NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • Contact Us
English (US)
NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish
  • Home
  • AutoElevate Knowledgebase
  • New to AutoElevate? START HERE

JIT Domain Log In (BETA)

Understanding how to setup JIT domain login

Written by Chris Liles

Updated at September 18th, 2026

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • AutoElevate Knowledgebase
    New to AutoElevate? START HERE AutoElevate Features & Troubleshooting Managing Rules in AutoElevate Integrations for AutoElevate AutoElevate FAQ Selling AutoElevate
  • CyberFOX Password Manager Knowledgebase
    Using CyberFOX Password Manager Administrating CyberFOX Password Manager Legacy Password Boss
  • CyberFOX DNS Filtering
    Getting Started with DNS Filtering DNS Filtering Concepts Network Requirements for DNS Filtering DNS Filtering Company and Location Setup Managing your DNS Filtering Policies Using Roaming Clients for DNS Filtering DNS Filtering Reports & Logs DNS Filtering Troubleshooting
  • Marketing Toolkit
    MSP Marketing & Education Toolkit CyberFOX Brand Guidelines
  • Changelogs for Autoelevate and Password Boss
  • CyberFOX Product Roadmap
  • Current Status
+ More

Table of Contents

Overview What Is JIT Domain Log In? Feature Description Why It Matters Platform-Specific Configuration & Usage Admin Portal Configuration Domain Controller (Server-Side Setup) Technician Mobile App — Enabling JIT Log In on a Device JIT Domain Login is a Beta Feature Login Workflow Mobile App (iOS / Android) Device Approval Security Requirements Advanced Use Cases Best Practices Troubleshooting Issue: Logon Failure – User Not Granted Logon Type Issue: Domain Not Appearing in Authorization Settings Issue: Mobile Device Cannot Approve Requests Issue: Connectivity Failures Security & Sync Behavior Related Articles

Overview


Just-in-Time (JIT) Domain Log In in AutoElevate enables technicians to securely authenticate into Active Directory domains using temporary privilege elevation, eliminating the need for persistent admin credentials. This feature improves security posture by enforcing least-privilege access while maintaining operational efficiency for support teams.

 

What Is JIT Domain Log In?


Feature Description

JIT Domain Log In allows technicians to request and receive temporary domain access using controlled authorization workflows. Instead of using static domain admin accounts, the system dynamically provisions and manages domain user privileges during the login session.

Key capabilities include:

  • Temporary domain user creation tied to the technician
  • Role- and group-based authorization controls
  • Mobile device approval workflows
  • Automatic privilege downgrade after login

Why It Matters

  • Eliminates persistent domain admin credentials
  • Reduces risk of credential theft or lateral movement
  • Provides full audit visibility of privileged access
  • Aligns with Zero Trust and least-privilege security models

 

Platform-Specific Configuration & Usage


Admin Portal Configuration

Enable JIT Domain Log In

  1. Navigate to Settings → Just-in-Time (JIT) Log In→ Just-in-Time (JIT) Log In - Configuration
  2. Check the Enable feature option.
  3. Fill In the Username and Credential Tile Label Override fields
  4. Check Domain Log In Enabled.
     

Configure Authorizations

Define which:

  • Domains are included
  • Users/roles can approve requests
  • Groups or OUs can be selected during login

Multiple authorization rules can apply simultaneously (additive model).

Edit Just-in-Time (JIT) Log In - Authorizations panel

Certificate generation and technician device approval are now handled automatically once authorizations are configured — there's no separate certificate download or manual device-approval step for admins to run.

Domain Controller (Server-Side Setup)

  1. Ensure the AutoElevate agent (V 2.11.1769 or higher) is installed on at least one write-enabled Domain Controller.

Requirements

  • At least one Primary Domain Controller must run the AutoElevate agent.
  • Domain availability appears only after the agent begins reporting.
  • Domain-joined workstations must have the same agent installed

Technician Mobile App — Enabling JIT Log In on a Device

JIT Domain Login is a Beta Feature

JIT Domain Log In is a Beta feature. Switch the mobile app to Beta first:

  1. Click the hamburger menu.
  2. Rapid-click the logo at the top of the menu 8–10 times.
  3. Select Beta, then let the mobile app restart.
 

 

  1. From the mobile device, click the hamburger menu and select Enable JIT Log In.

Mobile app menu with Enable JIT Log In highlighted

  1. Once approval completes, the mobile device indicates the device is ready for JIT Domain Log In.

This Device Is Ready For JIT Domain Log In confirmation

Login Workflow

  1. From the server login screen:
    1. Click the Just In Time Admin Login user.
    2. Click Begin Just-in-Time Login…

Begin Just-in-Time Log In screen

  1. You should be presented with a QR code.

Sample JIT QR code

  1. Using the AutoElevate Mobile app:
    1. Select the Scan barcode icon.

Scan barcode icon

  1. Scan the JIT QR code.
  2. Select the Domain Group or OU.
  3. Click Submit Just-in-Time Log In Request.

Just-in-Time Log In request screen

  1. Use strong biometric authentication to complete the domain login.

Mobile App (iOS / Android)


Device Approval

Devices are automatically approved:

Security Requirements

  • Strong biometric authentication required
  • Minimum OS versions:
    • Android 12+
    • iOS 5.1+

 

Advanced Use Cases


Secure MSP Operations — Grant technicians domain access across multiple tenants without sharing credentials.

Just-in-Time Privileged Access — Allow temporary access for specific tasks, such as AD changes or troubleshooting.

Granular OU-Based Access Control — Restrict technicians to only specific organizational units.

Compliance & Audit Readiness — Maintain detailed logs of who accessed domain resources and when.

 

Best Practices


  • Use role-based authorizations instead of individual user assignments.
  • Limit access scope to specific OUs whenever possible.
  • Enforce biometric authentication on all mobile devices.
  • Regularly review authorization configurations.
  • Ensure Domain Controllers have consistent agent deployment.

 

Troubleshooting


Issue: Logon Failure – User Not Granted Logon Type

Error example: Logon failure: the user has not been granted the requested logon type

Resolution:

  1. Open secpol.msc.
  2. Navigate to Local Policies → User Rights Assignment.
  3. Update Allow log on locally to include required users.

Issue: Domain Not Appearing in Authorization Settings

  • Confirm the Domain Controller agent is installed and reporting.
  • Allow time for initial state sync.

Issue: Mobile Device Cannot Approve Requests

  • Ensure the device has been approved using the correct private key.
  • Verify biometric authentication is enabled.
  • Confirm correct user context (approval is user-specific per device).

Issue: Connectivity Failures

  • Ensure outbound access to https://main.realtime.ably.net/event-stream.
  • Check firewall or proxy restrictions.

 

Security & Sync Behavior


  • Temporary domain users are reused per technician, but do not retain admin privileges after login.
  • Privileges are automatically downgraded post-session.
  • Certificate Authority files are NOT stored by AutoElevate — customers are responsible for secure storage.
  • Mobile approvals are tied to both the device and the user.
  • Multiple public keys can exist on Domain Controllers for redundancy.

 

Related Articles


  • AutoElevate Notify App for Mobile Devices
  • AutoElevate Notify App Screen Guide
  • Firewall Whitelisting (AutoElevate)
  • System Agent Installation
  • Web Admin Portal Overview
access authentication jit autoelevate domain admin msp security endpoint security approval process elevation workflow temporary admin rights admin access least privilege privilege elevation domain login just in time login windows elevation secure login audit logging compliance privilege management autoelevate policies technician access remote support security elevation logs session timeout endpoint agent access control

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • System Overview – How It Works
  • System Overview – System Agent
  • System Agent Installation
  • Firewall Whitelisting (AutoElevate)
  • AutoElevate Notify App for Mobile Devices
CyberFOX

PRACTICAL CYBERSECURITY FOR LEAN IT TEAMS

Platforms
  • Privileged Access Management
  • Password Management
  • DNS Filtering
  • SASE
Industry
  • Higher Education
  • K-12 Education
  • State and Local Government
  • Manufacturing
Company
  • About
  • Awards
  • Partnerships
  • Trust & Legal
  • Contact
  • Login
  • FAQ
  • Referral Program
  • Support
© 2026 CYBERFOX LLC ALL RIGHTS RESERVED | Privacy Policy | Terms of Service | Sitemap
Expand