Just-in-time (JIT) VM access and network layer threat detections are features of Microsoft Defender for Cloud (formerly Azure Security Center "Azure Defender" plans). These capabilities are enabled by turning on the relevant Defender plans at the subscription level, which then apply to resources in that subscription. Workspace- or individual resource-level enablement won't activate JIT or the broad network detections across your estate.