An engineer activates a privileged role in Microsoft Entra PIM on Monday morning. They activate it again after lunch, and again before they log off. Over the next thirty days the same role gets checked out more than forty times.
Every one of those activations followed policy. The approval fired, the role was time-bound, the audit log is spotless. That is exactly what makes it easy to miss.
Just-in-Time That Never Turns Off
The point of just-in-time access is that privilege is the exception, not the default. An identity that activates the same time-bound role fifteen, thirty, forty times a month has quietly turned the exception into the default. The role is functionally standing access wearing a just-in-time costume.
That pattern usually means one of three things: access the person needs continuously and should be granted a different way, an automated workload running on a human's account instead of a service principal, or a compromised identity reaching for privilege over and over.
Watch the Cadence, Not Just the Checkbox
Compliance monitoring asks whether an activation followed the rules. It rarely asks how often. The stronger question is behavioral: what does a normal elevation rhythm look like for this person, and who sits far outside it? Attune baselines that cadence, excludes service accounts and low-frequency users so the signal stays clean, and surfaces the over-frequent activators automatically.
From there the fix is concrete. Confirm the business justification, migrate genuine automation to a scoped service principal, tighten the policy with approval and shorter activation windows, and if the pattern looks wrong, treat the account as potentially compromised and pull the sign-in logs.
Just-in-time access only earns its name when someone is watching how often "just this once" actually happens.
See the latest from Abnormal's product and engineering teams.

