services / Azure / JIT network access policies
Just-in-time (JIT) VM access policies in Microsoft Defender for Cloud that define which VM ports may be opened on demand, to which source IPs, and for how long, keeping management ports closed until an approved request.
These policies gate inbound network access to production VMs; tampering can open real network paths to compromise workloads, beyond mere detection posture.
Microsoft.Security/locations/jitNetworkAccessPolicies/write
Creating/updating a JIT policy can widen allowed ports, source ranges, or durations, weakening the gate so inbound access to VMs (e.g. RDP/SSH) can be opened broadly.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog