> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/ams/v3.0/help-and-support/support-articles/kb000011.md).

# KB000011: Users report delays in obtaining just-in-time access via AD

## Summary

Users may report a delay in between being granted (just-in-time) JIT access via the web app, and the access seemingly being available.

## Cause

There are several possible causes for delayed JIT access.

1. The user needs to log off and log back on Windows only calculates group membership at logon. This means that for a user to be seen as a member of the local administrators group, they need to log onto a brand new session. There is no way for windows to force a group membership update otherwise.
2. Cross-site replication delays Active Directory has a default inter-site replication delay on 15 minutes. This means changes between domain controllers across sites is only replicates once every 15 minutes, at most. This delay can be longer if there are more sites downstream that need to be replicated to, or if the replication has been set to happen only at scheduled times.

   Access Manager will always try and find a DC in the same site as the computer that is being JIT'd into. However, if there is no DC in the site, or AMS cannot correctly determine the site, AMS will use a DC from it's own site to make the change.

   1. You can improve the site discovery process by installing the Access Manager agent on your devices. The agent will report its connected DC to the AMS server regularly.
   2. If the AMS server can contact the target computer via SMB (TCP 445), it can ask the computer what domain controller it is using.
   3. You can use authorization rules to specify which site or DC should be targeted for any give rule. If you have an OU of computers that are always in a specific OU, you can update the computer authorization rule to specify the site or DC that should be used.

## Further Troubleshooting

The `access-manager-webapp.log` log file contains information about the DC location decision making process. You can perform a JIT operation, locate the relevant section of the log and look for `DCLocator` events, which will indicate the DC that was chosen for the JIT operation and why.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/ams/v3.0/help-and-support/support-articles/kb000011.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
