JIT Domain Log In (BETA)
Understanding how to setup JIT domain login
Table of Contents
Overview
Just-in-Time (JIT) Domain Log In in AutoElevate enables technicians to securely authenticate into Active Directory domains using temporary privilege elevation, eliminating the need for persistent admin credentials. This feature improves security posture by enforcing least-privilege access while maintaining operational efficiency for support teams.
What Is JIT Domain Log In?
Feature Description
JIT Domain Log In allows technicians to request and receive temporary domain access using controlled authorization workflows. Instead of using static domain admin accounts, the system dynamically provisions and manages domain user privileges during the login session.
Key capabilities include:
- Temporary domain user creation tied to the technician
- Role- and group-based authorization controls
- Mobile device approval workflows
- Automatic privilege downgrade after login
Why It Matters
- Eliminates persistent domain admin credentials
- Reduces risk of credential theft or lateral movement
- Provides full audit visibility of privileged access
- Aligns with Zero Trust and least-privilege security models
Platform-Specific Configuration & Usage
Admin Portal Configuration
Enable JIT Domain Log In
- Navigate to Settings → Just-in-Time (JIT) Log In→ Just-in-Time (JIT) Log In - Configuration
- Check the Enable feature option.
- Fill In the Username and Credential Tile Label Override fields
- Check Domain Log In Enabled.

Configure Authorizations
Define which:
- Domains are included
- Users/roles can approve requests
- Groups or OUs can be selected during login
Multiple authorization rules can apply simultaneously (additive model).

Certificate generation and technician device approval are now handled automatically once authorizations are configured — there's no separate certificate download or manual device-approval step for admins to run.
Domain Controller (Server-Side Setup)
- Ensure the AutoElevate agent (V 2.11.1769 or higher) is installed on at least one write-enabled Domain Controller.
Requirements
- At least one Primary Domain Controller must run the AutoElevate agent.
- Domain availability appears only after the agent begins reporting.
- Domain-joined workstations must have the same agent installed
Technician Mobile App — Enabling JIT Log In on a Device
JIT Domain Login is a Beta Feature
JIT Domain Log In is a Beta feature. Switch the mobile app to Beta first:
- Click the hamburger menu.
- Rapid-click the logo at the top of the menu 8–10 times.
- Select Beta, then let the mobile app restart.
- From the mobile device, click the hamburger menu and select Enable JIT Log In.

- Once approval completes, the mobile device indicates the device is ready for JIT Domain Log In.

Login Workflow
- From the server login screen:
- Click the Just In Time Admin Login user.
- Click Begin Just-in-Time Login…

- You should be presented with a QR code.

- Using the AutoElevate Mobile app:
- Select the Scan barcode icon.

- Scan the JIT QR code.
- Select the Domain Group or OU.
- Click Submit Just-in-Time Log In Request.

- Use strong biometric authentication to complete the domain login.
Mobile App (iOS / Android)
Device Approval
Devices are automatically approved:
Security Requirements
- Strong biometric authentication required
- Minimum OS versions:
- Android 12+
- iOS 5.1+
Advanced Use Cases
Secure MSP Operations — Grant technicians domain access across multiple tenants without sharing credentials.
Just-in-Time Privileged Access — Allow temporary access for specific tasks, such as AD changes or troubleshooting.
Granular OU-Based Access Control — Restrict technicians to only specific organizational units.
Compliance & Audit Readiness — Maintain detailed logs of who accessed domain resources and when.
Best Practices
- Use role-based authorizations instead of individual user assignments.
- Limit access scope to specific OUs whenever possible.
- Enforce biometric authentication on all mobile devices.
- Regularly review authorization configurations.
- Ensure Domain Controllers have consistent agent deployment.
Troubleshooting
Issue: Logon Failure – User Not Granted Logon Type
Error example: Logon failure: the user has not been granted the requested logon type
Resolution:
- Open
secpol.msc. - Navigate to Local Policies → User Rights Assignment.
- Update Allow log on locally to include required users.
Issue: Domain Not Appearing in Authorization Settings
- Confirm the Domain Controller agent is installed and reporting.
- Allow time for initial state sync.
Issue: Mobile Device Cannot Approve Requests
- Ensure the device has been approved using the correct private key.
- Verify biometric authentication is enabled.
- Confirm correct user context (approval is user-specific per device).
Issue: Connectivity Failures
- Ensure outbound access to
https://main.realtime.ably.net/event-stream. - Check firewall or proxy restrictions.
Security & Sync Behavior
- Temporary domain users are reused per technician, but do not retain admin privileges after login.
- Privileges are automatically downgraded post-session.
- Certificate Authority files are NOT stored by AutoElevate — customers are responsible for secure storage.
- Mobile approvals are tied to both the device and the user.
- Multiple public keys can exist on Domain Controllers for redundancy.