Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Just-in-time access and standing privilege: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15817
Topic starter  

TL;DR: Standing privilege is the default in most enterprise identity environments, and JIT access shifts permissions to time-bound, task-scoped grants that are automatically revoked, according to Oleria Security and Verizon’s 2025 DBIR. That matters because dormant access, over-permissioned roles, and delayed offboarding still drive excessive blast radius across human and non-human identities.

NHIMG editorial — based on content published by Oleria Security: just-in-time access and the standing privilege problem

Questions worth separating out

Q: How should organisations implement just-in-time access without slowing operations?

A: Start with the privileged roles that create the highest exposure and the clearest business case for temporary elevation.

Q: Why do standing privileges increase the impact of credential theft?

A: Because the attacker inherits whatever access is already attached to the compromised identity, including permissions that exceed the current task.

Q: What do teams get wrong about just-in-time access for non-human identities?

A: Teams often assume just-in-time access is enough on its own.

Practitioner guidance

  • Map standing privilege before implementing JIT Build an inventory of persistent access across privileged users, service accounts, contractors, and API credentials.
  • Automate revocation at the end of the access window Make expiry the default control and remove any dependency on manual cleanup.
  • Set approval thresholds by risk and context Auto-approve low-risk, routine access while routing privileged systems, unusual timings, and sensitive data stores to human review.

What's in the full article

Oleria Security's full article covers the operational detail this post intentionally leaves for the source:

  • Step-by-step JIT request workflow design for privileged users, contractors, and emergency access
  • Practical guidance on approval routing, expiry windows, and audit logging in live environments
  • Examples of how JIT can be applied to service accounts, bots, and API tokens
  • Implementation trade-offs between session-based and role-based elevation models

👉 Read Oleria Security's analysis of just-in-time access and standing privilege →

Just-in-time access and standing privilege: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15402
 

Standing privilege is the control assumption that JIT access exposes most clearly. The article shows that many enterprise identity programmes still assume access can remain available between reviews without materially increasing risk. That assumption fails when credentials are stolen, neglected, or inherited by contractors who have already moved on. The implication is that persistent privilege is not just a configuration issue, it is a governance model that has already expired.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when a time-bound access model fails?

A: Accountability sits with the identity, PAM, and application owners who define the policy, approve the scope, and ensure revocation is enforced. If access persists past its intended window, the failure is usually governance, not just tooling. Frameworks such as NIST CSF and NIST SP 800-53 help formalise that ownership.

👉 Read our full editorial: Just-in-time access reduces standing privilege exposure in enterprise IAM



   
ReplyQuote
Share: