Key Points
Benefits
Configuring JIT Requests
Monitoring & Audit
Just-In-Time (JIT) access in ManageEngine Application Control Plus is a privilege management approach that grants users elevated rights only when they are needed — and only for as long as they are needed. Rather than assigning permanent administrative privileges to endpoint users, JIT access ensures that elevated access is temporary, scoped, and fully auditable.
Application Control Plus supports two models of JIT access:
This guide focuses on the request-based model — specifically, how end users can submit JIT Elevation Requests, and how administrators can streamline the approval process.
When a user attempts to run an application that requires elevated privileges, they are presented with an on-screen prompt to submit a JIT elevation request. The user specifies the time duration required and provides a business justification. This request is then routed to the administrator for approval. To learn how to configure JIT access requests using ManageEngine Application Control Plus, refer to the video guide.
Before users can submit JIT elevation requests, the option must be explicitly enabled in the Privileged Application List policy. Follow these steps:
Select Reason option against the 'Allow users to elevate applications with' setting. This enables the request-based JIT flow for end users. Refer here to learn more about configuring the Privileged Application List.

Once the policy is deployed, end-users can initiate elevation requests directly from their endpoints. Here is how the workflow unfolds:
When a user attempts to launch an application by right-clicking and selecting the 'Run as ManageEngine' option, a JIT elevation request prompt appears on their screen. The user must provide the time duration for which they need elevated access and a justification explaining why access is required.

All pending elevation requests appear in the Just-In-Time Access tab under Policies in the Application Control Plus console. Administrators can review each request, including the user's submitted justification, and take one of the following actions:
Approved access is governed by the requested time duration:
All JIT activity — including user requests, admin approvals, declines, and access revocations — is captured in the JIT Events Report. To access it:
Navigate to the Just-In-Time Access section under Policies.

Click on any JIT policy, then select the Audit tab.

The audit trail provides a full record of privilege usage, which is critical for compliance, forensic investigations, and periodic access reviews.
Start your 30-day free trial and manage unlimited endpoints — secure and protected!