Just-in-Time (JIT) Access
Also known as: JIT Access · Just-In-Time Elevation
Definition
Just-in-Time (JIT) access provisions elevated privileges only for the specific duration and scope a user needs to complete a task, automatically revoking afterward.
JIT access is the operational answer to "least privilege at scale." Rather than permanently assigning admin rights, the system grants them on request — sometimes with manager approval, always time-bound, always audited. CyberArk, BeyondTrust, Delinea, and the cloud providers (AWS IAM Identity Center, Azure PIM) all implement JIT.
JIT is the primary mechanism for achieving Zero Standing Privilege (ZSP). The benefits are dramatic: the attack surface (privileged accounts at rest) collapses, audit findings on standing privilege disappear, and incident blast radius shrinks.