FREE STUDY NOTES · SC-500

Just-in-time VM access in Defender for Cloud

How JIT locks management ports and opens them on request, with the plan and permissions it needs.

From Ultra Transcenders SC-500 by Tony Rough (publishing soon)

JIT narrows the window in which management ports are open: they stay closed until someone requests access, and close again automatically. It controls how long a port is open, which a static rule or Bastion can’t do.

Four steps: JIT adds deny-all inbound rules for management ports to the VM's NSG, a user requests access from the Connect page or Defender for Cloud, the port opens for the requester's source IP within the allowed ranges, and the deny is restored when the window ends. A timeline shows the port closed, open to the requester's IP for up to the per-port maximum (default 3 hours), then closed again.
Figure 10.1: How just-in-time VM access opens and closes a management port

Request rules

Port Use
3389 RDP
22 SSH
5986 / 5985 PowerShell remoting (WinRM) HTTPS / HTTP
25 SMTP

Common trap: Treating a VM with no NSG as supported, or Linux VMs as unsupported - JIT needs an NSG (or Azure Firewall) and supports Linux.

Common trap: Believing RDP works from a source outside the allowed range after requesting, or from any source without requesting - JIT always requires a request and only opens the port to the allowed source ranges.

Get the whole book

This note is one section of Ultra Transcenders SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Publishing soon on Amazon in Kindle and paperback editions.

About the book · Free SC-500 glossary · All SC-500 study notes

More SC-500 study notes