Key Points
Benefits
Configuring JIT Requests & Autonomous Approval
Monitoring & Audit
Just-In-Time (JIT) access in ManageEngine Application Control Plus is a privilege management approach that grants users elevated rights only when they are needed — and only for as long as they are needed. Rather than assigning permanent administrative privileges to endpoint users, JIT access ensures that elevated access is temporary, scoped, and fully auditable.
Application Control Plus supports two models of JIT access:
This guide focuses on the request-based model — specifically, how end users can submit JIT Elevation Requests, and how administrators can streamline the approval process using the Autonomous Approval feature.
When a user attempts to run an application that requires elevated privileges, they are presented with an on-screen prompt to submit a JIT elevation request. The user specifies the time duration required and provides a business justification. This request is then routed to the administrator for approval — or automatically approved if Autonomous Approval is enabled. To learn how to configure JIT access requests using ManageEngine Application Control Plus, refer to the video guide.
Setting up this feature involves two parts:
Before users can submit JIT elevation requests, the option must be explicitly enabled in the Privileged Application List policy. Follow these steps:
Select Reason option against the 'Allow users to elevate applications with' setting. This enables the request-based JIT flow for end users. Refer here to learn more about configuring the Privileged Application List.

Once the policy is deployed, end-users can initiate elevation requests directly from their endpoints. Here is how the workflow unfolds:
When a user attempts to launch an application by right-clicking and selecting the 'Run as ManageEngine' option, a JIT elevation request prompt appears on their screen. The user must provide the time duration for which they need elevated access and a justification explaining why access is required.

All pending elevation requests appear in the Just-In-Time Access tab under Policies in the Application Control Plus console. Administrators can review each request, including the user's submitted justification, and take one of the following actions:
Approved access is governed by the requested time duration:
For low-risk applications, manually reviewing every request can create unnecessary bottlenecks. The Autonomous Approval feature allows administrators to define conditions under which requests are automatically approved — without requiring admin intervention. Follow the steps below to enable autonomous approval:
Toggle the button against 'Allow autonomous approval of JIT elevation requests by EPM Agent'.

Note: Autonomous Approval does not bypass governance — all auto-approved requests are still logged and visible in the Just-In-Time Access audit trail.
All JIT activity — including user requests, admin approvals, declines, auto-approvals, and access revocations — is captured in the JIT Events Report. To access it:
Navigate to the Just-In-Time Access section under Policies.

Click on any JIT policy, then select the Audit tab.

The audit trail provides a full record of privilege usage, which is critical for compliance, forensic investigations, and periodic access reviews.
Start your 30-day free trial and manage unlimited endpoints — secure and protected!