GuideInformationBusiness ContinuityIT

Check the explicit EPM report permission when a reader receives HTTP 403

Why can an Intune reader lose access to EPM report data despite device-configuration read permission?

Integrated video surveillance and controlled entry at a modern commercial facility.
DSE visual intelligencePhysical securityGuide · 2 min read
Executive summary

What you need to know

Why can an Intune reader lose access to EPM report data despite device-configuration read permission?

Potentially affected

Use this diagnostic for an intended EPM report consumer, including an existing custom-role reader. Keep authorization failure separate from an authorized report that has no recent matching data.

DSE recommendation

Inspect the dedicated report permission before adding broad administration rights.

Source facts

Access to Endpoint Privilege Management reports in the Intune portal or Microsoft Graph requires the EPM Policy Authoring View Reports permission, identified as EpmPolicy.ViewReports in Graph. Device configurations Read, which previously allowed access, is no longer sufficient. Without that permission, the privilegeManagementElevations endpoint returns HTTP 403. Separately, report content depends on each device’s configured reporting scope and is processed once every 24 hours. Microsoft Learn.

Applicability

Use this diagnostic for an intended EPM report consumer, including an existing custom-role reader. Keep authorization failure separate from an authorized report that has no recent matching data.

DSE recommendation

Inspect the dedicated report permission before adding broad administration rights. Ask the Intune role owner to confirm the reader’s approved reporting responsibilities and effective role assignment. If a change is justified, grant the specific reporting capability through the organization’s scoped role process. Do not add policy creation, assignment, or elevation-approval authority merely to recover read access.

Verification

With the intended identity, compare the report request before and after the approved role adjustment. Confirm a report can be read and that unrelated management operations remain unavailable. Then evaluate reporting scope and processing delay if expected entries are missing. Save the endpoint, response status, and role evidence without exporting sensitive elevation details unnecessarily.

Official references

Microsoft Learn: Monitor your Endpoint Privilege Management policies for Microsoft Intune.

Primary reference

Review the official source

Monitor your Endpoint Privilege Management policies for Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE