Identity

Just-in-Time Access

Just-in-Time Access grants privileged rights only when required and for a short time, automatically revoking them afterwards.

Just-in-Time Access provides privileged rights only when needed and for a limited period. The rights are automatically revoked once this period expires.

How it works

Admins do not have permanent elevated rights by default. They request them through a system when needed for a specific task. Depending on the rule, the request is approved automatically or by a second person. The rights are then valid for a set duration, such as two hours. Every request and its usage is logged. Common implementations include Privileged Identity Management in Entra ID or PAM solutions.

For example, a cloud administrator needs to modify a firewall rule. They request the relevant role for one hour and provide a reason. A colleague approves the request. After one hour, the administrator automatically loses the role. If their account is compromised the next day, the attacker has no admin rights.

What to look out for

  • Begin with the most critical roles, such as global admins and domain admins.
  • Keep the duration of access as short as is practical.
  • Require approval from a second person for critical roles.
  • Secure emergency accounts separately and monitor their usage.
  • Review if service accounts require permanent privileged access.

Why it matters

Permanent admin rights represent a major risk. Every account with such rights is an attractive target. Just-in-Time access reduces the time a compromised account can cause damage to a few hours or minutes.

Switzerland and regulation

The Swiss Financial Market Supervisory Authority (FINMA) expects financial institutions to strictly control privileged access. ISO 27001 requires the restriction and monitoring of privileged rights. Just-in-Time access helps meet these requirements and provides clear audit trails.

Typical mistakes

A common mistake is introducing Just-in-Time access while allowing some admins to keep permanent rights 'just in case'. Another error is when approvals are granted without proper review because they are seen as a nuisance.

How we implement it

In our SOC, we monitor requests and the use of privileged roles, reporting any anomalies. We are happy to discuss architecture questions as part of our Security Consulting.

How ANOMAL implements this