# Do not mistake EPM's default response for a universal application block

> Which elevation attempts does EPM's default response actually govern?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-344-do-not-mistake-epm-s-default-response-for-a-universal-application-block/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:12+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Which elevation attempts does EPM's default response actually govern?

## Potentially affected

Review the fallback configuration on EPM-enabled Windows devices. Distinguish matching rules, the EPM context-menu path, and users' existing administrator rights before describing the result as enforcement.

## DSE recommendation

Write the intended unmatched-file behavior explicitly and verify the route used to request elevation.

## Article

## Source facts

An EPM default elevation response applies only when no file rule matches and the user requests elevation through Run with elevated access. Leaving the response unconfigured falls back to denying those requests. Requiring user confirmation permits unmatched files to elevate by default. Conversely, Deny all requests does not stop a user who already has administrative permissions from using Windows Run as administrator for unmanaged files. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/epm/manage-elevation-settings).

## Applicability

Review the fallback configuration on EPM-enabled Windows devices. Distinguish matching rules, the EPM context-menu path, and users’ existing administrator rights before describing the result as enforcement.

## DSE recommendation

Write the intended unmatched-file behavior explicitly and verify the route used to request elevation. Prefer the source’s restrictive fallback choices unless an approved requirement justifies something else. Do not interpret a confirmation click as proof that a file was preapproved. Review retained local administrator access separately, and explain the difference between the two elevation entry points in helpdesk guidance.

## Verification

Use a harmless unmatched file and test the EPM request with an intended standard user. Separately inspect behavior for an authorized test administrator using the Windows entry point. Record which path was exercised and why its outcome is expected. Investigate a matched rule before attributing its result to the default response.

## Official references

[Microsoft Learn: Managing Elevation Settings for Endpoint Privilege Management](https://learn.microsoft.com/en-us/intune/epm/manage-elevation-settings).

## Primary reference

- Name: Managing Elevation Settings for Endpoint Privilege Management - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/epm/manage-elevation-settings
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not mistake EPM's default response for a universal application block,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-344-do-not-mistake-epm-s-default-response-for-a-universal-application-block/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
