Skip to main content

Integrate with Zoom

Use JumpCloud SAML Single Sign On (SSO) to give your users convenient but secure access to all their web applications with a single set of credentials. Provision, update, and deprovision users in Zoom in real-time from JumpCloud using the SCIM integration.

Read this article to learn how to setup the Zoom integration.

Prerequisites

Important Considerations

  • SSO must be enabled before you can configure SCIM
  • You will need to create two separate application integrations:
    • SSO - ZoomJWT
    • SCIM - ZoomOAuth
  • If you would like to manage Zoom licensing, there are additional steps needed in both JumpCloud and Zoom's SSO configuration to add this functionality
  • For user provisioning, ensure the Provision User field on the Single Sign-On page is set appropriately:
    • JIT Provisioning - At Sign In
    • SCIM Provisioning - Prior to Sign In
  • Don't add a user group to multiple instances of a SCIM connector for the same application (i.e., multiple Slack SCIM connectors). If you do, users who are members of that user group will be deactivated in the application if one of the instances is unbound from the user group
  • If you delete an integrated Zoom application from your Applications list, the application is removed from JumpCloud, but any previously bound users remain active in Zoom. These users will be able log in to Zoom with the password they used prior to enablement of SSO to the Zoom application from your JumpCloud account
  • When you deactivate SCIM on your Zoom application, previously bound users remain active in Zoom and able to authenticate using SSO. No further updates will be made to user accounts via the SCIM integration
  • Newly provisioned users will receive an email about being provisioned with Zoom after attempting to log in to the connector for the first time
  • When you deprovision users, they’re removed from the Zoom user group, but their user account remains
  • If you remove a user from the JumpCloud user group(s) that are bound to Zoom, the user is deactivated in Zoom, but the account still exists in Zoom:
    • If you add the user back to the JumpCloud user group(s) bound to Zoom, the user is reactivated
    • If you delete a user who is still associated to Zoom, then the user is deleted from Zoom
  • The expiration date for the access token generated during JWT App creation in Zoom determines the length of the connection between Zoom and JumpCloud; an expired token will break the connection, and you will need to reconfigure the connector
    • The token is active for a 90 days
Important

Zoom doesn't provide alerts when a token is about to expire. The default expiration is 90 days so you should set a calendar reminder before the token expiration date.

  • You cannot share Client IDs and Secrets between connectors. Each connector must have its own ID and Secret

Attribute considerations

  • A default set of attributes are managed for users. See the Attribute Mappings section for more details
  • Zoom doesn’t support password synchronization
  • Role is always set to Member
  • Even though multiple phone numbers are accepted, only the first one passed is displayed in the Zoom UI. For example, if a user has a work phone and a work cell configured in JumpCloud, only the work phone is shown in the Zoom phone field

Creating a new JumpCloud Application Integration

    1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access> SSO Applications.
  2. Click + Add New Application.
  3. You can also enter the name of the application in the Search field and select it.
  4. You can either select an application from the available list or select Custom Application, and click Next.
  5. Select the required options from the Select Options page and click Next. The Enter General Info page is displayed.
  6. On the Enter General Info page, you can customize the display label, description and how the application displays:
    • Description - add a description that users will see in their user portal
    • User Portal Image - choose Logoor Color Indicator
    • Show in User Portal - select to ensure the app is visible in the user portal
  7. Optionally, expand the Advanced Settings section and customize the IdP URL:
    • Enter a custom value to replace the default application name in the SSO IdP URL endpoint ( https://sso.jumpcloud.com/saml2/{custom_value})
warning

The SSO IdP URL is not editable after the application is created. If you need to change this URL later, you must delete and recreate the connector.

  1. Click Save Application.
  2. Next, click:
    • Configure Application and go to the next section
    • Close to configure your new application at a later time
tip

Users are implicitly denied access to applications. See Authorize Users to an SSO Application.

note

Linking the Application to AI Gateway

  • The sections below walk through SSO configuration for this application. When that is complete, you can connect this application to JumpCloud AI Gateway so users can access its data from supported AI clients (for example, Cursor or ChatGPT).
  • Register the MCP server under Access > AI Gateway and link it to this application. The server appears under Servers in AI Gateway. When you open the application from Access > SSO Applications, the same server appears on the application's AI Gateway tab.
  • Not all applications support MCP. Confirm support with the application vendor or see Configure AI Gateway Integrations to learn more about supported integrations.

Configuring the SSO Integration

To navigate to your JumpCloud SSO connector

  1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access > SSO Applications.

  2. Create a new application or select it from the Configured Applications list.

  3. Select the SSO tab.

To configure JumpCloud

  1. Replace any instances of YOURDOMAIN or YOURCOMPANY with your Zoom values.
  2. Optionally, configure:
MFA Claims
note

The Authentication Methods References (AMR) is automatically included in the SAML assertion by default. No additional configuration is required to enable this.

Complete the MFA Claim Configuration to define how the authentication context is sent in the SAML assertion.

  1. Under Auth Context, choose one of the following options based on your SP's requirements:
    • Send a single value for all successful MFA factors - select if the Service Provider accepts a generic confirmation for any MFA login. Enter the single URL or URN they accept
    • Send specific factors - select this option to map individual JumpCloud MFA methods to distinct values. In the Factor Mapping table, add each MFA factor enabled in your organization and enter the corresponding value required by the Service Provider
    • Send single value and specific factors - select to send both a generic identifier and specific factor details in the assertion
tip

Refer to your Service Provider's documentation to determine the specific URN or URL values required (e.g., Salesforce Session Security Levels). The values entered in this configuration must exactly match what the Service Provider expects.

MFA FactorService ProviderNotes
---------
PasswordReference your Service Providers's documentation for the values they expect for each factor
TOTP
WebAuthN
Push NotificationJumpCloud Protect or other authenticator application
Duo Security
Device Trust
Device Trust + User VerificationJumpCloud Go (requires explicit configuration - see the next table)
API Key
External Identity Provider
MFA MethodMFA Value in AMR Claim
------
apikeyswk
duomfa
pwdpwd
totpotp
unk
wanhwk
pushmfa
uv
durthwk
durt_uvhwk
ext_idp

Learn more about MFA Claims.

Attributes

Configure User Attributes to be sent to the SP in assertions. User attributes are unique to each user. You can include attributes for standard user detail attributes or for custom attributes. For example, you can include standard attributes for users’ employee ID and department, or you can include a custom attribute for users’ application ID. Standard attributes are configured in the User Panel Details tab's User Information andEmployee Information sections.

Unlike user attributes, a Constant Attribute can be sent for every user in a specific group or application profile.

note

If required attributes are present, they are not editable.

  1. Under User Attributes, click add attribute:
    • Service Provider Attribute Name - enter the service provider’s name for the attribute
    • JumpCloud Attribute Name - select the corresponding attribute from the drop down list
  2. Repeat these steps for any desired user or custom attributes.
  3. Under Constant Attributes, click add attribute:
    • Service Provider Attribute Name - enter the service provider’s name for the attribute
    • Value - enter the corresponding attribute in JumpCloud
  4. Optionally, if groups are supported, select Include Group Attribute.

Learn More

  1. Optionally, to manage Zoom user licensing:
    • Click add attribute under User Attributes
    • Enter employeeType for both the Zoom and JumpCloud attribute names.
note

You can use any attribute, but the attribute used in JumpCloud must match the attribute used in Zoom. This will ensure that Zoom knows how to identify which attribute is being used for the user licensing type.

  1. Click Save.

Download the certificate

  1. If you closed the application, find it in the Configured Applications list and click anywhere in the row to reopen its configuration window.
  2. Click Actions > Download Certificate.
tip

The certificate.pem will download to your local Downloads folder.

To configure Zoom

  1. Sign in to the Zoom web portal.
  2. Navigate to Advanced > Single Sign-On, then click Enable Single Sign-On.
  3. Select the vanity URL you want to configure with an IdP.
note

If you have only one vanity URL, you will not see additional options. Learn about multiple vanity URLs.

  1. Enter the following:
    • Sign-in Page URL - copy and paste the JumpCloud IDP URL
    • Sign-out Page URL - enter https://console.jumpcloud.com/userconsole/ (this will take users back to the User Portal when they log out)
    • Identity provider certificate - copy the portion between -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- of the certificate downloaded in the previous section
    • Service Provider (SP) Entity ID - copy and paste the JumpCloud SP Entity ID
    • Issuer (IDP Entity ID) - copy and paste the JumpCloud IdP Entity ID
    • Binding - select HTTP-Redirect
    • Signature Hash Algorithm - select SHA-256
  2. Click Save Changes.
  3. Select the SAML Response Mapping tab.
  4. Click the Edit link and then Map to SAML Attribute for the following options:
    • Email address - enter email
    • Last name - enter lastname
    • First name - enter firstname
  5. Optionally, to manage Zoom user licensing:
    • Scroll down to the SAML Advanced Information Mapping section.
    • Click Add for the License Type attribute and enter the following:
      • SAML Attribute - enter employeeType (or the attribute(s) used in the previous section)
      • SAML Value - Licensed
      • Resulting Value - Licensed
  6. If additional attributes were added in JumpCloud, add the matching attributes.
  7. Select Save Changes.

Authorizing SSO Application Access

Users are implicitly denied access to SSO Applications. After you connect an application to JumpCloud, you need to authorize user access to that application. You can authorize user access from the Applications, Users List or User Groups page.

To authorize user access from the SSO Application’s page

    1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access > SSO Applications, then select the application to which you want to authorize user access.
  2. Select the User Groups tab. If you need to create a new group of users, see Get Started: User Groups.
  3. Select the check box next to the desired group of users to which you want to give access.
  4. Click Save.

To learn how to authorize user access from the Users or User Groups pages, see Authorize Users to an SSO Application.

Authorizing agent access

Agents are implicitly denied access to SSO applications. After you configure SCIM for a supported application, bind one or more agent groups on the application to grant agents access and start agent provisioning.

Agent access is managed through agent groups only. You cannot bind an individual agent directly to an application.

To authorize agent access from the SSO application page:

  1. In JumpCloud Admin Portal, go to Access > SSO Applications and select the application.
  2. Click the Agent Groups tab.
  3. Select the checkbox next to each agent group that should have access to the application.
  4. Click Save.

Agents in a bound agent group inherit access to the application. Removing an agent group removes access for the agents that inherited it through that group.

To authorize agent access from an agent group:

  1. In JumpCloud Admin Portal, go to Identity Management > Agent Groups and select the agent group you want to configure.
  2. Click the Applications tab.
  3. Select the application and click Save.
note

Only applications that support agent identities appear for assignment from an agent group. If an application does not support agents, it is not available on the Applications tab.

Validating SSO user authentication workflow(s)

Check your SP's documentation to ensure that both workflows are supported.

IdP-initiated user workflow

  • Access the JumpCloud User Console
  • Go to Applications and click an application tile to launch it
  • JumpCloud asserts the user's identity to the SP and is authenticated without the user having to log in to the application

SP-initiated user workflow

  • Go to the SP application login - generally, there is either a special link or an adaptive username field that detects the user is authenticated through SSO
note

This varies by SP.

  • Login redirects the user to JumpCloud where the user enters their JumpCloud credentials
  • After the user is logged in successfully, they are redirected back to the SP and automatically logged in
tip

See Additional User Experience Considerations when setting up JumpCloud SSO.

Using JIT Provisioning

Additional attributes are required to use JIT provisioning. JIT required attributes are prepopulated and are on by default to enable JIT provisioning. You can’t edit the JIT required service provider attributes. You can customize the JumpCloud attribute name and the constant value for JIT required attributes. Toggle off the attributes to opt out of sending the attributes in the SAML assertion.

To complete the provisioning process

  1. Authorize a user’s access to the application in JumpCloud.
  2. Have the user log in to the application using SSO. The SAML assertion passes from JumpCloud to the service provider, and gives the service provider the information it needs to create the user account.

Configuring the SCIM Integration

warning

Zoom is deprecating the JWT app type. If you currently have SCIM enabled with Zoom, you must deactivate only the SCIM connector and recreate it with the ZoomOAuth app. We are planning to reinstate IdM on the existing Zoom application connector at a later date. You will have two Zoom apps:, Zoom JWT for SSO and ZoomOAuth for SCIM. Do not delete the ZoomJWT application or deactivate SSO.

Important

Before starting, ensure:

  1. The JWT SSO connector is configured and enabled.
  2. The JWT IdM connector has been deactivated.
  3. You have an existing verified associated domain.
  4. You will not share Client IDs and Secrets between new and existing connectors.

To configure Zoom

  1. Sign in to Zoom App Marketplace.
  2. Navigate to Develop in the top right corner of the page and then select Build App.
  3. Select General App and click Create.
  4. In Select how the app is managed:
    • Select Admin-managed
    • Click Save (you must click this or it will revert back to User-managed)
  5. In App Credentials:
    • Copy the Client ID and Client Secret
warning

The Client ID and Secret (token) may only be shown once. Copy them to a secure location, like the JumpCloud Password Manager, for future reference.

  1. In Oauth Information:
    • OAuth Redirect URL - enter https://console.jumpcloud.com/api/v2/provision/zoomoauth/callback
    • OAuth Allow List - ensure it is https://console.jumpcloud.com/api/v2/provision/zoomoauth/callback
  2. Click Continue.
  3. On the Access, Surface, and Embed pages, click Continue.
  4. On the Scopes page:
    • Click + Add Scopes
    • Scroll down and expand SCIM2 and then Call Zoom SCIM2 API
    • Select Call Zoom SCIM2 API
    • click Done
  5. Click Continue.
  6. Click Add App Now and sign into Zoom.
  7. Click Allow.
note

If you receive a Pretty-print error in a new tab, close the tab and return to the configuration.

  1. Click the pencil icon next to the name of your new Zoom app.
  2. Type in the desired name for your new app and click anywhere outside of the field to save the new name.

To configure JumpCloud

  1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access > SSO Applications.
  2. Click + Add New Application.
  3. Type ZoomOAuth in the Search field and select it from the dropdown.
  4. Click Next.
  5. Enter the Bookmark URL.
Important

Any valid URL can be used, but if you have multiple Zoom applications, the URL must be unique.

  1. Deselect Show this application in User Portal.
  2. Click Save Application and then click Configure Application.
  3. Select the Provisioning tab.
  4. Click Configure.
  5. Paste the Client ID and Client Secret you generated in the previous section.
  6. Click Activate and sign into Zoom, or if already signed in, click Allow.
  7. You will be redirected back to JumpCloud.

To update your JumpCloud SCIM token

  1. After generating a new token in your SP, log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access > SSO Applications.
  2. Search for the application and click to open its configuration panel.
  3. Select the Provisioning tab.
  4. Expand the Configuration Settings section.
  5. In the Token Key field, paste your updated token.
note
  • This may also be called API Key, Client Secret or Bearer Token.
  • If present, you do not need to update the Client ID.
  1. Click Update.
warning

Clicking Save will not update your token. You must click Update.

  1. You will get a message saying your SCIM integration has been successfully verified.

Provisioning Agents with SCIM

JumpCloud provisions agents and agent groups to supported SCIM applications using the same SCIM connection you configured for users. You do not create a separate SCIM connection for agents.

  • When an agent group is bound to a supported application, JumpCloud automatically creates, updates, and deprovisions agent accounts in that application based on the agent lifecycle in JumpCloud.

    • Agent group bound to the application: Agents in the group are provisioned when SCIM is active
    • Agent attribute changes: The downstream agent account is updated
    • Agent is suspended: The downstream account is set to inactive (active: false)
    • Agent is re-activated: The downstream account is re-enabled (active: true)
    • Agent group is unbound, or agent is removed from the group: The downstream account is deprovisioned
  • Agents and users are provisioned independently. An agent is never created, updated, or deleted through the user provisioning path.

  • There is no separate setting to turn agent provisioning on. If the application supports agents and an agent group is bound, agents in that group are provisioned automatically.

Group Management and agent groups

The Enable management of User Groups and Group Membership in this application setting on the Provisioning tab controls group push for both user groups and agent groups:

  • When group management is enabled, user groups and agent groups (for applications that support agent groups) provision as SCIM groups.
  • When group management is disabled, neither user groups nor agent groups are pushed as SCIM groups.
  • Individual agent account provisioning is not controlled by the group management setting. Agents in a bound agent group are provisioned as accounts regardless of whether group push is enabled.
note
  • Agent credentials, secrets, and tokens are never sent in a SCIM payload.
  • To stop provisioning agents to an application, unbind the agent groups from the application or delete the agents in JumpCloud.

Attribute Mappings

The User Attributes/User Group Attributes table lists the Required and Optional Mappings that JumpCloud sends to the Service Provider. See Attribute Considerations for more information regarding attribute mapping considerations.

Learn about JumpCloud Properties and how they work with system users in our API.

Modifying Attributes

To add user attributes

Important

It's highly recommended you use all optional mappings. This creates a more complete user profile, enabling better automation and more accurate access management within the application.

  1. From your connector’s configuration page, select the Provisioning tab.

  2. Expand the User Attributes section and click Edit. The Edit Attribute Mappings table will open.

  3. Scroll to the bottom of the table and click +Add Attribute.

  4. Select one of the mapping types:

    • Direct Mapping (JSON Path) - send the value from a user attribute in JumpCloud directly to an attribute in the service provider
      • From the JumpCloud Attribute dropdown, select the desired attribute
        • If you choose “Custom User Attribute” you must type the name of the attribute exactly as it on the user details page. To see the dropdown again, you must delete the attribute and add a new attribute
      • From the SCIM Attribute dropdown, select the corresponding (destination) attribute
    • Expression - transform or combine multiple user attributes into a single, custom value before sending it to the service provider
      • Enter the expression in the JumpCloud Attribute field
      • From the SCIM Attribute dropdown, select the corresponding (destination) attribute
    • Constant - send a fixed, predefined value—like a specific company name —for every user to the service provider
      • This is a free text field with no validation, e.g., the attribute must match exactly, including case, to the corresponding attribute in the user record. Once the custom attribute is added, you must delete it and readd a new custom attribute to see the dropdown again.
  5. Repeat these steps for additional attributes.

  6. Click Preview Mappings to review the User Schema.

    • If you do not select a specific user from the Preview Filter dropdown, the schema will default to the first user.
  7. Click:

    • Save and Sync to initiate an immediate full sync of the updated attributes
    • Update to initiate the update during the next modification of the user group's record, like adding a space to the Description field

To add group attributes

  1. From your connector’s configuration page, select the Provisioning tab.
  2. If not already enabled, toggle on Enable management of User Groups and Group Membership in this application.
  3. Expand the User Group Attributes section and click Edit.
  4. Click +Add Attribute.
  5. Select one of the mapping types:
    • Direct Mapping (JSON Path) - send a dynamically pulled JumpCloud group value directly to an attribute in the SP. From the JumpCloud Attribute dropdown, select:
      • Custom User Group Attribute - the value will change to jcUserGroup.attributes.
        • Add a <value> (name of the group) at the end of the attribute (jcUserGroup.attributes.DevOps)
        • From the SCIM Attribute dropdown, select Custom User Group Attribute and enter the corresponding destination attribute
      • id - the SCIM Attribute will change to externalId
      • name - the SCIM Attribute will change to displayName
    • Expression - use EXPR expressions to allow for more complex mapping logic:
      • Enter the expression in the JumpCloud Attribute field
      • From the SCIM Attribute dropdown, select the corresponding (destination) attribute
    • Constant - enter a fixed, hardcoded value you want assigned to a group:
      • Enter the value in the Constant Value field
      • From the SCIM Attribute dropdown, select the corresponding (destination) custom group attribute
  6. Click Preview Mappings to review the Group Schema.
  7. If everything is mapping correctly, click:
    • Save and Sync to initiate an immediate full sync of the updated attributes
    • Update to initiate the update during the next modification of the user group's record, like adding a space to the Description field

To modify existing attributes

  1. From your connector’s configuration page, select the Provisioning tab.
  2. Expand the User Attributes/User Group Attributes section and click Edit.
  3. For the type of attribute you would like to modify:
    • Direct - select the new attribute from the dropdown(s)
    • Expression - click in the Expression field and make the desired edits. If necessary, select the new attribute from the SCIM Attribute dropdown
    • Custom - delete the existing values in either or both of the attribute fields and enter the new values
  4. Click Preview Mappings to review the updated User Schema.
  5. If the mappings look correct, click:
    • Save and Sync and then Continue to initiate an immediate full sync of the updated attributes
    • Update to initiate the update during the next modification of the user group's record, like adding a space to the Description field

Deleting attributes

  1. From your connector’s configuration page, select the Provisioning tab.

  2. In the User Attributes/User Group Attributes section, click Edit. The Optional Mappings table will open.

  3. Click Delete (Delete icon) to remove any optional attributes.

  4. Click:

    • Save and Sync and then Continue to initiate an immediate full sync of the updated attributes
    • Update to initiate the update during the next modification of the user group's record, like adding a space to the Description field
note

Attributes that were initially included and populated in the user record and then deleted at a later time will not be modified or removed from the user record.

Restoring the default attribute table

  1. From your connector’s configuration page, select the Provisioning tab.
  2. In the User Attributes/User Group Attributes section, click Edit. The Edit Attribute Mappings table will open.
  3. Scroll to the bottom of the table and select Restore Defaults.
  4. Click:
    • Save and Sync and then Continue to initiate an immediate full sync of the updated attributes
    • Update to initiate the update during the next modification of the user group's record, like adding a space to the Description field

JumpCloud EXPR Functions

SyntaxDescriptionParametersExamples
------------
nullOrEmpty(value)Checks if a piece of information is completely missing (null) or if it's just empty text (a blank space). If the information is a number or a list, it is considered not empty.value: The piece of user information you want to check (e.g., an ID or email address).- nullOrEmpty(providerUser.externalId) ? providerUser.externalId : jcUser.id - nullOrEmpty(jcUser.email) ? "unknown@example.com" : jcUser.email
notNullOrEmpty(value)Checks if the information actually exists and has content. For text, it must have at least one character. For a list, it must have at least one item.value: The user data you are checking to ensure it exists before you use it.notNullOrEmpty(jcUser.email) ? jcUser.email : providerUser.userName
toScimPhoneNumbers(phoneNumber)Turns a single JumpCloud phone number (like the digits and type) into the list format that SCIM needs. It sets the type as "work" and "primary." If there is no phone data, it returns an empty list.phoneNumber: A block of data that holds the phone number digits and, optionally, the type (e.g., "work" or "mobile").toScimPhoneNumbers(find(jcUser.phoneNumbers, .type == 'work') ?? first(jcUser.phoneNumbers))
toScimAddresses(address)Turns a single JumpCloud address (like street, city, state) into the list format that SCIM needs. It combines street lines and sets the address type as "work" and "primary." If there is no address data, it returns an empty list.address: A block of data containing all the parts of the address (street, city, state/region, zip/postal code, etc.).toScimAddresses(find(jcUser.addresses, .type == 'work') ?? first(jcUser.addresses))
toScimEmails(email)Takes a single email address and puts it into the list format that SCIM requires. This is useful when the destination system expects a list. The email is marked as "work" and "primary."email: The actual email address, provided as text.toScimEmails(jcUser.email)
toScimEntitlements(entitlement)Creates one entitlement record to be included in the SCIM list of entitlements. It uses the value, type, and display name you provide and marks it as primary. If you don't provide input, it returns an empty list.email: The actual email address, provided as text.toScimEntitlements(jcUser.entitlements)
setDefaults(m, defaults)Fills in any missing data in your main data block (m) using backup values from a separate data block (defaults). Important: If the same piece of information is in both blocks, the value from the defaults block is used. If your main data block (m) is missing, the function returns nothing.- m: The primary block of data you are starting with (e.g., a user's address). - defaults: The block of backup values used to fill in any missing parts of the primary block (m).setDefaults({ "region": "CA", "country": "US" }, { "region": "" })
isMemberOfAny(groups, nameOrIDs)Checks if a user is a member of any of the groups you list. It can check by group name or unique ID, ignoring upper/lower case in names. The result is always true or false.- groups: The list of all groups the user belongs to (usually jcGroups). - nameOrIDs: The name, unique ID, or a list of names/IDs of the specific groups you are looking for.- isMemberOfAny(jcGroups, "engineering_group") - isMemberOfAny(jcGroups, ["engineering_group", "sales_group"])
isMemberOfAll(groups, nameOrIDs)Checks if a user is a member of every single group you list. If the user is missing even one group, the answer is false. Matching works like isMemberOfAny.- groups: The list of all groups the user belongs to (usually jcGroups). - nameOrIDs: The name, unique ID, or a list of names/IDs of all the required groups.- isMemberOfAll(jcGroups, "engineering_group") - isMemberOfAll(jcGroups, ["engineering_group","sales_group"])
- getGroups(groups) - getGroups(groups, field) - getGroups(groups, fields, "string")Gathers a user's group information in different ways: you can get all details (name, ID, attributes), a list of just one specific detail from each group (e.g., only the name), or a list of several specific details. Adding the text "string" as the third parameter makes sure the final output is simple text.groups: The user's list of groups (jcGroups). field or fields (optional): The specific piece(s) of information you want to extract from each group (e.g., the group's name or a custom attribute like costCenter). "string" (optional third): Include this text if you need the result to be simple text strings.- getGroups(jcGroups) - getGroups(jcGroups,"name") - getGroups(jcGroups,"id") - getGroups(jcGroups,"name", "string") - getGroups(jcGroups, ["name", "roles"])
- getGroupAttr(groups, nameOrID, attrPath) - getGroupAttr(groups, nameOrID, attrPath, default)Looks up a specific piece of information (an "attribute") from a single group (which you find by its name or ID). If the group or the information is missing, it returns a backup value (default) if you provided one; otherwise, it returns blank text.groups: The user's list of groups (jcGroups). nameOrID: The name or unique ID of the group you want to search. attrPath: The "path" (using dots) to the exact information you want (e.g., role). default (optional): The backup value to use if the group or the information you asked for cannot be found.- getGroupAttr(jcGroups,"admin_group", "role") - getGroupAttr(jcGroups,"admin_group", "role", "user")
filterGroups(groups, attrPath, matchValue)Narrows down the list of groups to keep only the ones where a specific piece of information matches one of the values you provide. The check ignores upper/lower case. The result is a list of the matching groups and all their details.groups: The user's list of groups (jcGroups). attrPath: The specific piece of information (attribute) you want to check in each group (e.g., role). matchValue: A text value or a list of text values that the attribute must equal to be included in the result.- filterGroups(jcGroups, "role", "admin") - filterGroups(jcGroups, "role", ["admin", "user"])
- findFirstGroupAttr(groups, attrPath, priorityList) - findFirstGroupAttr(groups, attrPath, priorityList, default)Checks a list of groups, in the order you specify, and returns the first piece of non-empty information (an "attribute") it finds. This lets you prioritize data from certain groups. If the information is not found in any group, it returns the backup value (default) if you provided one; otherwise, it returns blank.groups: The user's list of groups (jcGroups). attrPath: The specific piece of information (attribute) you are trying to find. priorityList: A list of group names or IDs, listed in the exact order you want them checked. default (optional): The backup value to use if the required information cannot be found in any of the groups.- findFirstGroupAttr(jcGroups, "role",["admin_group","user_group" ]) - findFirstGroupAttr(jcGroups, "role",["admin_group","user_group"],"user")
toID("...") toID('...')This function is a special shortcut. Before your expression runs, JumpCloud automatically swaps the group name you put inside the parentheses for that group's permanent, unique ID (a sequence of numbers and letters). It is best to use this when you need to refer to a specific group in a way that won't break if someone renames the group later. For example: getGroupAttr(jcGroups, toID("Engineering"), "costCenter")."..." or '...': Group name between single or double quotes. The match is case sensitive.getGroupAttr(jcGroups, toID("Engineering"), "costCenter")

Zoom User Attributes

JumpCloud AttributeSCIM AttributeNotes
---------
Required Mappings
emailuserName
Optional Mappings
{{if .JCUser.addresses[work]}}{{.JCUser.addresses[type="work",primary="true"]}}{{else}}{{.JCUser.addresses[0]}}{{end}}addresses
{{if .JCUser.Displayname}}{{.JCUser.Displayname}}{{else}}{{if .JCUser.Lastname}}{{.JCUser.Firstname}} {{.JCUser.Lastname}}{{else}}{{.JCUser.Firstname}}{{end}}{{end}}displayName
{{if .JCUser.phoneNumbers[work]}}{{.JCUser.phoneNumbers[type="work",primary="true"]}}{{else}}{{.JCUser.phoneNumbers[0]}}{{end}}phoneNumbers
{{if .ProviderUser.Locale}}{{.ProviderUser.Locale}}{{else}}en-US{{end}}locale
{{if .ProviderUser.PreferredLanguage}}{{.ProviderUser.PreferredLanguage}}{{else}}en-US{{end}}preferredLanguage
{{if and .ProviderUser.ExternalID (ne .ProviderUser.ExternalID "")}}{{.ProviderUser.ExternalID}}{{else}}{{printf "%x" .JCUser.Id}}{{end}}externalId
companyEnterpriseUser.organization
costCenterEnterpriseUser.costCenter
departmentEnterpriseUser.department
emailemails[primary=true,type="work"].value
employeeIdentifierEnterpriseUser.employeeNumber
employeeTypeuserType
firstnamename.givenName
isAssignedToApp && !(jcUser.suspended == true)active
jobTitletitle
lastnamename.familyName

Zoom has a user schema extension which is optional not mandatory.

Zoom User Schema Extension

AttributeType
------
urn🇺🇸zoom:scim:schemas:extension:1.0:ZoomUserobject
-> loginType.workEmailboolean
-> loginType.ssoboolean

It also allows you to add emails to the existing user:

Zoom User Email Attributes

AttributeType
------
emails[].typestring
emails[].valuestring
emails[].primaryboolean

Agent Attributes

On the Provisioning tab, the Agent Attributes section lists the default mappings JumpCloud sends when an agent is provisioned to this application.

Default Agent Attribute Mappings

JumpCloud AttributeSCIM AttributeNotes
---------
Required Mappings
emailuserNameThe agent email is used as the username.
Optional Mappings
displaynamedisplayNameAgent display name.
notNullOrEmpty(providerAgent.externalId) ? providerAgent.externalId : jcAgent.idexternalIdExisting provider external ID, otherwise the JumpCloud agent ID.
isAssignedToApp && jcAgent.state == "ACTIVATED"activeActive only while the agent is bound to the application and in the ACTIVATED state.

To review or edit agent attribute mappings:

  1. Open the application and click the Provisioning tab.
  2. Expand Agent Attributes and click Edit.
  3. Review the Required Mappings and Optional Mappings tables.
  4. Click Preview mappings to review how an agent will appear in the target application.
  5. Click Save and Sync or Update.
  6. To revert to the defaults shown above, click Restore Defaults.

Agent Group Attributes

For applications that support agent groups, the Agent Group Attributes section lists the default mappings JumpCloud sends when an agent group is provisioned as a SCIM group.

Default Agent Group Attribute Mappings

JumpCloud AttributeSCIM AttributeNotes
---------
Required Mappings
namedisplayNameAgent group name.
Optional Mappings
notNullOrEmpty(providerAgentGroup.externalId) ? providerAgentGroup.externalId : jcAgentGroup.idexternalIdExisting provider external ID, otherwise the JumpCloud agent group ID.
Group membershipmembersAdding or removing an agent from the group updates membership in the downstream SCIM group.

To review or edit agent group attribute mappings:

  1. Open the application and click the Provisioning tab.
  2. Confirm Enable management of User Groups and Group Membership in this application is selected if you want agent groups pushed as SCIM groups.
  3. Expand Agent Group Attributes and click Edit.
  4. Review or change mappings, then click Preview Mappings.
  5. Click Save and Sync or Update.
note

Agent SCIM applies to the SCIM integration configured with the ZoomOAuth app (the Provisioning flow in this article). The ZoomJWT connector is for SSO only and does not support agent SCIM provisioning.

SCIM Directory Insights Events

SCIM Events Tables

The following Directory Insights (DI) events provide visibility into failures and detailed information about the user and group data and attributes being added or updated from HR or other external solutions to JumpCloud.

note

Customers with no package or the Device Management Package will need to add the Directory Insights à la carte option. Directory Insights is included in all other packages.

SCIM DI Integration Events

Event NameEvent Description
------
idm_integration_activateLogged when an IT admin attempts to activated new SCIM integration.
idm_integration_updateLogged when an IT admin attempts to update a configured and activated SCIM integration.
idm_integration_deleteLogged when an IT admin attempts to deactivate an activated SCIM integration.
idm_integration_authLogged when an IT admin authenticates/authorizes a SCIM integration.
idm_integration_reauthLogged when an IT admin attempts to change the credentials for an activated SCIM integration.

SCIM DI User Events

Event NameEvent Description
------
user_lookup_provisionLogged when JumpCloud encounters an issue when trying to lookup a user to determine if the user needs to be created or updated.
user_create_provisionLogged when JumpCloud tries to create a new user in service provider application.
user_update_provisionLogged when JumpCloud tries to update an existing user in service provider application.
user_deprovisionLogged when JumpCloud tries to change an existing user to inactive in the service provider application.
user_delete_provisionLogged when JumpCloud tries to delete an existing user in service provider application.

SCIM DI Attribute Events

Event NameEvent Description
------
attributemappings_addLogged when the attribute mappings of an application are added.
attributemappings_deleteLogged when the attribute mappings of an application are deleted.
attributemappings_updateLogged when the attribute mappings of an application are updated.
tip

You can filter these events for users or groups by using the Resource Type filter and then selecting user\_attribute\_mapping or user\_group\_attribute\_mapping.

SCIM DI Group Events

Important

These DI events will only be present if SCIM Groups are supported.

Event NameEvent Description
------
group_create_provisionLogged when JumpCloud tries to create a new group in service provider application.
group_update_provisionLogged when JumpCloud tries to update an existing group in service provider application.
group_delete_provisionLogged when JumpCloud tries to delete an existing group in service provider application.

Removing the Integration

Removing the Integration
warning

These are steps for removing the integration in JumpCloud. Consult your SP's documentation for any additional steps needed (like disabling "mandatory SSO login" settings) to remove the integration in the SP. Failure to remove the integration successfully for both the SP and JumpCloud may result in users, including admins, losing access to the application.

Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

To deactivate the SCIM Integration

    1. Log in to the JumpCloud Admin Portal.
  1. Go to Access > SSO Applications.

  2. Search for the application that you’d like to deactivate and click to open the configuration window.

  3. Click Actions > Deactivate IdM and then click confirm.

To deactivate the SSO Integration

  1. Log in to the JumpCloud Admin Portal.
  2. Go to Access > SSO Applications.
  3. Search for the application that you’d like to deactivate and click to open its details panel.
  4. Select the SSOtab.
  5. Scroll to the bottom of the configuration.
  6. Click Deactivate SSO.
  7. Click Save.
  8. If successful, you will receive a confirmation message.

To delete the application

  1. Log in to the JumpCloud Admin Portal.

  2. Go to Access > SSO Applications.

  3. Search for the application that you’d like to delete.

  4. Check the box next to the application to select it.

  5. Click Delete.

  6. Enter the number of the applications you are deleting

  7. Click Delete Application.

  8. If successful, you will see an application deletion confirmation notification.

Was this information helpful?