[GH-ISSUE #3951] [Feature Request]: Configurable timeframe limit for JIT admins #1776

Closed
opened 2026-03-02 13:47:00 +03:00 by kerem · 2 comments
Owner

Originally created by @inventitinkoop on GitHub (Apr 11, 2025).
Original GitHub issue: https://github.com/KelvinTegelaar/CIPP/issues/3951

Please confirm:

  • I have searched existing feature requests (open and closed) and found no duplicates.
  • **me or my organization is currently an active sponsor of the product at the $99,- level.

Problem Statement

The problem is that users create JIT admins with unlimited expiry time. So they can always use it in the future (it's the easy way, but it's not secure).

Benefits for MSPs

This mitigates security leaks because of the maximum numbers of global admins and increases secure score. This also gives more granular control.

Value or Importance

This is almost critical, regarding the fact that the function is now being abused.

PowerShell Commands (Optional)

No response

Originally created by @inventitinkoop on GitHub (Apr 11, 2025). Original GitHub issue: https://github.com/KelvinTegelaar/CIPP/issues/3951 ### Please confirm: - [x] **I have searched existing feature requests** (open and closed) and found no duplicates. - [x] **me or my organization is currently an active sponsor of the product at the $99,- level. ### Problem Statement The problem is that users create JIT admins with unlimited expiry time. So they can always use it in the future (it's the easy way, but it's not secure). ### Benefits for MSPs This mitigates security leaks because of the maximum numbers of global admins and increases secure score. This also gives more granular control. ### Value or Importance This is almost critical, regarding the fact that the function is now being abused. ### PowerShell Commands (Optional) _No response_
kerem 2026-03-02 13:47:00 +03:00
Author
Owner

@github-actions[bot] commented on GitHub (Apr 24, 2025):

This issue is stale because it has been open 10 days with no activity. We will close this issue soon. If you want this feature implemented you can contribute it. See: https://docs.cipp.app/dev-documentation/contributing-to-the-code . Please notify the team if you are working on this yourself.

<!-- gh-comment-id:2825985903 --> @github-actions[bot] commented on GitHub (Apr 24, 2025): This issue is stale because it has been open 10 days with no activity. We will close this issue soon. If you want this feature implemented you can contribute it. See: https://docs.cipp.app/dev-documentation/contributing-to-the-code . Please notify the team if you are working on this yourself.
Author
Owner

@KelvinTegelaar commented on GitHub (Jun 14, 2025):

Duplicate https://github.com/KelvinTegelaar/CIPP/issues/3908

<!-- gh-comment-id:2972834357 --> @KelvinTegelaar commented on GitHub (Jun 14, 2025): Duplicate https://github.com/KelvinTegelaar/CIPP/issues/3908
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/CIPP#1776
No description provided.