Our 2 Cents and Conclusion
Making end users administrators on their machines is never advisable. Therefore, we must first ensure that all end users in our workforce are standard users.Does this mean we need to assign EPM licenses to all end users so they can elevate themselves to admin status for an application session? The answer is NO. Our primary method for installing applications on devices should be to push them as required via Intune. If we are unsure whether an end user truly needs an application, we have the option to push those apps as 'Available.' This makes the applications accessible in the Company Portal, allowing end users to download and install them as needed without requiring elevation to admin status.EPM is designed for scenarios where end users may need to perform extensive testing and install applications that are not commonly deployed by the admin through the Intune portal. Instead of relying on the admin to deploy the application, the user can request elevation...