[GH-ISSUE #4077] [Feature Request]: JIT for Groups, not just admin roles #1851

Closed
opened 2026-03-02 13:47:37 +03:00 by kerem · 2 comments
Owner

Originally created by @HappyEarthDay on GitHub (May 12, 2025).
Original GitHub issue: https://github.com/KelvinTegelaar/CIPP/issues/4077

Please confirm:

  • I have searched existing feature requests (open and closed) and found no duplicates.
  • **me or my organization is currently an active sponsor of the product at the $99,- level.

Problem Statement

We love the Just-In-Time (JIT) Admin feature in CIPP—it’s a powerful tool for managing temporary access. We’d love to see this extended to support temporary group membership for users.

This would open up several powerful use cases, such as:

  • Temporarily excluding users from Intune or other conditional access policies by removing them from policy-enforcing groups.
  • Granting time-limited access to licensed features or applications (e.g., adding users to a group that applies a specific license).
  • Allowing secure, time-bound access to group-scoped resources, such as SharePoint sites or Teams channels.
  • Reducing the risk of overprovisioned access by ensuring group-based roles and permissions expire automatically.

Ideally, this would function similarly to the JIT Admin experience today, with a timed expiration and optional approval workflow.

Benefits for MSPs

It would significantly enhance our operational flexibility, usage of CIPP, and security posture.

Value or Importance

Extending JIT Admin to support temporary group membership would bring the same time-bound, least-privilege benefits to group-based access, licensing, and policy control. This would enhance security, reduce administrative overhead, and enable more flexible, controlled access to Microsoft 365 resources.

PowerShell Commands (Optional)

No response

Originally created by @HappyEarthDay on GitHub (May 12, 2025). Original GitHub issue: https://github.com/KelvinTegelaar/CIPP/issues/4077 ### Please confirm: - [x] **I have searched existing feature requests** (open and closed) and found no duplicates. - [x] **me or my organization is currently an active sponsor of the product at the $99,- level. ### Problem Statement We love the Just-In-Time (JIT) Admin feature in CIPP—it’s a powerful tool for managing temporary access. We’d love to see this extended to support temporary group membership for users. This would open up several powerful use cases, such as: - Temporarily excluding users from Intune or other conditional access policies by removing them from policy-enforcing groups. - Granting time-limited access to licensed features or applications (e.g., adding users to a group that applies a specific license). - Allowing secure, time-bound access to group-scoped resources, such as SharePoint sites or Teams channels. - Reducing the risk of overprovisioned access by ensuring group-based roles and permissions expire automatically. Ideally, this would function similarly to the JIT Admin experience today, with a timed expiration and optional approval workflow. ### Benefits for MSPs It would significantly enhance our operational flexibility, usage of CIPP, and security posture. ### Value or Importance Extending JIT Admin to support temporary group membership would bring the same time-bound, least-privilege benefits to group-based access, licensing, and policy control. This would enhance security, reduce administrative overhead, and enable more flexible, controlled access to Microsoft 365 resources. ### PowerShell Commands (Optional) _No response_
Author
Owner

@github-actions[bot] commented on GitHub (May 22, 2025):

This issue is stale because it has been open 10 days with no activity. We will close this issue soon. If you want this feature implemented you can contribute it. See: https://docs.cipp.app/dev-documentation/contributing-to-the-code . Please notify the team if you are working on this yourself.

<!-- gh-comment-id:2899703210 --> @github-actions[bot] commented on GitHub (May 22, 2025): This issue is stale because it has been open 10 days with no activity. We will close this issue soon. If you want this feature implemented you can contribute it. See: https://docs.cipp.app/dev-documentation/contributing-to-the-code . Please notify the team if you are working on this yourself.
Author
Owner

@github-actions[bot] commented on GitHub (May 28, 2025):

This issue was closed because it has been stalled for 14 days with no activity.

<!-- gh-comment-id:2914674864 --> @github-actions[bot] commented on GitHub (May 28, 2025): This issue was closed because it has been stalled for 14 days with no activity.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/CIPP#1851
No description provided.