Elevated Access on Windows Labs via EPM for Run Apps

Body

This article will show you how to use Microsoft Endpoint Privilege Management (EPM) in campus Public Windows Computer labs.

Students and faculty sign in as standard users for security, but some apps need extra permissions.

EPM lets you temporarily elevate an app without an administrator.

 

Before You Start

  • EPM can only elevate the following file types:

    • .exe – application installers

    • .msi – Windows installers

    • .ps1 – PowerShell scripts

  • If the elevation option doesn’t appear or your file type isn’t supported (e.g., .zip, .bat, drivers), reach out to the CIT HelpDesk.

  • Drivers cannot be elevated by EPM. If you need a driver installed or updated, contact the CIT HelpDesk.

How to Elevate an App Using EPM

  1. Open the Start Menu and locate the app you want to run.

    • You can also right-click the app if it’s on the Desktop.

  2. Right-click the app and Choose “Run with elevated access.” If you do not see Run with elevated access, please contact the CIT HelpDesk to submit a request for a specific app.

  3. A Microsoft EPM pop-up window will appear, click continueAn Endpoint Privilege Management dialog window asking Open this app as administrator? for LockDownBrowserOEM.exe, with Cancel and Continue buttons.

  4. Sign in with your SUNY Geneseo email and password. A Windows Security window prompting Enter your credentials to grant administrative privileges, showing a password input field for user account Madelyn Herbert (GENESEO\mherbert).

  5. The app will open with admin rights
    You can now install, update, or run the tool as needed.

You will need to repeat these steps each time you need elevated access for that app.

 

Still Need Help?

Ask CIT! 📞 (585) 245-5588 | 📧 Email | 💬 Chat | 📝 Submit a Request and we'll be happy to assist you.

 

Details

Details

Article ID: 1456
Created
Wed 6/3/26 2:21 PM
Modified
Mon 7/20/26 12:34 PM