{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/",
        "slug": "dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/"
        },
        "title": "Do not equate managed-application JIT notifications with manual approval",
        "summary": "Automatic approval mode notifies approvers but grants the request without waiting for one of them to approve it.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:26+00:00",
        "modified_at": "2026-09-10T02:04:58+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 223,
        "potentially_affected": "Consumers configuring publisher just-in-time access for Azure Managed Applications.",
        "dse_recommendation": "Record the intended automatic or manual approval behavior before deploying the managed application.",
        "primary_source": {
            "name": "Approve just-in-time access - Azure Managed Applications | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/approve-just-in-time-access",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Managed-application JIT can limit when and for how long the publisher accesses the managed resource group. In automatic approval mode, approvers receive notifications but requests are approved automatically. Manual mode also notifies them, but requires one approver to approve the request.</p>\n<p>The consumer can enable JIT only during deployment. Selecting No gives the publisher permanent access in this documented workflow, and JIT cannot be enabled later. <a href=\"https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/approve-just-in-time-access\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review the publisher&#8217;s JIT-enabled offering, current licensing and access prerequisites, intended approvers and deployment decision. Keep notification delivery distinct from the approval mode that controls the request.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends documenting whether the business requirement is time-limited access alone or time-limited access with a human gate. Select and review the corresponding approval mode before deployment. Confirm who will respond when manual approval is required and how urgent maintenance is handled. Do not describe automatic-mode notifications as evidence of independent authorization.</p>\n<h2>Verification</h2>\n<p>In an approved test deployment, submit a low-impact publisher access request and observe whether it waits for an approver or is automatically approved. Compare the grant duration and expiration with the configured decision. Verify the intended approvers receive notifications separately. Retain the mode, request and outcome without claiming that receiving an email proves anyone reviewed the request before access began.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/approve-just-in-time-access\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Approve just-in-time access</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nManaged-application JIT can limit when and for how long the publisher accesses the managed resource group. In automatic approval mode, approvers receive notifications but requests are approved automatically. Manual mode also notifies them, but requires one approver to approve the request.\nThe consumer can enable JIT only during deployment. Selecting No gives the publisher permanent access in this documented workflow, and JIT cannot be enabled later. Microsoft Learn.\nApplicability\nReview the publisher’s JIT-enabled offering, current licensing and access prerequisites, intended approvers and deployment decision. Keep notification delivery distinct from the approval mode that controls the request.\nDSE recommendation\nDSE recommends documenting whether the business requirement is time-limited access alone or time-limited access with a human gate. Select and review the corresponding approval mode before deployment. Confirm who will respond when manual approval is required and how urgent maintenance is handled. Do not describe automatic-mode notifications as evidence of independent authorization.\nVerification\nIn an approved test deployment, submit a low-impact publisher access request and observe whether it waits for an approver or is automatically approved. Compare the grant duration and expiration with the configured decision. Verify the intended approvers receive notifications separately. Retain the mode, request and outcome without claiming that receiving an email proves anyone reviewed the request before access began.\nOfficial references\nMicrosoft Learn: Approve just-in-time access. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nManaged-application JIT can limit when and for how long the publisher accesses the managed resource group. In automatic approval mode, approvers receive notifications but requests are approved automatically. Manual mode also notifies them, but requires one approver to approve the request.\n\nThe consumer can enable JIT only during deployment. Selecting No gives the publisher permanent access in this documented workflow, and JIT cannot be enabled later. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/approve-just-in-time-access).\n\n## Applicability\n\nReview the publisher’s JIT-enabled offering, current licensing and access prerequisites, intended approvers and deployment decision. Keep notification delivery distinct from the approval mode that controls the request.\n\n## DSE recommendation\n\nDSE recommends documenting whether the business requirement is time-limited access alone or time-limited access with a human gate. Select and review the corresponding approval mode before deployment. Confirm who will respond when manual approval is required and how urgent maintenance is handled. Do not describe automatic-mode notifications as evidence of independent authorization.\n\n## Verification\n\nIn an approved test deployment, submit a low-impact publisher access request and observe whether it waits for an approver or is automatically approved. Compare the grant duration and expiration with the configured decision. Verify the intended approvers receive notifications separately. Retain the mode, request and outcome without claiming that receiving an email proves anyone reviewed the request before access began.\n\n## Official references\n\n[Microsoft Learn: Approve just-in-time access](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/approve-just-in-time-access). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not equate managed-application JIT notifications with manual approval",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/",
                "headline": "Do not equate managed-application JIT notifications with manual approval",
                "description": "Automatic approval mode notifies approvers but grants the request without waiting for one of them to approve it.",
                "abstract": "Automatic approval mode notifies approvers but grants the request without waiting for one of them to approve it.",
                "articleBody": "Source facts\nManaged-application JIT can limit when and for how long the publisher accesses the managed resource group. In automatic approval mode, approvers receive notifications but requests are approved automatically. Manual mode also notifies them, but requires one approver to approve the request.\nThe consumer can enable JIT only during deployment. Selecting No gives the publisher permanent access in this documented workflow, and JIT cannot be enabled later. Microsoft Learn.\nApplicability\nReview the publisher’s JIT-enabled offering, current licensing and access prerequisites, intended approvers and deployment decision. Keep notification delivery distinct from the approval mode that controls the request.\nDSE recommendation\nDSE recommends documenting whether the business requirement is time-limited access alone or time-limited access with a human gate. Select and review the corresponding approval mode before deployment. Confirm who will respond when manual approval is required and how urgent maintenance is handled. Do not describe automatic-mode notifications as evidence of independent authorization.\nVerification\nIn an approved test deployment, submit a low-impact publisher access request and observe whether it waits for an approver or is automatically approved. Compare the grant duration and expiration with the configured decision. Verify the intended approvers receive notifications separately. Retain the mode, request and outcome without claiming that receiving an email proves anyone reviewed the request before access began.\nOfficial references\nMicrosoft Learn: Approve just-in-time access. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:24:26+00:00",
                "dateModified": "2026-09-10T02:04:58+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not equate managed-application JIT notifications with manual approval"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 223,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Approve just-in-time access - Azure Managed Applications | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/approve-just-in-time-access"
                }
            }
        ]
    }
}