You can use a JumpCloud policy called JumpCloud App Controls to hide the Windows App from devices in your organization. The Windows App lets users quickly navigate to and access their resources in the JumpCloud User Portal from the system tray app, so that they don't have to bookmark or remember the User Portal URL. The user’s JumpCloud password also provides access to the device, software, WiFi, and everything else an IT infrastructure has to offer. The user can also change the JumpCloud password without admin intervention using the Windows App.
The JumpCloud agent silently installs the Windows App automatically. You don't have to remember to manually install the Windows App on a user’s device. If you don't want to provide the user with access to the Windows App, you must manually hide it. Although you can hide the Windows App on a user’s device, we recommend that you leave it enabled. You can read about the reasons in Get Started: The JumpCloud Windows App.
In some cases, the Windows App can’t be used on a device and should be hidden. One of these cases is when user accounts are managed by Active Directory through AD Integration. These user accounts can’t use the Windows App to reset passwords.
Considerations
- To apply a policy to a device, it must be running on a supported OS. Before you assign a policy, follow the instructions in Get Started: Devices.
- To apply a policy to a group of devices, you must define device groups. Before you assign a policy, follow the instructions in Get Started: User Groups.
- Restart all devices where you applied the JumpCloud App Controls policy.
Creating the Policy
To create a JumpCloud App Controls policy for Windows devices, do the following:
Selecting the Policy Template
- Log in to the JumpCloud Admin portal.
If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.
- Go to Device Management > Policy Management. The Policy Management page is displayed.
- On the Policy Management page, click +Add New.
- Select Device Policy to assign the policy to devices and device groups. On the New Device Policy page:
- Select the Windows tab.
- Search and select the policy name and click Configure. The Details tab of the policy is displayed.
- On the Details tab, configure the required policy configuration settings.
- (Optional) In the Policy Name field, enter a new name for the policy or keep the default. Policy names must be unique.
- (Optional) In the Policy Notes field, enter details such as creation date of the policy, and information on testing and deployment of the policy.
Configuring the Policy
- Under Settings, select the Hide Windows App option.

Applying the Policy
- (Optional) Select the Policy Groups tab. Select one or more policy groups where you want to add this policy.
- Select the Device Groups tab. Select one or more device groups where you want to apply this policy to. For device groups with multiple OS member types, the policy only applies when a user logs into a supported Windows device that is enrolled in MDM.
- Or, select the Devices tab. Select one or more devices where you want to apply this policy.
- Click Create Policy. A success message is displayed indicating the completion of policy creation.
Viewing Policy Status
- Select the Status tab.
- To see the last Result Log for a device where this policy is applied, click view.
- If any errors occur, they're listed in Exit Status. If you have an Exit Status of 0, no errors occurred when applying or enforcing this policy.