Blog

Using Endpoint Privilege Management with Azure Virtual Desktop: Secure Elevation Without Local Admin Rights

Azure Virtual Desktop is commonly used to provide secure access to corporate applications, development environments, cloud platforms, support tools, and administrative workspaces.

However, one challenge I've see is this:

How do we let users perform the tasks they need without giving them permanent local administrator rights?

Granting local admin access inside AVD session hosts can introduce unnecessary risk, including accidental system changes, malware running with elevated permissions, and increased lateral movement potential if an account or session is compromised.

This is where Microsoft Intune Endpoint Privilege Management (EPM) can add real value.

EPM allows organisations to remove standing local administrator rights while still permitting approved applications, scripts, installers, diagnostic tools, or support utilities to run with elevated privileges when required. This supports a least-privilege and Zero Trust-aligned approach without creating unnecessary blockers for users.

For Azure Virtual Desktop, EPM is particularly useful for helping secure developer, admin, and operational desktop sessions by allowing users to operate as standard users and only elevate specific approved tasks. It’s important to note that Microsoft currently supports EPM on AVD single-session virtual machines.

Key Benefits

  • Least privilege by default Users can complete day-to-day activities without being local administrators.
  • Just-in-time elevation Approved files, binaries, scripts, or tools can be elevated only when required.
  • Policy-based control IT teams can define what can elevate, who can elevate it, and under what conditions.
  • Improved auditability Elevation activity can be captured through Intune reporting, helping security and operations teams review privileged activity.
  • Reduced operational risk Organisations can avoid giving broad local administrator access across AVD session hosts.
  • Supports Zero Trust principles EPM helps reduce standing privilege and aligns well with a modern least-privilege access model.

Important Pre-Requisites to Consider

Before deploying EPM with AVD, it’s worth validating a few key areas:

🔹 Licensing Endpoint Privilege Management requires the appropriate Intune and EPM licensing, so entitlement should be confirmed before design or deployment.

🔹 AVD host type EPM support for AVD currently applies to single-session virtual machines, so host pool design needs to be checked carefully.

🔹 Operating system support Session hosts need to be running supported Windows 10 or Windows 11 versions and builds.

🔹 Device join and management state Devices must be Microsoft Entra joined or hybrid joined, and enrolled in Microsoft Intune or co-managed with Microsoft Configuration Manager.

🔹 Network connectivity AVD session hosts need to communicate with the required EPM service endpoints, and SSL inspection should not interfere with this traffic.

🔹 Clear operating model Before rollout, teams should identify user personas, applications requiring elevation, approval owners, reporting requirements, and the process for handling future elevation requests.

Real-World Examples

EPM can be valuable in several practical AVD scenarios:

Developers Developers may need to update selected development tools, run approved installers, or execute specific build utilities without being local admins on the AVD host.

Support teams Service desk or support engineers may need to run approved diagnostic tools or troubleshooting utilities with elevated permissions, without having broad admin access.

Engineering teams Engineers may need to execute approved scripts or utilities that require elevation for operational tasks, while still working from a standard user session.

Application owners Application teams may need controlled elevation to update approved line-of-business components or maintenance tools in a secure and auditable way.

Security-focused environments For organisations with strict security requirements, EPM helps remove unnecessary local admin rights while still enabling business-critical activities through controlled elevation.

A Sensible Deployment Approach

A good rollout usually starts small:

  1. Confirm licensing, OS support, Entra join status, and Intune enrolment
  2. Identify the AVD users and groups that require elevation
  3. Capture the specific apps, scripts, installers, and tools that need admin rights
  4. Create pilot EPM policies and elevation rules
  5. Test the user experience and reporting
  6. Refine the rules before wider production rollout
  7. Monitor elevation activity and manage new requests through a defined approval process

…and finally

Don’t give users permanent local admin rights when you can provide controlled, approved, and auditable elevation instead.

Endpoint Privilege Management with Azure Virtual Desktop gives organisations a practical way to improve security, reduce operational risk, and maintain productivity all while supporting a stronger Zero Trust posture.

Leave a Reply

Your email address will not be published. Required fields are marked *

This field is mandatory

This field is mandatory

This field is mandatory

There was an error submitting your message. Please try again.

Security Check

Invalid Captcha code. Try again.

©Copyright. All rights reserved.

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.