New Capability: Privilege On Demand

:new_button: New Capability

Privilege on Demand

:sparkles: Description

Privilege on Demand (JIT-P v1.0) helps customers reduce standing access by shifting privileged access to just-in-time activation windows. This improves security posture and auditability while keeping authorized users productive.

:red_exclamation_mark: Problem

Today, many organizations rely on standing elevated access that remains active longer than needed. That increases exposure and audit risk, and creates an ongoing tradeoff between security controls and operational speed.

:light_bulb: Solution

Privilege On Demand introduces an activation-based model for eligible entitlements: users request and receive access, then activate it when work begins for a bounded duration, with automatic expiration.

This gives teams stronger least-privilege enforcement, clear activation/expiration events, and less manual cleanup than traditional standing access models.

:busts_in_silhouette: Who is affected?

  • Customers using Identity Security Cloud who need tighter control of elevated access

  • IAM/Security Admins configuring JIT policy and entitlement eligibility

  • End users activating approved access via Launchpad

  • Business+ suite customers (Privilege on Demand (JIT-P) packaging)

:clipboard: Action required (customer-facing)

  1. Confirm Privilege on Demand (JIT-P v1.0) is enabled for the tenant/licensing package.

  2. In Admin settings, configure global JIT activation/extension durations.

  3. Mark target entitlements as requestable and configure JIT entitlement assignments.

  4. Validate approval behavior (auto-approve or approval-required) for target access.

  5. Communicate end-user activation flow in Launchpad.

:date: Important dates

Sandbox availability: Starts Jul 6, 2026, End: TBD, estimated Jul 19, 2026
Production rollout: Subject to change based on previous phases, estimated to begin Jul 20, 2026 , estimated completion Aug 21, 2026
Milestones / phases (if any): Production will roll out to low, medium, and then high risk targets

:books: Resources

  • Documentation:

    • Admin: (link coming soon)

      • Additional Email Templates

        • [MOD] Access Request Decision

        • [NEW] Access Request Assignment

        • [NEW] JIT Activation - 15 Minute Reminder

        • [NEW] Just-In-Time Activation Extended

        • [NEW] Just-In-Time Activation Failed

        • [NEW] Just-In-Time Activation Ready

        • [NEW] Just-In-Time Deactivated

    • End-User: (link coming soon)

1 Like

The links appear to be broken.

3 Likes

I’m excited to read more about this but this link takes you to a 404 error page.

Only entitlements are mentioned. Will it work with Access Profiles? Roles? (the latter is less needed)

Hi! Apologies about that! The links will be updated when this feature hits prod.

Could you provide an update on the deployment schedule? @Zia_Hotaki
I believe the sandbox rollout is not done at all? Has it started, or not?
Thanks

@Zia_Hotaki Could you please provide the deployment date ?

Really interested by this feature as this was a missing piece in the Privileged Access Management perspective.
I hope that both documentation and deployment dates for for both Sandbox and prod will be available soon to investigate further the possibilities of this feature !
Looking forward also for the event on 30/07 : Improving privilege posture in Identity Security Cloud that should demo this feature.