EPM and User Account Control issue

Anna Valvanne 0 Reputation points
2025-05-19T15:54:25.1266667+00:00

Hi community,

I'm trying to setup Endpoint privilege management for the organization for the first time with the goal of changing all our users from local admins to standard users on their Intune managed devices. However, I run into issues as soon as I remove the users local admin rights and assign them to an admin group.

I have my EPM Settings policy (Require support approval) and my Rules policies assigned to my test user group all setup and the setup works until I remove the local admin rights from my test user and assign them to the admins group (using the Account protection). After that the user is not able to send elevation requests for tasks that require elevation like managing Bitlocker or opening the Device manager as a UserAccess Control pop-up requires an admin to log in on the computer. It seems like the UAC is overriding EPM.

I would like the users to be able to ask for an elevation in these situations instead of having them all run to my office.

I also tried to create a rule for Bitlocker to allow users to confirm elevations themselves, but that does not work. The users till gets the UAC admin credentials pop up. Same with Device manager and some other tasks.

Obviously as an admin I do also need to be able to access all the settings on the laptops if I do troubleshooting on them.

How do organizations usually manage these or does anyone have personal experience of setting this kind of an environment? Am I missing something?

Licences: M365 Business Premium with Intune EPM add-on

Microsoft Security | Intune | Application management
{count} votes

5 answers

Sort by: Most helpful
  1. Prathista Ilango 345 Reputation points Microsoft Employee
    2025-06-17T13:28:11.1933333+00:00

    Hello Anna,

    Settings policy is configured for default operations/apps that are not controlled by rules policy.

    Refer to: https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-policies#about-windows-elevation-settings-policy

    Couple of things to check -

    1. If you are using settings policy (no rule policy for the app), confirm the user is requesting elevation explicitly by clicking - "Run with elevated access"
    2. If the rule policy is configured for the file, make sure you have configured this with strong file detection values (not just name but stronger mapping like certificate, file hash or other attributes). Refer to: Guidance for creating elevation rules with Endpoint Privilege Management | Microsoft Learn
    3. Look for policy conflicts if any. Refer to: https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-policies#policy-conflict-handling-for-endpoint-privilege-management

    Also refer to: https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-guidance-for-creating-rules#deploying-rules-created-with-endpoint-privilege-management

    https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-guidance-for-creating-rules#endpoint-privilege-management-and-user-account-control

    Hope this helps!

    If you found the information above helpful, please Click Yes. This will assist others in the community who encounter a similar issue, enabling them to quickly find the solution and benefit from the guidance provided.

    1 person found this answer helpful.
    0 comments No comments

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  4. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  5. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.