User-Centric Policy Management: Security That Follows the User

Written by Dixitha Srinivasan on August 5, 2026

Connect

Device management has long followed a rigid, one-to-one model. One employee, one company laptop, with policy locked to the machine instead of the person using it. That model breaks down fast today. Shared workstations, roaming employees, and bring-your-own-device (BYOD) setups do not fit neatly into it. The result is fragmented security, personal devices that are over- or under-protected, and growing technical debt across platforms.

True Zero Trust requires security to follow the user, not the hardware. Devices change hands all the time. They get shared, reassigned, or replaced. The identity behind them does not change. Anchor policy to identity, and protection travels automatically wherever the user logs in next. That is the shift we have built JumpCloud around.

The Solution: A User-Centric Zero Trust Model

Today, we’re excited to announce the launch of User-Centric Policy Management in JumpCloud. Identity becomes the single source of truth, with policy dynamically extending outward to devices, networks, cloud apps, and data through the same real-time handshake, giving Windows and macOS fleets true cross-platform parity.

Key Features

  • Dynamic, identity-centric management. Policies follow the user across every managed platform whether company-owned or personal. Jumpcloud evaluates configurations, certificates, and compliance checks against the user’s role and directory identity. It does not tie them to the device serial number.
  • Cross-platform user scoping (Windows & macOS). Deploy identity-based policies across both Windows and macOS with ease. JumpCloud offers native support for Windows multi-user scenarios and macOS network user workflows.
  • A foundation for advanced enterprise profiles. Anchoring policy to the identity session lays the groundwork for consistent, enterprise-grade profiles going forward including SCEP (Simple Certificate Enrollment Protocol and automated VPN configuration deployed globally from a single platform.

Key Benefits

  • True Zero-Touch Network Access (ZTNA): Pair user-scoped SCEP and Wi-Fi policies with JumpCloud RADIUS, and you get seamless, certificate-based 802.1X Wi-Fi. Security settings deploy silently. End users never have to walk through manual credential prompts or network onboarding checklists.
  • Granular Shared Workstation Isolation: Rather than enforcing a blanket, device-level Wi-Fi or VPN configuration for every user on a machine, JumpCloud ties certificates directly to the verified logged-in user via User Principal Name (UPN) or Security Identifier (SID).
  • Contextual Access Tunnels: VPN profiles switch automatically based on the logged-in user’s organizational role. A contractor and a system administrator logging into the exact same terminal will inherit entirely different network access paths based on their identity-assigned profiles.
  • Proactive Attack Surface Reduction: Securing the active user session, rather than just the hardware, removes standing privilege risks. When a user logs out, their permissions leave with them. That keeps you audit-ready even under close review.
  • Frictionless End-User Experience: Employees get a personalized, secure environment the moment they log into any authorized machine. No manual setup. No waiting on tickets.

Get Started Today

Security should follow your people, not just your hardware. User-Centric Policy Management is available now to all JumpCloud customers.

New to JumpCloud? Sign up for a free trial now and see how an open directory platform secures your people and devices from a single control plane.

Dixitha Srinivasan

Dixitha is a Product Marketing Manager at JumpCloud with extensive experience in the IT and Security domain. Outside work, she enjoys cooking, writing, and exploring new places.

Continue Learning with our Newsletter