services / Azure / JIT network access policies

Just-in-time (JIT) VM access policies in Microsoft Defender for Cloud that define which VM ports may be opened on demand, to which source IPs, and for how long, keeping management ports closed until an approved request.

These policies gate inbound network access to production VMs; tampering can open real network paths to compromise workloads, beyond mere detection posture.


Microsoft.​Security/​locations/​jitNetworkAccessPolicies/​delete

Deleting a JIT policy removes the on-demand access control governing a VM's management ports, altering the enforced network access posture.

Risks

Scope: HIGH

This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​Security
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog