By NHI Mgmt Group Editorial TeamBased on SecurEnds: “Just-in-Time Access for Admins: A Smarter Way to Reduce Risk” (August 20, 2025)

TL;DR: Always-on admin access keeps standing privilege alive long after a task ends, expanding attack and audit risk, according to SecurEnds. Just in time access narrows that exposure window, but the real security gain comes from replacing persistent entitlement with tightly governed, task-scoped elevation.


At a glance

What this is: This is an explanation of just in time privileged access management, arguing that time-bound elevation reduces the risk and audit burden created by always-on admin rights.

Why it matters: It matters because PAM teams, IAM leads, and security architects need to replace persistent privilege with governed, task-scoped access for both human admins and non-human identities where appropriate.

By the numbers:

  • Gartner says 70% of cloud breaches involve overprivileged accounts.
  • Access is approved for 30 minutes, an hour, or whatever the policy allows before it automatically disappears.

Context

Just in time access is a privilege model that grants elevation only when a task needs it and removes it when the task ends. The governance problem is standing privilege, where admin rights persist far beyond the point of need and create avoidable exposure for human operators and NHI-adjacent admin paths.

Most legacy admin models still treat elevated access as a durable entitlement rather than a time-bound control. That assumption breaks down when the real requirement is temporary, context-aware access for patching, troubleshooting, or contractor work, because the account remains usable outside the approved window.


Key questions

Q: What is the first step in reducing risk from always-on admin access?

A: Start by identifying which privileged accounts stay active outside a task window and rank them by system reach and business criticality. That inventory tells you where standing privilege creates the largest blast radius and where JIT controls will reduce exposure fastest.

Q: How should security teams govern privileged access in cloud and hybrid environments?

A: Teams should govern privileged access around runtime authorization, not just connectivity or login. That means scoping elevation to a specific task, setting an expiry, logging approvals, and revoking access automatically when work is complete. The goal is to reduce standing privilege and create evidence that can withstand incident review and audit.

Q: What breaks when privileged access is not continuously governed?

A: When privileged access is not continuously governed, standing privilege persists, dormant accounts remain usable, and the attack surface expands across human and machine identities. In practice, that creates a larger blast radius for credential theft and a weaker ability to prove who had access, when, and why. The result is operational drift, not just security exposure.

Q: What is the difference between just-in-time access and standing privilege?

A: Just-in-time access grants privilege only for a defined task window, while standing privilege remains active until someone removes it. JIT reduces exposure by shrinking the time an identity can be abused, but standing privilege creates a constant attack surface. For NHI programs, the difference is often the difference between contained risk and persistent exposure.


Technical breakdown

How just in time access changes privilege issuance

Just in time access replaces always-on elevation with a request, approval, use, and expiry cycle. The account or identity does not hold standing admin rights; it receives them only for a defined window, often tied to a ticket, task, or policy trigger. In operational terms, the control shifts from static assignment to temporary authorisation, which reduces the time an attacker can abuse a stolen credential. For PAM programmes, the key design issue is not whether access exists, but whether access is bound to context and automatically revoked at session end.

Practical implication: design elevated access so the grant is temporary by default and automatically removed when the work is complete.

Why standing privilege expands the attack path

Standing admin rights create an exposure multiplier because one compromised credential can be reused across many systems and longer time periods. That is why overprivileged accounts are so frequently involved in cloud incidents: the attacker does not need a new escalation path if the account already has broad reach. This also increases insider risk, since legitimate users can overstep task boundaries accidentally or intentionally. The technical issue is not just privilege level, but privilege persistence, which makes review and containment harder once the entitlement exists.

Practical implication: prioritise the accounts with the broadest and longest-lived access when assessing lateral movement and audit risk.

How approval and policy triggers make JIT governable

A workable JIT model depends on policy gates that define when elevation can be issued, how long it lasts, and what conditions must be met before it activates. Common triggers include maintenance windows, ticket IDs, location checks, or task severity. Those controls do not eliminate risk, but they make the access path observable and bounded. In practice, the value comes from combining policy decisioning with automated expiry and logging, so the organisation can explain why access existed and when it stopped.

Practical implication: use policy, time limits, and logging together so every privileged session has a clear start, end, and owner.


Threat narrative

Attacker objective: The attacker aims to turn one privileged foothold into broad operational control over production systems and sensitive data.

  1. Entry occurs through a compromised admin credential that still has standing privilege across key systems.
  2. The attacker uses that persistent access to move laterally and escalate control without needing a new approval step.
  3. Impact follows when broad, always-on rights allow database, server, or configuration changes at scale.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Standing privilege is the real blast-radius problem, not admin convenience. The article correctly frames persistent elevation as the condition that turns one compromised credential into enterprise-wide exposure. In PAM terms, the issue is not admin access itself but access that outlives the task and survives beyond the point of accountability. Practitioners should treat privilege duration as a first-class control variable.

Just in time access makes least privilege operational instead of aspirational. Too many programmes claim least privilege while still leaving users with broad rights between tasks. The stronger model is task-scoped elevation with enforced expiry, because it aligns authorisation with actual work rather than assumed need. That shift matters most where cloud and hybrid estates make every permanent entitlement a latent escalation path.

Auditability improves when the access lifecycle is explicit. The article’s emphasis on approvals, expiry, and logging shows why JIT is as much a governance control as a security control. When every privileged session has a reason, a reviewer, and an end time, access reviews become evidence-based rather than guesswork. The implication is that PAM programmes should measure entitlement persistence, not just entitlement count.

Ephemeral privilege is the named governance concept this article sharpens. Ephemeral privilege means elevation that exists only for the time required to complete a specific task. That concept matters because it reframes admin access as a governed event rather than a standing condition, which is the difference between containable risk and permanent exposure. Practitioners should use that lens when evaluating modern PAM design.

JIT reduces risk, but it does not remove the need for lifecycle discipline. Temporary elevation still depends on correct approval logic, accurate task scoping, and reliable revocation after use. If those controls are weak, the organisation simply creates a more sophisticated version of the same access problem. The practical conclusion is to govern privilege lifecycle with the same rigor as credential issuance.

From our research library:

  • 91% of organisations say at least half of their privileged access is always-on, and only 1% have fully implemented just-in-time privileged access, according to a CyberArk study.

What this signals

Access governance breaks down when elevation is treated as a permanent entitlement instead of a time-bounded event. For IAM and PAM teams, the operational question is no longer whether admins can be trusted, but how quickly privilege can be issued, used, and removed without leaving standing exposure behind.

Ephemeral privilege: this is the control pattern that matters most in modern PAM design. The useful unit of governance is not the role itself but the short-lived elevation granted for a specific task, because that is what shrinks the attack window and clarifies accountability.


For practitioners

  • Map standing admin rights first Inventory which admin and superuser accounts remain active outside a task window, then rank them by blast radius, system reach, and business criticality.
  • Replace persistent elevation with task-scoped approval Require a request, approval, and automatic expiry for privileged sessions tied to patching, troubleshooting, contractor work, or other defined tasks.
  • Bind privileged access to policy triggers Use maintenance windows, ticket references, and context checks to decide when elevation can be issued and when it must shut off.
  • Log every elevation event for review Capture start time, end time, approver, target system, and reason so auditors and IAM teams can reconstruct each privileged session.

Key takeaways

  • The article argues that the core risk is standing admin privilege that remains active long after a task ends, not admin access in the abstract.
  • It cites Gartner research that 70% of cloud breaches involve overprivileged accounts, underscoring how often persistent elevation becomes an attack path.
  • JIT access limits exposure by tying elevation to approval, context, and automatic expiry, which makes privilege easier to govern and audit.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centers on excessive standing admin rights that enlarge blast radius.
NHI-07 — Long-Lived SecretsJIT logic is used here to shorten the lifespan of privileged access and avoid lingering entitlement.
Recommendation — Reduce standing elevation and scope privileged access to the minimum task requirement. Replace persistent credentials and durable admin grants with time-bound access that expires automatically.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe access model depends on governed issuance and revocation of privileged authenticators.
Recommendation — Enforce authenticator lifecycle controls so elevated access is issued, limited, and revoked on schedule.
CIS Controls v8CIS-5 — Account ManagementThe post discusses lifecycle governance for privileged accounts and access removal.
Recommendation — Manage privileged accounts with strict joiner-mover-leaver rules and remove access when tasks end.

Key terms

  • Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org