Use Multi-Factor Authentication (MFA) with JumpCloud to secure access to your organization’s Admin Portal. Read this article to learn how to enable MFA for administrators.
Prerequisites:
- Obtain an application to generate TOTP tokens. See Set Up Authenticator App for User Account.
Considerations:
- An admin with the Administrator with Billing role can enable MFA for themself.
- An admin with the Administrator role cannot enable MFA for an admin with the Administrator with Billing role.
- The JumpCloud MFA requirement is not applicable when administrators use Sign in with Google for login. In such cases, the MFA configured on the Google account will apply.
Enabling MFA for the Administrator
JumpCloud now requires MFA for all admins. The non-editable Global MFA Requirement setting can be viewed in the Admin Portal under Settings > Security > Admin Accounts.
Viewing Enrollment Requirements and Enrollment Status
View at-a-glance information on the MFA health of all admins in your org in Settings > Administrators. The administrators list shows two relevant columns for MFA - MFA: Requirement and MFA: Enrollment.
For MFA: Requirement, possible statuses are:
- Required: Admin is required to use MFA
- Not Required: Admin is not required to use MFA
For MFA: Enrolled, possible statuses are:
- Enrolled: Admin has taken a step to enroll in MFA.
- Not Enrolled: Admin has not yet taken a step to enroll in MFA.
Monitoring Enrollment Status
The Admins Without MFA Required widget on the Admin Portal Home page shows how many Admins in your org do not have MFA required for Admin Portal login. Click the tile to view a list of the Admins without MFA required. From the list view, you can take the bulk action of enforcing MFA for some or all of the Admins listed.
Administrator roles determine who will be able to see and interact with this widget:
- Administrator with Billing - Can see the widget and can take action on the list
- Administrator Only, Help Desk, Manager, Read Only - Can see the widget but cannot take action on the list
- Billing Only - Cannot see the Home page
- Command Runner, Command Runner with Billing - Can see the Home page but cannot see this widget
See Admin Portal Roles for more information on roles.
To require MFA for Admins on Admin Portal login:
- From the Admin Portal Home page, click the Admins Without MFA Required tile.
- From the Admins Without MFA Required list, select the Admins you want to enforce MFA login for.
- Click Actions, then click Require MFA.
- On the confirmation modal, click Require MFA.
- The Admin will be required to log in with MFA on their next Admin Portal login.
You can enforce MFA for all admins by enabling the Global MFA Requirement under Settings > Security.
The Admins Without MFA Required widget can be removed from the Admin Portal Home page, if desired.
To remove the Admins Without MFA Required widget:
- From the Admin Portal, go to Home.
- Click Settings.
- Under Configure and Customize Widgets, toggle Admins Without MFA Required to off.
Resetting or Enrolling in MFA as an Admin
If you haven't enrolled in MFA and your organization requires it, or if you’re locked out of your JumpCloud Administrator account after enabling MFA, you can enroll or reset from the Admin Portal login flow.
When prompted for MFA, click the link at the bottom of the Verify Your Identity page to reset or enroll. You may also ask the designated admin for your company to reset it for you.
You will be sent an email to to begin the MFA enrollment or reset:
- Check your email inbox.
- Click Set Up MFA in the email message.
- Enter your Email address and Password.
- When you enter them, Set Up MFA becomes activated.
- Click Set Up MFA.
- Download an Authenticator App if you do not have one already or click I Have An App if you already do.
- Use the app to scan the QR code.
- When you enter the verification code, the Submit button becomes activated. Click Submit.
- A message will display stating that the MFA reset was successful.
- An email will be sent to you confirming that your TOTP MFA reset was successful.