Skip to content
Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune

Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune

Written By Vaishnav K
Last Updated July 14, 2026
Posted In Intune
SHARE

In this article am going to explain how the Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Microsoft Intune. This new EPM feature got added to Intune from Service Release 2501 onwards.

EPM is available as an Intune Suite add-on capability and as well as you can purchase it as a Standalone add-on offering. If your Azure Tenant is licensed for Microsoft Security Copilot, you can now leverage its capabilities to investigate Endpoint Privilege Manager (EPM) file elevation requests within the EPM support-approved workflow.

While reviewing a file elevation request, you’ll now see an option to Analyze with Copilot. Selecting this option prompts Security Copilot to use the file’s hash to query Microsoft Defender Threat Intelligence, assessing potential indicators of compromise. This allows you to make more informed decisions on whether to approve or deny the elevation request.

With Copilot’s AI-driven insights and Endpoint Privilege Manager (EPM) in Microsoft Intune, IT teams can proactively detect, assess, and mitigate privilege elevation risks. This ensures a secure, least-privilege environment while allowing users to perform necessary administrative tasks in a controlled manner.

Patch My PC
Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 1
Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 1

Key insights Provided in the Intune Admin Center

The below table shows some of the results that are returned to your current view in the Intune admin center.

Key InsightsDescription
File ReputationDetermines whether the file has been flagged as malicious or suspicious
Publisher Trust InformationEvaluates the credibility of the file’s publisher
User Risk ScoreAssesses the risk level of the user requesting elevation.
Device Risk ScoreAnalyzes the security posture of the device submitting the request
Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Table. 1

End User Actions – Support Approved EPM Elevation

As a standard user, you need to right-click the respective binary that you are going to install on the device and run the file using elevated context. Please keep in mind the EPM Elevation method should be in Support Approved.

In this example, I am using WinSCP-6.3.7-Setup.exe. So right-click on that and select “Run with elevated access

Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 2
Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 2

Here, you will get a pop-up window to “Request to open this app as administrator?” In the Enter the business justification section type a valid business justification and click on Send.

Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 3
Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 3

On the next screen will get a Request sent message saying “You’ll be able to run this app as administrator after your request is approved“. The support-approved elevation request has been sent successfully to the respective Intune Tenant. Just we need to click on Close.

Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 4
Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 4

Anayazise the Support Approved EPM Elevation Request from Intune Portal

Now the Intune admin needs to Analyze the Support Approved Endpoint Privilege Management Request, follow the below steps.

  • Sign In to the Microsoft Intune admin center
  • Navigate to Endpoint SecurityEndpoint Privilege Management > Choose Elevation requests.
  • Click on WinSCP-6.3.7-Setup.exe the latest elevated file by the user
Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 5
Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 5

Once you click on the WinSCP-6.3.7-Setup.exe it will take you through the Elevation request properties screen. As per the latest Intune update, you can see the “Analyze with Copilot” option available on the top side of the screen. Click on that.

Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 6
Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 6

Now the Copilot will start Analyzing the binary and provide the result. So that the Intune admin can decide whether he needs to Approve or Deny the Elevation from the user.

Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 7
Copilot with Endpoint Privilege Manager to Identify Potential Elevation Risks using Intune. Fig. 7

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Vaishnav K has over 11 years of experience in SCCM, Device Management, and Automation Solutions. He writes and imparts knowledge about Microsoft Intune, Azure, PowerShell scripting, and automation. Check out his profile on LinkedIn.

Written by

Vaishnav K has over 12+ years of experience in SCCM, Modern Device Management, and Automation Solutions. He writes and imparts his knowledge about Microsoft Intune, Windows 365, Azure, PowerShell scripting and automations. LinkedIn Profile : https://www.linkedin.com/in/vaishnav-k-957b0589/

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read