GuideInformationBusiness ContinuityIT

Do not mistake EPM's default response for a universal application block

Which elevation attempts does EPM's default response actually govern?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 1 min read
Executive summary

What you need to know

Which elevation attempts does EPM's default response actually govern?

Potentially affected

Review the fallback configuration on EPM-enabled Windows devices. Distinguish matching rules, the EPM context-menu path, and users' existing administrator rights before describing the result as enforcement.

DSE recommendation

Write the intended unmatched-file behavior explicitly and verify the route used to request elevation.

Source facts

An EPM default elevation response applies only when no file rule matches and the user requests elevation through Run with elevated access. Leaving the response unconfigured falls back to denying those requests. Requiring user confirmation permits unmatched files to elevate by default. Conversely, Deny all requests does not stop a user who already has administrative permissions from using Windows Run as administrator for unmanaged files. Microsoft Learn.

Applicability

Review the fallback configuration on EPM-enabled Windows devices. Distinguish matching rules, the EPM context-menu path, and users’ existing administrator rights before describing the result as enforcement.

DSE recommendation

Write the intended unmatched-file behavior explicitly and verify the route used to request elevation. Prefer the source’s restrictive fallback choices unless an approved requirement justifies something else. Do not interpret a confirmation click as proof that a file was preapproved. Review retained local administrator access separately, and explain the difference between the two elevation entry points in helpdesk guidance.

Verification

Use a harmless unmatched file and test the EPM request with an intended standard user. Separately inspect behavior for an authorized test administrator using the Windows entry point. Record which path was exercised and why its outcome is expected. Investigate a matched rule before attributing its result to the default response.

Official references

Microsoft Learn: Managing Elevation Settings for Endpoint Privilege Management.

Primary reference

Review the official source

Managing Elevation Settings for Endpoint Privilege Management - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE