Using Intune Endpoint Privilege Management to run admin apps as a standard user

Specify requirements for securing server and client endpoints
Answer Correct answer: C — Intune Endpoint Privilege Management lets standard users run approved admin-required apps without local admin rights.

You have a Microsoft 365 subscription that contains 1,000 users and a group named Group1. All the users have Windows 11 devices. The users sign in to their devices by using their Microsoft Entra account. The users do NOT have administrative rights to their devices. The members of Group1 remotely assist the users by taking control of user sessions. The remote control sessions run in the security context of the users they are assisting. You need to recommend a solution that will enable the Group1 members to run apps that require administrative rights to the users' devices. The solution must ensure that the apps are run in the context of each signed-in standard user. What should you include in the recommendation?

  1. Windows Local Administrator Password Solution (Windows LAPS)
  2. Microsoft Entra Permissions Management
  3. Microsoft Intune Endpoint Privilege Management Correct Answer
  4. Privileged Identity Management (PIM) in Microsoft Entra ID

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

EPM lets standard users run specific elevated apps without being local admins; LAPS manages local admin passwords, Permissions Management is cloud CIEM, and PIM governs Entra roles—none provide on-demand app elevation for standard users.

To let Group1 members run apps that require admin rights in the context of signed-in standard users without granting those users admin rights, use Microsoft Intune Endpoint Privilege Management (EPM), which elevates approved apps on demand.

Choosing LAPS (A) — LAPS manages and rotates the local administrator account password but does not let a standard user elevate specific apps.

Community Discussion (3 comments)

AleFerrillo 👍 2 Selected: C
"With Microsoft Intune Endpoint Privilege Management (EPM) your organization’s users can run as a standard user (without administrator rights) and complete tasks that require elevated privileges" https://learn.microsoft.com/en-us/mem/intune-service/protect/epm-overview
676ae1a 👍 2 Selected: C
Respuesta correcta
Ali96 👍 2 Selected: C
C. Microsoft Intune Endpoint Privilege Management.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Intune Endpoint Privilege Management (EPM) lets organizations' users run as standard users (without administrator rights) while still completing tasks that require elevated privileges, running the app in the context of the signed-in standard user. This exactly matches the requirement.

Why the Other Options Are Wrong

Windows LAPS (A) only manages the local administrator password, not per-app elevation. Entra Permissions Management (B) is a multicloud CIEM tool. PIM in Entra ID (D) governs eligible directory roles, not local device app elevation.

Community Comment Notes

The community favored C (100 votes). Comments cite the EPM overview stating standard users can run elevated apps via EPM, with no dissent.

Official Reference

Related Analysis

Practice All SC-100 Questions

Access 110 questions with complete answers and detailed explanations.

View Full SC-100 Practice Test →

← Back to SC-100 Study Guide