Endpoint Privilege Management is arguably one of the strongest features of Intune Suite. It's built in, straight-forward to setup, and works great.
But I'm often asked how we can use this to give users the ability to install applications they download themselves (whether this is a good idea or not will depend on the situation and your security team).
Today we'll talk about using the Support-Approved elevation feature to allow users to request permission to install software, and even create a permanent rule for certain installers going forward.
Join the official Discord server
/ discord
Read more at
https://www.getrubix.com
Chapters
0:00:00 Hot dog eating olympics
0:00:55 Reminder: Endpoint privilege management is cool
0:01:34 Default elevation settings
0:03:01 How do you elevate if you don't know about the app?
0:03:55 Create support approval default setting
0:04:40 Request approval
0:05:22 Admin approval process
0:07:08 Make a policy for that installer
0:07:49 Grab the file hash
0:08:19 Create a new rule
0:09:33 Install the app without approval
0:09:54 Privilege management is maturing
#intune #autopilot #windows10 #windows11 #microsoftgraph #azureadministrator #azure #powershellscripting #powershell #activedirectory #bitlocker #windows365 #zerotrust #certificate #entra #microsoftdefender #zerotrust #mdm