mirror of
https://github.com/KelvinTegelaar/CIPP.git
synced 2026-04-25 16:26:09 +03:00
[GH-ISSUE #4957] [Feature Request]: JIT Admin - support multiple actions at expiration #2338
Labels
No labels
API
Feature
NotABug
NotABug
Planned
Sponsor Priority
Sponsor Priority
bug
documentation
duplicate
enhancement
needs more info
no-activity
no-priority
not-assigned
pull-request
react-conversion
react-conversion
roadmap
security
stale
unconfirmed-by-user
unconfirmed-by-user
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/CIPP#2338
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @zenturash on GitHub (Nov 17, 2025).
Original GitHub issue: https://github.com/KelvinTegelaar/CIPP/issues/4957
Please confirm:
Problem Statement
within "JIT Admin" it would be nice if it would support multiple expiration actions.
Usecase: Fx if you have a JIT admin that persists aka is reused sometimes you would like be able to choose the option to both remove roles and disable the user.
Reasoning: This would reduce the role creep over time and minimize the attack surface.
Benefits for MSPs
This would reduce the role creep over time and minimize the attack surface.
Fx if you have a JIT account that also have RBAC permision to azure subs or resources that persists where you only use TAP to sigin and it's disabled after use, if you added entra roles via JIT there is currently no option to both remove the roles assigned and disable the account leading admin role creepy.
Value or Importance
nice-to-have: but to follow least privilege principle it would be nice and giving a more fully featured PAM/JIT solution via CIPP
PowerShell Commands (Optional)
No response
@github-actions[bot] commented on GitHub (Nov 27, 2025):
This issue is stale because it has been open 10 days with no activity. We will close this issue soon. If you want this feature implemented you can contribute it. See: https://docs.cipp.app/dev-documentation/contributing-to-the-code . Please notify the team if you are working on this yourself.
@zenturash commented on GitHub (Nov 27, 2025):
this feature would be lovely to have not only for the org i work at.
@github-actions[bot] commented on GitHub (Dec 7, 2025):
This issue is stale because it has been open 10 days with no activity. We will close this issue soon. If you want this feature implemented you can contribute it. See: https://docs.cipp.app/dev-documentation/contributing-to-the-code . Please notify the team if you are working on this yourself.
@github-actions[bot] commented on GitHub (Dec 13, 2025):
This issue was closed because it has been stalled for 14 days with no activity.