Skip to main content

Integrate with AWS IAM Identity Center

Use JumpCloud SAML Single Sign On (SSO) to give your users convenient but secure access to all their web applications with a single set of credentials. Automate and centralize AWS IAM Identity Center user and group management through the full lifecycle by configuring an SCIM integration between your JumpCloud account and AWS IAM Identity Center.

Read this article to learn how to configure the AWS IAM Identity Center Integration.

Prerequisites

  • A JumpCloud administrator account
  • JumpCloud SSO Package or higher or SSO add-on feature
  • AWS Admin account (AWS root user)
  • AWS organization

Important Considerations

  • Single sign-on for AWS IAM Identity Center is recommended, but not required, when creating an SCIM integration with AWS IAM Identity Center
  • SAML is the recommended method for managing secure user authentication into AWS IAM Identity Center
  • For the connector to work, usernames in AWS IAM Identity Center need to match email addresses in JumpCloud
  • If you deactivate SCIM integration on an AWS IAM Identity Center application connector, you will need to generate a new access token if you want to activate it again
  • If you delete an integrated AWS IAM Identity Center application from your Applications list, the application is removed from JumpCloud, but any previously bound users remain active in AWS IAM Identity Center. These users will be able to log in to AWS IAM Identity Center with the password they used prior to enablement of SSO to the AWS IAM Identity Center application from your JumpCloud account
  • When a user is deleted in JumpCloud, the user is deleted from AWS IAM Identity Center
  • Once the Identity Source is changed to “External Identity Provider” and SCIM Provisioning is enabled in AWS IAM Identity Center, you can no longer create or update users and groups in AWS IAM Identity Center:
    • To manage AWS IAM Identity Center users who were created before SCIM provisioning was enabled, you need to add them in JumpCloud and add them to a User Group that is associated with the AWS IAM Identity Center application connector
    • To manage AWS IAM Identity Center groups that were created before SCIM provisioning was enabled, in JumpCloud, you have to select the Enable management of User Groups and Group Membership in this application. Then, create user groups with the same name as your existing AWS IAM Identity Center groups, and add those groups to the AWS IAM Identity Center application connector
  • AWS IAM Identity Center is only capable of returning 50 groups from their ListGroups API
  • Group names in JumpCloud cannot have a ‘:’ character. Otherwise, they won't sync
  • The username in AWS IAM Identity Center must match the email address in JumpCloud. If users were manually created in AWS IAM Identity Center before JumpCloud was configured as the external identity source, the username must be updated to the email address specified for that user in JumpCloud. If the username is not a valid JumpCloud email, then the following will occur:
    • Jumpcloud won't be able to take over management of the user in AWS IAM Identity Center
    • The user won't be able to log in via SSO
    • The user encounters an invalid MFA credentials error

Attribute considerations

  • A default set of attributes are managed for users. See the Attribute Mappings section for more details
  • If the display name is updated in JumpCloud, AWS IAM Identity Center won't overwrite it
  • When you update a Group name in the JumpCloud administrator portal, it will update in AWS IAM Identity Center as well
  • When a new user is provisioned to AWS IAM Identity Center, the value of the displayName attribute is set to combine the firstName and lastName attributes. For example, the attribute displayName = firstName + lastName:
    • firstName = “John”
    • lastName = “Doe”
    • displayName = “John Doe”

Creating a new JumpCloud Application Integration

    1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access> SSO Applications.
  2. Click + Add New Application.
  3. You can also enter the name of the application in the Search field and select it.
  4. You can either select an application from the available list or select Custom Application, and click Next.
  5. Select the required options from the Select Options page and click Next. The Enter General Info page is displayed.
  6. On the Enter General Info page, you can customize the display label, description and how the application displays:
    • Description - add a description that users will see in their user portal
    • User Portal Image - choose Logoor Color Indicator
    • Show in User Portal - select to ensure the app is visible in the user portal
  7. Optionally, expand the Advanced Settings section and customize the IdP URL:
    • Enter a custom value to replace the default application name in the SSO IdP URL endpoint ( https://sso.jumpcloud.com/saml2/{custom_value})
warning

The SSO IdP URL is not editable after the application is created. If you need to change this URL later, you must delete and recreate the connector.

  1. Click Save Application.
  2. Next, click:
    • Configure Application and go to the next section
    • Close to configure your new application at a later time
tip

Users are implicitly denied access to applications. See Authorize Users to an SSO Application.

note

Linking the Application to AI Gateway

  • The sections below walk through SSO configuration for this application. When that is complete, you can connect this application to JumpCloud AI Gateway so users can access its data from supported AI clients (for example, Cursor or ChatGPT).
  • Register the MCP server under Access > AI Gateway and link it to this application. The server appears under Servers in AI Gateway. When you open the application from Access > SSO Applications, the same server appears on the application's AI Gateway tab.
  • Not all applications support MCP. Confirm support with the application vendor or see Configure AI Gateway Integrations to learn more about supported integrations.

Configuring the SSO Integration

To configure AWS IAM Identity Center 1

  1. Log in to the AWS IAM Identity Center management console.
  2. Under **Enable****IAM Identity Center,**choose Enable.
  3. If there is not an existing AWS organization, click Create AWS organization to create one.
  4. Under Recommended setup steps, select Choose your identity source.
  5. Next to Identity Source, click Change.
  6. Select External identity provider.
  7. In the Service provider metadata section, click download metadata file.
  8. Keep the AWS console open because you need to access it for To configure AWS IAM Identity Center 2.

To navigate to your JumpCloud SSO connector

  1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access > SSO Applications.

  2. Create a new application or select it from the Configured Applications list.

  3. Select the SSO tab.

To configure JumpCloud

  1. Under Configuration Settings, go to Service Provider Metadata, and click Choose a File to upload metadata.
  2. Browse to the location of the Service Provider Metadata downloaded from the previous section and click Open.
  3. Once this file is uploaded, all fields should populate automatically.
  4. Click Export Metadata under JumpCloud Metadata.
  5. Optionally, if you want to force SP Initiated Authentication, in the Login URL field, replace the value with your Login URL.
tip

This is the URL provided by Amazon to log directly into your company-specific AWS access portal.

  1. Optionally, configure:
MFA Claims
note

The Authentication Methods References (AMR) is automatically included in the SAML assertion by default. No additional configuration is required to enable this.

Complete the MFA Claim Configuration to define how the authentication context is sent in the SAML assertion.

  1. Under Auth Context, choose one of the following options based on your SP's requirements:
    • Send a single value for all successful MFA factors - select if the Service Provider accepts a generic confirmation for any MFA login. Enter the single URL or URN they accept
    • Send specific factors - select this option to map individual JumpCloud MFA methods to distinct values. In the Factor Mapping table, add each MFA factor enabled in your organization and enter the corresponding value required by the Service Provider
    • Send single value and specific factors - select to send both a generic identifier and specific factor details in the assertion
tip

Refer to your Service Provider's documentation to determine the specific URN or URL values required (e.g., Salesforce Session Security Levels). The values entered in this configuration must exactly match what the Service Provider expects.

MFA FactorService ProviderNotes
---------
PasswordReference your Service Providers's documentation for the values they expect for each factor
TOTP
WebAuthN
Push NotificationJumpCloud Protect or other authenticator application
Duo Security
Device Trust
Device Trust + User VerificationJumpCloud Go (requires explicit configuration - see the next table)
API Key
External Identity Provider
MFA MethodMFA Value in AMR Claim
------
apikeyswk
duomfa
pwdpwd
totpotp
unk
wanhwk
pushmfa
uv
durthwk
durt_uvhwk
ext_idp

Learn more about MFA Claims.

Attributes

Configure User Attributes to be sent to the SP in assertions. User attributes are unique to each user. You can include attributes for standard user detail attributes or for custom attributes. For example, you can include standard attributes for users’ employee ID and department, or you can include a custom attribute for users’ application ID. Standard attributes are configured in the User Panel Details tab's User Information andEmployee Information sections.

Unlike user attributes, a Constant Attribute can be sent for every user in a specific group or application profile.

note

If required attributes are present, they are not editable.

  1. Under User Attributes, click add attribute:
    • Service Provider Attribute Name - enter the service provider’s name for the attribute
    • JumpCloud Attribute Name - select the corresponding attribute from the drop down list
  2. Repeat these steps for any desired user or custom attributes.
  3. Under Constant Attributes, click add attribute:
    • Service Provider Attribute Name - enter the service provider’s name for the attribute
    • Value - enter the corresponding attribute in JumpCloud
  4. Optionally, if groups are supported, select Include Group Attribute.

Learn More

  1. Click Save.

To configure AWS IAM Identity Center 2

  1. Go back to the AWS IAM Identity Center management console.
  2. In the Identity provider metadata section, click Choose file, and upload the JumpCloud metadata file.
  3. Click Next: Review.
  4. In the text box, type ACCEPT to change your identity source.
  5. Click Change identity source.

Authorizing SSO Application Access

Users are implicitly denied access to SSO Applications. After you connect an application to JumpCloud, you need to authorize user access to that application. You can authorize user access from the Applications, Users List or User Groups page.

To authorize user access from the SSO Application’s page

    1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access > SSO Applications, then select the application to which you want to authorize user access.
  2. Select the User Groups tab. If you need to create a new group of users, see Get Started: User Groups.
  3. Select the check box next to the desired group of users to which you want to give access.
  4. Click Save.

To learn how to authorize user access from the Users or User Groups pages, see Authorize Users to an SSO Application.

Validating SSO user authentication workflow(s)

Check your SP's documentation to ensure that both workflows are supported.

IdP-initiated user workflow

  • Access the JumpCloud User Console
  • Go to Applications and click an application tile to launch it
  • JumpCloud asserts the user's identity to the SP and is authenticated without the user having to log in to the application

SP-initiated user workflow

  • Go to the SP application login - generally, there is either a special link or an adaptive username field that detects the user is authenticated through SSO
note

This varies by SP.

  • Login redirects the user to JumpCloud where the user enters their JumpCloud credentials
  • After the user is logged in successfully, they are redirected back to the SP and automatically logged in
tip

See Additional User Experience Considerations when setting up JumpCloud SSO.

Configuring the SCIM Integration

To navigate to your JumpCloud SCIM connector

  1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access > SSO Applications.

  2. Create a new application or select it from the Configured Applications list.

  3. Select the Provisioning tab.

To configure JumpCloud

  1. Click Configure, and keep the window available.
  2. In a new window, log in to the AWS administrator console.
  3. Go to All Services > Security, Identity & Compliance, and select AWS Single Sign-On.
  4. Under Recommended setup steps, select Choose your identity provider.
  5. In the Identity source section, select Enable automatic provisioning.
  6. Copy the SCIM Endpoint URL from the Inbound automatic provisioning modal.
  7. Go back to the AWS IAM Identity Center application connector in JumpCloud.
    • Click Enable management of User Groups and Group Membership in this application if you want to provision, manage, and sync groups.
    • *SP Base URL: Paste the SCIM Endpoint URL you copied from AWS.
  8. Go back to the AWS IAM Identity Center Inbound automatic provisioning modal. Click Show token, then copy the token. Important: When you click Show token, you have to keep the window open until you have copied and entered the token into JumpCloud. After you close the Inbound automatic provisioning modal, it doesn’t show you this information again.
  9. Go back to the AWS IAM Identity Center application connector in JumpCloud. *SP SPI Token: Paste the Access token you copied from AWS.
  10. Click Activate.

To configure Attribute Based Access Control (ABAC)

AWS IAM Identity Center supports the use of attributes to control access to your AWS resources across multiple AWS accounts. This authorization strategy is known as attribute-based access control (ABAC). Within the AWS IAM Identity Center console, you can define fine-grained permissions and policies based on attributes sent from JumpCloud. Attributes used for ABAC are called tags in AWS. Using user attributes as tags in AWS helps you simplify the process of creating and managing permissions in AWS and allows you to extend your zero trust security model to your AWS resources.

Configuring ABAC in AWS IAM Identity Center is done through the Attributes for access controls page in the AWS IAM Identity Center console. There are two ways to configure ABAC. You can use SCIM user attributes or SAML attributes.

Important: In scenarios where the same attributes are sent to AWS IAM Identity Center through SAML and SCIM, the SAML attributes values take precedence in access control decisions.

To enable ABAC in AWS IAM Identity Center

To use attributed based access control (ABAC), you need to enable the Attributes for access control feature in AWS IAM Identity Center console. For more information about how to do this, see Enable and configure attributes for access control

  1. Log in to the AWS IAM Identity Center console.
  2. Click Settings from the left hand navigation panel.
  3. On the Settings page, under Identity source, next to Attributes for access control, click Enable.

To configure ABAC Using SCIM User Attributes

You can select user attributes sent to AWS IAM Identity Center via the JumpCloud SCIM integration to be used as attributes to manage access (ABAC) to your AWS resources. Then, you create a permission set in AWS IAM Identity Center to manage access based on the attributes you passed from JumpCloud. For more information about which user attributes are passed from JumpCloud, see Attribute Mappings, below. For more information about configuring attributes for access controls, see Enable and configure attributes for access control.

  1. Log in to the AWS IAM Identity Center console.
  2. Click Settings from the left hand navigation panel.
  3. On Settings > Identity source, next to Attributes for access control, click View details.
  4. Enter a Key value.
    • Note: You can provide any name you want. Key represents the name you are giving to the attribute for use in policies and is case sensitive. You need to specify that exact name in the policies you author for access control. The Key must also be named exactly the same in your aws:PrincipalTag condition key (i.e., "ec2:ResourceTag/CostCenter": "${aws:PrincipalTag/CostCenter}")
  5. Select the Value.
  6. Click Save changes.

To configure ABAC using SAML Attributes

You can configure SAML attributes for AWS IAM Identity Center to manage access to your AWS resources. The attributes that you define in JumpCloud will be passed in a SAML assertion to AWS IAM Identity Center. You then create a permission set in AWS IAM Identity Center to manage access based on the attributes you passed from JumpCloud.

  1. Open the JumpCloud AWS Single Sign-On application that you installed as part of configuring SAML for JumpCloud. Go to Access > SSO Applications.
  2. Click the AWS Single Sign-On application, and then click the second tab, SSO.
  3. At the bottom of this tab you have User Attribute Mapping, click Add new attribute.
  4. To use one of the predefined JumpCloud Attribute values:
    1. In the Service Provide Attribute Name field, enter https://aws.amazon.com/SAML/Attributes/AccessControl:AttributeName replacing AttributeName with the name of the attribute you are expecting in AWS IAM Identity Center. For example, https://aws.amazon.com/SAML/Attributes/AccessControl:Region
    2. In the JumpCloud Attribute Name field, select user attributes from your JumpCloud directory. For example, addresses.region.
    3. Repeat steps 1-2 for each additional attribute you want to map.
    4. Click save.
  5. To use dynamic attributes from the user or group record:
    1. In the Service Provide Attribute Name field, enter https://aws.amazon.com/SAML/Attributes/AccessControl:AttributeName replacing AttributeName with the name of the attribute you are expecting in AWS IAM Identity Center. For example, https://aws.amazon.com/SAML/Attributes/AccessControl:CostCenter.
    2. In the JumpCloud Attribute Name field, select Custom User or Group Attribute.
    3. Enter a name for the attribute. For example, AWS-ABAC-Project.
    4. Repeat steps 1-3 for each additional attribute you want to map.
    5. Click save.
    6. Open the user or group record for which you to pass the value for the attribute you created.
    7. In the Users or Group Details tab, go to the Custom Attributes section and click add new custom attributes.
    8. Select string.
    9. For Attribute Name, enter the name of one of the custom attributes that’s listed on the AWS IAM Identity Center configuration. For example AWS-ABAC-Project.
    10. For Attribute Value, enter the value you want to send for the attribute.
    11. Repeat steps 1-5 for each additional attribute you want to map.
    12. Click save.

To use ABAC in Permission Policies

Once you have configured attributes for use with ABAC, you can create permission policies that use those attributes for controlling access to AWS resources, services, and actions.

To apply a permission policy from the AWS IAM Identity Center console:

  1. Log in to the AWS IAM Identity Center console.
  2. Navigate to AWS Accounts > Permission Sets.
  3. Select the permission to which you want to add a permission set.
  4. Click Edit Permissions in the Permissions Policy.
  5. Enter the json for the permission policy you want to add or update.

For example, denying certain actions by Project or Region:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": [
"iam:*",
"organizations:DescribeAccount",
"organizations:DescribeOrganization",
"organizations:DescribeOrganizationalUnit",
"organizations:DescribePolicy",
"organizations:ListChildren",
"organizations:ListParents",
"organizations:ListPoliciesForTarget",
"organizations:ListRoots",
"organizations:ListPolicies",
"organizations:ListTargetsForPolicy"
],
"Resource": "*",
"Condition": {
"StringEquals": {
"aws:PrincipalTag/Project": "Automation"
}
}
}
]
}
OR
{
"Sid": "DenyAccessByRegion",
"Effect": "Deny",
"NotAction": [
"cloudfront:*",
"iam:*"
],
"Resource": "*",
"Condition": {
"StringNotEquals": {
"aws:RequestedRegion": "${aws:PrincipalTag/Region}"
}
}
}

  1. Click Save Policy.
  2. *Optionally, select the accounts to which the permission has been applied, so the new or updated policy can be applied and click Reprovision. Otherwise, click Skip for now.
  3. If you don’t already have tags defined for your permission, click Add tags in the Tags section. Otherwise, click Edit Tags to add a new tag.
  4. Add all the attributes you will be using in your Permissions Policy.
    • For example, Project and Region.
    • *Optionally, enter a value for the Key.
      • Note: Key is case sensitive and must exactly match the attribute you defined in Attributes for access control interface in the AWS IAM Identity Center console and in the SAML attributes you pass from JumpCloud.
  5. Click Save changes.

To update the AWS Token

AWS Tokens are generated with a validity of one year. When your token is set to expire in 90 days or less, AWS sends you reminders in the IAM Identity Center console and over the AWS Health Dashboard. JumpCloud will not send you any notifications. Your SCIM access token should be rotated before it expires to continually secure automatic provisioning of user and group information.

Important

Ensure you have deactivated the SCIM integration in JumpCloud before starting this section.

  1. Log in to the IAM AWS administrator console and click Go to Settings.
  2. Go to Identity Source > Actions dropdown > Manage provisioning.
  3. In the Access Token section, click Generate Token.
  4. Click Show token and copy the token.
warning

The Client ID and Secret (token) may only be shown once. Copy them to a secure location, like the JumpCloud Password Manager, for future reference.

To update your JumpCloud SCIM token

  1. After generating a new token in your SP, log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access > SSO Applications.
  2. Search for the application and click to open its configuration panel.
  3. Select the Provisioning tab.
  4. Expand the Configuration Settings section.
  5. In the Token Key field, paste your updated token.
note
  • This may also be called API Key, Client Secret or Bearer Token.
  • If present, you do not need to update the Client ID.
  1. Click Update.
warning

Clicking Save will not update your token. You must click Update.

  1. You will get a message saying your SCIM integration has been successfully verified.

Attribute Mappings

The User Attributes/User Group Attributes table lists the Required and Optional Mappings that JumpCloud sends to the Service Provider. See Attribute Considerations for more information regarding attribute mapping considerations.

Learn about JumpCloud Properties and how they work with system users in our API.

Modifying Attributes

To add user attributes

Important

It's highly recommended you use all optional mappings. This creates a more complete user profile, enabling better automation and more accurate access management within the application.

  1. From your connector’s configuration page, select the Provisioning tab.

  2. Expand the User Attributes section and click Edit. The Edit Attribute Mappings table will open.

  3. Scroll to the bottom of the table and click +Add Attribute.

  4. Select one of the mapping types:

    • Direct Mapping (JSON Path) - send the value from a user attribute in JumpCloud directly to an attribute in the service provider
      • From the JumpCloud Attribute dropdown, select the desired attribute
        • If you choose “Custom User Attribute” you must type the name of the attribute exactly as it on the user details page. To see the dropdown again, you must delete the attribute and add a new attribute
      • From the SCIM Attribute dropdown, select the corresponding (destination) attribute
    • Expression - transform or combine multiple user attributes into a single, custom value before sending it to the service provider
      • Enter the expression in the JumpCloud Attribute field
      • From the SCIM Attribute dropdown, select the corresponding (destination) attribute
    • Constant - send a fixed, predefined value—like a specific company name —for every user to the service provider
      • This is a free text field with no validation, e.g., the attribute must match exactly, including case, to the corresponding attribute in the user record. Once the custom attribute is added, you must delete it and readd a new custom attribute to see the dropdown again.
  5. Repeat these steps for additional attributes.

  6. Click Preview Mappings to review the User Schema.

    • If you do not select a specific user from the Preview Filter dropdown, the schema will default to the first user.
  7. Click:

    • Save and Sync to initiate an immediate full sync of the updated attributes
    • Update to initiate the update during the next modification of the user group's record, like adding a space to the Description field

To add group attributes

  1. From your connector’s configuration page, select the Provisioning tab.
  2. If not already enabled, toggle on Enable management of User Groups and Group Membership in this application.
  3. Expand the User Group Attributes section and click Edit.
  4. Click +Add Attribute.
  5. Select one of the mapping types:
    • Direct Mapping (JSON Path) - send a dynamically pulled JumpCloud group value directly to an attribute in the SP. From the JumpCloud Attribute dropdown, select:
      • Custom User Group Attribute - the value will change to jcUserGroup.attributes.
        • Add a <value> (name of the group) at the end of the attribute (jcUserGroup.attributes.DevOps)
        • From the SCIM Attribute dropdown, select Custom User Group Attribute and enter the corresponding destination attribute
      • id - the SCIM Attribute will change to externalId
      • name - the SCIM Attribute will change to displayName
    • Expression - use EXPR expressions to allow for more complex mapping logic:
      • Enter the expression in the JumpCloud Attribute field
      • From the SCIM Attribute dropdown, select the corresponding (destination) attribute
    • Constant - enter a fixed, hardcoded value you want assigned to a group:
      • Enter the value in the Constant Value field
      • From the SCIM Attribute dropdown, select the corresponding (destination) custom group attribute
  6. Click Preview Mappings to review the Group Schema.
  7. If everything is mapping correctly, click:
    • Save and Sync to initiate an immediate full sync of the updated attributes
    • Update to initiate the update during the next modification of the user group's record, like adding a space to the Description field

To modify existing attributes

  1. From your connector’s configuration page, select the Provisioning tab.
  2. Expand the User Attributes/User Group Attributes section and click Edit.
  3. For the type of attribute you would like to modify:
    • Direct - select the new attribute from the dropdown(s)
    • Expression - click in the Expression field and make the desired edits. If necessary, select the new attribute from the SCIM Attribute dropdown
    • Custom - delete the existing values in either or both of the attribute fields and enter the new values
  4. Click Preview Mappings to review the updated User Schema.
  5. If the mappings look correct, click:
    • Save and Sync and then Continue to initiate an immediate full sync of the updated attributes
    • Update to initiate the update during the next modification of the user group's record, like adding a space to the Description field

Deleting attributes

  1. From your connector’s configuration page, select the Provisioning tab.

  2. In the User Attributes/User Group Attributes section, click Edit. The Optional Mappings table will open.

  3. Click Delete (Delete icon) to remove any optional attributes.

  4. Click:

    • Save and Sync and then Continue to initiate an immediate full sync of the updated attributes
    • Update to initiate the update during the next modification of the user group's record, like adding a space to the Description field
note

Attributes that were initially included and populated in the user record and then deleted at a later time will not be modified or removed from the user record.

Restoring the default attribute table

  1. From your connector’s configuration page, select the Provisioning tab.
  2. In the User Attributes/User Group Attributes section, click Edit. The Edit Attribute Mappings table will open.
  3. Scroll to the bottom of the table and select Restore Defaults.
  4. Click:
    • Save and Sync and then Continue to initiate an immediate full sync of the updated attributes
    • Update to initiate the update during the next modification of the user group's record, like adding a space to the Description field

JumpCloud EXPR Functions

SyntaxDescriptionParametersExamples
------------
nullOrEmpty(value)Checks if a piece of information is completely missing (null) or if it's just empty text (a blank space). If the information is a number or a list, it is considered not empty.value: The piece of user information you want to check (e.g., an ID or email address).- nullOrEmpty(providerUser.externalId) ? providerUser.externalId : jcUser.id - nullOrEmpty(jcUser.email) ? "unknown@example.com" : jcUser.email
notNullOrEmpty(value)Checks if the information actually exists and has content. For text, it must have at least one character. For a list, it must have at least one item.value: The user data you are checking to ensure it exists before you use it.notNullOrEmpty(jcUser.email) ? jcUser.email : providerUser.userName
toScimPhoneNumbers(phoneNumber)Turns a single JumpCloud phone number (like the digits and type) into the list format that SCIM needs. It sets the type as "work" and "primary." If there is no phone data, it returns an empty list.phoneNumber: A block of data that holds the phone number digits and, optionally, the type (e.g., "work" or "mobile").toScimPhoneNumbers(find(jcUser.phoneNumbers, .type == 'work') ?? first(jcUser.phoneNumbers))
toScimAddresses(address)Turns a single JumpCloud address (like street, city, state) into the list format that SCIM needs. It combines street lines and sets the address type as "work" and "primary." If there is no address data, it returns an empty list.address: A block of data containing all the parts of the address (street, city, state/region, zip/postal code, etc.).toScimAddresses(find(jcUser.addresses, .type == 'work') ?? first(jcUser.addresses))
toScimEmails(email)Takes a single email address and puts it into the list format that SCIM requires. This is useful when the destination system expects a list. The email is marked as "work" and "primary."email: The actual email address, provided as text.toScimEmails(jcUser.email)
toScimEntitlements(entitlement)Creates one entitlement record to be included in the SCIM list of entitlements. It uses the value, type, and display name you provide and marks it as primary. If you don't provide input, it returns an empty list.email: The actual email address, provided as text.toScimEntitlements(jcUser.entitlements)
setDefaults(m, defaults)Fills in any missing data in your main data block (m) using backup values from a separate data block (defaults). Important: If the same piece of information is in both blocks, the value from the defaults block is used. If your main data block (m) is missing, the function returns nothing.- m: The primary block of data you are starting with (e.g., a user's address). - defaults: The block of backup values used to fill in any missing parts of the primary block (m).setDefaults({ "region": "CA", "country": "US" }, { "region": "" })
isMemberOfAny(groups, nameOrIDs)Checks if a user is a member of any of the groups you list. It can check by group name or unique ID, ignoring upper/lower case in names. The result is always true or false.- groups: The list of all groups the user belongs to (usually jcGroups). - nameOrIDs: The name, unique ID, or a list of names/IDs of the specific groups you are looking for.- isMemberOfAny(jcGroups, "engineering_group") - isMemberOfAny(jcGroups, ["engineering_group", "sales_group"])
isMemberOfAll(groups, nameOrIDs)Checks if a user is a member of every single group you list. If the user is missing even one group, the answer is false. Matching works like isMemberOfAny.- groups: The list of all groups the user belongs to (usually jcGroups). - nameOrIDs: The name, unique ID, or a list of names/IDs of all the required groups.- isMemberOfAll(jcGroups, "engineering_group") - isMemberOfAll(jcGroups, ["engineering_group","sales_group"])
- getGroups(groups) - getGroups(groups, field) - getGroups(groups, fields, "string")Gathers a user's group information in different ways: you can get all details (name, ID, attributes), a list of just one specific detail from each group (e.g., only the name), or a list of several specific details. Adding the text "string" as the third parameter makes sure the final output is simple text.groups: The user's list of groups (jcGroups). field or fields (optional): The specific piece(s) of information you want to extract from each group (e.g., the group's name or a custom attribute like costCenter). "string" (optional third): Include this text if you need the result to be simple text strings.- getGroups(jcGroups) - getGroups(jcGroups,"name") - getGroups(jcGroups,"id") - getGroups(jcGroups,"name", "string") - getGroups(jcGroups, ["name", "roles"])
- getGroupAttr(groups, nameOrID, attrPath) - getGroupAttr(groups, nameOrID, attrPath, default)Looks up a specific piece of information (an "attribute") from a single group (which you find by its name or ID). If the group or the information is missing, it returns a backup value (default) if you provided one; otherwise, it returns blank text.groups: The user's list of groups (jcGroups). nameOrID: The name or unique ID of the group you want to search. attrPath: The "path" (using dots) to the exact information you want (e.g., role). default (optional): The backup value to use if the group or the information you asked for cannot be found.- getGroupAttr(jcGroups,"admin_group", "role") - getGroupAttr(jcGroups,"admin_group", "role", "user")
filterGroups(groups, attrPath, matchValue)Narrows down the list of groups to keep only the ones where a specific piece of information matches one of the values you provide. The check ignores upper/lower case. The result is a list of the matching groups and all their details.groups: The user's list of groups (jcGroups). attrPath: The specific piece of information (attribute) you want to check in each group (e.g., role). matchValue: A text value or a list of text values that the attribute must equal to be included in the result.- filterGroups(jcGroups, "role", "admin") - filterGroups(jcGroups, "role", ["admin", "user"])
- findFirstGroupAttr(groups, attrPath, priorityList) - findFirstGroupAttr(groups, attrPath, priorityList, default)Checks a list of groups, in the order you specify, and returns the first piece of non-empty information (an "attribute") it finds. This lets you prioritize data from certain groups. If the information is not found in any group, it returns the backup value (default) if you provided one; otherwise, it returns blank.groups: The user's list of groups (jcGroups). attrPath: The specific piece of information (attribute) you are trying to find. priorityList: A list of group names or IDs, listed in the exact order you want them checked. default (optional): The backup value to use if the required information cannot be found in any of the groups.- findFirstGroupAttr(jcGroups, "role",["admin_group","user_group" ]) - findFirstGroupAttr(jcGroups, "role",["admin_group","user_group"],"user")
toID("...") toID('...')This function is a special shortcut. Before your expression runs, JumpCloud automatically swaps the group name you put inside the parentheses for that group's permanent, unique ID (a sequence of numbers and letters). It is best to use this when you need to refer to a specific group in a way that won't break if someone renames the group later. For example: getGroupAttr(jcGroups, toID("Engineering"), "costCenter")."..." or '...': Group name between single or double quotes. The match is case sensitive.getGroupAttr(jcGroups, toID("Engineering"), "costCenter")

AWS IAM Identity Center User Attributes

JumpCloud AttributeSCIM AttributeNotes
---------
Required Mappings
emailuserName
firstnamename.givenName
lastnamename.familyName
toScimEmails(jcUser.email)emails
Optional Mappings
company$enterpriseUser.organization
costCenter$enterpriseUser.costCenter
department$enterpriseUser.department
employeeIdentifier$enterpriseUser.employeeNumber
employeeTypeuserType
isAssignedToApp && !(jcUser.suspended == true)active
jobTitletitle
notNullOrEmpty(jcUser.lastname) ? jcUser.firstname + ' ' + jcUser.lastname : jcUser.firstnamedisplayName
notNullOrEmpty(providerUser.externalId) ? providerUser.externalId : jcUser.idexternalId
notNullOrEmpty(providerUser.locale) ? providerUser.locale : 'en-US'locale
notNullOrEmpty(providerUser.preferredLanguage) ? providerUser.preferredLanguage : 'en-US'preferredLanguage
toScimAddresses(find(jcUser.addresses, .type == 'work') ?? first(jcUser.addresses))addresses
toScimPhoneNumbers(find(jcUser.phoneNumbers, .type == 'work') ?? first(jcUser.phoneNumbers))phoneNumbers

Group Attributes

JumpCloud AttributeSCIM AttributeNotes
---------
Required Mappings
namedisplayName
Optional Mappings
notNullOrEmpty(providerUserGroup.externalId) ? providerUserGroup.externalId : jcUserGroup.idexternalId
Group Management Considerations
Enabling Group Management

You must toggle on the Enable management of User Groups and Group Membership in this application option to manage groups and group membership in the application from JumpCloud.

Provisioning and Syncing Groups
  • JumpCloud takes over management of existing groups in the application when the user group name in JumpCloud matches the name of the group in the application
  • All user groups associated with the application in JumpCloud are synced. Syncing occurs when:
    • A membership or group change event occurs
    • You click Save and Sync after editing group attributes
  • If a user group is disassociated from the application in JumpCloud, syncing immediately stops and the group is left as-is in the application. All members of that user group are deactivated in the application unless they are associated with another active application group that is managed from JumpCloud
Deleting Groups
  • Managed groups deleted in JumpCloud are deleted in the application
  • All members of the deleted group are deactivated in the application, unless they are associated with another active application group that is managed from JumpCloud
Disabling Group Management
  • Disable group and group membership management by toggling off the Enable management of User Groups and Group Membership in this application option
  • The managed groups and group membership are left as-is in the application
  • JumpCloud stops sending group membership information for the user, but the user’s identity will continue to be managed from JumpCloud

Removing the Integration

Removing the Integration
warning

These are steps for removing the integration in JumpCloud. Consult your SP's documentation for any additional steps needed (like disabling "mandatory SSO login" settings) to remove the integration in the SP. Failure to remove the integration successfully for both the SP and JumpCloud may result in users, including admins, losing access to the application.

Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

To deactivate the SCIM Integration

    1. Log in to the JumpCloud Admin Portal.
  1. Go to Access > SSO Applications.

  2. Search for the application that you’d like to deactivate and click to open the configuration window.

  3. Click Actions > Deactivate IdM and then click confirm.

To deactivate the SSO Integration

  1. Log in to the JumpCloud Admin Portal.
  2. Go to Access > SSO Applications.
  3. Search for the application that you’d like to deactivate and click to open its details panel.
  4. Select the SSOtab.
  5. Scroll to the bottom of the configuration.
  6. Click Deactivate SSO.
  7. Click Save.
  8. If successful, you will receive a confirmation message.

To delete the application

  1. Log in to the JumpCloud Admin Portal.

  2. Go to Access > SSO Applications.

  3. Search for the application that you’d like to delete.

  4. Check the box next to the application to select it.

  5. Click Delete.

  6. Enter the number of the applications you are deleting

  7. Click Delete Application.

  8. If successful, you will see an application deletion confirmation notification.

Was this information helpful?