Skip to main content
compliance · azure

Azure VMs not covered by a Defender for Cloud just-in-time access policy

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Azure VM that no Microsoft Defender for Cloud just-in-time access policy covers. Without JIT, management ports such as SSH 22 and RDP 3389 have no request-based, time-limited gate in front of them. JIT requires Defender for Servers Plan 2 on the subscription, so enabling it adds cost rather than saving money.

Signal and threshold

How ZopNight evaluates Azure VMs not covered by a Defender for Cloud just-in-time access policy.
Field Value
Rule IDsRC-1301
Categorycompliance
Severitymedium
Metricnone — pure configuration read
Thresholdno JIT policy for the VM
SourceZopNight
Permissions usedMicrosoft.Compute/virtualMachines/read · Microsoft.Security/locations/jitNetworkAccessPolicies/read

Standing open ports versus access on request

Firewalls and network security groups often keep allow rules for SSH and RDP in place permanently, just in case an administrator needs them. Defender for Cloud’s just-in-time VM access replaces that with a deny by default: a user requests access, and the port opens only for their source address, only on the ports configured, and only for the maximum request time you set.

The ports Defender for Cloud recommends protecting are 22 for SSH, 3389 for RDP and 5985 and 5986 for WinRM, and you can add others. Every request is logged, which also gives you a record of who connected and when.

Listing JIT policies

Terminal window
az security jit-policy list
az security jit-policy show --location westeurope --name default --resource-group my-rg

Each policy lists the VMs it covers and the ports and time limits for each. A VM that appears in no policy has no JIT protection.

What the finding is based on

ZopNight retrieves the subscription’s JIT policies and records, for each VM, whether any policy covers it. The rule fires when that lookup succeeded and the VM is not covered. There is no metric or time window involved.

VMs the rule leaves alone

If the JIT policy lookup did not return a result for a VM, ZopNight treats its state as unknown and raises nothing. Tags claiming JIT is configured are ignored. JIT itself only works for Resource Manager VMs protected by an NSG or Azure Firewall, so classic VMs and machines without either cannot be fixed this way.

Reduced exposure, at the price of a Defender plan

No saving is claimed. JIT needs Microsoft Defender for Servers Plan 2 enabled on the subscription, which is a paid plan. The benefit is fewer hours per month in which management ports are reachable at all; for rules already open to the internet, see Azure NSG Open to Internet.

Enabling JIT on a VM

  1. Enable Defender for Servers Plan 2 on the subscription in Defender for Cloud.
  2. Confirm the VM has an NSG or Azure Firewall in its path.
  3. In Defender for Cloud, open Just-in-time VM access, select the VM and enable JIT.
  4. Review the port list and set a short maximum request time for each port.
  5. Grant operators a role that lets them request access; Microsoft provides a script to build a least-privileged custom role for this.
  6. Remove any permanent allow rules for the same ports that JIT now manages.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·