What is just-in-time access?

Just-in-time (JIT) access grants a privilege at the moment it is needed, for a bounded period, and removes it when the work is finished. Between requests, the account holds no elevated rights at all.

The alternative, which most environments still run, is standing access: an account is added to an administrators group once and stays there for years.

Request → Approve → Expire
Request → Approve → Expire

Standing access versus just-in-time

Standing access Just-in-time access
When the privilege exists Always Only during an approved window
What an attacker gets from the account Administrative rights, immediately An ordinary account
How the privilege ends Someone remembers to remove it A timer
What the audit shows Group membership A request, an approval, a window, and what was done
Typical failure Nobody reviews the group A window set too long

The security argument is about exposure time. An administrator who needs elevated rights for twenty minutes a week does not need them for the other 10,060 minutes, and every one of those minutes is an opportunity for a stolen session or a malicious process.

How it works in practice

  1. A person requests elevation for a named task on a named system.
  2. Policy either grants it automatically or routes it to an approver.
  3. The privilege is granted for a stated period.
  4. The work is done, and the activity is recorded.
  5. The privilege expires. No cleanup task is required, because expiry is the default.

The design principle is that removal is automatic and granting is deliberate. Standing access reverses both.

Where frameworks ask for it

No framework uses the phrase "just-in-time," but several require the outcome.

Framework Requirement
NIST SP 800-53 AC-6(1) and AC-6(2), authorize access to security functions and use non-privileged accounts for non-security functions; AC-2(11) usage conditions
NIST SP 800-171 3.1.5 employ least privilege; 3.1.6 use non-privileged accounts for nonsecurity functions
CMMC Level 2 AC.L2-3.1.5, AC.L2-3.1.6, AC.L2-3.1.7
Essential Eight Restrict administrative privileges, which asks for privileged access to be limited and time-bound

What the kit does

Item

  • Just-in-time elevation through the Agent on the system, or by remote control from the AIC Server, with one-time activation codes, challenge and response, signed grants, or agentless WinRM and SSH. Windows is the most complete today. Apple Mac and Unix/Linux are expanding.
  • Approvals on a privileged session, with the session brokered so the credential is never handled by the person
  • Privileged-action records, Windows Event Log, and syslog forwarding of what was done during the window
  • Check a credential out of the vault for a bounded period

See privileged user management for the elevation detail and capabilities for the full list.

Common questions

Does just-in-time access slow people down?

It adds a request step. Whether that is friction depends on how fast approval is. A policy that grants routine elevation automatically and routes only unusual requests to a person keeps the cost low.

What happens if the approver is unavailable?

Design that before you deploy. A break-glass path with heavier recording is the usual answer, and it should be the exception that produces the loudest audit record.

Is this the same as zero standing privileges?

They are close. Zero standing privileges is the end state. Just-in-time access is the mechanism that gets you there.

Can it work on a system with no network?

Elevation on an air-gapped system is handled on the system itself by the Agent. See air-gapped systems.

Related pages

Sources