JumpCloud’s Access Risk Detection continuously monitors login activity across your organization and identifies logins that look suspicious. The following is a list of commonly asked questions about JumpCloud Access Risk Detection.
Access Risk Detection requires time to learn what constitutes normal behavior for each user. During the first 30 to 60 days, user profiles are actively forming, meaning routine variations in user habits may frequently be flagged as deviations.
The system automatically baselines existing users/admins using their last 60 days of data, while new users require a minimum of 50 successful events before risk scoring begins. Marking a false-positive risk as Safe trains the system on that event, continuously improving future detection accuracy.
If the initial alert volume is difficult to manage while profiles are maturing, go to the Detections tab and filter the list to display only Medium and Critical alerts.
Access Risk Detection identifies deviations from a user's established baseline, not objectively malicious behavior. A legitimate login will trigger an alert if it differs from a user's normal routine—such as an employee traveling internationally for the first time, authenticating from a new device, or working at an unusual hour.
When you investigate a flagged event and confirm it is legitimate, mark the detection as Safe on the Detections page. This trains the system to accept the new behavior and integrate it into the user's updated baseline profile.
No. Access Risk Detection only surfaces authentication events that cross the risk threshold. Logins that fall within a user's normal pattern are considered safe and are omitted from the Detections log to prevent alert fatigue and keep your workflow focused on anomalies.
If you need to audit a comprehensive, unfiltered log of all successful and failed login attempts across your organization, go to Insights > Directory Insights.
Detection and Resolution
The detection status changes to Resolved-Safe, and the alert is removed from the Unresolved queue. Over time, marking false positives as safe refines the user's behavioral baseline.
No. Confirming a risk records your assessment but does not trigger any automatic remediation. You will need to take separate action through the appropriate JumpCloud workflow — for example, forcing a password reset from the user's profile or suspending the user account.
Resolved detections remain visible in the Detections page with their resolution status and your comment. They cannot be reverted to the Unresolved status, but the historical record of the detection and how it was handled is preserved for 90 days.
Data and Integration
Yes. Since detections are tied to your event logs, data can be exported using the standard JumpCloud data export mechanisms aligned with your Directory Insights retention limits.