPM application can start another executable. Identify the actual parent rule and launch chain, not just the rule attached to the child file.

DSE recommendation

Review parent elevation and child restrictions together before accepting a deny rule as effective.

Source facts

In Endpoint Privilege Management, allowing child processes to run elevated skips their rule evaluation, including explicit deny rules. A child can therefore receive elevated access even when a deny rule identifies that file. Microsoft cautions against broad elevation rules for programs that launch other processes. It also warns that changing child-process behavior can affect applications that expect normal Windows inheritance. Microsoft Learn.

Applicability

Use this review when an approved EPM application can start another executable. Identify the actual parent rule and launch chain, not just the rule attached to the child file.

DSE recommendation

Review parent elevation and child restrictions together before accepting a deny rule as effective. Have the application owner enumerate the subprocesses required for the approved task. Ask the policy owner to explain any unrestricted child-elevation setting and reduce it where compatible with that task. Keep exceptions tied to the specific parent and business operation; do not approve a general command shell merely to make one installer work.

Verification

In an isolated test, launch the same harmless child directly and through the approved parent, and inspect its effective privilege and policy result. Include a child intended to be denied. Resolve discrepancies before rollout, then repeat the business task to check compatibility. Preserve the parent rule, child identity, launch path, and observed outcome as one evidence set.

Official references

Microsoft Learn: Creating elevation rules with Endpoint Privilege Management.

Primary reference

Review the official source

Creating elevation rules with Endpoint Privilege Management - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE