> ## Documentation Index
> Fetch the complete documentation index at: https://docs.idemeum.com/llms.txt
> Use this file to discover all available pages before exploring further.

# JIT for computers features

> Major features that you can use with JIT for computer access.

## JIT computer elevation

When you login as technician with mobile device, you might need to perform certain actions that require elevation. When the elevation screen comes up, you can simply scan the QR-code to elevate the application. For instance, on Windows simply click `More options`, then enlarge idemeum QR-code, and scan with your mobile app. The action will be elevated and UAC will be handled by idemeum agent behind the scenes. Similar experience is offered on macOS workstations.

<img src="https://mintcdn.com/idemeum/zMDClmhiuqchpIB_/images/jit-elevation.png?fit=max&auto=format&n=zMDClmhiuqchpIB_&q=85&s=d323df3b8641fd26a4d8f279fc7c7c1b" alt="Jit Elevation" width="1600" height="1289" data-path="images/jit-elevation.png" />

## JIT for computers login methods

<AccordionGroup>
  <Accordion title="QR-code login" defaultOpen>
    Navigate to workstation where idemeum agent is installed, click on the QR-code at the bottom of the screen, and then scan the QR-code with idemeum mobile app.

    <img src="https://mintcdn.com/idemeum/7P--3LYDGeS82raH/images/qrlogin.png?fit=max&auto=format&n=7P--3LYDGeS82raH&q=85&s=f39fa9f89bb7a99340ad72fe7e74e51c" alt="Qrlogin" width="1600" height="1289" data-path="images/qrlogin.png" />
  </Accordion>

  <Accordion title="Push notification login" defaultOpen>
    <Note>
      You need to [enable](/jit/jit-for-computers-confiruation) this option in JIT settings first.
    </Note>

    Navigate to workstation where idemeum agent is installed, click on the QR-code icon at the bottom left to load idemeum login option, click on `Send notification` link. Now you are able to enter your email address (the one you registered with in idemeum) and you will receive a login notification.

    <img src="https://mintcdn.com/idemeum/7P--3LYDGeS82raH/images/pushlogin.png?fit=max&auto=format&n=7P--3LYDGeS82raH&q=85&s=82a7d2b25f6c6ad49db8f0e0db31b080" alt="Pushlogin" width="1600" height="1289" data-path="images/pushlogin.png" />
  </Accordion>

  <Accordion title="OTP login" defaultOpen>
    You can use this method when computer is offline. When computer is offline, idemeum agent can not render a QR-code and automatically switches to OTP login mode. Or you can enable this option to login with OTP even when computer is not offline. Navigate to workstation, click on QR-code at the bottom left to load idemeum login options, click on `Login via OTP`. Now you can retrieve username and OTP for the workstation from your idemeum mobile app.

    <img src="https://mintcdn.com/idemeum/7P--3LYDGeS82raH/images/otplogin.png?fit=max&auto=format&n=7P--3LYDGeS82raH&q=85&s=a8acafc48145cc86777b05b4f2e983bb" alt="Otplogin" width="1600" height="1289" data-path="images/otplogin.png" />
  </Accordion>
</AccordionGroup>

## Offline computer access

When the computer is offline, idemeum credential provider will automatically switch to offline mode. Instead of displaying the QR-code for admin access, it will show the username and offline secret fields.

<img src="https://mintcdn.com/idemeum/vgWvqHLqXL4qMoyr/images/offline.png?fit=max&auto=format&n=vgWvqHLqXL4qMoyr&q=85&s=fa3b6aec3306ec9077fb86fdfbd93630" alt="Offline" width="1600" height="1289" data-path="images/offline.png" />

To retrieve username and your offline OTP code, open idemeum mobile application, switch to appropriate organization / customer, then search for workstation, click on `...` and retrieve username and OTP code.

<img src="https://mintcdn.com/idemeum/vgWvqHLqXL4qMoyr/images/offlinecode.jpeg?fit=max&auto=format&n=vgWvqHLqXL4qMoyr&q=85&s=cf6ba0a2d6003840bd9085b624163698" alt="Offlinecode" title="Offlinecode" style={{ width:"31%" }} width="1170" height="2532" data-path="images/offlinecode.jpeg" />

## Selective computer JIT login

<Note>
  You need to enable this feature for the tenant. More about configuration [here](/jit/jit-for-computers-confiruation).
</Note>

For domain-joined workstations where idemeum desktop client is installed, you can choose what account to use for technician login on the fly at login time. When you scan the QR-code you will be presented with the option to use domain account or local. This feature is useful if you want to control on which workstations you want to expose your domain admin account.

<img src="https://mintcdn.com/idemeum/ev9YUJw5Wvsfh5-g/images/select.png?fit=max&auto=format&n=ev9YUJw5Wvsfh5-g&q=85&s=dd2c342047761a5594540557c374e019" alt="Select" width="1600" height="1077" data-path="images/select.png" />

## RDP with JIT accounts

<Warning>
  RDP with JIT accounts works between domain-joined workstations. You need to make sure idemeum agent is installed on domain controller, source, and destination Windows workstation.
</Warning>

<Card title="RDP access with JIT accounts" icon="youtube" horizontal href="https://www.youtube.com/watch?v=OrDygvIN-B4">
  Quick demo for how to RDP with JIT accounts.
</Card>

When idemeum desktop agent is installed on domain-joined workstations, technicians can RDP from one machine to the other without the need to use any passwords - simply scan the QR-code and approve with biometrics. Just-in-time accounts will be used behind the scenes, accounts will be enabled / disabled on-demand, and passwords will be rotated after each login.

### RDP JIT prerequisites

* Supported on domain-joined workstations only
* Desktop agent installed on `source` and `target` machine
* Domain accounts login enabled for the customer tenant
* Domain controller is reachable from the RDP `source` workstation
* Agent is installed on domain controller

### How to RDP with JIT account

* Login to `source` domain-joined workstation
* Open Windows Remote Desktop Client and connect to the `target` domain-joined machine
* You will then be prompted to authenticate. Click `More options` and then select `idemeum credential provider` to scan the QR-code.
* You can enlarge the QR-code so that it is easier to scan by clicking on `Click here to expand QR code`
* Scan the QR-code with idemeum mobile application and approve with biometrics
* You will be logged in to the `target` workstation

<img src="https://mintcdn.com/idemeum/dYg10_f5UEMaAL4G/images/enlarge.png?fit=max&auto=format&n=dYg10_f5UEMaAL4G&q=85&s=ed758fc02a58271fa16249a65df1ed11" alt="Enlarge" width="1600" height="1136" data-path="images/enlarge.png" />

## Computer access control

You can control what technicians have access to what workstations. Important to note that if technician is a `Global admin`, she can access and edit everything everywhere. If you want to apply access control you first need to delegate technician access to certain customer / organization with `read-only` permissions, and then edit workstation access control settings.

* Navigate to admin portal of customer / organization
* Access `Devices`, then click on `...` for the device you want to edit, and choose `Share device`
* By default `All admins` and `All users` will be there
* To control technician access, remove `All admins` role and only add technicians that need to access this workstation

<img src="https://mintcdn.com/idemeum/vidH6EXpXzSy32Wx/images/CleanShot-2026-05-25-at-15.32.29@2x.png?fit=max&auto=format&n=vidH6EXpXzSy32Wx&q=85&s=6e58314a99f4788ff3abf420a6486f94" alt="Clean Shot 2026 05 25 At 15 32 29@2x" width="3268" height="2138" data-path="images/CleanShot-2026-05-25-at-15.32.29@2x.png" />

## JIT domain account auto removal

When technicians use JIT access for computers in domain environments, individual domain admin accounts are created every time new technician logs in for the first time. When these accounts are not in use, they are in disabled state.

In order to make the number of accounts manageable, idemeum agent that is installed on domain controller will periodically inventory all technicain JIT accounts. And if the account has not been used for the last 30 days, it will be deleted.

<Note>
  Let's look at the example. Technician `alex` logs into the domain controller and the account `msp-alex` is created. Once `alex` logs out, the JIT account is disabled. For 30 days `alex` does not login to this domain environment. As a result, the account is deleted after 30 days. If `alex` tries to login after a period of 30 days the account `msp-alex` will be recreated.
</Note>
