# Evaluate the profile dependency before choosing EPM current-user elevation

> When does an application's user-profile dependency justify EPM Elevate as current user?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-154-evaluate-the-profile-dependency-before-choosing-epm-current-user-elevation/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:22+00:00
- Modified: 2026-09-10T00:55:35+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

When does an application's user-profile dependency justify EPM Elevate as current user?

## Potentially affected

Apply this decision to an application already being evaluated for EPM elevation. Identify which task depends on the active profile rather than assuming every installer needs the current-user mode.

## DSE recommendation

Require a reproducible profile-related failure before granting the less-isolated elevation mode.

## Article

## Source facts

Endpoint Privilege Management normally elevates through a virtual account, separating the elevated process from the user’s profile. Elevate as current user instead keeps the signed-in identity and its profile paths, environment variables, and personalized settings; Windows authentication is required. Microsoft describes this as a compatibility choice that increases exposure to user data, and advises using it only when virtual-account elevation causes application failures. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/epm/deployment-planning).

## Applicability

Apply this decision to an application already being evaluated for EPM elevation. Identify which task depends on the active profile rather than assuming every installer needs the current-user mode.

## DSE recommendation

Require a reproducible profile-related failure before granting the less-isolated elevation mode. Ask the application owner to document the failed operation, relevant profile dependency, and approved executable location. Prefer a narrowly scoped exception over changing an entire software category. Have the security owner explicitly review the additional user-data exposure and the intended credential prompt.

## Verification

Compare the same approved task under virtual-account and current-user elevation in a representative test profile. Inspect which identity and profile paths the process actually uses, then verify that the task succeeds without unrelated privileged activity. Retain the comparison and exception owner. Revisit the exception after an application update instead of assuming the compatibility need is permanent.

## Official references

[Microsoft Learn: Plan and Prepare for Endpoint Privilege Management Deployment](https://learn.microsoft.com/en-us/intune/epm/deployment-planning).

## Primary reference

- Name: Plan and Prepare for Endpoint Privilege Management Deployment - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/epm/deployment-planning
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Evaluate the profile dependency before choosing EPM current-user elevation,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-154-evaluate-the-profile-dependency-before-choosing-epm-current-user-elevation/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
