Open cardosec

Case 10FC92 · Identity & AD · L1 Foundations

Just-in-Time Access

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Zero standing privilege: nobody holds admin rights permanently; they request elevation for a task and time window
  2. Implemented with PIM/PAM tools: approval, MFA at elevation, justification, and automatic expiry
  3. Shrinks the window in which a stolen admin credential is useful and makes every elevation auditable
  4. Pair with break-glass accounts stored offline and heavily monitored for emergencies
  5. Trade-off: friction for on-call engineers; mitigate with pre-approved roles for incident response

If the interviewer pushes back

  • How would you design break-glass access so it is usable in an outage but alarming when misused?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.