ADI in the Enterprise Portal (Preview)

JumpCloud’s Enterprise Portal (EP) centralizes the control and management of Organizations from one dashboard. This enables admins to control all of their organizations efficiently, from a single, browser-based portal. EP Admins can view top-level data for all of their managed orgs at-a-glance. They can also securely launch full management sessions from the EP for any org they administer.

The Active Directory Integration (ADI) is JumpCloud's identity and access management directory integration that enables the syncing of users, groups, and passwords between JumpCloud and on or off-premise AD. ADI can be used to extend AD to the Cloud, minimize the number of resources managed by AD, and migrate away from AD.

As covered in Get Started: Active Directory Integration, ADI uses two agents; an Import Agent and a Sync Agent that can be installed in three (3) configurations, referred to as deployment configurations. For the EP, Manage users and passwords in AD, JumpCloud, or both is the preferred configuration.

Terminology:

  • Enterprise Portal: Portal where Enterprise Admins manage settings for multiple organizations under one Enterprise Configuration. Differs from the JumpCloud Admin Portal, which is for one organization
    • Enterprise (formerly Enterprise Configuration): Centralized hub for all the organizations' objects in the Enterprise Portal. Items can be created and shared for organizations in the Enterprise Portal from this hub
  • Organizations: A division of the enterprise (for example a region or a country) that maintains its own users, devices, and resources

Prerequisites:

Before getting started with ADI, JumpCloud recommends going through this list and ensuring all items have been completed before continuing.

You will need:

  • AD Domain Admin credentials
  • Access to all Domain Controllers (DCs) or member servers in your AD domain
  • Network access to the internet from DCs or member servers and ability to communicate outbound (only) to console.jumpcloud.com over HTTPS port 443
    • The JumpCloud AD Import and Sync Agent services use SSL/TLS for all communication. If no network connectivity exists to JumpCloud, ADI will fail to connect and won't work properly
  • Access to the Enterprise Configuration interface

Review Configure ADI: Manage users, groups and passwords in AD, JumpCloud, or both to understand the system requirements, considerations, prerequisites, and installation steps.

ADI Configuration

To create a new enterprise-level ADI Instance:

  1. Log in to your EP.
  2. Go to the Identity Management > Active Directories, and click ( + Add ADI Domain ).
    • If you have an existing ADI instance, click + Directory to add another instance
  3. Select Manage users and passwords in JumpCloud, AD or both and then click Next.
ADI Use cases window
  1. Enter the name of an Active Directory Domain that you want to integrate with your JumpCloud tenant. For example, “DC=example;DC=com” and then click Next.

Important:

The “DC” must be in capital letters. Each value must be separated with a semicolon (;) not a comma. There should be no spaces. The domain case must be the same as it is in the AD import configuration file.

  1. Review and update (if necessary) the JumpCloud Attribute values for userPrincipalName and sAMAccountName.

Warning:

You cannot change these two mappings after clicking Save.

  1. Click Save.
  2. If you want to use delegated authentication, select the checkbox for Delegated Password Validation. You can also download your ADI agents on this screen.
  3. Click Close (to finish setup later) or Configure ADI.

Note:

This option may be useful when importing existing users from AD to JumpCloud. It allows them to log in to the JumpCloud User Portal using their existing AD credentials for the first time.

  1. Follow the instructions in Configure ADI: Manage users, groups and passwords in AD, JumpCloud, or both to finish setting up your AD integration.

Sharing ADI Enterprise-Level Instances

  1. Log in to your EP.
  2. Go to the Identity Management > Active Directories and select your ADI instance.
  3. Select the Organizations tab and select any organization(s) you would like to share the instance with.
  4. Click Save.

Managing Access

To manage org access to enterprise-level ADI instances

  1. Log in to your EP.
  2. Go to the Identity Management > Active Directories and select your ADI instance.
  3. Click on the name of the instance:
    • Select the box next to the organizations where you want the ADI instance to be available.
    • Deselect the box next to the organizations where the ADI instance should no longer be available.
  4. Click Save.

To manage end-user access to enterprise-level ADI instances

  1. Log in to your EP.
  2. Go to the Identity Management > Active Directories and select your ADI instance.
  3. Go to the User Groups tab or Users tab:
    • Select the checkbox next to the user groups or users you want to give access to the ADI instance.
    • Deselect the checkbox next to the user groups or users you want to remove access from the ADI instance.
  4. Click Save.
Back to Top

List IconIn this Article

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case