# Do not equate managed-application JIT notifications with manual approval

> Automatic approval mode notifies approvers but grants the request without waiting for one of them to approve it.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:26+00:00
- Modified: 2026-09-10T02:04:58+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Automatic approval mode notifies approvers but grants the request without waiting for one of them to approve it.

## Potentially affected

Consumers configuring publisher just-in-time access for Azure Managed Applications.

## DSE recommendation

Record the intended automatic or manual approval behavior before deploying the managed application.

## Article

## Source facts

Managed-application JIT can limit when and for how long the publisher accesses the managed resource group. In automatic approval mode, approvers receive notifications but requests are approved automatically. Manual mode also notifies them, but requires one approver to approve the request.

The consumer can enable JIT only during deployment. Selecting No gives the publisher permanent access in this documented workflow, and JIT cannot be enabled later. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/approve-just-in-time-access).

## Applicability

Review the publisher’s JIT-enabled offering, current licensing and access prerequisites, intended approvers and deployment decision. Keep notification delivery distinct from the approval mode that controls the request.

## DSE recommendation

DSE recommends documenting whether the business requirement is time-limited access alone or time-limited access with a human gate. Select and review the corresponding approval mode before deployment. Confirm who will respond when manual approval is required and how urgent maintenance is handled. Do not describe automatic-mode notifications as evidence of independent authorization.

## Verification

In an approved test deployment, submit a low-impact publisher access request and observe whether it waits for an approver or is automatically approved. Compare the grant duration and expiration with the configured decision. Verify the intended approvers receive notifications separately. Retain the mode, request and outcome without claiming that receiving an email proves anyone reviewed the request before access began.

## Official references

[Microsoft Learn: Approve just-in-time access](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/approve-just-in-time-access). Source retrieved September 9, 2026.

## Primary reference

- Name: Approve just-in-time access - Azure Managed Applications | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/approve-just-in-time-access
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not equate managed-application JIT notifications with manual approval,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-450-do-not-equate-managed-application-jit-notifications-with-manual-approval/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
