Just-in-Time (JIT) Access
Granting elevated permissions only when needed, for a limited duration, and revoking them automatically. JIT eliminates standing privilege, the largest contributor to blast radius after compromise.
Just-in-time access is the most effective single change available to a privileged access program, because it converts a permanent target into a time-boxed one. It only works if the request path is fast enough that engineers use it rather than routing around it, which usually means approval automation and chat-based requests rather than a ticket queue. Measure standing privilege count as the outcome, not the number of requests processed.
See also: zero standing privileges, what is PAM, least privilege, PAM vendors
Related on Start with Identity
- GlossaryBreak-Glass Account
A tightly controlled emergency account used only when normal access fails, with strong vaulting, monitoring, and alerting. Tested regularly so it works in a rea
- GlossaryIAM
Identity and Access Management. Workforce identity for employees, contractors, and partners. Covers authentication, authorization, lifecycle, and audit. Distinc
- Blog1Password buys Apono, moving from credential vault to access control plane
Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, a
- ArticleTop 5 Just-in-Time Access Tools in 2026
A detailed comparison of five leading just-in-time (JIT) access tools, CyberArk, BeyondTrust, Britive, Apono, and Opal, that eliminate standing privileges and e
- GlossaryAccess Certification
Periodic review of who has access to what, with managers or resource owners attesting that access is still appropriate. A regulatory requirement in many industr
- CVEBeyondTrust PRA and Remote Support unauthenticated command injection
Privileged Remote Access and Remote Support accepted a malicious client request and ran OS commands as the site user. Unauthenticated. CVSS 9.8. CISA KEV. A PAM