> For the complete documentation index, see [llms.txt](https://docs.cipp.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cipp.app/user-documentation/identity/administration/jit-role-templates.md).

# JIT Role Templates

A JIT Role Template is a named allow-list of Entra ID directory roles. Assigning one to a [CIPP custom role](/user-documentation/cipp/advanced/authentication/cipp-roles.md) restricts members of that role to only grant the roles in the template when creating a JIT Admin, and they can only see existing JIT Admins whose roles fall entirely within the template.

{% hint style="info" %}
Restriction combines the same way CIPP handles multiple custom roles elsewhere - restrictively, not additively. A custom role with no template assigned does not restrict anything on its own, but as soon as a user holds a role that has a template they are restricted, and their allowed roles are the intersection of every template they hold. An untemplated role cannot be used to bypass a template assigned alongside it. Admin and Super Admin users are unaffected, and if no template is assigned anywhere nothing changes, so existing configurations are not disturbed until you assign one.
{% endhint %}

## Action Buttons

{% content-ref url="/pages/VLIQtPub9jt3hRdqc6VR" %}
[Add JIT Role Template](/user-documentation/identity/administration/jit-role-templates/add.md)
{% endcontent-ref %}

## Table Details

| Column        | Description                                              |
| ------------- | -------------------------------------------------------- |
| Template Name | The name of the template given at creation or last edit. |
| Roles         | The directory roles included in this allow-list.         |
| Created By    | The user that created the template.                      |
| Created Date  | The date the template was created.                       |

## Table Actions

<table><thead><tr><th>Action</th><th>Description</th><th data-type="checkbox">Bulk Action Available</th></tr></thead><tbody><tr><td>Edit Template</td><td>Opens the selected template for editing in <a data-mention href="/user-documentation/identity/administration/jit-role-templates/edit.md">Edit JIT Role Template</a>.</td><td>false</td></tr><tr><td>Delete Template</td><td>Deletes the template. A custom role still assigned this template is not reverted to unrestricted - it fails closed, so its members can no longer grant or see any roles via JIT Admin until a different template is assigned or the assignment is cleared.</td><td>false</td></tr></tbody></table>

***

## Feature Requests / Ideas

We value your feedback and ideas. Please raise any [feature requests](https://github.com/CyberDrain/CIPP/issues/new?template=feature.yml) on GitHub.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cipp.app/user-documentation/identity/administration/jit-role-templates.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
