Skip to main content

Configure Jump Server Credentials Backup

Jump Server Backup keeps a daily encrypted copy of privileged credentials and resources on each Jump Server. If the JumpCloud cloud is unavailable, you can open that backup on the Jump Server host and work offline.

Backups stay on the Jump Server. They are not a substitute for normal Admin Portal access. Use them when you need local access without depending on the JumpCloud cloud.

note

This article is for administrators who manage Jump Server Backup keys in Privileged Access Management (PAM) Settings, and who may need to open a backup on a Jump Server host.

Prerequisites​

  • Your Admin Portal role must include the PAM Backup permission.
  • At least one Jump Server installed in your environment. Backups are written on the Jump Server host.
  • A secure company location to store the Backup Key. Treat the key as company property, not personal data.

Considerations​

  • Daily backups do not start until you generate a Backup Key. If you never generate a key, Jump Servers do not keep these encrypted backup files.
  • The Admin Portal shows a new Backup Key only once. After you leave the reveal screen, the key is masked and you cannot reveal it again.
  • Rotating the key does not rewrite older backup files. New backups use the new key. Older backups still need the previous key.

Understanding Jump Server Backup​

  1. In the JumpCloud Admin Portal, generate a Backup Key in Settings > Jump Server Backup.
  2. After the key exists, each Jump Server keeps a daily encrypted backup of privileged credentials and resources on that host.
  3. For offline access, open a backup file on the Jump Server host with the CLI and enter the Backup Key that matches that file.
ItemWhere it lives
Backup KeyGenerated in Admin Portal Settings. You must store a copy securely. The portal shows a new key only once.
Encrypted backup filesOn each Jump Server host (daily). The Admin Portal does not store the backup files.
Offline recoveryOn the Jump Server host, using the CLI and the matching Backup Key.
Important

Daily backups do not start until you generate a Backup Key. If you never generate a key, Jump Servers do not keep these encrypted backup files.

Opening Jump Server Backup​

  1. Log in to the JumpCloud Admin Portal.
  2. Go to Privileged Access Management > Settings.
  3. Open the Jump Server Backup tab.

If no key exists yet, you see the empty state Enable Jump Server Backup.

Enable Jump Server Backup empty state

Generating a Backup Key for the First Time​

  1. Click Generate Backup Key.
  2. In the confirmation dialog Enable Jump Server Backup?, confirm that you understand the key is shown only once, then click Generate Backup Key.
  3. When the key appears, copy it immediately and store it in your organization’s secure location.
warning

The Backup Key is shown only once. After you leave this screen, the Admin Portal masks the key and you cannot reveal it again. If you do not copy it now, you will not be able to decrypt backups that use this key.

On this screen you see:

FieldDescription
Backup KeyThe secret you use later to decrypt backup files on the Jump Server. Copy it now.
Key VersionAn identifier for this key generation. Use it when you track which key belongs to which backups.

Backup Key reveal screen

Viewing Active Backups​

When you return to Jump Server Backup, the portal shows that backups are active. The Backup Key and Key Version are masked. You cannot copy the previous key from this screen.

note

With an active key, each Jump Server keeps a daily encrypted backup of privileged credentials and resources on that host. Check the Jump Servers list Last Backup column to see when a Jump Server last completed a backup cycle.

Jump Server Backup active state

Generating a New Backup Key​

Use Generate New Key when your organization needs to rotate the key. This does not rewrite older backup files.

  1. On Jump Server Backup, click Generate New Key.
  2. Read the confirmation dialog carefully, then confirm.
  3. Copy the new key when it appears. Store it with your previous keys.
warning

New backups use the new key. Older backups still need the previous key. Save your current key before you generate a new one. Do not discard older keys if you still need older backup files.

Generate a new backup key confirmation

Backup Key Best Practices​

PracticeWhy
Copy the key during the one-time revealThe Admin Portal will not show that key again.
Store the key in a secure company location or sealed processThe key decrypts privileged credentials and resources offline.
Keep every previous key after a rotationOlder .bkp files still need the key that was active when they were created.
Limit who can use the Backup permissionOnly trusted admins should generate or rotate keys.
Test recovery in a maintenance windowConfirm a saved key opens a real backup file on a Jump Server before you need it in an outage.

Accessing a Backup Offline on the Jump Server​

Use these steps on the Jump Server Linux host when you need offline access.

Listing Available Commands​

On the Jump Server host, run:

docker exec vo-sync vaultone-sync

This shows the usage guide and available operations, including backup commands.

vaultone-sync CLI help

Listing Backup Files​

docker exec vo-sync vaultone-sync backup list

A list of backup files on that Jump Server is displayed.

Opening a Backup File​

Run:

docker exec -it vo-sync vaultone-sync backup open <FILENAME.bkp>

When prompted:

  1. Confirm you want to open the backup file (Y or N).
  2. Provide a reason for accessing the backup. This is logged for auditing.
  3. Enter the Backup Key that matches that file. The key is not shown as you type.

After authentication succeeds, browse the offline backup data on the Jump Server.

note

Enter the Backup Key that was active when that backup file was created. If you rotate keys later, the newest key opens only newer backups. Older files still need their original key.

tip

If a backup file does not change from one day to the next, no new records were added. The most recent backup file is still the latest snapshot.

Open a backup file with vaultone-sync

Was this information helpful?