The Endpoint Privilege Management cost question has a different answer since 1 July 2026, and most of the pricing pages ranking for it have not caught up. Microsoft folded Endpoint Privilege Management into Microsoft 365 E5 at no extra charge on that date, and left it a paid add-on everywhere below. The conclusion people jump to, that every E5 tenant can cancel a standalone subscription today, is nearly right. What follows is what each route costs, what the entitlement actually covers, and the cases where the correct spend is nothing at all.
The same July change moved Microsoft Cloud PKI across the same line in the same way, so what changed in the Intune Cloud PKI cost reads as a companion to this one. If the question underneath is the uplift itself rather than any single feature, the cliff edges that justify Microsoft 365 E5 is the wider version of the same calculation.
What the Endpoint Privilege Management cost actually buys
There are four routes to the same feature and they are priced very differently. The figures below are from Microsoft’s United Kingdom Intune pricing page as it stood on 9 September 2026. Microsoft publishes a sterling list price for the individual add-ons but not for the Intune Suite, so the Suite figure is the dollar price quoted in the FAQ on that same page. Licensing in this area has moved twice in eighteen months, so treat any figure you find without a date on it as wrong.
| Route | Cost | Base licence still required |
|---|---|---|
| Microsoft 365 E5, from 1 July 2026 | Included | Nothing further |
| Endpoint Privilege Management standalone add-on | £2.30 per user per month, paid yearly | Intune Plan 1 or Plan 2 |
| Microsoft Intune Suite | $10.00 per user per month | Includes Plan 2 and the other advanced capabilities |
| Microsoft 365 E3 | Not included | Add-on or Suite required |
Two lines in that table are routinely misread. The first is Plan 2. It is not a route to this feature. Microsoft’s deployment planning guidance states that the capability requires a subscription in addition to Microsoft Intune Plan 1 or Plan 2, so an organisation that buys Plan 2 hoping to reach elevation control has bought specialty device management and not much else. The second is the unit. The add-on is priced per user, not per tenant, so you licence the people who need to elevate rather than the whole estate. On a 2,000 seat estate where 200 developers and engineers need elevation, that distinction is the difference between a small line item and a real one.
The July split is asymmetric, and the asymmetry is where the money sits. Microsoft 365 E3 gained Remote Help, Advanced Analytics and the Intune Plan 2 capabilities. Microsoft 365 E5 gained all of that plus Endpoint Privilege Management, Enterprise Application Management and Microsoft Cloud PKI. Elevation control landed on the E5 side of that line. For an E3 tenant the Endpoint Privilege Management cost is still £2.30 per user per month, or the E5 uplift, and the add-on is almost always the cheaper of the two if this is the only thing you want.
Check what you already own before you buy anything
The change is described by Microsoft as a rollout tied to the July 2026 pricing update rather than a switch thrown once for every tenant on the same morning. That is a distinction worth taking seriously before you raise a purchase order or cancel one. Read your own tenant rather than a blog post, including this one.
# Every SKU in the tenant and the service plans inside it.
# Look for the endpoint privilege plan under your E5 SKU before buying the add-on.
Connect-MgGraph -Scopes Organization.Read.All
Get-MgSubscribedSku | Select-Object SkuPartNumber, ConsumedUnits, @{n='Plans';e={ ($_.ServicePlans | ForEach-Object ServicePlanName) -join ', ' }} | Format-List
If the capability is already inside your E5 subscription and you are also paying for the standalone add-on bought before July, you are paying twice for the same thing and nobody will tell you. That is the single highest value thing on this page for most readers, and it takes about two minutes to check.
What the money buys that removing local admin does not
Taking local administrator rights away is free and it is the right first move. The reason people pay for elevation control is the week after, when the service desk queue fills with the eleven legitimate tasks that genuinely needed those rights. Endpoint Privilege Management exists to answer those requests without handing the account back.
Microsoft documents five elevation behaviours. Automatic elevation runs a named file elevated with no prompt. User confirmed asks the person to acknowledge, and can require Entra authentication or a written business justification first. Elevate as current user runs the process elevated under the signed in account, which preserves access to the user profile and, in Microsoft’s own words, broadens the attack surface. Support approved sends the request to an administrator who approves it in the admin centre. Deny blocks a file from running elevated at all.
The pairing that earns the licence fee is support approved plus the elevation report. You start in audit, let the report tell you which applications people actually elevate, promote the defensible ones to rules, and leave the rest going through approval. That is a different job from password rotation. If what you actually need is a break glass local administrator password rather than day to day elevation, Windows LAPS in Intune is free with the licences you already hold and this add-on is the wrong purchase.
The failure modes
These are the constraints that decide whether the licence is usable on your estate, taken from Microsoft’s planning documentation rather than from experience, and they are worth reading before procurement rather than after.
- 64 bit only. Windows 11 and Windows 10 on 64 bit, including Arm64. Devices must be Microsoft Entra joined or hybrid joined, and enrolled in Intune or co-managed. Anything else is out of scope and the licence does nothing for it.
- Specific builds and updates. Windows 11 22H2 needs KB5029351 and 23H2 needs KB5031455. Windows 10 22H2 and 21H2 need KB5030211. Windows 10 itself reached end of support on 14 October 2025, so an estate still on it is buying a capability with a short remaining life.
- Silent non application. Elevation settings report as not applicable on unsupported operating system versions rather than failing loudly. You get a green tenant and no elevation. The same class of quiet outcome is covered in which Intune policy actually wins.
- Files on network shares are not supported and should not be used in rule definitions. If your line of business installer lives on a UNC path, that rule will not do what you expect.
- SSL inspection breaks it. Devices need a clear line of sight to the required endpoints without inspection in the path. On estates with a decrypting proxy this is the constraint that turns a two week rollout into a two month one.
- The trial has a hard edge. Microsoft’s advanced capabilities documentation gives 90 days, a maximum of 250 users per tenant, one trial per capability per tenant, and a 30 day grace period after which the capability is no longer available in the admin centre. One trial. There is no second run at it if you spend the first 90 days on a proof of concept nobody watched.
What I would do differently
I have not run Endpoint Privilege Management across a production estate. My tenant is a lab with no enrolled devices, so I have no elevation counts, no service desk ticket reduction and no rollout duration to offer, and anyone quoting those numbers without saying whose estate they came from should be read carefully. What I can do is read the licensing and the constraints, which is the part most of the pages competing for this query get wrong or leave dated.
Three things I would order differently to the way this is usually approached. First, check the E5 entitlement before anything else, because for a large share of readers this is now a procurement question that has already answered itself. Second, do not buy the Intune Suite for this one capability. The Suite earns its price when you deploy two or more of its modules at scale, which is Microsoft’s own framing, and one module at $10.00 against a £2.30 add-on is a poor trade. Third, spend the 90 day trial on discovery rather than on a demonstration. The elevation report telling you which twelve applications your estate actually elevates is worth more than a working approval workflow shown to a steering group, and you only get one trial to produce it.
The honest summary of the Endpoint Privilege Management cost in September 2026 is that for E5 tenants it is now zero and the remaining work is operational, and for E3 tenants it is a modest per user add-on that is still cheaper than the uplift. The prices and terms above come from Microsoft’s United Kingdom Intune pricing page, read on the date below.
Last verified: 9 September 2026.



