Secure AI with JumpCloud

JumpCloud gives IT admins several ways to secure how employees use AI and SaaS applications. SSO Applications control who can sign in to applications with JumpCloud credentials. AI & SaaS Management discovers AI and SaaS usage and helps you restrict unapproved apps. AI Gateway secures the connection between AI clients and enterprise MCP servers.

These features secure different stages of the AI and SaaS lifecycle. Use this article to choose the right tool, understand how they fit together, and find detailed setup guides for each area.

Tip:

For more information about product features that use AI, such as AI Assistant or AI Search, see Get Started: AI-Powered Features to learn more.

Understanding AI Security Features

Goal Feature Access layer Reason
Let users sign in to enterprise apps with JumpCloud credentials SSO Applications User sign-in and app access SSO controls application sign-in and user group access.
Discover which AI and SaaS apps employees use, track usage, and warn or block unapproved apps AI & SaaS Management App discovery and usage governance Connectors and discovery methods collect license and usage data directly from applications, the browser, or devices.
Secure AI client access to enterprise application data through MCP servers AI Gateway MCP connections The gateway operates at the MCP layer. It authenticates and routes tool calls between the AI client and configured MCP servers.
Audit AI tool calls against connected MCP servers AI Gateway (Activity Log) MCP activity audit Tool call activity is published as Directory Insights events.

Using SSO Applications

SSO Applications let you connect enterprise applications to JumpCloud using SSO (and optionally SCIM or Just-In-Time provisioning). Users are implicitly denied access until you authorize a user group.

How admins use SSO Applications:

  • Add and configure an application under Access > SSO Applications
  • Bind user groups to control who can access the app
  • Export metadata and complete configuration in the service provider

When you add an MCP server in AI Gateway, the App dropdown lists SSO Applications already configured in your org. An app in that list does not mean it natively supports MCP. Verify with the application vendor before configuring it as an MCP server.

AI & SaaS Management also integrates with existing JumpCloud SSO apps. When you enable AI & SaaS Management, existing SSO apps are added automatically as approved apps.

Using AI & SaaS Management

AI & SaaS Management gives you visibility and control over shadow IT, including SaaS and generative AI apps used in your org.

Discovery methods include:

  • JumpCloud SSO Apps — existing SSO apps are added automatically when you enable the feature
  • JumpCloud Go browser extension — discovers AI and SaaS apps users access in the browser
  • Connectors — API-driven discovery that collects information directly from AI and SaaS service providers
  • JumpCloud Agent — discovers locally installed desktop applications on managed devices

How admins use AI & SaaS Management:

  • Enable the feature under Access > AI & SaaS Management
  • Classify discovered apps and set warning or blocking actions for unapproved apps
  • Configure connectors to expand discovery and track usage, including license information for supported providers
  • Review usage on the Overview tab
  • Open an app from the Applications tab to review Overview, Accounts, and Licenses.

Connectors interface directly with the application to gather license, usage, and related data. This is separate from how AI Gateway secures MCP connections.

Using AI Gateway

AI Gateway is a centralized MCP control plane. It secures the connection between AI clients (for example, ChatGPT, Cursor, or VS Code) and MCP servers registered in the Admin Portal.

Core terms:

  • MCP server — A connector that exposes a system’s data and actions to AI clients through the Model Context Protocol (MCP). It publishes tools the modal can invoke, resources it can read, and authenticates to the underlying system on the user’s behalf. . Admins register and manage servers under Access > AI Gateway.
  • AI client — An AI-powered application that users configure to connect to the JumpCloud AI Gateway endpoint: https://ai.jumpcloud.com/mcp

How admins use AI Gateway:

  • Add MCP servers on the Servers tab (Access > AI Gateway > + Add Server)
  • Configure trusted redirect URLs in AI Gateway Settings for each AI client your org uses
  • Review the Activity Log tab for MCP tool call events

Authentication at the gateway:

  • Admins configure each MCP server to use OAuth (recommended when supported) or API Token authentication.
  • Users authenticate to each configured MCP server when connecting their AI client through the gateway.
  • AI Gateway secures the connection between AI clients and configured MCP servers.

Understanding How the Features Work Together

Use multiple JumpCloud features to secure the entire AI lifecycle:

  1. SSO Applications — Connect enterprise apps and control access through user groups.
  2. AI & SaaS Management — Discover which AI and SaaS apps are in use, classify them, and restrict unapproved apps.
  3. AI Gateway — Register supported enterprise MCP servers so users can access approved application data through AI clients.
  4. User Portal — Users authenticate and configure AI clients to use the gateway endpoint. Users retrieve setup details from the User Portal when connecting supported AI clients.
  5. Directory Insights — Review AI Gateway MCP tool call activity on the Activity Log tab. The same activity is available in Directory Insights.

These features complement rather than replace each other. Use them together for sign-in and access control, usage visibility, and secured MCP access. 

For example: You can create a GitHub SSO application to control access via user groups, connect it to AI & SaaS Management to track usage, register it as an MCP server in AI Gateway to secure access between AI clients and GitHub data, and audit tool calls with the AI Gateway Activity Log.

Back to Top

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case