Event banner
Limit your attack surface with Endpoint Privilege Management
Event details
Learn how to balance security and productivity by managing standard users more efficiently. Endpoint Privilege Management (EPM) in Microsoft Intune enables admins to set policies that limit the applications that can elevate, reducing attack surface, improving IT efficiency, and streamlining work for employees.
This session is part of the Microsoft Intune Suite Tech Accelerator. RSVP for event reminders, add it to your calendar, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event. |
43 Comments
- MikePhuCopper Contributorcurious to know how this compares to cyberark
- Matt_Call
Microsoft
We have several customers comparing us to other tools that have similar capability. We are excited to solve the problem and make sure that we have the right set of tools to allow organizations to run as standard user. If there is anything we need to add to make sure you can run as standard users with our tools, please let us know.
- HeyHey16KIron ContributorEPM is a premium extra cost 😞 Can we just pay for the users who need to use it?
- JaneStebbsCopper ContributorSay for example 5 users need to regularly update a package and 5 more users need to install a printer driver. Also that we have 100 users on our tenant. Will we need 5 bolt-ons to Intune that can be re-deployed as required, 10 or 100 to use this feature?
- DaneaGalbraithIron Contributor
How long does the data last? And do we have to pay for storage for the data.
- PriyankaDua
Microsoft
The reporting data lasts 30 days. EPM has a license, that is what we pay for, not for data storage.
- Matt_Call
Microsoft
EPM Looks awesome! 🙂 - Olaf_ThyssenBrass ContributorAre the policies cached on the device and if offline (no Internet/Intune connectivity) the rules still work?
- Mark Silvey
Microsoft
Yes, elevation rules apply on disconnected devices.
- Scarbossa17Copper ContributorIncluded in 365 E3 and E5?
- Joe_Lurie
Microsoft
Scarbossa17 EPM is available as part of the Intune Suite or as a stand-alone product. See our Intune Plans and Pricing page for more information: Microsoft Intune Plans and Pricing
- MattAljanabiCopper ContributorCan we use EPM for one folder system inside c drive? we really need it.
- Matt_Call
Microsoft
We do support File Path as a parameter. You can pair the file path with something like a certificate rule to make sure anyone with 'write' capability has some guard rails in place.- MattAljanabiCopper ContributorMatt, can you please give us an example to let the user log in to C:\Windows\ccmcache as folder? Thanks
- treestryderIron Contributor
I have never had to root a mobile phone to make it useful. Why is regularly rooting a Windows device still "normal" procedure?
#ShouldBeUWP
- Joe_Lurie
Microsoft
treestryder Curious what you mean by the Windows device needing to be rooted to make it useful. I will reach out via DM for more information on this.
- rejohnsonIron ContributorI hope this gets rolled into ConfigMgr co-management!
- Matt_Call
Microsoft
There isn't a matching on-premises workload that would require us to support co-management. Today we are exclusively supporting Intune managed devices, and we will look at how we expand the footprint in the future. Thanks for the feedback.
- Heather_Poulsen
Community Manager
Welcome to Limit your attack surface with Endpoint Privilege Management and the Tech Accelerator for the Microsoft Intune Suite. Let's get started! Have a question? Post here in the Comments so we can help. Let’s make this an active Q&A!