Azure VMs not covered by a Defender for Cloud just-in-time access policy
What does ZopNight detect here?
ZopNight flags an Azure VM that no Microsoft Defender for Cloud just-in-time access policy covers. Without JIT, management ports such as SSH 22 and RDP 3389 have no request-based, time-limited gate in front of them. JIT requires Defender for Servers Plan 2 on the subscription, so enabling it adds cost rather than saving money.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1301 |
| Category | compliance |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | no JIT policy for the VM |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/virtualMachines/read · Microsoft.Security/locations/jitNetworkAccessPolicies/read |
Where it applies
Standing open ports versus access on request
Firewalls and network security groups often keep allow rules for SSH and RDP in place permanently, just in case an administrator needs them. Defender for Cloud’s just-in-time VM access replaces that with a deny by default: a user requests access, and the port opens only for their source address, only on the ports configured, and only for the maximum request time you set.
The ports Defender for Cloud recommends protecting are 22 for SSH, 3389 for RDP and 5985 and 5986 for WinRM, and you can add others. Every request is logged, which also gives you a record of who connected and when.
Listing JIT policies
az security jit-policy listaz security jit-policy show --location westeurope --name default --resource-group my-rgEach policy lists the VMs it covers and the ports and time limits for each. A VM that appears in no policy has no JIT protection.
What the finding is based on
ZopNight retrieves the subscription’s JIT policies and records, for each VM, whether any policy covers it. The rule fires when that lookup succeeded and the VM is not covered. There is no metric or time window involved.
VMs the rule leaves alone
If the JIT policy lookup did not return a result for a VM, ZopNight treats its state as unknown and raises nothing. Tags claiming JIT is configured are ignored. JIT itself only works for Resource Manager VMs protected by an NSG or Azure Firewall, so classic VMs and machines without either cannot be fixed this way.
Reduced exposure, at the price of a Defender plan
No saving is claimed. JIT needs Microsoft Defender for Servers Plan 2 enabled on the subscription, which is a paid plan. The benefit is fewer hours per month in which management ports are reachable at all; for rules already open to the internet, see Azure NSG Open to Internet.
Enabling JIT on a VM
- Enable Defender for Servers Plan 2 on the subscription in Defender for Cloud.
- Confirm the VM has an NSG or Azure Firewall in its path.
- In Defender for Cloud, open Just-in-time VM access, select the VM and enable JIT.
- Review the port list and set a short maximum request time for each port.
- Grant operators a role that lets them request access; Microsoft provides a script to build a least-privileged custom role for this.
- Remove any permanent allow rules for the same ports that JIT now manages.