What is just-in-time access?
Just-in-time (JIT) access grants a privilege at the moment it is needed, for a bounded period, and removes it when the work is finished. Between requests, the account holds no elevated rights at all.
The alternative, which most environments still run, is standing access: an account is added to an administrators group once and stays there for years.
Standing access versus just-in-time
| Standing access | Just-in-time access | |
|---|---|---|
| When the privilege exists | Always | Only during an approved window |
| What an attacker gets from the account | Administrative rights, immediately | An ordinary account |
| How the privilege ends | Someone remembers to remove it | A timer |
| What the audit shows | Group membership | A request, an approval, a window, and what was done |
| Typical failure | Nobody reviews the group | A window set too long |
The security argument is about exposure time. An administrator who needs elevated rights for twenty minutes a week does not need them for the other 10,060 minutes, and every one of those minutes is an opportunity for a stolen session or a malicious process.
How it works in practice
- A person requests elevation for a named task on a named system.
- Policy either grants it automatically or routes it to an approver.
- The privilege is granted for a stated period.
- The work is done, and the activity is recorded.
- The privilege expires. No cleanup task is required, because expiry is the default.
The design principle is that removal is automatic and granting is deliberate. Standing access reverses both.
Where frameworks ask for it
No framework uses the phrase "just-in-time," but several require the outcome.
| Framework | Requirement |
|---|---|
| NIST SP 800-53 | AC-6(1) and AC-6(2), authorize access to security functions and use non-privileged accounts for non-security functions; AC-2(11) usage conditions |
| NIST SP 800-171 | 3.1.5 employ least privilege; 3.1.6 use non-privileged accounts for nonsecurity functions |
| CMMC Level 2 | AC.L2-3.1.5, AC.L2-3.1.6, AC.L2-3.1.7 |
| Essential Eight | Restrict administrative privileges, which asks for privileged access to be limited and time-bound |
What the kit does
Item
- Just-in-time elevation through the Agent on the system, or by remote control from the AIC Server, with one-time activation codes, challenge and response, signed grants, or agentless WinRM and SSH. Windows is the most complete today. Apple Mac and Unix/Linux are expanding.
- Approvals on a privileged session, with the session brokered so the credential is never handled by the person
- Privileged-action records, Windows Event Log, and syslog forwarding of what was done during the window
- Check a credential out of the vault for a bounded period
See privileged user management for the elevation detail and capabilities for the full list.
Common questions
Does just-in-time access slow people down?
It adds a request step. Whether that is friction depends on how fast approval is. A policy that grants routine elevation automatically and routes only unusual requests to a person keeps the cost low.
What happens if the approver is unavailable?
Design that before you deploy. A break-glass path with heavier recording is the usual answer, and it should be the exception that produces the loudest audit record.
Is this the same as zero standing privileges?
They are close. Zero standing privileges is the end state. Just-in-time access is the mechanism that gets you there.
Can it work on a system with no network?
Elevation on an air-gapped system is handled on the system itself by the Agent. See air-gapped systems.
Related pages
- Privileged user management: elevation and delegation
- What is zero standing privileges
- What is least privilege
- What is privileged access management
- What is session recording
- Air-gapped systems
- Privileged access requirements checklist
- Capabilities and pricing
- Glossary