What you need to know
When does an application's user-profile dependency justify EPM Elevate as current user?
Potentially affected
Apply this decision to an application already being evaluated for EPM elevation. Identify which task depends on the active profile rather than assuming every installer needs the current-user mode.
DSE recommendation
Require a reproducible profile-related failure before granting the less-isolated elevation mode.
Source facts
Endpoint Privilege Management normally elevates through a virtual account, separating the elevated process from the user’s profile. Elevate as current user instead keeps the signed-in identity and its profile paths, environment variables, and personalized settings; Windows authentication is required. Microsoft describes this as a compatibility choice that increases exposure to user data, and advises using it only when virtual-account elevation causes application failures. Microsoft Learn.
Applicability
Apply this decision to an application already being evaluated for EPM elevation. Identify which task depends on the active profile rather than assuming every installer needs the current-user mode.
DSE recommendation
Require a reproducible profile-related failure before granting the less-isolated elevation mode. Ask the application owner to document the failed operation, relevant profile dependency, and approved executable location. Prefer a narrowly scoped exception over changing an entire software category. Have the security owner explicitly review the additional user-data exposure and the intended credential prompt.
Verification
Compare the same approved task under virtual-account and current-user elevation in a representative test profile. Inspect which identity and profile paths the process actually uses, then verify that the task succeeds without unrelated privileged activity. Retain the comparison and exception owner. Revisit the exception after an application update instead of assuming the compatibility need is permanent.
Official references
Microsoft Learn: Plan and Prepare for Endpoint Privilege Management Deployment.
Review the official source
Plan and Prepare for Endpoint Privilege Management Deployment - Microsoft Intune | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE