JIT for computers accounts - Idemeum Docs

Named vs. shared accounts

All compliance frameworks require administrative access to be performed with individual admin accounts that can be audited.

Named admin accounts

Named accounts is the default option.

When technicians login, an individual account for their assigned username is created on the workstation (or domain controller). Each account is enabled only for the duration of the session and the password is rotated to a random value after each log out. In the audit logs, you will see information about who logged in where and what individual account was used.

Shared admin account

We offer this option to reduce the number of accounts created; however, this option does not pass security and compliance requirements. One individual account is used to login all technicians. This account is enabled only for the duration of the session, and the password is rotated behind the scenes after every log out. The agent automatically generates the account in the form msp-XXXX (i.e., msp-1234) for each customer/organization. In the logs, you still have visibility into who logged in where with the shared account.

Domain vs. local admin accounts

Local admin accounts

Local admin account is the default option.

Regardless of the computer state (local, domain, or Entra joined), Idemeum will create a local admin account for each technician. In this case, there is no need to install the Idemeum agent on the domain controller. Simply install it on user workstations.

Domain admin accounts

You need to install the Idemeum agent on all domain controllers to be able to create and use JIT domain accounts.

When a technician tries to login by scanning a QR-code on the user workstation, the Idemeum agent reaches out to the domain controller to provision and enable the domain account. After the session, the domain account is disabled and the password is rotated.