services / Azure / JIT network access request
The action that initiates a just-in-time access request, opening the requested inbound ports on a VM to specified source IPs for a limited time under an existing JIT policy.
This action opens live inbound network access to production VMs, directly enabling reachability to workloads rather than only affecting detection.
Microsoft.Security/locations/jitNetworkAccessPolicies/initiate/action
Initiating a JIT request opens inbound access (e.g. RDP/SSH) to a VM from a chosen source, giving the attacker a live network path to reach and move toward the workload.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog