This page provides a comprehensive list of everything we’ve built so far in 2026.
Interested in previous release notes? See last year's feature releases: Release Notes 2025. Alternately, see our List of Bug Fix Reports or List of JumpCloud Agent Release Notes, updated weekly.
February
February 5th, 2026
SAML SSO MFA Configuration
Admins can now configure a SAML SSO integration to send the MFA Claim in the AuthnContext within the SAML assertion, providing verifiable proof of MFA. This change helps customers meet strict access requirements for high-security applications like Salesforce, PayPal, and Epic/Impravata while eliminating no access or the "double MFA" friction for end-users.
- MFA Configuration Section: New section in SAML SSO integrations featuring a read-only AMR option and a selectable AuthContext sub-section
- Flexible Mapping Modes: 3 options for how the MFA claim will be sent in the AuthnContext
- Custom Factor Mapping Table: A new mapping table for mappingJumpCloud-supported factors (such as Push or TOTP) to specific strings, URLs, or URNs required by the SP
Full API Support: Configuration for these claims can be doe via the API
See SSO using Custom SAML Application Connectors to learn more.
Asset Management: AI Search and AI Filtering Support
- JumpCloud AI Search now supports Asset Management data, letting you quickly find and generate reports on all of your assets.
- We've also added an AI-powered filtering widget within Asset Management to help filter your list of assets using natural language queries.
See Configure Asset Management and Get Started: JumpCloud AI Search to learn more.
JumpCloud Go
We have updated JumpCloud Go extension permissions for Vault users to improve password management. This update prevents your browser's native password manager from displaying password saving prompts and ensures that sensitive credentials remain private.
January
January 29th, 2026
Windows Users Can Now Preserve Credentials After Remote Password Changes
We’ve introduced a new password sync flow on Windows devices to preserve the Credential Manager and related application access after remote or off-device password resets.
- For the best experience, we recommend users reset their password directly in the JumpCloud Tray App on their device.
- If users reset their password off-device (for example in the User Portal or Admin Portal) they are prompted on their next login to sync their previous and current passwords. This preserves saved credentials and access to Windows applications.
- This change is being rolled out in phases and may not be immediately available in your organization.
See Manage Windows Password to learn more.
January 22nd, 2026
Advanced OIDC Configuration Settings
A new Advanced Settings section is available for OIDC SSO applications, giving IT admins granular control over session security and token architecture. This update enables per-app customization of token lifetimes, token formats (JWT vs. Opaque), and audience scoping, allowing customers to meet strict compliance mandates and complex integration requirements without relying on global system defaults.
- Granular Token Lifetimes: Admins can now manually set distinct expiration windows for ID, Access, and Refresh tokens within validated ranges (from 10 minutes up to 90 days).
- Access Token Strategy: A new toggle allows admins to choose between Opaque and JWT formats for access tokens to ensure compatibility with any resource server.
- Additional Audience Configuration: Support for up to 5 additional access token audiences to facilitate complex microservices integrations or to specify the target API to receive the access token as part of the audience claim.
See SSO with OIDC to learn more.
January 19th, 2026
NEW: Timed Access Requests are here!
Feature: Access Requests
We have now added timed access to our Access Requests feature. Using this, admins can configure workflows to allow users to request access for a specific duration (one day, 15 days, 30 days, and so on).
You can now replace permanent permissions with timed access to ensure users have the right level of permissions exactly when they need it—and never longer.
See Manage Approval Flows to learn more.
