Password Vault: Admins

JumpCloud Password Vault provides a unified, cloud-first solution to secure, and manage shared company credentials. With a scalable architecture, it eliminates identity and tool sprawl and reduces the risk of credential-based attacks across the organization.

Enabling Password Vault

To enable the password vault:

  1. Log in to JumpCloud Admin Portal.
  1. Go to Access > Vault.
  2. Click Enable Password Vault.
    A screenshot showing 'Enable Password Vault' screen in the JumpCloud Admin portal
  3. After this, Admins can assign vault access to other users and user groups.

Overview
A screenshot showing password vault overview.

This page gives an overview of some of the most important password vault statistics like:

  • Password Health
  • Count of Resources in tiles (websites, credentials, folders, users, etc.)
  • Most Connected Websites
  • Expiring and Expired credentials
  • Weak Passwords and Inactive Credentials

The View All button next to each tile takes you to the respective tab in Password Vault where all the resources are filtered. For example, clicking the View All button in the Weak Passwords tile takes you to the Credentials tab where all the weak passwords are filtered and displayed.

Users

From this page, Admins can enroll user groups into Password Vault. You can see the enrolled user groups on this page.

Enrolling a New User Group

To enroll a new user group:

  1. Click the Add button.
  2. Select the desired user group.
  3. Click Enroll User Groups.

For each user group, the following options are available.

  • Manage Permissions: Share and manage the permissions for shared resources (such as credentials and websites) for the user group.
  • Revoke Access: Revoke the access of user groups.

Websites

The website page allows administrators to configure and manage a non-SSO website application. The Admin can add multiple passwords to the same website and share with users and user groups. 

For every website, you can perform following actions:

  • Take Ownership: Gives you administrative control of the selected website(s). You will be able to connect, edit, duplicate, archive, and manage sharing for the website after taking ownership.
  • Refresh: Click this button to refresh the Websites page.
  • Export: Click this button to export the available websites’ data.

With the centralization of the password management system, administrators can assume ownership and manage any shared organizational website/credential. This page also allows the user to launch and autofill the website.

Note:

Personal credentials of a user cannot be accessed by the Admin.

To add a website:

  1. Log in to the JumpCloud Admin Portal.
  2. Go to Access > Password Vault > Websites.
  3. Click the Add button.
  4. Enter the following details:
    1. Website Details: Website name, URI, Tags, Folder, Additional Info.
    2. Linked Credentials: It allows you to attach existing credentials to a website or add a new password.
    3. Sharing Preferences: Manage the permissions for the users/ user groups to whom this credential is attached.
    4. Autofill parameters: set autofill parameters so that the vault can identify username and password fields that might be named differently and are not automatically recognized by the Vault autofill extension.


For example: Consider a website where the username and password field are mapped as User ID and Secret respectively. The browser extension may not identify these fields. As a result, the user may have to enter the credentials manually. To prevent this, password vault has a feature to set autofill parameters. Once you define the field selectors for the User ID and Secret, password vault will automatically fill the username and password in these fields.

Credentials

Manage and share your administrative passwords, keys, and credentials on this page.

Password Vault allows you to add as many credentials as needed to access websites, computers, devices, and other resources. Each credential securely stores access information, including different passwords or keys.

There are two main ways to create a credential in Password Vault:

Adding a Credential from the Credentials Menu

To add a credential from the Credentials tab:

  1. Log in to the JumpCloud Admin Portal.
  2. Go to Access > Password Vault > Credentials.
    A screenshot showing the 'Credentials' home page.
  3. Click + Add button and enter the following required credential information.
    A screenshot showing 'Credential Details' page in password vault.
    • Credential Type
    • Name
    • Username
    • Email
    • Password 
    • Expiration Date
  4. Select the required tags and folder from the dropdown.

Note:

The private credential toggle is turned on automatically if you select Default Private Folder in the Folder dropdown.

  1. Click Save to store the credential.
  2. Turn on the Private Credential toggle button if you want to save this credential in your default private folder.
  3. In Sharing Preferences, click Add to share the credential with other users. Also, assign them appropriate access by selecting the required checkboxes next to their names.
    A screenshot showing sharing preferences for credential in password vault.

Note:

Credentials created this way are not automatically associated with any asset. To link them to an asset later, go to the relevant menu (e.g., Websites, Servers).

Adding a Credential Directly from a Resource

To add a credential directly from a resource:

  1. Navigate to the menu for the resource you want to add a credential to (e.g., Websites).
  2. Next to the resource name, click Connect. A popup is displayed.
  3. Click the Link Credential button.
  4. From the available websites, select the required credential.
  5. Click Link Credential. The new credential is now associated with this asset.

Importing items from the existing JumpCloud Password Manager

To import items/credentials from the existing JumpCloud Password Manager:

  1. Open your existing JumpCloud Password Manager.
  2. Go to Settings > General and click Export as CSV option. Each .csv file corresponds to an item type/folder.
  3. Open the Password Vault.
  4. Go to Credentials.
  5. In the Import dropdown, click Import from external tools.
  6. Map the appropriate columns corresponding to Vault's credential fields.
  7. Select sharing preferences as required and click Import.

You can perform the following actions for each credential.

  • View Secret: You can view the details by clicking this option. You can also view secrets after clicking Take Ownership.
  • Click the three dots next to the View Secret button to view activity details, duplicate, archive, or delete the credential.

Folders

The folders page allows users to group multiple websites and credentials in folders and share it across to both users and user groups.
A screenshot showing the Folders page in password vault
You can create the following types of folders:

  • Personal folders: Used to store personal credentials. These can’t be accessed by the Organizational Admin and will be deleted once the user leaves the Org.
  • Shared folders: Used to share websites and credentials with Users and Groups with four different access permissions:

    Folder Access Permissions in Password Vault

    Folder Access Permission Description
    Connect Only allows users to auto-login on to the websites without exposing the credentials
    View New Access Permission, unavailable in Legacy Password Manager. Users can view the secret and autofill credentials on website forms.
    Edit Users can add, edit, delete credentials and websites present in the folders. Users can view the secret and autofill credentials on website forms.
    Manage Provides users with complete ownership of the websites/credential. Users can view, edit, share, and delete the websites/credentials and folder.

Personal Folders

The credentials saved in these folders are visible to you only. These can’t be accessed by others unless shared individually by the folder owner. When you click a folder, all the credentials in it are displayed along with their details.

Adding a New Personal Folder

To add a new personal folder:

  1. Log in to the JumpCloud admin portal.
  2. Go to Access > Password Vault > Folders.
  3. Click the Add button.
  4. Enter the following details:
    • Folder name and description
    • Folder type: Turn the Toggle on for Personal Folder.
  5. Click Next.
  6. Add Websites/ Credentials: Choose the resources to add this folder.
  7. After selecting all the credentials, click Create Folder.
    A new personal folder is created.

Shared Folders

Use Shared Folders to organize and securely distribute credentials to team members.

Note:
  • Credentials can be shared either individually or via a folder, but not both.
  • A credential or website can be assigned to only one folder at a time.
  • Credentials can be shared either individually or via a folder, but not both.
  • A credential or website can be assigned to only one folder at a time.

Adding a New Shared Folder

To add a new shared folder:

  1. Log in to the JumpCloud admin portal.
  2. Go to Access > Password Vault > Folders.
  3. Click the Add button.
  4. Enter the following details:
    1. Folder name and description
    2. By default, unless personal folders are toggled, the created folder will be a shared folder.
  5. Click Next.
  6. Add Websites/ Credentials: Choose the resources to add the shared folder. Click Next.
  7. Select users/ user groups with whom you want to share the contents of the folder.
    A screenshot showing 'Sharing Preferences' page in Shared Folder.
  8. Once done, click Create Folder.
    A new shared folder is created. Once shared, it appears in the folders tab for all the added users/ users groups.

You can perform the following actions on this page:

  • Search for websites and credentials.
  • Filter by credential types.
  • Refresh: Refresh the folder data.
  • Add: Add existing credentials to the folder.
  • Share: Share the folder content with more users/ user groups.
  • Edit: Edit the folder name and description.
  • Delete: Delete the folders.

Settings

Admins can see the following options on this page.
A screenshot showing settings in password vault.

  • Platform Access
    • Browser Extension Management: Enable password vault for capabilities such as autofill, username/password capture, etc. through the JumpCloud Go extension.
    • Mobile App Access: Users can access vault credentials and website apps for mobile application autofill via the JumpCloud Protect app.
  • Credential Management
    • Block expired credentials preventing the user to rotate password prior to accessing it.
    • Allow users to store personal credentials
    • Allow users to create personal credentials by default.
  • Notifications: Select the toggle button to inform Admins about security alerts through email notification.
  • Data Export: Turn on or off the toggle buttons to allow websites and credentials export in the user portal by users. Export via admin portal is always supported.

Audit Logs

You can find the audit logs in the Directory Insights section. You can see the details for various actions performed by users. See View the Directory Insights data Activity Log to learn more.

Back to Top

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case