Join our Newsletter — 33% off our NHI Course

What breaks when vaulting is used without JIT privileged access?

Vaulting without JIT usually leaves standing privilege in place between rotations or checkouts. That means the secret may change, but the access pattern does not. In practice, attackers and auditors both care about the live privilege window, because a stored credential can still be usable long after the team thinks it is controlled.

What breaks in the access model when vaulting is used without JIT?

Vaulting answers a different problem than JIT. A vault can store, rotate, and govern the secret itself, but if access is still continuously available between checkouts, the privilege model remains standing rather than time-bound. That weakens the security outcome, because the control on paper is not the same as the control in use.

Why standing privilege remains the real failure

The core break is that vaulting can reduce secret exposure without shrinking the window of authority. If a user, admin, or system can still authenticate at will with a vaulted credential, the environment still has persistent access paths that can be abused, replayed, or inherited after a compromise. The secret may be better managed, but the blast radius is not materially reduced.

That distinction matters in practice: JIT changes the access pattern, not just the storage location. Without JIT, teams may believe they have made access temporary when they have only made the credential harder to see. For a broader view of how vault-centred and JIT-centred PAM differ, see the PAM Buyer’s Guide and the Privileged Access Management Guide.

What operationally changes, and what does not

Vaulting is strong for custody, rotation, and inventory, but it does not by itself force privilege to expire when work is done. That means approvals, session limits, and just-in-time elevation remain necessary if the goal is to remove standing privilege. In other words, vaulting can protect the secret while still leaving the account or role permanently capable of doing damage.

A useful way to think about it is this: rotation reduces how long a credential stays valid, while JIT reduces how long an identity is authorised to act. Those are complementary controls, not substitutes. The difference is visible in cloud admin roles, break-glass patterns, and service access paths where vaulting alone still leaves broad eligibility to act.

For related lifecycle and governance detail, the Just-in-Time Access and Zero Standing Privilege Guide and the NHI Lifecycle Management Guide show why expiration, offboarding, and access review are separate from vaulting itself.

Risk and Threat Considerations

When organisations stop at vaulting, they often create a false sense of control: the secret is centralised, but the live privilege window is still open. That exposes accounts, service credentials, and admin roles to reuse after compromise, because attackers care more about usable authority than about where the secret is stored.

Failure mechanism: The vault changes secret custody but does not bound the time or context in which the credential can be used, so standing privilege remains exploitable between rotations or checkouts.

Impact: An attacker, contractor, or internal operator can keep using valid access long after the team believes the exposure has been reduced, which undermines auditability, increases blast radius, and delays containment.

That is why both secret exposure and privilege escalation remain relevant. A compromised vaulted secret can still become a full access path if the underlying role is overprivileged, which is why the control stack needs approval, session control, and least privilege in addition to storage. The Cloud PAM and CIEM Guide is a useful companion when the issue is effective privilege rather than just secret management, and the Azure Key Vault Contributor escalation 2024 illustrates how vault-related privilege can still overreach.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Vaulting and rotation govern credential lifecycle and checkout risk.
AC-6 — Least Privilege JIT is needed to remove standing privilege and reduce excess access.
Recommendation — Apply IA-5 to rotate, protect, and expire privileged authenticators. Apply AC-6 to limit privilege to the minimum needed and duration.
CIS Controls v8 CIS-5 — Account Management The issue is persistent access paths that account controls must time-box.
Recommendation — Use CIS-5 to govern privileged accounts and remove persistent access.
ISO/IEC 27001:2022 A.5.15 — Access Control Vaulting without JIT leaves access decisions insufficiently constrained.
Recommendation — Enforce A.5.15 to restrict access by role, purpose, and time.
OWASP Non-Human Identity Top 10 NHI-05 — Overprivileged NHI Vaulting without JIT can leave machine or service access overprivileged.
NHI-07 — Long-Lived Secrets Vaulting may store secrets safely while still leaving long-lived usable access.
Recommendation — Reduce standing access and excess privilege for non-human identities. Replace long-lived secrets with time-bound credentials and expiry.

Practitioner Guidance

What to prioritise: Treat vaulting as custody control, not privilege control. If the same account or role can still act freely after checkout, you do not yet have JIT in any meaningful sense.

What to verify: Confirm that checkouts are time-bound, approval-backed where appropriate, and followed by automatic revocation or session termination. A vaulted credential with no expiry on use is still standing access in practice.

Decision rule: If the access path can reach production, administrative, or cross-environment systems, require JIT or equivalent time-boxing before calling the control complete. Vaulting alone is acceptable only when the remaining privilege is genuinely low impact.

Practitioner takeaway: The meaningful question is not whether the secret is vaulted, but whether the authority to use it disappears when the task is over.