Choosing Multi-factor Authenticators in Conditional Access Policies

Admins can configure and enforce specific Multi-factor authenticators while configuring conditional access policies for any resource. The Admin can select from a number of available factors such as JumpCloud Go, TOTP, etc.
A screen showing available MFA methods in conditional access policies.

Here are some use cases for various multi-factor authenticators in relation to JumpCloud Go:

Note:

IIn the following use cases, it is assumed that the JumpCloud Go browser extension is present on the users’ devices when JumpCloud Go is enabled.

Choosing MFA in Conditional Access Policies

Admin-Configured MFA in CAP User MFA enrolment Status Resulting User Experience
JumpCloud Go Registered

JumpCloud Go grants access.

Note: User portal prevents selecting JumpCloud Go as the only factor

Other MFA only (non-JC Go) Registered

The administrator-configured MFA is enforced.

 

Note: If the device is registered with JumpCloud Go, users benefit from passwordless login but must still complete the required MFA factor.

JumpCloud Go + Other MFA Registered JumpCloud Go takes precedence over other authenticators to provide a seamless access experience.
JumpCloud Go + Other MFA Device Not Registered/MFA nor enrolled

User Portal: Users are prompted to register for JumpCloud Go. If they choose an alternate login method, they must enroll for other required MFA factors.

SSO/Admin Portal: Users are redirected to the User Portal with instructions to register their device. For other factors, they are prompted to complete enrollment as mandated by the policy.

JumpCloud Go Not Registered

Users will see an error message with instructions to register their device for JumpCloud Go before accessing the Admin Portal or SSO applications.

Note: CAP for User Portal prevents selecting JumpCloud Go as the only factor.

Note:

When JumpCloud Go is the primary factor for SSO applications, users may still be prompted to verify their identity via local device biometrics or security keys.

The JumpCloud tray app specifically supports JumpCloud Push, TOTP, and Cisco Duo. Since tray app password resets are governed by the User Portal CAP, administrators must include at least one of these factors in the policy.

FAQs: Multi-factor Authenticators in CAP

What if a user hasn’t enrolled for the required MFA?

If an Admin requires an MFA method, an unenrolled user accessing an app (governed by CAP) will be denied access until they visit the user portal to enroll. After enrollment, users can access their apps directly.

What if I only require MFA but don’t specify factors?

You must select at least one factor or select All Enabled.

Can I select multiple multi-factor authenticators?

Yes. Users can authenticate with any of the allowed multi-factor authenticators.

What if JumpCloud Go is selected as the MFA but not installed on the user’s device?

The JumpCloud Go extension must be installed for the user to complete authentication.

What happens if JumpCloud Go is registered by the user but the selected MFA is non-JumpCloud Go?

JumpCloud Go will provide credentials, and then the user will be prompted for the CAP configured MFA, ensuring admin settings are honored.

Back to Top

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case