Using Intune Endpoint Privilege Management to run admin apps as a standard user
You have a Microsoft 365 subscription that contains 1,000 users and a group named Group1. All the users have Windows 11 devices. The users sign in to their devices by using their Microsoft Entra account. The users do NOT have administrative rights to their devices. The members of Group1 remotely assist the users by taking control of user sessions. The remote control sessions run in the security context of the users they are assisting. You need to recommend a solution that will enable the Group1 members to run apps that require administrative rights to the users' devices. The solution must ensure that the apps are run in the context of each signed-in standard user. What should you include in the recommendation?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
EPM lets standard users run specific elevated apps without being local admins; LAPS manages local admin passwords, Permissions Management is cloud CIEM, and PIM governs Entra roles—none provide on-demand app elevation for standard users.
To let Group1 members run apps that require admin rights in the context of signed-in standard users without granting those users admin rights, use Microsoft Intune Endpoint Privilege Management (EPM), which elevates approved apps on demand.
Choosing LAPS (A) — LAPS manages and rotates the local administrator account password but does not let a standard user elevate specific apps.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Intune Endpoint Privilege Management (EPM) lets organizations' users run as standard users (without administrator rights) while still completing tasks that require elevated privileges, running the app in the context of the signed-in standard user. This exactly matches the requirement.Why the Other Options Are Wrong
Windows LAPS (A) only manages the local administrator password, not per-app elevation. Entra Permissions Management (B) is a multicloud CIEM tool. PIM in Entra ID (D) governs eligible directory roles, not local device app elevation.Community Comment Notes
The community favored C (100 votes). Comments cite the EPM overview stating standard users can run elevated apps via EPM, with no dissent.Official Reference
Related Analysis
Practice All SC-100 Questions
Access 110 questions with complete answers and detailed explanations.
View Full SC-100 Practice Test →