nerdexam
Microsoft

SC-100 · Question #212

You have a Microsoft 365 subscription that contains 1,000 users and a group named Group1. All the users have Windows 11 devices. The users sign in to their devices by using their Microsoft Entra…

The correct answer is C. Microsoft Intune Endpoint Privilege Management. With Microsoft Intune Endpoint Privilege Management (EPM) your organization's users can run as a standard user (without administrator rights) and complete tasks that require elevated privileges. Tasks that commonly require administrative privileges are application installs…

Design security operations, identity, and compliance capabilities

Question

You have a Microsoft 365 subscription that contains 1,000 users and a group named Group1. All the users have Windows 11 devices. The users sign in to their devices by using their Microsoft Entra account. The users do NOT have administrative rights to their devices. The members of Group1 remotely assist the users by taking control of user sessions. The remote control sessions run in the security context of the users they are assisting. You need to recommend a solution that will enable the Group1 members to run apps that require administrative rights to the users' devices. The solution must ensure that the apps are run in the context of each signed-in standard user. What should you include in the recommendation?

Options

  • AWindows Local Administrator Password Solution (Windows LAPS)
  • BMicrosoft Entra Permissions Management
  • CMicrosoft Intune Endpoint Privilege Management
  • DPrivileged Identity Management (PIM) in Microsoft Entra ID

How the community answered

(46 responses)
  • A
    17% (8)
  • B
    9% (4)
  • C
    70% (32)
  • D
    4% (2)

Explanation

With Microsoft Intune Endpoint Privilege Management (EPM) your organization's users can run as a standard user (without administrator rights) and complete tasks that require elevated privileges. Tasks that commonly require administrative privileges are application installs (like Microsoft 365 Applications), updating device drivers, and running certain Windows diagnostics. Endpoint Privilege Management supports your Zero Trust journey by helping your organization achieve a broad user base running with least privilege, while allowing users to still run tasks allowed by your organization to remain productive. For more information, see Zero Trust with Microsoft Intune. https://learn.microsoft.com/en-us/mem/intune/protect/epm-overview

Topics

#Endpoint Privilege Management#Microsoft Intune#Privilege Elevation#Remote Assistance

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice