GuideInformationBusiness ContinuityIT

Evaluate the profile dependency before choosing EPM current-user elevation

When does an application's user-profile dependency justify EPM Elevate as current user?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

When does an application's user-profile dependency justify EPM Elevate as current user?

Potentially affected

Apply this decision to an application already being evaluated for EPM elevation. Identify which task depends on the active profile rather than assuming every installer needs the current-user mode.

DSE recommendation

Require a reproducible profile-related failure before granting the less-isolated elevation mode.

Source facts

Endpoint Privilege Management normally elevates through a virtual account, separating the elevated process from the user’s profile. Elevate as current user instead keeps the signed-in identity and its profile paths, environment variables, and personalized settings; Windows authentication is required. Microsoft describes this as a compatibility choice that increases exposure to user data, and advises using it only when virtual-account elevation causes application failures. Microsoft Learn.

Applicability

Apply this decision to an application already being evaluated for EPM elevation. Identify which task depends on the active profile rather than assuming every installer needs the current-user mode.

DSE recommendation

Require a reproducible profile-related failure before granting the less-isolated elevation mode. Ask the application owner to document the failed operation, relevant profile dependency, and approved executable location. Prefer a narrowly scoped exception over changing an entire software category. Have the security owner explicitly review the additional user-data exposure and the intended credential prompt.

Verification

Compare the same approved task under virtual-account and current-user elevation in a representative test profile. Inspect which identity and profile paths the process actually uses, then verify that the task succeeds without unrelated privileged activity. Retain the comparison and exception owner. Revisit the exception after an application update instead of assuming the compatibility need is permanent.

Official references

Microsoft Learn: Plan and Prepare for Endpoint Privilege Management Deployment.

Primary reference

Review the official source

Plan and Prepare for Endpoint Privilege Management Deployment - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE