Manage Admins in the Enterprise Portal (Preview)
You can manage Enterprise Portal Admin accounts in each of your managed organizations within the JumpCloud Enterprise Portal. After you add a user and assign them an Admin role, you can view their details and perform a variety of other actions like requiring Multi-Factor Authentication (MFA), suspending/restoring accounts, and resetting passwords.
Terminology:
- Global Configuration: The primary organization. This is where you manage the settings for all organizations.
- Organizations: These are the managed sub-organizations.
Considerations:
- All Admins in your Enterprise Portal have access to all of the managed orgs in that Enterprise Portal.
- The Enterprise Portal supports granular permissions; you can restrict access to specific orgs per Enterprise Portal Admin account.
- Admins added to an org's Enterprise Portal are automatically given access to orgs created in the Enterprise Portal.
- When creating a new Admin, API access will be disabled by default.
- Only Super Admins (Admins with Billing or equivalent) can enable this. See Manage Administrator Roles and Access in the Enterprise Portal to learn more.
Adding an Admin
To add an Admin to your Enterprise Portal:
- Log in to your Enterprise Portal.
- Click on the Users tab.
- Under the Users tab, click the (+) New button in the top left corner.
- Select which Global Organization the new user should have access to, then click Add Users.
- The Admin Portal for the selected org launches in a new tab and brings you to the New User Details page.
- Fill out the information for each tab at the top of the New User page; Details, User Groups, Devices, and Directories, then click save user.
- Go back to the Enterprise Portal and Click the Users tab.
- Find the user you just added and click the Actions dropdown menu.
- Select Assign Administrator Access.
- Under Permissions, click the Role dropdown menu and select which role you want to assign the Admin.
- See Custom Admin Roles and Manage Administrator Roles and Access in the Enterprise Portal to learn more.
- Select Enable API access to allow the Admin to generate their own key.
- MFA is required for an Enterprise Portal Admin account, the Admin will be required to provide a TOTP token with their account credentials on their next login.
- In the Organization Access field, select the orgs you want to give your Admin access to.
- Click Save. You can now view details for this Admin account on the Administrators tab.
Viewing Details for Your Enterprise Portal Admins
To view details for Enterprise Portal Admins:
- Log in to the Enterprise Portal.
- Select the Administrators tab.
The following details are shown for admin accounts:
- Name - The Admin’s first and last name.
- Email - The Admin’s account email address.
- Role - The Admin's role/permission level.
- Organizations - The orgs your Admin can access.
- Status - The Admin’s account status; either active, pending, or suspended.
- API Key Access - If the Admin has access to generate and use an API key or not. Hover over the status to see what it means.
- Security: MFA Required - Admin is required to use MFA; status is either Required or Not Required
Editing Admins
To edit an Admin:
- Log in to the Enterprise Portal.
- Click the Administrators tab.
- Click on the Admin’s Name in the list.
- On the Details tab, modify the Admin's information:
- First Name - The Admin's first name.
- Last Name - The Admin's first name.
- Administrator Email Address*- The Admin's email address. This field is required.
- If you want to give the admin API access, select the checkbox next to Enable API access. If it's enabled and the Admin has generated a key, you'll see the first four characters of the Admin’s API key, and the date it was created as well. See JumpCloud API’s to learn more.
- Under Role, select the roles you want to assign to the Admin. See Custom Admin Roles and Manage Administrator Roles and Access in the Enterprise Portal to learn more.
You can assign up to 5 custom roles to an Admin. If Administrator with Billing role is assigned to an Admin, no other custom roles can be assigned.
- In the Organization Access field, select the orgs you want to give your Admin access to.
- Under Account Settings, you can see the status of the account (Active, Suspended)
- You can also Remove Administrator Access. This will remove their access to all organizations they have access to.
- Click Save.
Requiring MFA for Admins
MFA is mandatory for all Admins to sign in and you can’t disable it for any of the individual organizations.
Suspending and Restoring Admin Accounts in the Enterprise Portal
Before suspending an Admin account, see Suspend and Reactivate User Accounts to learn more.
To suspend an Admin account:
- Log in to the Enterprise Portal.
- Click the Users tab.
- Find or search for the Admin in the list.
- Click the Actions dropdown menu and click Suspend Now.
This immediately removes the Admin's access to the Enterprise Portal while maintaining their date and configuration records.
- Confirm that you want to suspend the selected account, then click Suspend.
- Click Save. The account appears as suspended in the Admins list.
To restore a suspended Admin account:
- Log in to the Enterprise Portal.
- Click the Users tab.
- Click an Admin from the list.
- This will launch the Admin Portal for that Admin.
- Under the Admin's name, click the Suspended dropdown menu, and click Activate. You can either schedule the activation, or click Activate Now > Activate User.
- Click Save. The account appears as Active in the Admins list.
Was this information helpful?