What you need to know
Can an EPM child-process allowance bypass a separate deny rule for the child?
Potentially affected
Use this review when an approved EPM application can start another executable. Identify the actual parent rule and launch chain, not just the rule attached to the child file.
DSE recommendation
Review parent elevation and child restrictions together before accepting a deny rule as effective.
Source facts
In Endpoint Privilege Management, allowing child processes to run elevated skips their rule evaluation, including explicit deny rules. A child can therefore receive elevated access even when a deny rule identifies that file. Microsoft cautions against broad elevation rules for programs that launch other processes. It also warns that changing child-process behavior can affect applications that expect normal Windows inheritance. Microsoft Learn.
Applicability
Use this review when an approved EPM application can start another executable. Identify the actual parent rule and launch chain, not just the rule attached to the child file.
DSE recommendation
Review parent elevation and child restrictions together before accepting a deny rule as effective. Have the application owner enumerate the subprocesses required for the approved task. Ask the policy owner to explain any unrestricted child-elevation setting and reduce it where compatible with that task. Keep exceptions tied to the specific parent and business operation; do not approve a general command shell merely to make one installer work.
Verification
In an isolated test, launch the same harmless child directly and through the approved parent, and inspect its effective privilege and policy result. Include a child intended to be denied. Resolve discrepancies before rollout, then repeat the business task to check compatibility. Preserve the parent rule, child identity, launch path, and observed outcome as one evidence set.
Official references
Microsoft Learn: Creating elevation rules with Endpoint Privilege Management.
Review the official source
Creating elevation rules with Endpoint Privilege Management - Microsoft Intune | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE