IT Glossary

Just-Enough-Access (JEA)

Just-enough-access limits every account to the exact permissions its task needs. Learn how JEA works and why it only pays off paired with JIT access.

August 7, 2026

What is just-enough-access (JEA)?

Just-enough-access (JEA) is a security principle that limits every identity to the minimum set of permissions its task requires, and nothing beyond it. It answers the scope question: not how long access lasts, but how wide it reaches. Microsoft popularized the term with Just Enough Administration for PowerShell, where an operator runs a defined set of commands without holding full administrator rights.

How just-enough-access works

  • Tasks are described by the specific operations they require, not by the role that traditionally performs them.
  • Permissions are assembled to match those operations, with everything else left out.
  • Delegated endpoints or scoped roles expose only the allowed commands or actions.
  • Broad built-in roles such as global administrator become exceptions rather than defaults.
  • The scope is re-examined when the task changes, not when somebody complains.

Just-enough-access and just-in-time access together

The two controls answer different questions and only work properly as a pair. Just-enough-access narrows what an identity is able to do. Just-in-time access narrows how long it can do it. Standing broad rights fail on both counts, which is why they remain the single most common finding in mid-market access reviews.

Examples and use cases

A help desk technician needs to reset passwords and unlock accounts. The default reflex is to add her to a broad administrator group, which also grants the ability to change policy and read mailboxes. Just-enough-access instead assigns a scoped role covering only those two operations. If a migration later requires more, that arrives as a time-bounded elevation rather than a permanent upgrade. Corma keeps the resulting picture visible across applications, so scope decisions stay reviewable instead of buried in each admin console.

Related concepts

FAQ

What is the difference between just-enough-access and least privilege?

Least privilege is the principle. Just-enough-access is its practical implementation, defining the exact permission set a given task requires.

Is JEA a Microsoft product?

Just Enough Administration is a specific PowerShell feature. Just-enough-access is the broader principle, applicable to any system that supports scoped roles.

How does JEA relate to just-in-time access?

JEA controls the breadth of permissions and JIT controls their duration. Together they turn least privilege from a policy statement into an enforceable configuration.

Where should a company start with just-enough-access?

With the accounts holding the broadest built-in roles, typically global administrators and application owners, since reducing scope there removes the most risk.

Request a demo