Skip to main content

Custom Admin Roles

JumpCloud uses roles to define access control and assign specific permissions to users, both within the Admin Portal, and across systems and resources (like users, groups, policies, and devices). This enables granular control, allowing Admins to tailor roles based on specific responsibilities and requirements. You can create custom Admin roles with specific view and edit access.

note

This feature is available for direct organizations only. In the Multi-tenant portal, it is available for all the managed organizations. It is not available on the MTP homepage. We are working on making it available.

Prerequisite:

  • Super Admin (Admin with Billing or equivalent) role is required for creating custom Admin roles.

Creating a Custom Role

To create a custom role:

    1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Settings > Administrators. All Admins are listed here.
  2. Go to the Custom Roles tab.
  3. Click +Add Custom Role.
    JumpCloud Settings page showing the Administrators section with the Custom Roles tab highlighted.
  4. Enter a Custom Role Name and Description (optional).
  5. Click Choose Default Role as Template, and select an option from the drop-down menu. For the selected role, the permissions appear.
    The Create Custom Role configuration panel showing fields for role name, description, and a template selector.
  6. Edit the permissions as required and click Save.
note

Only an **Admin with Billing** can edit the permissions.

You’ll see a success message stating that a custom role has been created.
Currently, we support a maximum of 20 custom roles. The Admin can assign a custom role to an existing or newly created Admin.

Custom Admin Roles Permission Categories

Admin with Billing role (Super Admin) can allow specific combinations of granular permissions in permission categories to the admins. Here is a table that describes the permission categories and the respective permissions:

Access Management

These permissions govern advanced security and authentication settings within the Admin portal.

Permission CategorySub-categoriesPermission Type
Access ManagementConditional Access Policies and IP ListsFull AccessViewNo Access
Multi Factor AuthenticationFull AccessViewNo Access
Radius AuthenticationFull AccessViewNo Access
Password ManagerFull AccessViewNo Access
JumpCloud Protect Push Notifications for User VerificationFull AccessN/ANo Access
Access Risk DetectionFull AccessViewNo Access
Search APIN/AViewNo Access

Application Management

Allow Admins to manage applications including user management integrations.

Permission CategorySub-categoriesPermission Type
Application ManagementApplicationsCreateUpdateDeleteView
Permission CategorySub-categoriesPermission Category
Application ManagementSearch APIN/AViewNo Access
note

For **Application Management**, the super admin can give CRUD and view permissions to the admins. Enable the **Full Access** toggle button to provide all permissions at once.

Associations

Create and manage associations between resources.

Permission CategorySub-categoriesPermission Type
AssociationsAssociationsFull AccessViewN/A
note

In a small number of scenarios, users with full-access to **Associations** category may encounter denials. We are working on resolving this.

Command & Automation

Manage and execute remote commands on systems. Additionally, Admins can create and manage reusable command templates.

Permission CategorySub-categoriesPermission Type
Command & AutomationCommandsFull AccessViewNo Access
Command Templates
Run CommandCheckbox Selection

Core Administration

Manage core administration tasks including notification channels and service accounts.

Permission CategorySub-categoriesPermission Type
Core AdministrationAdministrator ManagementFull AccessViewNo Access
Notification ChannelsFull AccessViewNo Access
Support AccessFull AccessViewNo Access
Role ManagementFull AccessViewNo Access
Organization ManagementFull AccessN/AFull Access
PKI CA ManagementFull AccessViewNo Access
PKI certificate ManagementFull AccessViewNo Access
Billing ManagementFull AccessN/ANo Access
Subscription InformationN/AViewNo Access
Service AccountsFull AccessViewNo Access

Device Management

Manage devices, volume purchase program, and remote assist permissions.

Permission CategorySub-categoriesPermission Type
Device ManagementMobile Device ManagementFull AccessViewNo Access
Volume Purchase ProgramFull AccessViewNo Access
Remote AssistFull AccessN/ANo Access
Remote Assist SessionsFull AccessN/ANo Access
DevicesFull AccessViewNo Access
Device SupportCheckbox Selection

Directory Integration Management

Create and manage directories and directory integrations.

Permission CategorySub-categoriesPermission Type
Directory Integration ManagementDirectory ManagementFull AccessViewNo Access

Groups Management

Create and manage user, device, and policy groups.

Permission CategorySub-categoriesPermission Type
Groups ManagementGroup ManagementFull AccessViewNo Access

Monitoring & Analytics

Manage monitoring and analytics tools.

Permission CategorySub-categoriesPermission Type
Monitoring & AnalyticsDirectory InsightsN/AViewNo Access
ReportsFull AccessViewNo Access
Search APIN/AViewNo Access
System InsightsN/AViewNo Access
AI SearchFull AccessViewNo Access
Health Monitoring RulesFull AccessViewNo Access
Health Monitoring AlertsFull AccessViewNo Access
Add-ons InformationN/AViewNo Access

SaaS and Asset Management

Manage SaaS applications. Also, track and manage organizational IT assets.

Permission CategorySub-categoriesPermission Type
SaaS and Asset ManagementSaaS ApplicationsFull accessViewNo Access
Asset Management

User Management

Manage users and set various user settings.

Permission CategorySub-categoriesPermission Type
User ManagementUser ManagementCreateUpdateDeleteView
Unlock User AccountsCheckbox Selection
Set password for UsersCheckbox Selection
Expire User PasswordCheckbox Selection
Activate / Suspend UsersCheckbox Selection
Manage User MFACheckbox Selection
Send Activation or Password Reset MailCheckbox Selection
note

For **User Management**, the super admin can give CRUD and view permissions to the admins. Enable the **Full Access** toggle button to provide all permissions at once.

Editing and Updating a Custom Role

To edit and update a custom role:

  1. From the JumpCloud Admin Portal, go to Settings> Administrators.
  2. Go to the Custom Roles tab.
  3. Click the Role Name that you want to edit the details for.
  4. Make changes and click Save.

Deleting a Custom Role

To delete a custom role:

  1. From the JumpCloud Admin Portal, go to Settings> Administrators. Go to the Custom Roles tab.
    A screenshot showing the list of custom admin roles on JumpCloud Admin portal
  2. Click Delete next to the role you want to delete. A pop-up will appear.
  3. Select an alternate role for the respective users who have been assigned the custom role. Then click Delete.
note

If a custom role hasn’t been assigned to any users, it can be deleted directly.

Was this information helpful?