Review the VM page's JIT defaults before using the access policy

Which just-in-time network-access settings need explicit review after enabling the feature from an Azure VM page?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Which just-in-time network-access settings need explicit review after enabling the feature from an Azure VM page?

Potentially affected

Azure VMs eligible for Defender for Cloud just-in-time network access.

DSE recommendation

Replace unexamined JIT policy defaults with an approved port, source and maximum-duration decision.

Source facts

Enabling just-in-time access from an Azure VM’s configuration page uses predefined settings: Windows receives RDP on port 3389; Linux receives SSH on port 22. Both permit requests lasting up to three hours and use Any for allowed source addresses. Defender for Cloud’s JIT page can change these settings and add ports. Microsoft Learn.

Enabling JIT is not the connection request: access must subsequently be requested. That request identifies ports, source addresses and the opening window. The source requires an NSG or supported firewall configuration; Azure Firewalls managed through Azure Firewall Manager are excluded. Microsoft Learn.

Applicability

Review Azure VMs eligible for Defender for Cloud just-in-time network access. Confirm the documented subscription, permission and network prerequisites before using the workflow. Distinguish the policy’s maximum allowance from a particular operator’s requested access.

DSE recommendation

DSE recommends inspecting the saved JIT policy immediately after VM-page enablement. Ask the service owner to approve the necessary management port, expected source and maximum task duration. Change inappropriate defaults through the JIT configuration page. Require access requests to identify their actual intended source rather than treating the policy’s broad allowance as a preferred operating scope.

Verification

Compare an approved request with the saved policy and resulting connection details. Review the VM’s JIT activity record for the actual operation and time. Check the intended access window and permitted source in a controlled test, recording unexpected reachability separately from successful authentication to the guest.

Official references

Microsoft Learn: Enable just-in-time access.

Primary reference

Review the official source

Enable Just-in-Time Access - Microsoft Defender for Cloud | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE