Overview
JumpCloud’s Access Risk Detection continuously monitors login activity across your organization and identifies logins that look suspicious. It works by learning how each of your users normally behaves (where they log in from, what devices they use, what times of day they are active) and then flagging logins that deviate from that established pattern.
Access Risk instantly evaluates threats by assigning a risk score and severity level, providing administrators with actionable insights into unusual behavior. Your admins can then investigate, mark the detection as safe, or confirm it as a genuine threat.
Monitored Activities
Access Risk Detection monitors both standard user accounts and administrator accounts across four login event categories. Because administrator accounts hold elevated privileges, deviations on admin accounts carry additional weight in the risk model.
The system evaluates:
- Device logins – Users logging into managed JumpCloud devices.
- Admin Portal logins – Administrators accessing the JumpCloud Admin Portal.
- User Portal logins – End users accessing the JumpCloud User Portal.
- SSO logins – Users authenticating to third-party applications through JumpCloud Single Sign-On (SSO).
This feature currently monitors interactive user authentications only. API calls and service account activities are not supported at this time.
How Access Risk Detection Works
Access Risk Detection follows a four-step lifecycle for every authentication event processed by JumpCloud:
- Learn: The system builds a behavioral profile for each user using their last 60 days of activity or their last 50 successful login events, whichever baseline is more comprehensive. This profile captures patterns related to location, device, login time, and application usage.
- Detect: The system evaluates every new login against nine distinct risk signals. Each signal compares the real-time event data against the user's established baseline.
- Score: Deviations are aggregated into a numerical score and mapped to a severity level: Low, Medium, or Critical.
- Display: The Access Risk dashboard displays a summary of all detections. Admins can view the Detections page to analyze full contextual data, including which risk factors triggered the alert, how they deviated from the baseline, and the user's risk history.
Use Cases
Use Access Risk Detection to:
- Detect account takeover attempts where an attacker is using valid stolen credentials
- Identify insider anomalies such as logins from unexpected locations or off-hours access
- Investigate whether a specific user's recent activity is normal for them
- Reduce the time spent manually reviewing login logs by surfacing only the events that actually warrant attention
Prerequisites
To use Access Risk Detection, your organization must meet the following requirements:
- An active JumpCloud org with login events flowing through Directory Insights
- Administrator or Administrator With Billing access to the JumpCloud Admin Portal
Known Issues
- Detections Page Slow Loading (Safari Only): Users accessing Access Risk Detection via Safari may experience slow loading times or issues rendering tables.
- Workaround: Reduce the number of visible rows and fixed columns to improve page performance.
User Roles
While Administrator and Administrator With Billing roles are required to execute end to end configurations with Access Risk Detections, some other specific roles also have view-only access to Access Risk Detections.
Only Administrator and Administrator With Billing roles can view, manage, and resolve detections. These roles are also needed to configure global Access Risk Detection settings, define threat thresholds, and manage whitelists.
Custom Roles
For custom roles, make sure you have the following permissions added.
Go to Settings > Administrators > Custom Roles. See Custom Roles to learn more about the different roles and how to set up permissions.
Open the role details and in the Permission Category section:
- In Access Management > Access Risk Detection, provide Full Access if you want the user to be able to complete all tasks.
- In Core Administration > Organisation Management, provide Full Access if you want users to be able to update Access Risk Detection Configuration page.
- In User Management, make sure the user has at least View access. Without this minimum access tier, the dashboard will restrict visibility into these user profile details for any detected account that is not a primary administrator.