Hello ChristianSievers,
Thanks for posting your question in the Microsoft Q&A Forum.
Below is the process to remove a Just-in-Time (JIT) VM access policy in Microsoft Defender for Cloud:
Go to the Azure portal → Microsoft Defender for Cloud.
In the left menu, select Workload protection.
Under Advanced protection, select Just-in-time VM access.
Open the Configured tab.
Select the VM(s) you want to remove from JIT protection.
- Click Remove to remove the VM from the JIT configuration.
Simply deleting or modifying the NSG rule will not work. JIT has a recovery mechanism that will automatically re-apply the rule as long as the VM is still enrolled.
I hope this information is helpful. If you need additional information or need assistance please let me know.