Just-in-Time Access to Azure Kubernetes Service

Published Mar 02 2021 01:42 PM 4,090 Views
Microsoft

Historically, we could assign an employee to an administrative role through the Azure portal or through Windows PowerShell and that employee would be a permanent administrator; their elevated access would remain active in the assigned role. Azure AD PIM introduced the concept of permanent and eligible administrators in Azure AD and Azure. Permanent administrators have persistent elevated role connections; whereas, eligible administrators have privileged access only when they need it. The eligible administrator role is inactive until the employee needs access, then they complete an activation process and become an active administrator for a set amount of time. 

 

For example, leverage Just-in-Time access to "Assign" an Administrator access to the CLI to run commands against the cluster during the allotted timeframe.

 

MichaelWithrow_0-1614720909010.png

 

For more information please refer to the document below to enable Just-in-Time access for your administrators.

 

Use Azure AD in Azure Kubernetes Service - Azure Kubernetes Service | Microsoft Docs

%3CLINGO-SUB%20id%3D%22lingo-sub-2179872%22%20slang%3D%22en-US%22%3EJust-in-Time%20Access%20to%20Azure%20Kubernetes%20Service%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2179872%22%20slang%3D%22en-US%22%3E%3CP%3EHistorically%2C%20we%20could%20assign%20an%20employee%20to%20an%20administrative%20role%20through%20the%20Azure%20portal%20or%20through%20Windows%20PowerShell%20and%20that%20employee%20would%20be%20a%20permanent%20administrator%3B%20their%20elevated%20access%20would%20remain%20active%20in%20the%20assigned%20role.%20Azure%20AD%20PIM%20introduced%20the%20concept%20of%20permanent%20and%20eligible%20administrators%20in%20Azure%20AD%20and%20Azure.%20Permanent%20administrators%20have%20persistent%20elevated%20role%20connections%3B%20whereas%2C%20eligible%20administrators%20have%20privileged%20access%20only%20when%20they%20need%20it.%20The%20eligible%20administrator%20role%20is%20inactive%20until%20the%20employee%20needs%20access%2C%20then%20they%20complete%20an%20activation%20process%20and%20become%20an%20active%20administrator%20for%20a%20set%20amount%20of%20time.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20example%2C%20leverage%20Just-in-Time%20access%20to%20%22Assign%22%20an%20Administrator%20access%20to%20the%20CLI%20to%20run%20commands%20against%20the%20cluster%20during%20the%20allotted%20timeframe.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22MichaelWithrow_0-1614720909010.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F260289i815B4489075D46B6%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22MichaelWithrow_0-1614720909010.png%22%20alt%3D%22MichaelWithrow_0-1614720909010.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20more%20information%20please%20refer%20to%20the%20document%20below%20to%20enable%20Just-in-Time%20access%20for%20your%20administrators.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Faks%2Fmanaged-aad%23configure-just-in-time-cluster-access-with-azure-ad-and-aks%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EUse%20Azure%20AD%20in%20Azure%20Kubernetes%20Service%20-%20Azure%20Kubernetes%20Service%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2179872%22%20slang%3D%22en-US%22%3E%3CP%3EIntegrate%20your%20Azure%20Kubernetes%20Service%20cluster%20with%20Azure%20Active%20Directory%20to%20leverage%20Privileged%20Identity%20Management%20(PIM)%20for%20Just-in-Time%20Access.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2179872%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Eazure%20kubernetes%20service%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Version history
Last update:
‎Mar 04 2021 04:00 PM
Updated by: