The Segura® Platform offers the possibility of using Just-In-Time (JIT) credentials. This configuration manages the use time of services, such as when an account is created or activated or needs specific permissions added during a period to perform actions.
Be aware that after this access, the account is deleted, inactivated, or removed.
JIT access configuration is done when you register or edit a credential. If you are registering a credential, access the documentation on How to configure a credential in Segura®. In case you are editing a credential, follow these steps:
- On Segura® Platform, in the navigation bar, hover over the Products menu and select PAM Core.
- In the side menu, select Credentials > All credentials.
- In the list of credentials, locate the credential you want to edit and in the Action column, click on the Edit option from the drop-down menu.
Before registering a JIT-type credential, you must first configure the creation/deletion and enable/disable templates for the systems the credentials will use. These templates will be configured in the credentials and then used when the proxy session is initialized. For more information on configuring execution templates, access the Templates documentation.
The user can't register plugins.
In both modes, the Credential form will open. In the form, go to the JIT Settings tab and fill in the following fields:
- Just In Time settings: select the Enabled field.
- In the Just In Time Type drop-down menu, select one of the two options:
- Creation and deletion: the JIT credential will be created when the Proxy session is requested to be initialized and will be deleted when the session ends. The creation and removal of a JIT credential is a previously defined privilege that makes it possible to create a credential for a specified period, which will be automatically deleted after that period.
- Enable/Disable: the JIT credential will be activated when it requests the initialization of the Proxy session and will be inactivated at the end of the session.
- In the Authentication settings section, check the Use own credential to connect option if you want to use the credential in question to connect. If not, uncheck the option and enter a credential for authentication in the Authentication credential drop-down menu.
According to the Type of Just In Time you have chosen, one of the two sections will be enabled.
In case you selected Enable/Disable, fill in the following fields:
- In the Credential enable plugin drop-down menu, select one of the registered plugins.
- In the Credential enable template drop-down menu, select one of the registered templates.
- In the Credential disable plugin drop-down menu, select one of the registered plugins.
- In the Credential disable template drop-down menu, select one of the registered templates.
In case you selected Creation and deletion, fill in the following fields:
- In the Credential creation plugin drop-down menu, select one of the registered plugins.
- In the Credential creation template drop-down menu, select one of the registered templates.
- In the Credential deletion plugin drop-down menu, select one of the registered plugins.
- In the Credential deletion template drop-down menu, select one of the registered templates.
- In the JIT execution field, select where the automation runs: Domain device or Target device. This field appears only for a domain credential. For what each option does, see Where the JIT automation runs.
Click the Continue button and Save.
Where the JIT automation runs
For a domain credential, Segura® runs the creation and deletion templates on one of two devices. The JIT execution field decides which one:
- Domain device: the automation runs on the device linked to the credential. This is the default. Active Directory grants the privilege in the domain and replicates it to the target device.
- Target device: the automation runs on the device the session targets. The creation template you selected runs on that device. It grants the JIT account membership in the device's local administrators group when the session opens. The removal template revokes it when the session ends.
In a domain distributed across regions, replication can take long enough that the privilege does not yet exist on the target device when the session starts. Target device grants the privilege where it is used, for the duration of the session, without waiting for replication.
JIT execution appears only for a domain credential that uses Creation and deletion. A local credential already runs its automation on its own device, and the Enable/Disable type activates a single existing credential.
The choice applies to the creation template and the deletion template together. Selecting it changes nothing for credentials you have already configured.
Requirements for Target device
With Target device, Segura® opens a direct WinRM connection to each target device and runs the template there. Every device you target this way must be reachable over WinRM.
Over WinRM HTTP on port 5985, the Windows RM execution template must include !unsecure. Confirm that the template you select carries this line before you use it.
If the template does not include !unsecure on port 5985, provisioning fails on an SSL handshake. The operator sees the message An error occurred while provisioning the credential. The session does not open, and the matching removal is recorded as canceled.
Do you still have questions? Reach out to the Segura® Community.