What should you do first to implement JIT VM access for VM1?
You have an Azure subscription named Sub1 that contains a resource group named RG1. RG1 contains the resources shown in the following table. Sub1 has Microsoft Defender for Servers enabled. You are assigned the Contributor role for Sub1. You need to implement just-in-time (JIT) VM access for VM1. What should you do first? - 
Community Votes
63% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you know JIT relies on an NSG (or Azure Firewall) to create temporary inbound rules, not on subscription ownership or enabling a Defender plan that is already enabled.
To implement just-in-time (JIT) VM access in Azure, the first step is to create a network security group (NSG) because JIT requires an NSG or Azure Firewall; since Defender for Servers is already enabled, Contributor access is sufficient. Community consensus strongly supports answer A.
The most common wrong answer is C, 'Request the Owner role for Sub1.' This mistake occurs because some sources list 'Owner' as a prerequisite, but the scenario already has Defender for Servers enabled, and Contributor can create and manage resources such as NSGs; JIT does not require Owner for this action.
Community Discussion (13 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
JIT VM access in Microsoft Defender for Cloud works by using NSG rules or Azure Firewall rules to allow temporary access to specific ports. If the VM does not already have an NSG (as implied by the resource table), you must create one and associate it with the VM before enabling JIT. Since Sub1 already has Microsoft Defender for Servers enabled, the only missing prerequisite is an NSG, making A the correct first step.
Why the Other Options Are Wrong
B is incorrect because enabling enhanced security in Microsoft Defender for Cloud is redundant; the question states Microsoft Defender for Servers is already enabled. C is incorrect because the Contributor role is sufficient to create and manage resources for JIT; Owner is only needed for delegating access, not for enabling JIT. D is incorrect because application security groups are not used by JIT; JIT relies on classic NSG rules or Azure Firewall rules.
Community Comment Notes
Comment [1] correctly quotes Microsoft Learn documentation stating that JIT requires an NSG or Firewall configuration, with no Azure Firewall mentioned in the question, so an NSG is required. Comment [5] explains that Owner would only be needed if Defender for Cloud enhanced security were not already enabled. Comment [7] reinforces that Contributor can create and manage all Azure resources, so Owner is unnecessary. The voting distribution (A: 63, C: 21, B: 16) supports A as the consensus correct answer.
Official Reference
Exam Strategy
For JIT access questions, first check whether the VM has an NSG or Azure Firewall; if not, creating/attaching an NSG is the priority. Do not assume you need Owner or an extra Defender plan when the question explicitly states Defender for Servers is already enabled.