Overview
This document applies to existing legacy JumpCloud Password Manager customers wanting to migrate to Password Vault.
Both products can work simultaneously together. Use the Go to Legacy Password Manager button to interchange between the two interfaces in the admin portal.
Prerequisites for Migration
- Password Vault must be enabled.
- Enable Cloud Backup in legacy JumpCloud Password Manager.
- Save the private key file on your computer. This key should be uploaded during the seamless migration process.
Background
Data Storage & Encryption
In the legacy password manager, sensitive data remained entirely decentralized. Our backend services had no visibility into user secrets.
- Locality: All items (passwords, secrets, and metadata) existed exclusively on user devices, local backups, and encrypted cloud backups.
- Zero-Knowledge Access: Cloud backups were not accessible by our backend. They are encrypted using a Private Key owned and managed solely by the Org Admin.
- Key Sovereignty: We do not store or have access to this private key; the responsibility for its safety rests with the org.
The Migration Process
The main aspects of the migration process to facilitate a seamless transition:
- Key Provisioning: The Admin uploads the private key to the migration service.
- Decryption: The service uses this key to decrypt the cloud backup files. This mirrors the standard recovery protocol used when an Admin restores a cloud backup for an individual user.
- Admins can choose to migrate specific user groups (ideal for testing) or the entire organization at once.
Duration
Depending on size and the queue, most migrations finish in minutes. For context, 11,000 credentials across 8 users were migrated in under 5 minutes. The process runs in the background, so you can stay productive while it completes the background process allowing admins to do other tasks during migration.
The Process
Data migrates instantly if a cloud backup exists. If not, the migration triggers as soon as the user opens their current Password Manager Desktop App.
Migration Visibility
Admins can track real-time status (Yet-to-be, Pending, In-Progress, Partially Migrated or Completed) and re-trigger attempts if needed. Migration Statuses Include:
| Migration Status | Definition | Recommended Action |
| Yet to Migrate | Migration has not been initiated for this group. | Select the group and click 'Start Migration'. |
| In Progress | Data is currently being transferred. | No action required; monitoring status. |
| Partially Migrated | Some users' data migration failed but was added to Password Vault (usually due to missing cloud backups). | Check the "Failed Users" list; ask those users to trigger a backup. |
| Failed | One or more users could not be migrated. | Click "Check Failed Users" for details; ask those users to trigger a backup. |
| Completed | Migration successful for all users in the group. | No further action required. |
Simultaneous Functioning of Legacy Password Manager and Password Vault
Both the legacy app and the new Vault can work simultaneously during the migration process allowing the users to utilize both the desktop app and Password Vault web app. There is no synchronization of these credentials between the products post migration.
Legacy Password Manager Deactivation
Once the organization is fully migrated, admins can deactivate the legacy password manager ceasing the function of all password manager desktop and browser extensions.
All the data within the legacy password manager desktop app will be erased post deactivation.
How to Migrate Data
Seamless Migration Using Cloud Backup
Admins can perform seamless migration using cloud backup by performing the following steps:
- Log in to the JumpCloud Admin Portal.
- Go to Access > Password Vault.
- Click Enable Password Vault.
- In the Overview tab, click the Migrate to Password Vault button under Migrate to Password Vault.
If Cloud backup is not enabled, you’ll be prompted to enable Cloud backups in the legacy JumpCloud Password Manager (Add a Learn More link for enabling cloud backups).
- Select which user groups to migrate. You can choose specific user groups or migrate all groups at once.
We recommend migrating specific groups first for testing to ensure passwords and sharing preferences are correctly retained. Once you have verified the results, proceed with migrating the remaining groups.
- Next, upload the Private Key file of the Legacy Password Manager to facilitate the migration and Click Start Migration to begin.
- While the migration is in progress, Admins can check the status in the Data migration tile.
Here are the different data migration statuses:- Yet to be migrated: These users weren’t selected for migration.
- In Progress: The cloud backup is being migrated to Password Vault.
- Completed: The data migration is complete.
- Failed: The migration process may fail but may likely be due to the lack of a cloud backup copy for the user. Please communicate with the users to open their password manager desktop app to automatically create a cloud backup copy. Users can manually trigger a cloud backup copy by going to Legacy Password Manager Desktop App > Settings > Backup Centre > Create a Backup.
Restarting Migration
You can re-trigger migration for any user group, including those where migration has already completed. This process captures the latest cloud backup, including any data added to the Desktop App since the previous attempt.
Check Failed Users
You can check Failed users and the appropriate reason by clicking on the Check Failed Users button. Please reach out to the users to create a Cloud Backup copy if one does not exist. End-users can Create a Cloud Backup by accessing: Legacy Password Manager > Settings > Backup Centre > Create a Backup.
Deactivating Legacy Password Manager
After the migration is complete, Admins can proceed to deactivate the legacy password manager.
Deactivating the legacy password manager will remove all your data and credentials from the password manager desktop app making it inaccessible. These can’t be restored. Make sure all data has been successfully migrated before deactivation.
Migrated Data in Password Vault
Folders and Access Permission post migration will be retained within Password Vault. A comparison of Access Permission level and its respective mapping post migration from Legacy Password Manager to Password Vault is summarized in the table below.
| Password Vault Access Permission | Legacy Password Manager Access Permission | Description |
| Connect | Folder Member | Only allows users to auto-login on to the websites without exposing the credentials |
| View | - | New Access Permission, unavailable in Legacy Password Manager. Users can view the secret and autofill credentials on website forms. |
| Edit | Item Manager | Users can add, edit, delete credentials and websites present in the folders. Users can view the secret and autofill credentials on website forms. |
| Manage | Folder Manager | Provides users with complete ownership of the websites/credential. Users can view, edit, share, and delete the websites/credentials and folder. |
Sharing Use-Cases
Sharing Individual Credentials/Websites
There are new sharing capabilities available in Password vault. Users can share individual credentials. You can also share credentials as part of websites as well. You can share credentials and resources through groups. User tags are filtered to easily sort credentials that are part of the folder and vault.
Credentials can be shared based as per 4 access permission levels: Connect, View Secret, View Detail and Manage.
| Access Permissions | Description |
| Manage | Provides full ownership of the credential to the end user. The user can edit, share, and delete the credential. |
| View Detail | Allows users to view the metadata of the credentials. This includes ID, created at, modified, etc. |
| View Secret | Allows users to view the credentials. |
| Connect | Allows users to auto-fill without exposing the secret. |
Websites can be shared as per 3 access permission levels: Manage, View Detail, and Connect.
| Access Permissions | Description |
| Manage | Provides full ownership of the website allowing the user to edit and delete the website. |
| View Detail | Allows users to view the metadata of the website. |
| Connect | Allows users to launch the website URL. |
Sharing Individual Credentials/Websites in Bulk
Admins can efficiently organize and secure access to credentials and websites by managing permissions at the user group level, while maintaining a clear overview of access rights.
To share multiple resources:
- Go to the Users tab.
- Next to a user group, click the Manage Permissions button.
- In the Add Resources popup, select the websites and credentials that you want to share with the user group. Also, select the permissions on the right.
- Manage: The user can manage, edit, delete the resource.
- View Detail: View more details such as ID, URI, Name, etc.
- View Password (Only for Credentials); View the password.
- Connect: Open the website and log in.
The selected permissions will determine the level of access that the users have for these resources. - Once done, click Save.
- Now you can see the selected resources and the respective assigned permissions for this user group.
To remove everyone’s access in a user group, click the three dots next to a user group and then click Revoke Access.
Add both the website and the linked credential to ensure that users in the group can successfully launch the website using that credential.
Manual Migration from Legacy Password Manager
Users can perform the following steps to manually import credentials from Legacy JumpCloud Password Manager to Password Vault:
Users can export their credentials in a CSV file from the Legacy Password Manager.
To import credentials from the existing JumpCloud Password Manager:
- Open your existing JumpCloud Password Manager.
- Go to Settings > General and click Export as CSV option. Each .csv file corresponds to an item type/folder.
- Open the Password Vault.
- Go to Credentials.
- Click Import
- Upload the CSV file containing credentials for each credential type. Alternatively, leverage the pre-loaded template by clicking Download Template and organize your credentials accordingly.
- Map the appropriate columns corresponding to Password Vault's credential fields.
- Select sharing preferences/shared folder as required and click Import.
Upon mapping selection of the “website URL” for a field, a check-box option is presented to “Create a single website for passwords with the same URL”. This option is selected by default.







