This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
--> Implement security for servers and virtual machines (VMs)
--> Enable and enforce use of just-in-time (JIT) VM access
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Overview
Azure virtual machines often require inbound management access through protocols such as:
- SSH — typically TCP port 22 for Linux VMs
- RDP — typically TCP port 3389 for Windows VMs
- WinRM — typically TCP ports 5985 and 5986
Leaving these ports permanently open increases the attack surface of a virtual machine. Attackers can continuously scan exposed management ports and attempt brute-force, credential-stuffing, or exploit-based attacks.
Just-in-time (JIT) VM access in Microsoft Defender for Cloud reduces this exposure by allowing inbound access to selected VM ports only when it is required, from an approved source IP address, and for a limited period.
JIT does not replace authentication, authorization, patching, or network segmentation. Instead, it adds a temporary network-access control layer around administrative access.
What Is Just-in-Time VM Access?
JIT VM access is a Microsoft Defender for Cloud capability that:
- Identifies VM management ports that should not remain permanently exposed.
- Creates or manages restrictive network rules for those ports.
- Requires an authorized user to request temporary access.
- Opens the requested ports only for the approved duration.
- Restricts access to the requesting IP address or specified address range.
- Restores the restrictive network configuration after the access window expires.
For example, an administrator may need to connect to a Linux VM using SSH. Instead of leaving port 22 open continuously, the administrator requests access for 30 minutes from their current public IP address. Defender for Cloud temporarily permits the connection and then closes the access window.
The basic security principle
Open administrative access only when needed, only to the required port, only from the required source, and only for the required duration.
Why JIT VM Access Is Important
1. Reduces the attack surface
Permanent inbound access to RDP or SSH gives attackers more opportunities to discover and target a VM. JIT minimizes the time during which these ports are reachable.
2. Reduces exposure to brute-force attacks
Because management ports remain restricted until access is requested, attackers cannot continuously attempt authentication against those ports during normal operation.
3. Supports least-privilege network access
JIT applies the principle of least privilege to network connectivity:
- Only selected ports are opened.
- Only selected source addresses are permitted.
- Access is available only for a limited time.
4. Improves auditing
JIT access activity can be reviewed to determine:
- Who requested access
- Which VM was accessed
- Which ports were opened
- Which source IP address was used
- When access was requested
- When access expired
5. Helps enforce security standards
Organizations can use Azure Policy to identify or enforce the requirement that supported VMs use JIT access.
JIT VM Access Prerequisites
The principal prerequisite for Azure VM JIT access is:
- Microsoft Defender for Servers Plan 2 must be enabled on the subscription.
The administrator also needs appropriate permissions to view, configure, or request JIT access.
Supported environments
JIT access supports Azure Resource Manager-based virtual machines. It can also work with supported VMs protected by Azure Firewall on the same virtual network.
Unsupported or restricted scenarios
Important limitations include:
- Classic deployment-model VMs are not supported.
- JIT does not support VMs protected by Azure Firewall configurations controlled by Azure Firewall Manager.
- The Azure Firewall configuration must use the supported rules model.
- A VM generally needs an appropriate NSG, Azure Firewall configuration, or both.
- JIT is not a replacement for Azure Bastion, a VPN, or an identity provider.
How JIT Works with Network Security Groups
When JIT is enabled, Defender for Cloud creates or manages restrictive inbound rules for the selected ports.
For example, a VM might normally have the following inbound rule:
| Priority | Source | Destination port | Action |
|---|---|---|---|
| 100 | Any | 3389 | Allow |
This permanently exposes RDP to the internet.
With JIT, the selected management port is restricted until an authorized request is made. Defender for Cloud ensures that deny rules exist for the selected ports in the applicable NSG and/or Azure Firewall configuration.
When access is requested and approved, Defender for Cloud temporarily creates an allow rule for:
- The selected port
- The requesting source IP address or range
- The requested duration
After the time window expires, the restrictive configuration is restored.
Important rule-processing consideration
Existing network rules can affect JIT behavior. If another rule already permits traffic to the selected port with a higher priority, that rule may take precedence over the JIT-generated rule.
Therefore, enabling JIT does not automatically correct every conflicting NSG or firewall rule. Administrators should review existing rules and ensure that permanent broad allow rules do not undermine the intended protection.
JIT Access Policy Settings
A JIT policy is configured for a VM and defines which ports can be opened temporarily.
For each protected port, the policy can specify:
- Port number
- Protocol
- Allowed source IP addresses
- Maximum request access duration
Common ports
| Port | Protocol or service | Typical use |
|---|---|---|
| 22 | SSH | Linux administration |
| 3389 | RDP | Windows administration |
| 5985 | WinRM over HTTP | Windows remote management |
| 5986 | WinRM over HTTPS | Secure Windows remote management |
The default recommendations commonly include ports 22, 3389, 5985, and 5986, although the actual ports should be based on the organization’s requirements. Custom ports can also be added.
Example policy
An organization might configure:
| Setting | Value |
|---|---|
| Port | 22 |
| Protocol | TCP |
| Allowed source | Administrator’s public IP range |
| Maximum duration | 1 hour |
This means the administrator cannot request unlimited access to port 22. The request must remain within the maximum duration defined by the policy.
Enabling JIT Access in the Azure Portal
JIT can be enabled from Microsoft Defender for Cloud or from the Azure virtual machine experience.
From Microsoft Defender for Cloud
- Open the Azure portal.
- Open Microsoft Defender for Cloud.
- Go to Workload protections.
- Open Just-in-time VM access.
- Select the Not configured virtual machines tab.
- Select one or more eligible VMs.
- Select Enable JIT on VMs.
- Review the recommended ports.
- Customize the ports, protocols, source addresses, and maximum duration.
- Save the policy.
From the Virtual Machines page
- Open Virtual machines in the Azure portal.
- Select the target VM.
- Open Configuration.
- Locate Just-in-time access.
- Select Enable just-in-time.
- Review or modify the default configuration.
- Save the settings.
For Windows VMs, the default RDP port is normally 3389. For Linux VMs, the default SSH port is normally 22. The default maximum access duration is commonly three hours, but this should be reduced when operationally practical.
Configuring JIT Access Securely
The default configuration may be functional but not sufficiently restrictive for a production environment.
Recommended configuration practices
Restrict source IP addresses
Avoid allowing access from Any unless there is a specific business requirement.
Prefer:
- A corporate public IP range
- A secured jump-host address
- A VPN egress address
- A privileged administrator workstation range
Use the shortest practical duration
If an administrator needs 20 minutes, do not configure a maximum duration of several hours without a reason.
Shorter access windows reduce exposure.
Protect only required ports
Do not enable JIT for unnecessary ports. If a VM is administered only through SSH, there may be no reason to expose RDP or WinRM.
Use custom ports carefully
Changing the port number does not provide meaningful security by itself. Nonstandard ports can reduce casual scanning noise, but they do not replace authentication, authorization, patching, or JIT.
Review existing NSG and firewall rules
Permanent allow rules can undermine the intended JIT protection. Review:
- NSG inbound rules
- Azure Firewall rules
- Load balancer rules
- Public IP exposure
- Routing and network virtual appliance rules
Requesting JIT Access
After JIT is enabled, a user must request access before connecting to the VM.
Request process
- Open the Just-in-time VM access page.
- Select the Configured tab.
- Select the target VM.
- Select Request access.
- Choose the required port or ports.
- Specify the source IP address or range.
- Specify the requested access duration.
- Select Open ports.
The request is evaluated against the user’s permissions and the VM’s JIT policy.
After the request is approved, the user connects using the normal RDP, SSH, or other supported management method.
Requesting access from the VM Connect page
A user can also:
- Open the VM in the Azure portal.
- Select Connect.
- If JIT is enabled, select Request access.
- Specify the required access parameters.
- Open the ports.
- Connect to the VM.
For VMs protected by Azure Firewall, Defender for Cloud may provide the appropriate connection details, including the relevant port mapping.
Does JIT Automatically Approve Every Request?
JIT is not necessarily an approval workflow in the same sense as a formal access-request system.
The user must have the required Azure permissions, and the request must comply with the JIT policy. Depending on the configuration and permissions, an authorized user may be able to open the permitted ports without a separate human approval step.
Organizations requiring managerial or security approval should combine JIT with additional controls, such as:
- Privileged Identity Management
- Access reviews
- Service management approval workflows
- Conditional Access
- Privileged access workstations
- Ticketing and change-management processes
JIT controls temporary network exposure. It does not independently provide a complete privileged-access approval process.
Permissions for JIT Access
Different activities require different permissions.
Viewing JIT information
A user needs appropriate read permissions to view JIT policies and status.
Configuring or editing a JIT policy
A user needs permissions to modify the JIT network access policy and, in some cases, the VM configuration.
Requesting access
A user needs permissions to initiate a JIT access request and read the relevant VM and network configuration.
The principle of least privilege should be applied. A user who only needs to request access should not automatically receive permissions to modify JIT policies or change VM settings.
Enforcing JIT with Azure Policy
Enabling JIT manually on individual VMs does not scale well in a large environment.
Azure Policy can be used to identify VMs that do not comply with the organization’s JIT requirements.
Typical governance approach
- Define the organization’s JIT requirement.
- Assign an Azure Policy at the subscription or management-group scope.
- Evaluate VMs for compliance.
- Identify noncompliant VMs.
- Remediate or configure JIT where appropriate.
- Monitor compliance continuously.
The policy may be used to audit whether JIT is enabled or to support an organizational requirement that eligible VMs use JIT.
Why policy enforcement matters
Without centralized governance, administrators may:
- Deploy a VM with RDP permanently exposed.
- Forget to enable JIT.
- Add a new management port without protecting it.
- Modify network rules after JIT is configured.
- Create inconsistent security configurations across subscriptions.
Azure Policy provides a repeatable method for identifying and managing these deviations.
JIT and Azure Bastion
JIT and Azure Bastion address related but different security concerns.
| Capability | JIT VM access | Azure Bastion |
|---|---|---|
| Primary purpose | Temporarily opens selected management ports | Provides managed RDP/SSH connectivity |
| VM public IP required | May be required depending on network design | Normally not required |
| Browser-based connection | Not the primary feature | Yes |
| Temporary port access | Yes | Not the primary feature |
| Works with existing RDP/SSH clients | Yes | Supported with appropriate Bastion SKU |
| Reduces permanently exposed management ports | Yes | Yes, by avoiding public VM management exposure |
| Main control | Time-bound network access | Managed secure connectivity |
A strong design may use both:
- Azure Bastion to provide private administrative connectivity.
- JIT to restrict management ports when direct network access is required.
JIT and Just-in-Time Privileged Identity Management
JIT VM access should not be confused with Microsoft Entra Privileged Identity Management.
JIT VM access
Controls temporary network access to VM ports.
Privileged Identity Management
Controls temporary privileged role activation.
For example:
- PIM may temporarily activate the Virtual Machine Administrator Login role.
- JIT may temporarily open port 3389 from the administrator’s IP address.
Using both controls provides stronger defense in depth because the user must have both:
- The appropriate identity and role permissions.
- Temporary network connectivity.
JIT and Network Security Groups
JIT does not eliminate the need for NSGs.
NSGs still provide:
- Subnet-level filtering
- NIC-level filtering
- Inbound and outbound traffic control
- Application-specific network segmentation
- Persistent baseline security rules
JIT adds temporary management-port control on top of the existing network security design.
Example
An NSG might permanently allow application traffic:
- TCP 443 from the internet to a web server
But administrative traffic could be controlled through JIT:
- TCP 3389 closed by default
- TCP 3389 opened only for an administrator’s IP
- TCP 3389 automatically restricted after the approved period
JIT and Azure Firewall
JIT can work with supported Azure Firewall configurations.
When Azure Firewall protects a VM, JIT can temporarily modify the relevant firewall access configuration. After the access window expires, the previous restrictive configuration is restored.
Important considerations include:
- Azure Firewall must use a supported configuration.
- Azure Firewall Manager-controlled firewall configurations are not supported for JIT.
- Firewall rules must be reviewed for conflicts.
- The user may receive a translated or mapped port when connecting through the firewall.
Auditing JIT Activity
JIT activity should be reviewed regularly.
Useful information includes:
- VM name
- User who requested access
- Request time
- Requested port
- Source IP address
- Access duration
- Whether access was granted
- Last access time
- Number of approved requests
This information can help identify:
- Unexpected administrative activity
- Excessively long access requests
- Repeated requests from unusual IP addresses
- VMs that are accessed more frequently than expected
- Potential misuse of administrative access
JIT activity should be correlated with other security data, including:
- Microsoft Entra sign-in logs
- Azure Activity Log
- NSG flow logs where available
- Microsoft Defender for Cloud alerts
- Microsoft Sentinel incidents
- Privileged Identity Management activation records
Common JIT Troubleshooting Scenarios
The VM does not appear as eligible
Possible causes include:
- Defender for Servers Plan 2 is not enabled.
- The VM uses an unsupported deployment model.
- The VM lacks a supported NSG or firewall configuration.
- JIT is disabled by a security policy.
- The VM is protected by an unsupported Azure Firewall configuration.
The user cannot request access
Check:
- Azure RBAC permissions
- VM read permissions
- JIT request permissions
- Subscription and resource-group scope
- Whether the VM is configured for JIT
- Whether the requested port is included in the policy
The user requested access but cannot connect
Check:
- The request was successfully opened.
- The correct source IP was specified.
- The user is connecting from the same IP address used in the request.
- The correct port and protocol are being used.
- The VM is running.
- The guest operating system firewall allows the traffic.
- The NSG or Azure Firewall does not contain conflicting rules.
- The VM service is listening on the expected port.
- Routing and DNS are functioning correctly.
Access remains available after the expected expiration
Remember that JIT controls network rules. An already established connection may not be interrupted when the access window expires. The expiration prevents new access rather than necessarily terminating an existing session.
A permanent allow rule defeats JIT
Review NSG and firewall priorities. A broad allow rule with a higher priority may continue to permit traffic even when JIT has created a restrictive rule.
Best Practices Summary
- Enable Defender for Servers Plan 2 for subscriptions containing eligible VMs.
- Enable JIT on all supported administrative VMs.
- Protect only required management ports.
- Restrict source IP addresses whenever possible.
- Use the shortest practical access duration.
- Review NSG and Azure Firewall rules for conflicts.
- Combine JIT with Azure Bastion where appropriate.
- Combine JIT with PIM for privileged role activation.
- Use Azure Policy to identify noncompliant VMs.
- Audit JIT requests and correlate them with identity and security logs.
- Do not treat changing an SSH or RDP port as a substitute for JIT.
- Remember that JIT does not replace patching, endpoint protection, strong authentication, or least-privilege RBAC.
Key Exam Takeaways
For the SC-500 exam, remember the following:
- JIT VM access is provided through Microsoft Defender for Cloud.
- Microsoft Defender for Servers Plan 2 is a prerequisite for Azure VM JIT access.
- JIT reduces exposure by restricting inbound management ports.
- Access is requested for a specific port, source IP address, and time window.
- Common ports include 22, 3389, 5985, and 5986.
- JIT policies can include custom ports.
- JIT works with supported NSG and Azure Firewall configurations.
- Existing higher-priority allow rules can undermine JIT protection.
- JIT can be enabled and managed through the Azure portal, PowerShell, or REST API.
- Azure Policy can be used to enforce or audit JIT adoption.
- JIT controls temporary network access; it does not replace RBAC, PIM, Bastion, or authentication.
- Expiration of a JIT window does not necessarily terminate an already established connection.
Practice Exam Questions
Question 1
An organization has several Azure Windows VMs with RDP port 3389 permanently open to the internet. Security administrators want to allow RDP only when an administrator needs access and only for a limited period.
Which solution should they implement?
A. Just-in-time VM access in Microsoft Defender for Cloud
B. Azure Resource Lock
C. Azure Storage firewall rules
D. Microsoft Defender for Storage
Answer: A
Explanation: JIT VM access restricts inbound management ports and temporarily opens them only when access is requested. Resource locks protect resources from deletion or modification, while Storage firewall rules and Defender for Storage do not control RDP access to VMs.
Question 2
What is required before enabling just-in-time access for Azure virtual machines through Microsoft Defender for Cloud?
A. Microsoft Defender for Containers
B. Microsoft Defender for Servers Plan 2
C. Azure Kubernetes Service
D. Microsoft Sentinel automation rules
Answer: B
Explanation: Microsoft Defender for Servers Plan 2 must be enabled on the subscription for Azure VM JIT access.
Question 3
A Linux administrator needs SSH access to a VM for 45 minutes from a corporate public IP address. The JIT policy protects SSH port 22 and allows a maximum request duration of two hours.
Which information should the administrator provide when requesting access?
A. The VM’s operating-system password only
B. The VM’s resource lock and subscription ID
C. Port 22, the corporate source IP address, and a duration of 45 minutes
D. The Azure Storage account and container name
Answer: C
Explanation: A JIT request specifies the port, source IP address or range, and requested access duration. Authentication to the VM is still required separately.
Question 4
An organization wants to ensure that all eligible Azure VMs use JIT access. Administrators should be able to identify VMs that do not comply with the requirement.
Which service should be used?
A. Azure Policy
B. Azure DNS
C. Azure Load Balancer
D. Azure Front Door
Answer: A
Explanation: Azure Policy can audit or enforce organizational requirements and identify VMs that do not comply with JIT-related governance requirements.
Question 5
A VM has JIT enabled for RDP. However, users can still connect to port 3389 even when no JIT request is active.
What should the administrator investigate first?
A. Whether the VM has a managed identity
B. Whether the VM uses a Premium SSD
C. Whether the VM has a resource lock
D. Whether another higher-priority NSG or firewall rule permanently allows RDP
Answer: D
Explanation: Existing higher-priority allow rules can take precedence over JIT-generated restrictions. NSG and Azure Firewall rules should be reviewed for conflicting permanent access.
Question 6
Which statement best describes the relationship between JIT VM access and Azure Bastion?
A. JIT replaces the need for Azure RBAC
B. Azure Bastion is required for every JIT request
C. JIT controls temporary network access, while Bastion provides managed RDP/SSH connectivity
D. Azure Bastion permanently opens RDP and SSH ports on the VM
Answer: C
Explanation: JIT and Bastion provide different controls. JIT manages temporary access to management ports, while Bastion provides secure managed connectivity without requiring a public IP on the target VM in the normal design.
Question 7
A security engineer wants administrators to request JIT access only from approved corporate IP addresses rather than from any internet address.
Which JIT setting should be configured?
A. Allowed source IP addresses
B. VM disk encryption type
C. Azure resource lock level
D. Guest operating system image version
Answer: A
Explanation: The JIT policy allows administrators to define permitted source IP addresses or ranges for each protected port.
Question 8
A user requests JIT access to a VM protected by a supported Azure Firewall configuration. After the request is approved, Defender for Cloud provides a port mapping that differs from the VM’s internal RDP port.
Why might this occur?
A. JIT has changed the VM’s operating system
B. Azure Firewall may use a DNAT port mapping for the connection
C. The VM has been converted into an App Service
D. The VM’s managed identity has expired
Answer: B
Explanation: When Azure Firewall protects the VM, the user may need to connect using the connection details and port mapping associated with the firewall’s DNAT configuration.
Question 9
An administrator requests JIT access for 30 minutes and establishes an SSH session. The 30-minute window expires, but the existing SSH session remains connected.
Is this behavior consistent with JIT?
A. Yes. JIT expiration restricts new access but does not necessarily terminate established connections
B. No. JIT must always forcibly terminate every active session
C. No. JIT only controls outbound traffic
D. Yes, but only when the VM uses Azure Bastion
Answer: A
Explanation: JIT expiration restores the restrictive network configuration. Existing connections may remain active, so organizations should use session controls and operational procedures when immediate termination is required.
Question 10
Which approach provides the strongest defense-in-depth design for administrative access to sensitive Azure VMs?
A. Change the RDP port and leave it permanently open
B. Use JIT alone and disable all identity controls
C. Use JIT, least-privilege RBAC, strong authentication, and Azure Bastion or another secure connectivity method where appropriate
D. Use a resource lock to protect the VM from network attacks
Answer: C
Explanation: JIT should be combined with identity, authorization, authentication, network, and endpoint security controls. Changing ports does not eliminate exposure, and resource locks do not protect network access.
Go to the SC-500 Exam Prep Hub main page
