No possible to disable totally JIT (it gets reenabled every time)

Rodriguez Antonio 0 Reputation points
2025-12-18T11:59:26.2733333+00:00

Hello,

In order to access easily Linux VM using ssh (and jump box), Customer asked me to eliminate JIT access to VMs in all subscriptions (they have a Defender for Servers Plan 2).

I deleted the JIT per VM going to Defender for Cloud, Cloud Security, Workload Protections, Just-in time VM Access and then delete all VM in the "configured" section. But when I try to access using RDP to one VM using connect in the VM blade, it appears "configure jit + request access" and I have to click it to be able to download the rdp for the VM.

Then, coming back to the Defender for Cloud area (selecting "manage JIT" also), I can see again this VM in the configured area for JIT.

Then, checking Azure Policies the only one I saw related to this is in a policy inside the ASC initiative (per subscription) the policy "Management ports of virtual machines should be protected with just-in-time network access control" but it is in audit mode, and seems it does not support removing jit (allowed values are AuditIfNotExits and disable).

Any experience on this?

thanks!

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.