QuestionQ195

Design security solutions for applications and data

You have a Microsoft 365 subscription that includes 1,000 users and a group named Group1. All users have Windows 11 devices. The users sign in to their devices using their Microsoft Entra accounts. The users do not have administrative rights on their devices.

Members of Group1 remotely assist users by taking control of user sessions. The remote-control sessions run in the security context of the users they assist.

You need to recommend a solution that enables Group1 members to run apps that require administrative rights on users' devices. The solution must ensure that the apps run in the context of each signed-in standard user.

What should you include in the recommendation?

  • A Windows Local Administrator Password Solution (Windows LAPS)
  • B Microsoft Entra Permissions Management
  • C Microsoft Intune Endpoint Privilege Management
  • D Privileged Identity Management (PIM) in Microsoft Entra ID
Explanation

Microsoft Intune Endpoint Privilege Management lets standard users run approved applications that require elevated privileges without granting permanent local administrator rights. Its Elevate as current user elevation type runs the elevated process under the signed-in user’s account, preserving the user context required for the remote-assistance session.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!