12.1 Configure Just-in-Time Protection

Key Takeaways

  • Just-in-time (JIT) protection blocks egress on never-evaluated or stale-classification files until Endpoint DLP finishes policy evaluation; it does not replace Devices-scoped DLP policies.
  • Configure JIT in the Microsoft Purview portal under Settings > Data Loss Prevention > Just-in-time protection, and allow at least an hour for setting changes—including disable—to reach clients.
  • Fallback Allow versus Block applies when classification or evaluation fails; it does not switch JIT Block versus JIT Audit for in-scope users.
  • If Network share coverage and exclusions is off, JIT applies only to local files; enabling both extends JIT to network shares and mapped drives.
  • JIT events appear in Activity explorer with JIT triggered set to true and do not create DLPRuleMatch events or alerts.
Last updated: August 2026

12.1 Configure Just-in-Time Protection

Quick Answer: Microsoft Purview just-in-time (JIT) protection is an Endpoint data loss prevention (Endpoint DLP) control that detects and blocks egress on JIT candidate files—items that have never been classified or that have a stale classification—until cloud policy evaluation finishes. Configure it in the Microsoft Purview portal under Settings > Data Loss Prevention > Just-in-time protection. The Fallback action in case of failure (Allow users to complete actions versus Block users from completing actions) applies only when classification or evaluation fails; it does not decide whether JIT Block or JIT Audit runs for in-scope users.

Why SC-401 tests this control

Endpoint DLP can enforce Block or Block with override only after it knows whether a file matches a Devices-scoped policy. Classification is not instantaneous. A user who copies an unclassified spreadsheet to USB, prints a newly downloaded PDF, or uploads a file whose last evaluation used an old policy version can complete the egress before the current cloud policy is applied. JIT closes that gap by holding the egress while evaluation runs.

JIT is not a replacement for Endpoint DLP policies, not a substitute for Microsoft Defender for Endpoint removable-storage device control, and not an alert generator. Official documentation states that JIT does not create a DLPRuleMatch event or an alert. On the exam, treat JIT as a timing and coverage control that sits on top of the Devices-scoped policies you designed in the Endpoint DLP configuration chapter.

JIT candidate files and stale classification

Microsoft uses these terms in the JIT conceptual article:

  • Stale classification: A classification that was not produced by the current DLP policy version. After you update a policy, previously classified files stay stale until Endpoint DLP reevaluates them.
  • JIT candidate file: A file that DLP has not evaluated, or that has a stale classification.
  • JIT audit: After JIT is enabled, Endpoint DLP writes an Activity explorer event for the candidate file with JIT triggered = true and Enforcement mode = Audit.
  • JIT block: The egress is blocked and the event uses Enforcement mode = Block, still with JIT triggered = true.

JIT blocks egress when all of the following are true:

  1. The user attempts an egress on a never-classified or stale item.
  2. The user is in the JIT scope.
  3. At least one DLP policy defines Block or Block with override for that egress activity.
  4. The destination is not an allowed printer, USB group, network share, or URL.
  5. Policy evaluation does not finish inside the documented resume window (Microsoft describes a five-second evaluation window before the JIT in-progress experience).

If the user is out of JIT scope, or no Block / Block with override exists for the activity, or the destination is already allowed, JIT does not block. Microsoft still records a JIT audit event in several of those cases so you can measure candidate-file volume before you tighten scope.

Supported platforms and client versions

JIT protection for Endpoint DLP supports:

  • Windows 10
  • Windows 11
  • macOS (the three most recent released major versions)

Deploy Microsoft Defender antimalware client 4.18.23080 or later before you enable JIT. Microsoft documents an improved end-user experience in 4.18.25080 or later; the resume timings and toast names in the conceptual article are written for that later client. Allow at least an hour for JIT setting updates—including disabling JIT—to reach clients.

To inventory client versions, Microsoft documents a Microsoft Defender portal Advanced hunting query against DeviceRegistryEvents for MsMpEng.exe. You can also open Data Loss Prevention > Diagnostics and use the Endpoint DLP not working card to check whether a specific device meets the JIT prerequisite. The device health report under Settings > Device onboarding > Device report includes a Device readiness for feature visualization that currently covers Just-in-time protection and Paste to supported browsers.

How to turn JIT on

  1. Sign in to the Microsoft Purview portal.
  2. Go to Settings > Data Loss Prevention > Just-in-time protection.
  3. Under Choose which locations to monitor, select Devices.
  4. Under Fallback action in case of failure, start with Allow users to complete actions.

Microsoft's deployment guidance is explicit: configure and deploy Endpoint DLP policies first, then enable JIT. Enabling JIT against unclassified files before policies exist produces avoidable holds while evaluation runs and does not add a policy verdict.

Fallback action: the exam trap

Fallback settingWhen it appliesWhat happens if evaluation fails
Allow users to complete actionsClassification or policy evaluation does not completeEgress is allowed
Block users from completing actionsClassification or policy evaluation does not completeEgress is blocked

Microsoft's caution: do not choose Block until you understand the impact on users and help-desk volume.

Keep these two levers separate:

  • JIT Block versus JIT Audit for candidate files is controlled by whether the user is in JIT scope and whether a policy uses Block / Block with override—not by the fallback dropdown.
  • Fallback is the enforcement mode when evaluation fails. Microsoft also applies it after the JIT in progress extra wait if evaluation still has not finished.
  • Either fallback still writes telemetry to Activity explorer.

If an exam item says classification failed on a JIT-scoped device, the answer is the fallback setting. If it says the user is in JIT scope and evaluation is still running, the answer is the JIT hold, not fallback.

Timing, resume, and toasts

Microsoft documents this sequence for the 4.18.25080 or later client:

  1. Evaluation starts.
  2. Activities that support pause and resume and finish within three seconds apply the policy action. For audit, the copy resumes with no toast. For block or block with override, the user sees the policy message.
  3. Items that need more time get two additional seconds (about five seconds total).
  4. If evaluation still is not done, Endpoint DLP blocks the activity, shows the Just-in-time in progress toast (a notification, not an alert), and logs a JIT block event.
  5. The in-progress state waits up to 30 more seconds.
  6. If evaluation finishes in that window, the user sees Just-in-time evaluation complete and must retry the activity.
  7. If evaluation still does not finish, the fallback action is applied.

Resume within three seconds is documented only for:

  • Copy to a removable media
  • Copy to a network share

The user must repeat these after evaluation completes:

  • Print
  • Copy or move using Remote Desktop Protocol (RDP)
  • Copy or move using an unallowed Bluetooth app
  • Copy to clipboard (JIT Audit by default)

Copy to clipboard is JIT Audit by default. The additional setting Control copying to clipboard can block clipboard copy while JIT is evaluating. Microsoft warns that this setting can hurt productivity; test it before you enable it broadly.

Egress activities JIT can audit or block

JIT audits and blocks these user egress activities on protected items:

  • Copy to a removable media
  • Copy to a network share
  • Print
  • Copy or move using RDP
  • Copy or move using a blocked Bluetooth app
  • Copy to clipboard (JIT Audit by default)
  • Upload to a restricted cloud service domain

JIT is not the control that classifies files at rest on a file server. Server onboarding, Enable Endpoint DLP for Windows Servers, and on-premises repository DLP remain separate topics.

Network share coverage and JIT

Network share coverage and exclusions lives under Endpoint DLP settings, not inside the JIT blade. It extends Devices-scoped DLP to new and edited files on network shares and mapped drives. If JIT is also enabled, JIT coverage and exclusions are extended to those same shares and drives. Exclude a specific UNC path for all monitored devices with Exclude these network share paths.

Microsoft publishes this matrix:

Network share coverageJust-in-time protectionResultant behavior
EnabledDisabledDevices-scoped DLP policies apply to network shares and mapped drives the device connects to
DisabledEnabledJIT applies only to files on storage that is local to the endpoint
EnabledEnabledDevices-scoped DLP and JIT both apply to network shares and mapped drives

If JIT is on but users still exfiltrate unclassified files over a mapped drive, the exam answer is often enable Network share coverage and exclusions, not that JIT is broken. JIT also does not block when the destination is already an allowed network share group, printer group, USB group, or URL—those allowed-group exceptions short-circuit the JIT hold.

Network share coverage complements DLP on-premises repository actions; it does not replace them. Devices-scoped actions protect the endpoint's copy/move/print path. On-premises repository policies protect data at rest in file shares and SharePoint document libraries when that location is in scope.

Exclusions: JIT-only versus Endpoint DLP-wide

Fine-tune JIT with:

  • App exclusions for Windows — maximum 50 apps
  • App exclusions for Mac — maximum 50 apps
  • File extension exclusions — those extensions are not evaluated by JIT
  • File path exclusions for Windows / Mac — those locations are not evaluated by JIT

Microsoft contrasts JIT path exclusions with Data loss prevention > Settings > Endpoint settings > File path exclusions for Windows:

  • JIT file path exclusions skip JIT only. Endpoint DLP still classifies and protects files in those folders.
  • Endpoint settings file path exclusions skip all Endpoint DLP classification and protection under those folders.

If the requirement is do not JIT-hold developer build folders, but still apply USB block policies, use JIT path exclusions. If the requirement is never inspect or restrict anything under a scratch volume, use Endpoint settings path exclusions.

Offline Windows devices

On Windows, policies already on the device keep applying to files that were already classified as sensitive after the device goes offline. With JIT enabled and the fallback in block mode, a new file created offline is prevented from being shared until the device reconnects to the data classification service and evaluation completes. Policy updates made while the device is offline apply after it reconnects. Microsoft states that this offline JIT behavior is not supported on macOS.

Staged rollout Microsoft documents

  1. Confirm antimalware version and JIT feature readiness.
  2. Publish Devices-scoped policies (simulation, then enforce).
  3. Enable JIT with Allow fallback and a small user scope.
  4. In Activity explorer, count unique devices firing JIT events (N) versus devices in the deployment scope (S). N/S estimates how many machines may see a JIT block when you expand scope.
  5. Add app, path, and extension exclusions; decide whether Control copying to clipboard is worth the productivity cost.
  6. Only then consider Block fallback.

Exam traps

  • Enabling JIT does not by itself block USB copy; you still need a Devices-scoped rule with Block or Block with override for that activity.
  • Fallback Allow versus Block is not the same as JIT Audit versus JIT Block.
  • JIT path exclusions are not the same as Endpoint settings path exclusions.
  • JIT toasts are not alerts; do not hunt JIT holds on the DLP Alerts dashboard.
  • Do not invent unpublished numeric caps (for example a tenant-wide maximum of JIT-scoped users). Microsoft publishes the 50-app exclusion ceilings and the 3 / 5 / 30 second evaluation windows; it does not publish a fixed maximum device count for JIT.

Official resources

Loading diagram...
JIT evaluation path from egress attempt to fallback
Test Your Knowledge

What does Microsoft Purview just-in-time (JIT) protection do on Endpoint DLP devices?

A
B
C
D
Test Your Knowledge

An administrator enables JIT and must choose Fallback action in case of failure. Which statement matches Microsoft's documented behavior?

A
B
C
D
Test Your Knowledge

JIT is enabled, but unclassified files copied to a mapped network drive are not held for evaluation. Network share coverage and exclusions is disabled. What is the documented result, and how do you extend JIT to those files?

A
B
C
D