Configuring Just-In-Time Access
Privilege on Demand Just-In-Time access allows access to be authorized ahead of time, but provisioned only when activated by the user. The access is then removed when the activation period ends, the user deactivates it, or it is revoked. Access is only provided for the defined duration, and permissions for the user are only active on their account when needed.
Just-In-Time access is configured based upon entitlement assignment types. For more information on configuring Privilege on Demand and Just-In-Time entitlements, refer to Just-In-Time Entitlements.
Managing Entitlement Assignments
Admins can configure or remove Just-In-Time entitlements to enable Just-In-Time provisioning for specific entitlements or to revert them back to standing access.
To configure an entitlement as Just-In-Time:
-
Go to Admin > System Settings > Feature Settings > Just-In-Time.
-
Select the Entitlements Assignments tab.
-
Select the Enable Just-In-Time for future assignments toggle.
-
Select Add Entitlements.
-
Select the desired entitlements.
You can search for a specific entitlement based on characters contained in the entitlement name. You can also use the Sort icon
to sort entitlements by their name, source, owner, whether it can be requested, and risk.Note
Only entitlements for direct-connect sources can be configured for Just-In-Time access.
-
Select Add Selected Entitlements to add the entitlements to the list.
Important
- Listed entitlements will be granted as Just-In-Time access for new assignments processed through the Request Center.
- Existing assignments for the added entitlement will remain with standing access. Existing standing access assignments can be modified on an individual entitlement's Identity tab.
To revert an entitlement to standing access:
-
Go to Admin > System Settings > Feature Settings > Just-In-Time.
-
Select the Entitlements Assignments tab.
-
Locate the entitlements you want to remove.
-
Remove the entitlements in one of the following ways:
- Multiple Entitlements - Select multiple checkboxes for multiple entitlements, and then select Remove Selected.
- Individual Entitlement - Select Remove for an individual entitlement.
The selected entitlements are removed from the list and will be assigned as standing access for new assignments processed through the Request Center.
Note
Existing assignments for the removed entitlement will remain with Just-In-Time access. Existing Just-In-Time access assignments can be modified on an individual entitlement's Identity tab.
Configuring Global Settings
Admins can configure global settings to define default activation durations and set boundaries for how long users can access their Just-In-Time entitlements.
Maximum Activation Duration - The maximum duration an activation can be initially activated.
Default Activation Duration - The duration an activation will be set to when a user selects Activate on the Launchpad.
Maximum Extension Duration - The maximum duration an activation can be extended by when a user extends an entitlement on the Launchpad.
Default Extension Duration - The duration an activation will be extended by when a user extends an entitlement on the Launchpad by the default duration.
Configuring the Maximum Activation Duration
To configure the maximum activation duration:
-
Go to Admin > System Settings > Feature Settings > Just-In-Time.
-
Select the Activation tab.
-
Select the Maximum Activation Duration dropdown and select the desired duration.
-
Select Save.
Future activations will be limited to the selected duration.
Note
Existing activations are unaffected and will maintain their original maximum activation duration.
Configuring the Default Activation Duration
To configure the default activation duration:
-
Go to Admin > System Settings > Feature Settings > Just-In-Time.
-
Select the Activation tab.
-
Select the Default Duration dropdown and select the desired duration.
-
Select Save.
Future activations using the Activate button will be set to the selected duration.
Note
Existing activations are unaffected and will maintain their original duration or extended duration.
Configuring the Maximum Extension Duration
To configure the maximum extension duration:
-
Go to Admin > System Settings > Feature Settings > Just-In-Time.
-
Select the Activation tab.
-
Select the Maximum Extension Duration dropdown and select the desired duration.
-
Select Save.
Future activation extensions will be limited to the selected duration.
Note
Existing extended activations are unaffected and will maintain their original extended duration.
Configuring the Default Extension Duration
To configure the default extension duration:
-
Go to Admin > System Settings > Feature Settings > Just-In-Time.
-
Select the Activation tab.
-
Select the Default Extension Duration dropdown and select the desired duration.
-
Select Save.
Future default activation extensions will be extended by the selected duration.
Note
Existing extended activations are unaffected and will maintain their original extended duration.
Viewing Activations
Admins can view active activations on the Just-In-Time Monitor page.
To view active activations:
-
Go to Admin > Dashboard > Just-In-Time Access.
-
Select the assignment type of the desired activation.
Details of the selected assignment are displayed.
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.