Configuring Endpoint Privilege Management
Endpoint Privilege Management (EPM) is a mechanism for elevating particular applications for end users without granting them administrative rights across the device. This could be for a particular line-of-business application that requires elevation or for your helpdesk to be able to run particular tools on devices. We can configure rules for EPM to allow automatic elevation or have it require approval first.
This recipe will demonstrate how to configure EPM and then add a file rule to allow a particular application to run elevated.
How to do it…
First, we will run through how to configure EPM in the UI:
- Navigate to Endpoint security and click on Endpoint Privilege Management.
- We need to start with a settings policy, so click Create and then, in the fly-out, select Windows 10 and later and Elevation settings policy. Then, click the Create button.
- Give your policy a Name and Description and click Next.
- On...