Event banner
Uplevel security with Endpoint Privilege Management + Windows LAPS
Event Ended
Tuesday, Nov 28, 2023, 07:00 AM PSTEvent details
It's simple. Running devices as standard user can help lower your attack surface. Let's talk about the threats we face today, the keys to implementing "just enough" access for your users with Microso...
Char_Cheesman
Updated Dec 27, 2024
Terry_Rutter
Nov 28, 2023Copper Contributor
You stated that EPM follows the same policy flow as normal policies. Does that mean that when you approve an elevation the endpoint must sync with Intune in order to get the permission to run elevated? If the client normally syncs every 8 hours, will that mean we need to tell our end users to manually kick off a sync? Under normal conditions there is a 15 minute "cool down" period where a device won't actually sync if it completed a sync within the last 15 minutes. How does that cool down period impact the elevation?
- Matt_CallNov 28, 2023
Microsoft
Hey Terry! We don't expect it will for a myriad of reasons. We will confirm this and add any notes and limitations to our documentation online if for some reason it does.- Terry_RutterNov 28, 2023Copper ContributorThanks Matt. We're actually planning to do a POC of EPM in mid- to late-January '24 and I'm hoping to have the docs you referenced above so we can get the most out of our POC.
- ericschreiberNov 30, 2023
Microsoft
Hi Terry - we've built EPM on new policy delivery / device check-in tech that's still being actively innovated on. You should never need to ask an end user to manually kick-off a sync. It is the case that for current Private Preview customers, it may take up to 4 hours for the new policy to be delivered, but by the time we GA we expect the policy-updated-so-notify-and-sync-now mechanism to be fully operational. We do have a background-processing delay that means the approval itself can take 15 minutes to be processed, but after it is processed we expect it to flow to the device and the user to receive the pop-up notification within seconds. And we'll be working on reducing that 15 minute background-processing delay, too.