# Staff the EPM approval queue before requiring support-approved elevation

> Can the helpdesk operate the EPM approval window and communicate both decisions?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:37+00:00
- Modified: 2026-09-10T00:55:36+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Can the helpdesk operate the EPM approval window and communicate both decisions?

## Potentially affected

Use this operating plan for support-approved Endpoint Privilege Management requests. Confirm who can review the relevant device population and who will communicate with the requester.

## DSE recommendation

Assign queue coverage and a documented checking interval before making approval a dependency for routine work.

## Article

## Source facts

Intune does not notify administrators when a new EPM elevation request arrives. An approval permits the requesting user to elevate that file on that device for 24 hours from approval; administrators cannot customize or cancel that period early. Denied users are not automatically notified. Reviewing requests requires the EPM elevation-request permissions within the administrator’s configured scope. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/epm/manage-support-approvals).

## Applicability

Use this operating plan for support-approved Endpoint Privilege Management requests. Confirm who can review the relevant device population and who will communicate with the requester.

## DSE recommendation

Assign queue coverage and a documented checking interval before making approval a dependency for routine work. Review the requested file, user, device, and business reason together. Approve only when the owner accepts the complete elevation window; do not promise an early withdrawal that the documented workflow cannot provide. Require a decision reason in the team’s procedure and contact denied users directly with the approved explanation.

## Verification

Submit an authorized test request and confirm that the assigned reviewer can find it without relying on an alert. Check the approval time and expiration, and verify the intended file’s behavior on the requesting device. Separately rehearse a denial and the helpdesk’s manual response. Retain the decision trail and any communication delay, then adjust staffing before expanding the workflow.

## Official references

[Microsoft Learn: Use EPM support approvals for file elevation requests with Intune](https://learn.microsoft.com/en-us/intune/epm/manage-support-approvals).

## Primary reference

- Name: Use EPM support approvals for file elevation requests with Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/epm/manage-support-approvals
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Staff the EPM approval queue before requiring support-approved elevation,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-199-staff-the-epm-approval-queue-before-requiring-support-approved-elevation/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
