Just-in-Time Access (JIT)

Just-in-Time Access (JIT) is the time-limited granting of access rights exactly when they are needed for a specific task. Instead of holding privileged permissions permanently, they are activated after request and review and automatically revoked again after a defined period of time.

A typical workflow comprises the request with justification or ticket reference, a policy check or approval, strong authentication and the activation of the right for a short time window. All steps are logged. Technically, JIT is implemented, for example, via time-limited group memberships, short-lived credentials or accounts that are created for a single session only. The main areas of use are administrative activities as well as production and cloud environments.

Taken to its logical conclusion, JIT leads to zero standing privileges (ZSP), a target state in which no privileged rights are permanently active anymore. Stolen credentials thereby lose a large part of their value, because the account has no critical rights outside approved time windows. JIT is a core function of Privileged Access Management (PAM), implements the Least Privilege principle in terms of time and is part of Identity Security.