Configuring JIT
By default, IT admins can connect to a session host through RDP on port 3389
. Even with Microsoft Entra PIM in place, making sure that IT admins don’t have permissions active the entire time, the RDP port is still reachable.
This is where JIT comes in. This setting needs to be activated in Defender for Cloud and is included in Defender for Servers plan 2. This adds extra security controls to the session hosts. In the Azure portal, search for Microsoft Defender for Cloud
and then select Environment Settings, as seen in the following figure.
Figure 8.21 – Defender for Cloud menu
In the Environment settings blade, an entire overview of the management group structure is displayed. An IT admin can continue by selecting the subscription where they want to activate session hosts for JIT access.
Figure 8.22 – Selecting a subscription
Defender for Servers has two different plans, but for JIT...