Just-In-Time Application Access
Grant time-bound, task-specific application access without permanently expanding your allowlist.
What is Just-in-Time Access?
JIT access grants temporary, limited privileges for specific tasks — and automatically revokes them when the window closes.
Time-bound access on demand
Just-in-Time (JIT) access allows administrators to grant temporary, limited privileges to specific devices for specific tasks. Rather than permanently expanding the allowlist or granting continuous administrative rights, access is provided only when needed — and only for the duration required.
JIT policies can target specific applications using a wide range of rule criteria, keeping the scope of each grant as narrow as possible.

Why JIT access matters
Continuous administrative rights are a persistent security liability. JIT access eliminates that exposure by ensuring endpoints have only the access they need for the duration they need it.
- Minimizes the window of exposure for elevated privileges.
- Reduces the risk of insider threats and lateral movement.
- Supports a least-privilege security posture without blocking legitimate work.
- Every grant is time-limited and auditable.
Creating JIT access policy
JIT policies specify the target device, the duration, and exactly which applications the user can access.
Policy creation steps
- Navigate to Just in Time Access under Deploy Policy.
- Click Create to start a new JIT policy and select Application Allowlisting.
- Enter a name and description for the policy.
- Specify the Computer Name of the device that should receive access.
- Set the duration type: Fixed (a set length of time) or Window (a defined time frame within which access is active).
- In Access Settings, choose the scope of access: All Applications (any unmanaged app), Include Blocklisted Applications (adds blocked apps to scope), or Specific Applications (only the applications you explicitly define).
- If using Specific Applications, define the target applications using rule types such as Vendor, Product, Verified Executable, File Hash, Store Apps, or Folder Path.
- Click Deploy Immediately.


Reviewing JIT activity
Every access event under a JIT policy is logged and available for audit.
JIT Events Report
To review events for a specific JIT policy, click the policy name and open the Audit tab. The report shows all application access activity that occurred under that policy during its active window.
