How JIT locks management ports and opens them on request, with the plan and permissions it needs.
From Ultra Transcenders SC-500 by Tony Rough (publishing soon)
JIT narrows the window in which management ports are open: they stay closed until someone requests access, and close again automatically. It controls how long a port is open, which a static rule or Bastion can’t do.
Microsoft.Compute/virtualMachines/read, NIC and public IP reads) plus the JIT initiate action. Write rights are needed only to configure the JIT policy.| Port | Use |
|---|---|
| 3389 | RDP |
| 22 | SSH |
| 5986 / 5985 | PowerShell remoting (WinRM) HTTPS / HTTP |
| 25 | SMTP |
Common trap: Treating a VM with no NSG as supported, or Linux VMs as unsupported - JIT needs an NSG (or Azure Firewall) and supports Linux.
Common trap: Believing RDP works from a source outside the allowed range after requesting, or from any source without requesting - JIT always requires a request and only opens the port to the allowed source ranges.
This note is one section of Ultra Transcenders SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · Free SC-500 glossary · All SC-500 study notes
How PIM activation, approval, maximum duration and notifications work, and what each role setting controls.
How a Conditional Access policy is built and how multiple policies combine.
Why control-plane roles can't read secrets, and which Key Vault role or access policy each task needs.
What Deny, Audit, Append, Modify and DeployIfNotExists do, and when you need a remediation task and managed identity.
Account keys, account and service SAS, user delegation SAS and Entra RBAC compared by scope and revocability.
Where each Azure SQL data protection feature works and who it protects data from.
How security admin rules are evaluated before NSGs, and when to use Allow, Deny or Always allow.