Join our Newsletter — 33% off our NHI Course

Should organisations prioritise just-in-time access over network segmentation?

They solve different problems, so the priority depends on the risk being reduced. If the issue is excessive entitlement to production systems, just-in-time access should come first because it removes privilege. If the issue is east-west movement after compromise, segmentation matters more. Many programmes need both, in different layers.

Why JIT and Segmentation Should Not Be Treated as Substitutes

Just-in-time access and network segmentation reduce risk in different ways. JIT narrows who can do what, and for how long, while segmentation limits where compromised access can move. If your dominant exposure is excessive privilege, JIT is the sharper control. If your dominant exposure is lateral movement, segmentation is the better first layer. A mature programme usually needs both.

That distinction matters because organisations often try to solve an authorisation problem with a network boundary, or a movement problem with temporary elevation alone. JIT is strongest when the objective is to remove standing privilege from human admins, service accounts, and admin workflows. Segmentation is strongest when trust between zones, systems, or environments needs to be reduced even after a valid login.

When JIT Is the Better Priority

Prioritise JIT when the main problem is permanent privilege that creates unnecessary blast radius. In that situation, the security gain comes from removing standing access and forcing explicit approval, time bounds, and session oversight for elevated actions. That is especially important for production systems, cloud admin roles, and break-glass paths that should not remain open by default.

JIT also changes the operating model for privileged credentials. Instead of keeping broad access continuously available, teams can require elevation only at the point of need, then revoke it automatically. For readers wanting a deeper control model, Privileged Access Management Guide and Just-in-Time Access and Zero Standing Privilege Guide show how that pattern supports zero standing privilege in practice.

When Segmentation Should Come First

Prioritise segmentation when the issue is post-compromise movement across zones, tiers, or environments. If an attacker already has a foothold, limiting east-west connectivity can stop a local compromise from becoming a domain-wide or environment-wide incident. That makes segmentation especially valuable in data centres, hybrid networks, remote access estates, and OT-like environments where trust is too broad.

Segmentation is also the control that preserves containment when identity controls fail elsewhere. A valid credential, a stolen token, or an over-privileged account is still dangerous, but segmentation can constrain the paths those credentials unlock. NIST’s Zero Trust Architecture guidance emphasises least privilege and micro-segmentation as complementary design ideas, not competing ones, and NIST SP 800-82 Rev. 3 treats segmentation as a core control for environments where lateral movement has high operational cost.

How to Decide What to Prioritise in Practice

If your highest-risk failure is excess entitlement, standing administrative privilege, or weak access governance, start with JIT. If your highest-risk failure is lateral movement, flat networks, or uncontrolled trust between systems, start with segmentation. In many environments, the decision is not binary: JIT should reduce who can enter a sensitive area, while segmentation should reduce where that access can reach once inside.

That is why cloud and infrastructure teams often pair identity-centric control with network containment. JIT reduces privilege duration and scope, while segmentation reduces reachability and blast radius. The control that gives the biggest immediate risk reduction is the one aligned to the most likely harm path, not the one that sounds more modern.

Risk and Threat Considerations

Choosing only one of these controls creates a predictable gap. If you remove standing privilege but leave the environment flat, a compromised session can still spread widely. If you segment the network but leave broad standing access in place, the attacker may not need to move far to reach valuable systems. The real risk is treating either control as a universal substitute for the other.

Failure mechanism: Excessive privilege enables misuse or takeover of powerful accounts, while poor segmentation lets valid access move laterally after compromise. In practice, the two weaknesses reinforce each other when admin paths, service access, and production trust zones are not separately constrained.

Impact: The likely outcome is larger blast radius, easier privilege abuse, and weaker containment during an incident. That can turn a single credential compromise into broader production exposure, especially where elevated access and network reach overlap.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST Zero Trust (SP 800-207), NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST Zero Trust (SP 800-207) PR.AA-05 — Least Privilege Access Permissions JIT and segmentation both support least-privilege access decisions in zero trust architectures.
Recommendation — Apply least-privilege access and segment trust zones to reduce standing exposure and movement paths.
NIST SP 800-53 Rev 5 AC-6 — Least Privilege The question is about reducing excessive entitlement versus limiting reach after compromise.
SC-7 — Boundary Protection Network segmentation is a direct boundary-protection control for containing lateral movement.
Recommendation — Restrict access to the minimum needed and remove standing privilege where possible. Partition networks and enforce boundary controls to contain compromise spread.
CIS Controls v8 CIS-6 — Access Control Management The topic centers on controlling who gets access and for how long.
CIS-12 — Network Infrastructure Management Segmentation depends on managed network boundaries and controlled pathways.
Recommendation — Enforce just-in-time elevation and review privileged access regularly. Define and maintain network zones so compromised access cannot move freely.
ISO/IEC 27001:2022 A.8.2 — Privileged access rights JIT is directly about reducing standing privileged access rights.
A.8.22 — Segregation of networks Segmentation is explicitly a network segregation control.
A.5.15 — Access control The comparison is fundamentally about access governance and containment.
Recommendation — Limit privileged access rights and time-box elevation to active tasks. Separate networks by trust level and restrict traffic between zones. Use access-control policy to decide where JIT is needed and where segmentation is required.

Practitioner Guidance

What to prioritise: Start with the control that addresses the most likely failure path in your environment. If privileged access is widespread and persistent, lead with JIT. If the environment is already heavily privileged but poorly partitioned, lead with segmentation.

What to verify: Check whether elevated access is actually time-bound, approved, and removed after use, and whether segmented zones still allow unnecessary east-west paths. If either answer is no, the control is not yet doing the job you think it is.

What good looks like: The best state is bounded privilege with bounded reach, where temporary elevation cannot automatically translate into broad network movement. That combination gives you both lower standing privilege and lower blast radius.

Practitioner takeaway: Do not ask which control is universally better, ask which risk you are trying to reduce first, then use the other control to close the remaining attack path.