NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • Contact Us
English (US)
NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish
  • Home
  • AutoElevate Knowledgebase
  • Getting Started with AutoElevate

JIT Domain Log In (BETA)

Understanding how to setup JIT domain login

Written by Chris Liles

Updated at September 24th, 2026

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • AutoElevate Knowledgebase
    Getting Started with AutoElevate AutoElevate Features & Troubleshooting Managing Rules in AutoElevate Integrations for AutoElevate AutoElevate FAQ Selling AutoElevate
  • CyberFOX Password Manager Knowledgebase
    Using CyberFOX Password Manager Administrating CyberFOX Password Manager Legacy Password Boss
  • CyberFOX DNS Filtering
    Getting Started with DNS Filtering DNS Filtering Concepts Network Requirements for DNS Filtering DNS Filtering Company and Location Setup Managing your DNS Filtering Policies Using Roaming Clients for DNS Filtering DNS Filtering Reports & Logs DNS Filtering Troubleshooting
  • Marketing Toolkit
    MSP Marketing & Education Toolkit CyberFOX Brand Guidelines
  • Changelogs for Autoelevate and Password Boss
  • CyberFOX Product Roadmap
  • Current Status
+ More

Table of Contents

Overview About JIT Domain Log In Requirements Step 1: Enable JIT Domain Log In Step 2: Configure Authorizations Step 3: Set Up the Domain Controller Upgrading from a File-Based Certificate Step 4: Enable the Mobile Device Logging In Domain Account Behavior Revoking a Mobile Device Limitations Advanced Use Cases Best Practices Troubleshooting "Unauthorized" in the Mobile App "This mobile device is not approved for Just-in-Time (JIT) Domain Log In" "No domain controller is available to complete this Just-in-Time (JIT) Domain Log In." "Just-in-Time (JIT) Log In is not enabled for this computer." Logon Failure: User Not Granted Logon Type Domain Not Appearing in Authorization Settings Domain Logins Fail After Upgrading Connectivity Failures Related Articles

Overview


AutoElevate Just-in-Time (JIT) Domain Log In lets technicians sign in to domain-joined Windows computers with temporary domain access, without persistent domain administrator credentials. Access is requested and approved through the AutoElevate Notify mobile app.

JIT Domain Log In is a Beta feature. No opt-in is required to use it.

Authorizations are required. Nobody can log in until the Just-in-Time (JIT) Log In - Authorizations setting contains a card that includes the computer's domain. Turning on Domain Log In Enabled also changes which cards apply to local administrator logins on domain-joined computers. See Step 2.

 

 

About JIT Domain Log In


Instead of using static domain administrator accounts, AutoElevate provisions and manages a domain account for each technician and adds it to the selected domain group or organizational unit for the login session.

Key capabilities:

  • A temporary-access domain account tied to each technician.
  • Role-, user-, and group-based authorization controls.
  • Approval through the technician's enrolled mobile device.
  • Domain group and organizational unit selection for each login.

Why it matters:

  • Eliminates persistent domain administrator credentials.
  • Reduces the risk of credential theft and lateral movement.
  • Provides audit visibility of privileged access.
  • Aligns with Zero Trust and least-privilege security models.

 

Requirements


  • Domain controller: The AutoElevate agent, version 2.11.1769 or later, installed on at least one writeable domain controller in the same domain. The domain controller must have checked in within the last 30 days. The Beta agent channel is not required.
  • Workstations: The AutoElevate agent installed on the domain-joined computers technicians will sign in to.
  • Configuration: JIT Admin Login enabled with Domain Log In Enabled checked.
  • Authorizations: At least one authorization card that includes the domain and grants a Domain Group or Organizational Unit.
  • Mobile device: The AutoElevate Notify app, with strong device security:
    • iOS 15.1 or later, with Face ID or Touch ID and a device passcode.
    • Android 12 or later, with strong biometrics (fingerprint or face unlock) and a screen lock.
    • Hardware key storage (the Secure Enclave on iPhone). A device without it shows "not supported" or "security setup required."

A mobile device without these security features cannot enroll for domain log in. Its technician can still select Local Groups for a local JIT Admin Login.

 

Step 1: Enable JIT Domain Log In


  1. In the Admin Portal, go to Settings → Just-in-Time (JIT) Log In → Just-in-Time (JIT) Log In - Configuration.
  2. Check Enabled.
  3. Fill in the Username and Credential Tile Label Override fields. The Username is used for local JIT logins only. Domain logins use a domain account named for the technician (see Domain Account Behavior).
  4. Check Domain Log In Enabled.
  5. Select Save.
Configuration dialog with Domain Log In Enabled checked

 

Step 2: Configure Authorizations


Go to Settings → Just-in-Time (JIT) Log In → Just-in-Time (JIT) Log In - Authorizations and select Add Authorization. Each card defines:

  • Roles and Users: which technicians the card applies to.
  • Domains: which domains the card applies to, selected from the domains your computers report. A domain appears only after an agent in that domain begins reporting.
  • Domain Groups and Organizational Units: which groups and OUs the technician can select during login. Typed by hand. These lists are available only after a Domain is set.
  • Local Groups: which local groups the technician can select for a local JIT login on the same computers, for example Administrators. Typed by hand. The name must match exactly, including capitalization.

Each list has an All box. Multiple cards can apply to the same technician, and their grants add up. The setting can be set at the Global, Company, Location, and Computer levels. The most specific level that has the setting replaces all others, so cards at different levels do not combine.

Domain-joined computers use only cards that include their domain. When Domain Log In Enabled is on, a domain-joined computer ignores cards with no Domains, even for local administrator logins. Workgroup computers, and computers where Domain Log In Enabled is off, use only cards with no Domains. If a customer has both, create two cards.

Authorizations migrated from the retired Authorized Roles & Users setting have no Domains. After Domain Log In Enabled is turned on, those technicians cannot log in to domain-joined computers until a card that includes the domain is added.

 
Authorizations card with Domain CONTOSO.LOCAL and a Domain Group
Authorizations editor showing a domain card and a workgroup card

For the full list of authorization rules, see Just-in-Time (JIT Admin Login) — Authorizations.

Certificate management and technician device approval are handled automatically. There is no certificate download or manual device-approval step.

 

Step 3: Set Up the Domain Controller


Install the AutoElevate agent, version 2.11.1769 or later (download the 2.11.1769 installer), on at least one writeable domain controller in each domain. The domain becomes available in the Authorizations setting after the agent begins reporting.

Upgrading from a File-Based Certificate

If you used JIT Domain Log In before automatic certificate management, complete this step on every domain controller that runs the agent. New customers can skip it.

  1. Upgrade the domain controller agent to 2.11.1769 or later first. Do not remove the certificate from a domain controller running an older agent.
  2. Open the certificates folder next to the domain controller agent in the AutoElevate installation directory.
  3. Delete the old .pem certificate file.

If an old .pem file is left on any domain controller, domain logins that are processed by that domain controller fail.

 

 

Step 4: Enable the Mobile Device


Each technician enrolls their mobile device once. Approval is automatic: there is no administrator step and no recovery phrase.

  1. In the AutoElevate Notify app, tap the menu icon and select Enable JIT Log In.
  2. Tap Set Up JIT Domain Log In.
  3. Complete the biometric prompt.
  4. The app displays "This Device Is Ready For JIT Domain Log In."
Mobile app menu with Enable JIT Log In highlighted
This Device Is Ready For JIT Domain Log In confirmation

Automatic enrollment (Beta): The Beta version of the AutoElevate Notify app enrolls the device automatically, so these steps are not needed and Enable JIT Log In does not appear in the menu. Automatic enrollment will come to the stable app in a future release.

 

 

Logging In


From the Windows sign-in screen of a domain-joined computer:

  1. Select the Just-in-Time Admin Login tile.
  2. Select Begin Just-in-Time Log In. A QR code appears. The QR code expires after 10 minutes.
Begin Just-in-Time Log In screen
Sample JIT QR code

In the AutoElevate Notify app:

  1. Select the scan icon.
Scan barcode icon
  1. Scan the QR code.
  2. On the Choose Login Options screen, select at least one group (Domain Group or Local Group). You can also select one Organizational Unit in the same login. Selecting only an Organizational Unit, with no group, fails.
  3. Tap Submit Just-in-Time Log In Request.
  4. Complete the Face ID, Touch ID, or fingerprint prompt. The phone asks for it whenever a Domain Group or Organizational Unit is selected.
Just-in-Time Log In request screen

 

Domain Account Behavior


  • The domain account is named for the technician (up to 20 characters). It does not use the Configuration Username.
  • The same account is reused for each of that technician's domain logins, with a new random password every time.
  • The account is not deleted after the session.
  • Automatic removal of the groups granted for a session is planned for a future update.
  • Approvals are tied to both the mobile device and the technician.

 

Revoking a Mobile Device


  1. In the Admin Portal, go to Settings → Just-in-Time (JIT) Log In → Just-in-Time (JIT) Log In - Domain Log In Device Authorization. This setting is available at the Global, Company, and Location levels.
  2. Find the mobile device and select Revoke.

Revoke a device when a technician leaves or a phone is lost or replaced.

 

Limitations


  • Only top-level organizational units can be selected, and only one organizational unit per login. An organizational unit must be selected together with at least one group.
  • The domain controller's clock must be within 10 minutes of the time of the request.
  • JIT Domain Log In is not available offline. Offline JIT Admin Login supports local logins only.

 

Advanced Use Cases


  • Secure MSP operations: Grant technicians domain access across multiple tenants without sharing credentials.
  • Just-in-time privileged access: Allow temporary access for specific tasks, such as Active Directory changes or troubleshooting.
  • OU-based access control: Restrict technicians to specific organizational units.
  • Compliance and audit readiness: Keep records of who accessed domain resources and when.

 

Best Practices


  • Use role-based authorizations instead of individual user assignments.
  • Limit access to specific organizational units whenever possible.
  • Enforce biometric authentication on all technician mobile devices.
  • Review authorization cards regularly.
  • Keep the agent deployed consistently across domain controllers.

 

Troubleshooting


"Unauthorized" in the Mobile App

The app displays: "Unauthorized — You do not have Just-in-Time (JIT) Admin authorization for this computer. Contact your administrator to configure permissions."

  • Confirm that a card names the technician or the technician's role.
  • Confirm that the card's Domains include the computer's domain (or All). Cards with no Domains do not apply to domain-joined computers when Domain Log In Enabled is on.
  • Confirm that the card grants at least one Domain Group, Organizational Unit, or Local Group.
  • Check whether a more specific level (Company, Location, or Computer) has its own Authorizations setting. The most specific level replaces the others.
Unauthorized screen

"This mobile device is not approved for Just-in-Time (JIT) Domain Log In"

  • Close and reopen the AutoElevate Notify app.
  • Confirm that the device meets the security requirements (biometrics and a passcode or screen lock).
  • Devices that were waiting for approval when automatic certificate management was introduced must be enrolled again. See Step 4.
  • If the message continues, contact CyberFOX Support.

"No domain controller is available to complete this Just-in-Time (JIT) Domain Log In."

No eligible domain controller was found. Confirm that at least one writeable domain controller in the computer's domain runs agent 2.11.1769 or later and has checked in within the last 30 days.

"Just-in-Time (JIT) Log In is not enabled for this computer."

Enabled is not checked in the Configuration setting that applies to this computer.

Logon Failure: User Not Granted Logon Type

Error: "Logon failure: the user has not been granted the requested logon type"

This usually occurs on a domain controller. On member workstations, the domain JIT account is added to the local Users group, so the default policy allows it to sign in. On a domain controller, the right is needed unless a selected Domain Group already has it.

  1. Open secpol.msc.
  2. Go to Local Policies → User Rights Assignment.
  3. Update Allow log on locally to include the required users.

Domain Not Appearing in Authorization Settings

  • Confirm that the domain controller agent is installed and reporting.
  • Allow time for the initial sync.

Domain Logins Fail After Upgrading

Confirm that the old .pem certificate file was removed from every domain controller. See Upgrading from a File-Based Certificate.

Connectivity Failures

  • Allow outbound access from the domain controller to https://main.realtime.ably.net/event-stream. Only the domain controller needs this address.
  • This is a long-lived connection. Proxies or TLS inspection that buffer traffic can break it, so exclude it from inspection if needed.
  • Workstations need the standard AutoElevate addresses and LDAP access to the domain controller.
  • Check firewall and proxy restrictions. See Firewall Whitelisting.

 

Related Articles


  • Just-in-Time (JIT Admin Login)
  • Offline Technician Mode and Just-in-Time Admin Login
  • AutoElevate Notify App for Mobile Devices
  • AutoElevate Notify App Screen Guide
  • Firewall Whitelisting
  • System Agent Installation
  • Web Admin Portal Overview
authentication jit autoelevate domain admin msp security endpoint security approval process elevation workflow temporary admin rights admin access least privilege privilege elevation domain login just in time login secure login audit logging compliance privilege management technician access access control jit domain log in domain controller organizational unit domain groups jit authorizations enable jit log in pem certificate

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • System Overview – How It Works
  • System Overview – System Agent
  • System Agent Installation
  • Firewall Whitelisting (AutoElevate)
  • AutoElevate Notify App for Mobile Devices
CyberFOX

PRACTICAL CYBERSECURITY FOR LEAN IT TEAMS

Platforms
  • Privileged Access Management
  • Password Management
  • DNS Filtering
  • SASE
Industry
  • Higher Education
  • K-12 Education
  • State and Local Government
  • Manufacturing
Company
  • About
  • Awards
  • Partnerships
  • Trust & Legal
  • Contact
  • Login
  • FAQ
  • Referral Program
  • Support
© 2026 CYBERFOX LLC ALL RIGHTS RESERVED | Privacy Policy | Terms of Service | Sitemap
Expand