Skip to content
Artwork for Techsplainers by IBM
Techsplainers by IBM · September 15 · 8 min

What is just-in-time access?

This episode of Techsplainers explores just-in-time access, an identity security model that grants users temporary permissions only when they need them and removes that access automatically when the task is complete. Building on the principle of least privilege, the episode explains why time matters just as much as scope when controlling access to sensitive systems. The discussion looks at the risks created by standing privileges, including how stolen credentials can give attackers ongoing access to critical environments and make lateral movement easier. It breaks down the typical JIT workflow and compares three common implementation models: broker-and-remove, ephemeral accounts and temporary elevation. Along the way, listeners learn how JIT fits into broader identity security practices like privileged access management, zero trust, and zero standing privileges. The episode also examines why JIT is increasingly important for nonhuman identities and AI agents, which often operate at higher speed and scale than human users. Find more information at https://www.ibm.com/think/topics/just-in-time-access Find more episodes: https://www.ibm.biz/techsplainers-podcast Narrated by Dan Nosowitz

0:00-8:55

transcript

No transcript — this publisher did not publish one.

show notes

This episode of Techsplainers explores just-in-time access, an identity security model that grants users temporary permissions only when they need them and removes that access automatically when the task is complete. Building on the principle of least privilege, the episode explains why time matters just as much as scope when controlling access to sensitive systems.

The discussion looks at the risks created by standing privileges, including how stolen credentials can give attackers ongoing access to critical environments and make lateral movement easier. It breaks down the typical JIT workflow and compares three common implementation models: broker-and-remove, ephemeral accounts and temporary elevation.

Along the way, listeners learn how JIT fits into broader identity security practices like privileged access management, zero trust, and zero standing privileges. The episode also examines why JIT is increasingly important for nonhuman identities and AI agents, which often operate at higher speed and scale than human users.

Find more information at https://www.ibm.com/think/topics/just-in-time-access Find more episodes: https://www.ibm.biz/techsplainers-podcast

Narrated by Dan Nosowitz
links2

more episodes

All episodes