Defender for Servers capability that keeps management ports closed through deny rules in an NSG or Azure Firewall, then opens them temporarily for the requester's IP, by default for at most 3 hours. VMs lacking either control aren't supported.
Also called JIT VM access.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Just-in-time VM access in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Defender for Servers
Covers Arc-enabled servers and Azure VMs in Defender for Cloud. Plan 1 brings integration with Defender for Endpoint; Plan 2 goes further with agentless scanning, file integrity monitoring and alerts from Defender for DNS.
- Capability
Something that a person, organisation or system is able to do.
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
- Default security rules
Built-in NSG rules at priorities 65000-65500: AllowVnetInBound, AllowAzureLoadBalancerInBound and DenyAllInBound, plus AllowVnetOutBound, AllowInternetOutBound and DenyAllOutBound. Removal is impossible; custom rules at 100-4096 take precedence.
- Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- Virtual machines
Infrastructure-as-a-service compute giving complete control of the operating system, making it a fit for lift-and-shift moves and for software relying on OS-level pieces like COM.
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
Related terms
- Azure Bastion
Managed service that lets you open RDP and SSH sessions from the portal over TLS on port 443, so VMs need no public IP. Just-in-time VM access differs in that it opens ports 3389 and 22.
- Defender for Servers Plan 2
Top Defender for Servers tier, which includes FIM, JIT VM access, agentless scanning and, from August 2023, Defender for DNS alerts. You turn it on per subscription or per Log Analytics workspace.
- JIT
Approach where access is switched on only at the moment it is needed and expires after a set time; examples are PIM role activation and JIT VM access, which opens ports 3389 or 22 temporarily.