Password Vault: Admins
JumpCloud Password Vault provides a unified, cloud-first solution to secure, and manage shared company credentials. With a scalable architecture, it eliminates identity and tool sprawl and reduces the risk of credential-based attacks across the organization.
Enabling Password Vault
To enable Password Vault:
-
Log in to JumpCloud Admin Portal.
-
Go to Access > Password Vault.
-
Click Enable Password Vault.

-
After this, Admins can assign vault access to other users and user groups.
Overview
This page gives an overview of some of the most important Password Vault statistics like:
- Password Health
- Count of Resources in tiles (websites, credentials, folders, users, etc.)
- Most Connected Websites
- Expiring and Expired credentials
- Weak Passwords and Inactive Credentials
The View All button next to each tile takes you to the respective tab in Password Vault where all the resources are filtered. For example, clicking the View All button in the Weak Passwords tile takes you to the Credentials tab where all the weak passwords are filtered and displayed.
Users
From this page, Admins can enroll user groups into Password Vault. You can see the enrolled user groups on this page.

Enrolling a New User Group
To enroll a new user group:
- Click the Add button.
- Select the desired user group.
- Click Enroll User Groups.
For each user group, the following options are available.
- Manage Permissions: Share and manage the permissions for shared resources (such as credentials and websites) for the user group.
- Revoke Access: Revoke the access of user groups.
Websites
The website page allows administrators to configure and manage a non-SSO website application. The Admin can add multiple passwords to the same website and share with users and user groups.
For every website, you can perform following actions:
- Take Ownership: Gives you administrative control of the selected website(s). You will be able to connect, edit, duplicate, archive, and manage sharing for the website after taking ownership.
- Refresh: Click this button to refresh the Websites page.
- Export: Click this button to export the available websites’ data.
With the centralization of the password management system, administrators can assume ownership and manage any shared organizational website/credential. This page also allows the user to launch and autofill the website.
Personal credentials of a user cannot be accessed by the Admin.
To add a website:
- Log in to the JumpCloud Admin Portal.
- Go to Access > Password Vault > Websites.
- Click the Add button.
- Enter the following details:
- Website Details: Website name, Website URL, Tags, Folder, Additional Info.
- Linked Credentials: It allows you to attach existing credentials to a website or add a new password.
- Sharing Preferences: Manage the permissions for the users/ user groups to whom this credential is attached.
- Autofill parameters: set autofill parameters so that the vault can identify username and password fields that might be named differently and are not automatically recognized by the Vault autofill extension.
For example: Consider a website where the username and password field are mapped as User ID and Secret respectively. The browser extension may not identify these fields. As a result, the user may have to enter the credentials manually. To prevent this, Password Vault has a feature to set autofill parameters. Once you define the field selectors for the User ID and Secret, Password Vault will automatically fill the username and password in these fields.
Credentials
Manage and share your administrative passwords, keys, and credentials on this page.
Password Vault allows you to add as many credentials as needed to access websites, computers, devices, and other resources. Each credential securely stores access information, including different passwords or keys.
There are two main ways to create a credential in Password Vault:
Adding a Credential from the Credentials Menu
To add a credential from the Credentials tab:
- Log in to the JumpCloud Admin Portal.
- Go to Access > Password Vault > Credentials.
- Click the Add button and enter the following required credential information.
- Credential Type
- Name
- Username or Email
- Password
- Expiration Date
- Turn on the Personal credential toggle to save as a personal credential.
- Select the required Tags and Shared Folder from the dropdowns.
- Under Link Websites, select from the dropdown or add websites to link to this credential.
- In Sharing Preferences, click Add to share the credential with other users. Also, assign them appropriate access by selecting the required checkboxes next to their names.
- Click Create to store the credential.
Credentials created this way are not automatically associated with any asset. To link them to an asset later, go to the relevant menu (e.g., Websites, Servers).
Adding a Credential Directly from a Resource
To add a credential directly from a resource:
- Navigate to the menu for the resource you want to add a credential to (e.g., Websites).
- Next to the resource name, click Connect. A popup is displayed.
- Click the Link Credential button.
- From the available credentials, select the required credential.
- Click Link Credential. The new credential is now associated with this asset.
Importing items from the existing JumpCloud Password Manager
To import items/credentials from the existing JumpCloud Password Manager:
- Open your existing JumpCloud Password Manager.
- Go to Settings > General and click Export as CSV option. Each .csv file corresponds to an item type/folder.
- Open the Password Vault.
- Go to Credentials.
- In the Import dropdown, click Import from external tools.
- Map the appropriate columns corresponding to Vault's credential fields.
- Select sharing preferences as required and click Import.
You can perform the following actions for each credential.
- View Secret: You can view the details by clicking this option. You can also view secrets after clicking Take Ownership.
- Click the three dots next to the View Secret button to view activity details, duplicate, archive, or delete the credential.
Folders
The folders page allows users to group multiple websites and credentials in folders and share it across to both users and user groups.
You can create the following types of folders:
-
Personal folders: Used to store personal credentials. These can’t be accessed by the Organizational Admin and will be deleted once the user leaves the Org.
-
Shared folders: Used to share websites and credentials with Users and Groups with four different access permissions:
Folder Access Permissions in Password Vault
| Folder Access Permission | Description |
|---|---|
| Connect | Only allows users to auto-login on to the websites without exposing the credentials |
| View | New Access Permission, unavailable in Legacy Password Manager. Users can view the secret and autofill credentials on website forms. |
| Edit | Users can add, edit, delete credentials and websites present in the folders. Users can view the secret and autofill credentials on website forms. |
| Manage | Provides users with complete ownership of the websites/credential. Users can view, edit, share, and delete the websites/credentials and folder. |
Personal Folders
The credentials saved in these folders are visible to you only. These can’t be accessed by others unless shared individually by the folder owner. When you click a folder, all the credentials in it are displayed along with their details.
Adding a New Personal Folder
To add a new personal folder:
- Log in to the JumpCloud admin portal.
- Go to Access > Password Vault > Folders.
- Click the Create button.
- Enter the following details:
- Folder name and description
- Folder type: You can turn on the Personal Folder toggle if you want this folder to be personal. New folders are shared by default.

- Click Next.
- Add Websites/ Credentials: Choose the resources to add this folder.
- After selecting all the credentials, click Create.
A new personal folder is created.
Shared Folders
Use Shared Folders to organize and securely distribute credentials to team members.
- Credentials can be shared either individually or via a folder, but not both.
- A credential or website can be assigned to only one folder at a time.
Adding a New Shared Folder
To add a new shared folder:
- Log in to the JumpCloud admin portal.
- Go to Access > Password Vault > Folders.
- Click the Create button.
- Enter the following details:
- Folder name and description
- Leave the Personal Folder toggle off. New folders are shared by default.
- Click Next.
- Add Websites/ Credentials: Choose the resources to add the shared folder. Click Next.
- Select users/ user groups with whom you want to share the contents of the folder.

- Once done, click Create.
A new shared folder is created. Once shared, it appears in the folders tab for all the added users/ users groups.
You can perform the following actions on this page:
- Search for websites and credentials.
- Filter by credential types.
- Refresh: Refresh the folder data.
- Add: Add existing websites or credentials to the folder.
- Share: Share the folder content with more users/ user groups.
- Edit: Edit the folder name and description.
- Delete: Delete the folders.
Settings
Admins can see the following options on this page.

- Platform Access
- Browser Extension Management: Enable Password Vault capabilities such as autofill, username/password capture, etc. through the JumpCloud Go extension.
- Mobile App Access: Allow users to access Password Vault credentials and websites via the JumpCloud Protect mobile app.
- Credential Management
- Expired Credentials Must Be Blocked: Block expired credentials, requiring the user to rotate the password before accessing it.
- Allow Users to Store Personal Credentials
- Allow Users to Create Personal Credentials by Default
- Notifications
- Send Email Security Alerts to Administrator: Select the toggle button to inform Admins about security alerts through email notification.
- Data Export: Turn the Allow Users to Export Credentials and Allow Users to Export Websites toggles on or off to control whether users can export this data in the user portal. Export via admin portal is always supported.
Audit Logs
You can find the audit logs in the Directory Insights section. You can see the details for various actions performed by users. See View the Directory Insights data Activity Log to learn more.
Was this information helpful?