Run processes with elevated privileges using the Entra account.

Mountain Pond 1,506 Reputation points
2025-02-20T18:18:16.3833333+00:00

Hello, Windows devices are managed by Intune.

All users have standard user privileges. For IT department employees, the "Microsoft Entra Joined Device Local Administrator" role is assigned

However, to perform any administrative actions, you need to end the user session and log in as an administrator.

Running a process from another user or with elevated privileges does not work. Because the user input format "AzureAD******@contoso.com" no longer works.

It will not be possible to use LAPS, because the local administrator account is disabled.

What can you recommend to run processes with elevated privileges and using the Entra ID account, without ending the user session.

Suppose the user works via RDP and many sessions do not work.

Thank you.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
467 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 52,216 Reputation points Microsoft Vendor
    2025-02-21T01:16:22.83+00:00

    @Mountain Pond, Thanks for posting in Q&A. For your scenario, you can consider Endpoint Privilege Management (EPM). With it, your organization’s users can run as a standard user (without administrator rights) and complete tasks that require elevated privileges. Tasks that commonly require administrative privileges are application installs and running certain Windows diagnostics. Maybe this is a good option for you. You can read the following link to know more details.

    https://learn.microsoft.com/en-us/mem/intune/protect/epm-overview

    Hope the above suggestion can give you some help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.