JEA Admin
Just Enough Administration (JEA)¶
Just Enough Administration (JEA) is a PowerShell security model that enables administrators to create restricted, role-based administrative interfaces. By limiting access to specific cmdlets, modules, and execution policies, JEA ensures users can perform only the tasks required for their role, reducing the risk of accidental or malicious damage. This section demonstrates how to configure JEA, restrict cmdlets, and enforce execution policies for secure automation.
Creating a JEA Configuration¶
To create a JEA configuration, define a role capability file (.psrc), which specifies the allowed cmdlets, modules, and execution policies. Here's a basic example:
# Example role capability file: MyJEAConfig.psrc
@{
RoleCapabilities = @(
@{
Role = "MyJEARole"
Capabilities = @(
@{
Name = "ProcessManagement"
Cmdlets = @("Get-Process", "Stop-Process")
Modules = @("Microsoft.PowerShell.Management")
}
)
ExecutionPolicy = "Restricted"
}
)
}
Save this as MyJEAConfig.psrc in a secure location. Then, create a JEA endpoint using the New-Item cmdlet:
New-Item -Path "C:\JEA\MyJEAConfig.psrc" -ItemType File -Value @'
@{
RoleCapabilities = @(
@{
Role = "MyJEARole"
Capabilities = @(
@{
Name = "ProcessManagement"
Cmdlets = @("Get-Process", "Stop-Process")
Modules = @("Microsoft.PowerShell.Management")
}
)
ExecutionPolicy = "Restricted"
}
)
}
'@
Restricting Cmdlets and Modules¶
JEA uses role capabilities to control access. For example, to restrict a user to only Get-Process and Stop-Process, define a capability block in the role capability file:
Capabilities = @(
@{
Name = "ProcessManagement"
Cmdlets = @("Get-Process", "Stop-Process")
Modules = @("Microsoft.PowerShell.Management")
}
)
To further restrict modules, explicitly list allowed modules and exclude others. For instance, prevent access to Microsoft.PowerShell.Utility:
Use the Get-JEAConfiguration cmdlet to verify the configuration:
Enforcing Execution Policies¶
JEA enforces the Restricted execution policy by default, which blocks script execution. To ensure this is applied, explicitly set the execution policy in the role capability file:
Users cannot bypass this policy, even if they have elevated privileges. For example, the following command will fail in a JEA session:
Key takeaways¶
- Role capabilities define allowed cmdlets, modules, and execution policies for JEA sessions.
- Restrict access to only the cmdlets and modules required for a user's role to minimize risks.
- JEA enforces the Restricted execution policy by default, preventing script execution.
- Test JEA configurations using
Enter-PSSessionto validate behavior and security constraints.