Epm Elevation Rules
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/protect/epm-elevation-rules.md.
New Cloud PKI guidance explains how to avoid certificate-issuance disruption when an issuing CA approaches expiration. Endpoint Privilege Management documentation also makes the child-process elevation choices and their security implications more explicit.
If an issuing CA expires, profiles using it cannot issue new certificates, risking Wi-Fi, VPN, email, corporate-resource, and certificate-authentication failures. Microsoft says administrators must create a new issuing CA and replace the old SCEP URI in each affected profile; Microsoft cannot do this automatically.
Elevation rules can require each child process to meet its own rule, deny all child elevation, or allow children to inherit elevation. The documentation warns that inherited elevation skips child rule and deny-rule evaluation, and recommends avoiding broad rules for shells and script engines.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updated Microsoft Intune documentation in intune/intune-service/protect/epm-elevation-rules.md.
Added Microsoft Intune documentation in intune/cloud-pki/renew-ca.md.
Updated Microsoft Intune documentation in intune/cloud-pki/renew-ca.md.
Updated Microsoft Intune documentation in intune/cloud-pki/renew-ca.md.