Epm Elevation Rules
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/protect/epm-elevation-rules.md.
The period’s main administrator-relevant change is new and expanded Cloud PKI guidance for expiring issuing CAs. It documents a customer-managed replacement procedure and the potential certificate, connectivity, and authentication impact of taking no action. Endpoint Privilege Management documentation also clarifies child-process elevation semantics. The remaining Cloud PKI edits are wording and heading maintenance; renewal of an existing CA is described as coming soon, not as an available feature.
The new guidance says Microsoft cannot automatically update a Cloud PKI CA or its SCEP profiles. Administrators must create a new issuing CA, replace the expiring CA’s SCEP URI in each affected profile, and verify all profiles reference the new CA. After expiration, affected profiles stop issuing new certificates, potentially causing Wi-Fi, VPN, email, corporate-resource, or certificate-authentication failures. The article says the ability to renew an existing CA is coming soon, so this is operational guidance for
The updated Endpoint Privilege Management page distinguishes three choices: require the child’s own rule, deny elevation to all child processes, or allow child processes to run elevated automatically. With the last option, child rule evaluation is skipped, including deny rules, so a child can run elevated despite an explicit denial. Microsoft’s documented best practice is to avoid overly broad rules for applications that can launch shells or script engines.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updated Microsoft Intune documentation in intune/intune-service/protect/epm-elevation-rules.md.
Added Microsoft Intune documentation in intune/cloud-pki/renew-ca.md.
Updated Microsoft Intune documentation in intune/cloud-pki/renew-ca.md.
Updated Microsoft Intune documentation in intune/cloud-pki/renew-ca.md.