Skip to content

Privilege on Demand

Privilege on Demand provides Just-In-Time access, allowing access to be authorized ahead of time, but provisioned only when activated by the user. The access is then removed when the activation period ends, the user deactivates it, or it is revoked.

Access is only provided for the defined duration, and permissions for the user are only active on their account when needed.

Just-In-Time Access helps you:

  • Enhance security by removing standing privileges.
  • Maintain user productivity without adding burden to your DevOps team by allowing users to provision access on their own.

Just-In-Time access is configured based upon entitlement assignment types. When an entitlement is configured as Just-In-Time, users receive the entitlement as available for activation instead of continuous standing access. For more information on configuring Just-In-Time and standing entitlement access, refer to Setting an Entitlement’s Assignment Type for an Identity.

Just-In-Time Entitlements

Entitlements configured as Just-In-Time can be assigned to a user by an admin or requested from the request center by a user. To allow users to request an entitlement, you will need to configure the access requests for the entitlement.

After the entitlement has been assigned to the user, the user activates the entitlement from the Launchpad. For more information on configuring entitlements for Just-In-Time, refer to Managing Entitlement Assignments.

Configuring Global Just-In-Time Settings

Admins can configure global settings to define default activation durations and set boundaries for how long users can access their Just-In-Time entitlements. For more information on configuring Just-In-Time global settings, refer to Configuring Global Settings.

Viewing Just-In-Time Activations

Admins can view active activations on the Just-In-Time Monitor page. For more information on viewing activations, refer to Viewing Activations.

Activating a Just-In-Time Entitlement

When a Just-In-Time entitlement is assigned to a user, the associated entitlement displays on the user's Launchpad > Just-In-Time Access page. To provision access, the user must activate the entitlement from the Launchpad for a defined duration. Users can view the status of activated entitlements and deactivate or extend active activations.

A notification email is sent to the user when their Just-In-Time access is due to expire in 15 minutes.

Access is automatically deprovisioned when the Just-In-Time activation expires.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.