# Review the VM page's JIT defaults before using the access policy

> Which just-in-time network-access settings need explicit review after enabling the feature from an Azure VM page?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:01+00:00
- Modified: 2026-09-10T02:11:18+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Which just-in-time network-access settings need explicit review after enabling the feature from an Azure VM page?

## Potentially affected

Azure VMs eligible for Defender for Cloud just-in-time network access.

## DSE recommendation

Replace unexamined JIT policy defaults with an approved port, source and maximum-duration decision.

## Article

## Source facts

Enabling just-in-time access from an Azure VM’s configuration page uses predefined settings: Windows receives RDP on port 3389; Linux receives SSH on port 22. Both permit requests lasting up to three hours and use Any for allowed source addresses. Defender for Cloud’s JIT page can change these settings and add ports. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access).

Enabling JIT is not the connection request: access must subsequently be requested. That request identifies ports, source addresses and the opening window. The source requires an NSG or supported firewall configuration; Azure Firewalls managed through Azure Firewall Manager are excluded. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access).

## Applicability

Review Azure VMs eligible for Defender for Cloud just-in-time network access. Confirm the documented subscription, permission and network prerequisites before using the workflow. Distinguish the policy’s maximum allowance from a particular operator’s requested access.

## DSE recommendation

DSE recommends inspecting the saved JIT policy immediately after VM-page enablement. Ask the service owner to approve the necessary management port, expected source and maximum task duration. Change inappropriate defaults through the JIT configuration page. Require access requests to identify their actual intended source rather than treating the policy’s broad allowance as a preferred operating scope.

## Verification

Compare an approved request with the saved policy and resulting connection details. Review the VM’s JIT activity record for the actual operation and time. Check the intended access window and permitted source in a controlled test, recording unexpected reachability separately from successful authentication to the guest.

## Official references

[Microsoft Learn: Enable just-in-time access](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access).

## Primary reference

- Name: Enable Just-in-Time Access - Microsoft Defender for Cloud | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review the VM page's JIT defaults before using the access policy,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-535-review-the-vm-page-s-jit-defaults-before-using-the-access-policy/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
