Cannot remove JIT rules from Defender for Servers

ChristianSievers 0 Reputation points
2025-09-22T22:10:15.7566667+00:00

We are using Microsoft Defender for Cloud. We need to turn off a JIT access rule for a particular NSG, however, the delete action never removes the rule. One guidance suggests to turn of Defender for the entire subscription, which we don't want to do.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. VEMULA SRISAI 2,040 Reputation points Microsoft External Staff Moderator
    2025-09-25T00:11:11.3+00:00

    Hello ChristianSievers,

    Thanks for posting your question in the Microsoft Q&A Forum.

    Below is the process to remove a Just-in-Time (JIT) VM access policy in Microsoft Defender for Cloud:

    Go to the Azure portal → Microsoft Defender for Cloud.

    In the left menu, select Workload protection.

    Under Advanced protection, select Just-in-time VM access.

    Open the Configured tab.

    Select the VM(s) you want to remove from JIT protection.

    1. Click Remove to remove the VM from the JIT configuration.

    Simply deleting or modifying the NSG rule will not work. JIT has a recovery mechanism that will automatically re-apply the rule as long as the VM is still enrolled.

    I hope this information is helpful. If you need additional information or need assistance please let me know.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.