Skip to main content

Admin Portal Roles

Admin Roles are part of the foundation of protecting your organization by restricting access to only the areas people need to perform their daily job duties. JumpCloud offers a variety of roles to help keep things organized and secure.

To set these roles, see Settings in the JumpCloud Admin Portal.

note
  • Role based permissions apply to administrator actions both in product, and the API key of each administrator.
  • When you apply roles with limited permissions, a banner is shown in the Admin Portal that explains the level of permissions the account has.

Administrator with Billing

warning

This role is considered a Super Admin. Carefully consider who you give this level of access.

Accounts with this role have all privileges and can:

  • Perform all User Management tasks: create, modify, and delete user and administrator accounts.
  • Perform all group management tasks: create, modify, and delete user and device groups.
  • Perform all device management tasks: create, modify, delete, and grant access to devices; configure and run commands; configure and run device configurations / policies; configure and manage MDM settings and policies.
  • Perform all user authentication tasks: configure, grant access to, and require authentication resources such as LDAP, RADIUS, SSO and SCIM applications.
  • Perform all directory integration tasks: configure and manage directory integrations, provision and deprovision users in integrated directories.
  • Perform all security management tasks: configure and require Multi-factor Authentication factors; configure Password Settings.
  • Perform all account management tasks: configure all of JumpCloud's settings.
  • Perform billing management tasks: update the account payment method. Only roles with billing privileges can manage payment methods for JumpCloud accounts. Learn about Billing roles.
  • Perform all administration tasks for the Multi-Tenant Portal: all previously mentioned administration tasks for organizations in a Multi-Tenant Portal.

Administrator

warning

Carefully consider who you give this level of access.

This role has all of the privileges of an Administrator With Billing except privileges to manage payments (Billing), administrators, or the Multi-Tenant Portal.

Manager

Accounts with this role can manage users, devices, and groups.

Command Runner With Billing

Accounts with this role can manage account payment methods.

Command Runner

Accounts with this role can only run commands they're given access to.

Help Desk

Accounts with this role can access and view JumpCloud resources, submit support requests, and manage users in the following ways:

  • Create and delete users
  • Reset account passwords
  • Unlock users
  • Set Admin/Sudo permissions on a user's device from the User > Devices tab

Billing Only

Accounts with this role can access the Account tab in the MTP, with Read Only permissions everywhere else. From the Account tab, Admins can review the Account Overview, review payment history, update mailing and billing information, and view the usage associated with the account.

Read Only

Accounts with this role have read-only permissions; they can access and view users and other JumpCloud resources, but can't perform any management tasks.

Asset Manager

Accounts with this role can only access Asset Management in the Admin Portal and the API.

Admin Portal Roles

The following table outlines role permission scope for new and legacy roles.

Admin Role
------------------------------
ScopeAdministrator with BillingAdministratorManagerCommand Runner with BillingCommand RunnerHelp DeskRead OnlyBilling OnlyAsset Manager
Administrators: - creating - editing - assigning roles - deletingEditRead OnlyRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Billing: Billing payment information, including: - adding - removing - managingEditNo AccessNo AccessEditNo AccessNo AccessNo AccessEditNo Access
Multi-Tenant Portal: - organization and administrator managementEditRead OnlyRead OnlyN/AN/ARead OnlyRead OnlyNo AccessNo Access
Organization & User Portal: - organization details - email configurations - User Portal session managementEditEditRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Authentication: - authentication policies - organization-level MFA configurationsEditEditRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Users: - creating - viewing - managing attributes - deleting - passwords - MFA requirements & enrollments - lockouts - direct assignments to resourcesEditEditEditNo AccessNo AccessEdit* *Read Only for direct assignments to resources Note: This does not grant access to view, retrieve, or export user passwords.Read OnlyNo AccessNo Access
Groups: - creating - viewing - deleting - configuring - managing attributes - membership & assignment of resources to groupsEditEditEditNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Devices: - installing agent - managing attributes - viewing - deleting - applying policies - MDM managementEditEditEditNo AccessNo Access*Read Only You can download and install both the .pkg and MDM mobile configuration. This does not create a new device record.Read OnlyNo AccessNo Access
Directory & App User Management: - directory integrations & application (SCIM Identity Management) - user exportsEditEditRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Notifications in the Admin Portal: - viewing - dismissingEditEditRead OnlyRead OnlyRead OnlyRead OnlyRead OnlyRead OnlyNo Access
Insights: Actions in Directory Insights and System Insights, including: - viewing - queryingEditEditEditNo AccessNo AccessEditEditNo AccessNo Access
Commands: - creating - viewing - scheduling - running - assigningEditEditEditRunning & Scheduling access to Commands for assigned CommandsRunning & Scheduling access to Commands for assigned CommandsRead OnlyRead OnlyNo AccessNo Access
Bulk User Imports: - bulk imports of users leveraging the JumpCloud job serviceEditEditEditNo AccessNo AccessEditRead OnlyNo AccessNo Access
SSO Applications: - configuring of SAML SSO for applicationsEditEditRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
RADIUS servers: - creating - editing - viewing - deletingEditEditRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Remote Assist: - launching remote sessions - viewing and controlling end-user devicesEditEditEditNo AccessNo AccessLaunch Remote Assist (if Remote Assist is enabled in Settings)No AccessNo AccessNo Access
AI & SaaS Management: - settings - reviewing applicationsEditEditEditNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Asset Management: - settings - viewing, editing, and creating assetsEditEditEditNo AccessNo AccessRead OnlyRead OnlyNo AccessEdit
JumpCloud AI Search: - settings - searching, queryingFull Access (Enable, Disable, and Search)Full Access (Enable, Disable, and Search)Search OnlyNo AccessNo AccessSearch OnlySearch OnlyNo AccessNo Access
note
  • **Case Portal Access and Permissions**: All JumpCloud Administrator roles are granted full access to the JumpCloud Case Portal. This ensures that every administrator within your organization can effectively manage support interactions and provide product feedback. With this access, administrators can:
  • Create new support cases.
  • View, search, and filter a complete history of current and past cases.
  • Submit Feature Requests directly to our product team.

Was this information helpful?