{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/",
        "slug": "dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/"
        },
        "title": "Review the VM page's JIT defaults before using the access policy",
        "summary": "Which just-in-time network-access settings need explicit review after enabling the feature from an Azure VM page?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:01+00:00",
        "modified_at": "2026-09-10T02:11:18+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 242,
        "potentially_affected": "Azure VMs eligible for Defender for Cloud just-in-time network access.",
        "dse_recommendation": "Replace unexamined JIT policy defaults with an approved port, source and maximum-duration decision.",
        "primary_source": {
            "name": "Enable Just-in-Time Access - Microsoft Defender for Cloud | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Enabling just-in-time access from an Azure VM&#8217;s configuration page uses predefined settings: Windows receives RDP on port 3389; Linux receives SSH on port 22. Both permit requests lasting up to three hours and use Any for allowed source addresses. Defender for Cloud&#8217;s JIT page can change these settings and add ports. <a href=\"https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>Enabling JIT is not the connection request: access must subsequently be requested. That request identifies ports, source addresses and the opening window. The source requires an NSG or supported firewall configuration; Azure Firewalls managed through Azure Firewall Manager are excluded. <a href=\"https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review Azure VMs eligible for Defender for Cloud just-in-time network access. Confirm the documented subscription, permission and network prerequisites before using the workflow. Distinguish the policy&#8217;s maximum allowance from a particular operator&#8217;s requested access.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends inspecting the saved JIT policy immediately after VM-page enablement. Ask the service owner to approve the necessary management port, expected source and maximum task duration. Change inappropriate defaults through the JIT configuration page. Require access requests to identify their actual intended source rather than treating the policy&#8217;s broad allowance as a preferred operating scope.</p>\n<h2>Verification</h2>\n<p>Compare an approved request with the saved policy and resulting connection details. Review the VM&#8217;s JIT activity record for the actual operation and time. Check the intended access window and permitted source in a controlled test, recording unexpected reachability separately from successful authentication to the guest.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Enable just-in-time access</a>.</p>",
        "content_text": "Source facts\nEnabling just-in-time access from an Azure VM’s configuration page uses predefined settings: Windows receives RDP on port 3389; Linux receives SSH on port 22. Both permit requests lasting up to three hours and use Any for allowed source addresses. Defender for Cloud’s JIT page can change these settings and add ports. Microsoft Learn.\nEnabling JIT is not the connection request: access must subsequently be requested. That request identifies ports, source addresses and the opening window. The source requires an NSG or supported firewall configuration; Azure Firewalls managed through Azure Firewall Manager are excluded. Microsoft Learn.\nApplicability\nReview Azure VMs eligible for Defender for Cloud just-in-time network access. Confirm the documented subscription, permission and network prerequisites before using the workflow. Distinguish the policy’s maximum allowance from a particular operator’s requested access.\nDSE recommendation\nDSE recommends inspecting the saved JIT policy immediately after VM-page enablement. Ask the service owner to approve the necessary management port, expected source and maximum task duration. Change inappropriate defaults through the JIT configuration page. Require access requests to identify their actual intended source rather than treating the policy’s broad allowance as a preferred operating scope.\nVerification\nCompare an approved request with the saved policy and resulting connection details. Review the VM’s JIT activity record for the actual operation and time. Check the intended access window and permitted source in a controlled test, recording unexpected reachability separately from successful authentication to the guest.\nOfficial references\nMicrosoft Learn: Enable just-in-time access.",
        "content_markdown": "## Source facts\n\nEnabling just-in-time access from an Azure VM’s configuration page uses predefined settings: Windows receives RDP on port 3389; Linux receives SSH on port 22. Both permit requests lasting up to three hours and use Any for allowed source addresses. Defender for Cloud’s JIT page can change these settings and add ports. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access).\n\nEnabling JIT is not the connection request: access must subsequently be requested. That request identifies ports, source addresses and the opening window. The source requires an NSG or supported firewall configuration; Azure Firewalls managed through Azure Firewall Manager are excluded. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access).\n\n## Applicability\n\nReview Azure VMs eligible for Defender for Cloud just-in-time network access. Confirm the documented subscription, permission and network prerequisites before using the workflow. Distinguish the policy’s maximum allowance from a particular operator’s requested access.\n\n## DSE recommendation\n\nDSE recommends inspecting the saved JIT policy immediately after VM-page enablement. Ask the service owner to approve the necessary management port, expected source and maximum task duration. Change inappropriate defaults through the JIT configuration page. Require access requests to identify their actual intended source rather than treating the policy’s broad allowance as a preferred operating scope.\n\n## Verification\n\nCompare an approved request with the saved policy and resulting connection details. Review the VM’s JIT activity record for the actual operation and time. Check the intended access window and permitted source in a controlled test, recording unexpected reachability separately from successful authentication to the guest.\n\n## Official references\n\n[Microsoft Learn: Enable just-in-time access](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Review the VM page's JIT defaults before using the access policy",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/",
                "headline": "Review the VM page's JIT defaults before using the access policy",
                "description": "Which just-in-time network-access settings need explicit review after enabling the feature from an Azure VM page?",
                "abstract": "Which just-in-time network-access settings need explicit review after enabling the feature from an Azure VM page?",
                "articleBody": "Source facts\nEnabling just-in-time access from an Azure VM’s configuration page uses predefined settings: Windows receives RDP on port 3389; Linux receives SSH on port 22. Both permit requests lasting up to three hours and use Any for allowed source addresses. Defender for Cloud’s JIT page can change these settings and add ports. Microsoft Learn.\nEnabling JIT is not the connection request: access must subsequently be requested. That request identifies ports, source addresses and the opening window. The source requires an NSG or supported firewall configuration; Azure Firewalls managed through Azure Firewall Manager are excluded. Microsoft Learn.\nApplicability\nReview Azure VMs eligible for Defender for Cloud just-in-time network access. Confirm the documented subscription, permission and network prerequisites before using the workflow. Distinguish the policy’s maximum allowance from a particular operator’s requested access.\nDSE recommendation\nDSE recommends inspecting the saved JIT policy immediately after VM-page enablement. Ask the service owner to approve the necessary management port, expected source and maximum task duration. Change inappropriate defaults through the JIT configuration page. Require access requests to identify their actual intended source rather than treating the policy’s broad allowance as a preferred operating scope.\nVerification\nCompare an approved request with the saved policy and resulting connection details. Review the VM’s JIT activity record for the actual operation and time. Check the intended access window and permitted source in a controlled test, recording unexpected reachability separately from successful authentication to the guest.\nOfficial references\nMicrosoft Learn: Enable just-in-time access.",
                "datePublished": "2026-09-10T00:23:01+00:00",
                "dateModified": "2026-09-10T02:11:18+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Review the VM page's JIT defaults before using the access policy"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 242,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Enable Just-in-Time Access - Microsoft Defender for Cloud | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access"
                }
            }
        ]
    }
}