The Principle of Least Privilege (PoLP) is a cybersecurity practice that restricts users, applications, and processes to the minimum access permissions strictly necessary to perform their jobs. It prevents over-privileged access, which naturally shrinks your security footprint and isolates damage if an account or system is compromised.
The desire to conform to PoLP has become one of the fundamental principles of modern endpoint security. In fact, these last few weeks I’ve been actively engaged in removing a non-Microsoft EPM solution from an environment, in favour of Microsoft EPM.
Previously, implementing least privilege controls has often required expensive specialist products from vendors such as BeyondTrust, Admin By Request, AutoElevate or Ivanti. Then Microsoft introduced EPM by way of Intune Suite, that from my experience, didn’t really sell… and well, this has now changed. Microsoft now includes Endpoint Privilege Management (EPM) with Microsoft 365 E5, bringing just-in-time elevation directly into Intune. (For what it’s worth, EPM remains available as a standalone product too).
How does Microsoft EPM hold up?
Microsoft EPM focuses on managed Windows devices – caveat number 1 right there, Microsoft EPM is Windows only! Administrators can define elevation rules, require business justification, control approval workflows and audit privileged activity without granting users permanent local administrator rights.
Compared with BeyondTrust, Microsoft’s solution is less feature-rich.
Compared with Admin By Request, it currently offers fewer workflow options.
Compared with AutoElevate, Microsoft’s approval experience is simpler but tightly integrated into the wider Microsoft ecosystem.
The biggest advantage
When using Microsoft tooling, inside the Microsoft ecosystem, everything PoLP related lives inside Intune. Policies, reporting, identity, Conditional Access and device compliance all come together in a single platform. There is no separate agent and no additional management portal.
My thoughts
As someone who is actively helping an organisation migrate away from A N Other privilege management products, I think this is one of Microsoft’s most significant additions to Microsoft 365. Plenty of people out there have PoLP on their to do, and are quite some way from starting the journey. So the inclusion into E5 will provide a lot of those folk with a quick win (potentially, assuming they implement it). But will Microsoft EPM replace every BeyondTrust or Ivanti deployment out there today? No. It’s simply not able to provide parity in it’s feature set – yet.
But for organisations already standardising on Microsoft Intune, it’s now difficult to justify purchasing a separate privilege management platform before properly evaluating what’s already included in E5. Or, renewing with an existing supplier, if Microsoft EPM meets your requirements — as with my active engagement.
Leave a Reply