Skip to main content

Settings in the Admin Portal

Settings within the Admin Portal give IT Admins quick access to update the features and resources important for their organization and users. Use Settings to manage your organization profile, security settings, feature access, and other organization-wide configurations. Each tab groups related settings and controls. Dive in and learn more about the Admin Portal's Settings below.

Accessing Your Settings​

To access Settings:

  1. Log in to your JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. In the left navigation, click on Settings.
  2. Click the tab for the settings you want to view or update:
  3. When you finish your updates in a tab, click Save changes.

Organization Profile​

Use the Organization Profile tab to manage your organization details, logo, and User Portal settings. You can view your Organization ID, set a logo for JumpCloud communications, control profile access and device enrollment for your users, set the User Portal session duration, add help desk contact details, and manage Google single sign-on (SSO) for the Admin Portal.

Naming Your Organization​

The General section is where you manage your organization details.

To name your organization:

  1. In the JumpCloud Admin Portal, go to Settings > Organization Profile > General.
  2. In the Organization Name field, enter a name for your organization.
  3. (Optional) In the Contact Name and Contact Email fields, enter your organization contact details.
  4. Click Save changes.
note
  • JumpCloud emails may include a contact link that uses the name and email entered in Contact Name and Contact Email.
  • Some actions require an Organization Name, including enabling mobile device management (MDM) or changing password settings. If the field is empty, the ‘Bad Request: name is required’ error may appear.

To view and copy your Organization ID:

  1. Go to Settings > Organization Profile > General.
  2. Next to Organization ID, click the ‘eye’ icon to display all characters.
  3. Click the ‘double page’ icon to copy the ID.

The logo you upload is used in all JumpCloud communications to your users.

To upload a logo:

  1. Go to Settings > Organization Profile > Customize Logo.
  2. Click Choose File, or drag a file into the upload area.
  3. Click the Header, Login, and Email tabs to preview your logo.
  4. Click Save changes.
note

Use a PNG or JPG file with a transparent or white background. The minimum resolution is 400px by 400px and the maximum file size is 780 KB.

Managing User Portal Settings​

In User Portal Settings, manage profile access and device enrollment for your Users.

To update User Portal settings:

  1. Go to Settings > Organization Profile > User Portal Settings.
  2. Toggle on Read-only profile for all users to prevent users from changing their profile details in the User Portal. Toggle it off to let users change their profile.
  3. Toggle on Device enrollment for all users to let users download the JumpCloud agent from the User Portal. Toggle it off to prevent enrollment. See Enable Users to Install the Agent to learn more.
  4. Click Save changes.
note

You can't customize the URL of the User Portal.

Setting the User Portal Session Duration​

Set how long idle User Portal sessions last. When a session expires, the user must log in again. This prevents an idle device from being used to reach sensitive data.

For example, if you set the duration to seven days, the user is logged out only after seven consecutive days of inactivity. The session remains active while the user continues to use the User Portal.

Considerations:

  • Activity is defined as interactions with the server, like launching apps (Identity Provider and Service Provider initiated) or updating user info.
  • Updates to the duration settings won’t affect a user’s current session but will apply the next time they log in.
  • The duration settings currently apply to all factors of authentication enabled for a user.
  • The duration settings apply only to the JumpCloud User Portal. In many cases, setting duration must be defined on the Service Provider side (ex: AWS, Slack etc).
  • When the browser session is terminated, the User Portal session will also be terminated.

To set the User Portal session duration:

  1. Go to Settings > Organization Profile > User Portal Session Duration.
  2. In the Days, Hours, and Minutes fields, enter how long a session stays active while idle. The minimum is one minute and the maximum is 90 days.
  3. Click Save changes.
Important

The default value for Admin Portal session timeout is 60 minutes. The session length is not configurable. However, you might be logged out sooner if the Admin Portal is inactive in a background tab or a minimized window. The portal relies on continuous API polling to maintain the active session. To prevent early logouts, keep the Admin Portal tab active and in focus.

Adding Help Desk Contact Information​

Add contact details for users who have login issues. The details appear in the User Portal.

Considerations:

  • You can enable or disable this feature at any time.
  • The contact details are shown to anyone who enters a user's email address and has login issues.
  • Use general business contact information, for example support@company.com, so you do not expose personal details.

To add help desk contact information:

  1. Go to Settings > Organization Profile > Help Desk Contact Information.
  2. Under Contact Table Setup, click Add Row.
  3. Enter the label and the contact detail for the row.
  4. Repeat steps 2 and 3 for each row you want to add.
  5. (Optional) Select the Include logo checkbox to show your organization logo in the contact table.
  6. Click Preview to see how the table appears to Users.
  7. Under Terms and Conditions, toggle on Enable help desk contact information.
  8. Click Save changes.

To edit help desk contact information:

  1. Go to Settings > Organization Profile > Help Desk Contact Information.
  2. Under Contact Table Setup, edit the information in any row. To remove a row, click the ‘trash’ icon.
  3. Click Preview to see how the table appears to users.
  4. Click Save.

To disable help desk contact information:

  1. Go to Settings > Organization Profile > Help Desk Contact Information.
  2. Under Terms and Conditions, toggle off Enable help desk contact information.
  3. Click Save changes.

Managing Google SSO for the Admin Portal​

Google single sign-on (SSO) is on by default for Admin Portal sign-in. Admins can use one set of credentials to log in to the Admin Portal.

To turn off Google SSO for the Admin Portal:

  1. Go to Settings > Organization Profile > Google SSO for Admin Portal.
  2. Toggle on Disable SSO with Google on Admin Portal.
  3. Click Save changes.

To let Admins log in with Google again, toggle off Disable SSO with Google on Admin Portal and click Save changes. See Disable Google SSO in the Admin Portal to learn more.

note

Each Admin must connect their Google account before they can log in to JumpCloud with Google.

To connect your Google account:

  1. From the Administrators tab, select the Admin you want to edit.
  2. In the Edit Administrator panel, scroll to Account Settings, then click Connect.
  3. Follow the Google prompts to connect your account.
  4. When your account is connected, click Sign in with Google on the JumpCloud Administrator login screen to sign in using your Google credentials.

Notification Channels​

Set up notification channels to get alerts delivered to specified email addresses or admin role.

Security​

Use the Security tab to configure password requirements, lockout rules, password recovery, User ID and Group ID management, and what happens to connected resource accounts when a password expires or a user is locked out.

Admin Accounts​

Admin Accounts require multi-factor authentication (MFA) for all Admins. Under Global MFA Requirement, MFA is required for all Admins and can't be turned off on individual Admin accounts.

note
  • JumpCloud now requires MFA for all admins and this setting isn't editable.
  • If a user is elevated to Admin role, MFA is mandatory for signing in. You can’t disable this setting.
  • You can't edit the Enable Multi Factor Authentication for Admin Login setting on the individual Admin level.

Password Settings​

Use Password Settings to configure organization-wide password requirements, account lockout behavior, password recovery, User ID (UID) and Group ID (GID) management, and actions for connected resources. See Manage Password and Security Settings to learn more.

Administrators​

The Admin list shows you all the org's admins, along with their details. From here, you can create new admins, edit existing ones, or request to delete an Admin.

note

For instructions on creating new admins, editing existing admins, and deleting admins, see Manage Admin Accounts.

The columns in the list show the name and email of the Admin along with their Role, the status of their API key, whether or not they are required to log in with MFA or not, and whether they are enrolled in MFA or not.

tip

Hover over the status of each API key to see what they mean. For example: There are 2 variants of the ENABLED status. One of them has a 'key' icon next to it, while the other version doesn't. The one with the 'key' icon means the API key is enabled for this Admin, and they have generated a key. The one without the 'key' icon means the API key is enabled for this Admin, but they haven't generated a key yet.

Service Accounts​

Add Service Accounts for APIs to eliminate individual admin accounts being tied to API Keys and other automated systems.

Customize Email​

Important

JumpCloud system-generated emails cannot have their sender address changed.

JumpCloud sends emails to users to notify them of various events. You can customize some of these emails to look and sound more like your org.

This feature is disabled for all new organizations by default. It has to be enabled for your account in order to be able to customize the emails you send to your users.

  • Please reach out to either your Account Manager, or Customer Success Manager to have this enabled for your org.
note

This feature is only available to paid customers. Free customers that have previously customized emails will see your templates in a read-only state in Settings > Customize Email in your Admin Portal. Emails will continue to be sent to users with the existing customized content as displayed in the Settings > Customize Email page. Templates may be reverted to the JumpCloud default content at any time.

Considerations:

  • There is a maximum of 500 characters allowed in each field. If you have previously created a custom email with more than 500 characters, you will still have access to it, but you won't be able to add any additional characters. You will be able to edit the character count to be 500 or less.
  • Non-Latin characters are supported.
  • HTML isn’t supported.

Email Disclaimer​

note

The Email Disclaimer is used in all email communication, regardless of whether they have customized email content or not.

  1. Under Settings > Customize Email > Email Customization > Email Disclaimer you can add a message that will be added to the bottom of all communication from JumpCloud to your org’s users.
  2. You can see a preview of what the disclaimer will look like on the email by toggling Template Preview on. It will be seen at the bottom of the email right above Powered by JumpCloud.

Choose a Template​

  1. Under Settings > Customize Email > Choose a template, select which Email Template you’d like to customize. The available templates are:
    • Password Expiration Warning: This email encourages users to reset their password before an upcoming expiration date.
    • Lockout Notice: This tells users when they’ve been locked out of their account after multiple failed login attempts.
    • Password Expiration: This tells users that their password has expired and needs to be reset.
    • Password Reset Confirmation: This email confirms a recent password change.
    • Password Reset: This asks new users to activate their account or reset their password.
    • Activation Email: This asks new users to activate their account.
    • Welcome Email - Google Workspace: This is sent to users when they are bound to Google Workspace.
    • Welcome Email - M365/Azure AD: This is sent to users when they are bound to M365/Entra ID.
note

When adding users via Entra sync or the API, a welcome email is sent to users, but that email is not customizable.

Email Content​

  1. Under Settings > Customize Email > Email Content, you can view and modify the content of the currently selected Email Template. Tokens can be included in the various fields and the token’s value at the time each email is sent will replace the token. This allows for greater customization.
  2. The following email fields are customizable:
    • Subject: Content for the email’s subject line.
    • Title: Content for the email’s title that appears at the top of the email.
    • Header: Content for the email’s header that appears after the title and before the message content.
    • Message: Content for the email’s main message.
    • Button Call to Action: Content for a button in the email message that calls for users to take an action, like Reset Your Password.
    • Footer: Content for the email’s footer that appears below the message content.
  3. Click Save if these are your only changes.
tip

Click the Reset to Default Content to revert all of your changes back to the default JumpCloud content.

Available Tokens​

Tokens are variables that are replaced with attributes for your organization or your JumpCloud managed users. You can add tokens to email templates to include content that's specific to your organization.

Considerations:

  • If you mistype a token, it appears as plain text in the Template Preview. Valid tokens appear as links.
  • If a token attribute isn't defined for your organization, the token appears as blank space in the email.
  • Tokens must be included exactly as they appear in the following list or they appear as plain text in emails.

You can include the following tokens in your email templates:

TokenDescription
#{admin_email_link}This token is populated by your organization’s contact name and contact email. It shows the contact name with a mailto link to the contact email. If you don’t have both the contact name and contact email defined for your organization, this token appears as a blank space in the email. You can update these on the Organization Profile tab in the Settings page.
#{contact_email}This token is populated by your organization’s contact email. If you don’t have a contact email defined for your organization, this token appears as a blank space in the email. You can update your organization’s contact email on the Organization Profile tab in the Settings page.
#{contact_name}This token is populated by your organization’s contact name. If you don’t have a contact name defined for your organization, this token appears as a blank space in the email. You can update your organization’s contact name on the Organization Profile tab in the Settings page.
#{expiration_day}This token is populated with a password’s expiration date and is only available for the Password Expiration Warning template.
#{first_name}This token is populated by the receiving user’s first name. If you don’t have a first name defined for the user, this token appears as a blank space in the email.
#{lockout_source}This token identifies the source of the last login failure that triggered the Lockout Email. This is either; the System Display Name of the user’s managed device, or User Portal.
#{org_name}This token is populated by your organization’s name. If you don’t have a name defined for your organization, this token appears as a blank space in the email. You can update your organization’s name on the Organization Profile tab in the Settings page.
#{user_email}This token is populated by the receiving user’s email. This field is required, so it should always show in emails.
#{user_name}This token is populated by the receiving user’s JumpCloud username. This field is required, so it should always show in emails.
#{user_company_email}This token is populated by the user’s Company email. It is a required field, so it should always display. This token is only available for the Activation Email template.

JumpCloud AI​

Enable and configure AI-powered features that streamline administrative workflows, optimize command generation, and allow external AI tools to interact securely with your organization's data. See Get Started: AI-Powered Features to learn more.

From this tab, view and manage the following areas:

  • AI Assistant: Quickly find, manage, and report on your users, devices, and Single Sign-On (SSO) applications from a chat interface, without the need to go to different pages within the Admin Portal.
  • AI Search: Generate search queries based on your natural language input. No customer data is used to train internal or external AI models.
  • AI Commands Builder: Generate and optimize commands for managed devices, reducing troubleshooting time and eliminating command-line errors.
  • MCP Server for admins: Connect external AI clients to your JumpCloud organization via the Model Context Protocol (MCP) standard, allowing AI tools to securely administer your directory using natural language.
    • Connected OAuth clients: Click Manage to monitor active MCP sessions authorized via OAuth that have access to your organization's data.
      • Note: The UI displays the current number of active sessions, such as 5 Connected OAuth clients.
    • Auto revoke access: Select a timeframe from the drop-down menu to set how long each session stays active after the initial connection. Expired sessions are automatically revoked, and the client must reconnect.

Features​

Use the Features tab to view Feature Trials and manage Directory Insights, System Insights, Remote Access, and JumpCloud Go. The tab shows Feature Trials when your organization has an active trial. Some fields are disabled based on your Admin role permissions.

Feature Trials​

The Feature Trials section lists the trials you have underway. You can try features outside of your package for free. Trials appear in order of trial start date, with the most recent at the top.

Each trial card shows the feature name, a TRIAL badge with the days remaining or the days since the trial ended, and a short description. Click Learn More to read about the feature. Click View Plan Options to see the plans that include it.

note

The Feature Trials section appears only when your organization has an active trial.

Learn more about trials:

JumpCloud Go™​

JumpCloud Go™ enables secure, passwordless sign-in to the User Portal and SSO applications on managed devices using device authenticators. With the JumpCloud Go browser extension installed, users verify their identity with their device authenticator, such as Apple Touch ID or Windows Hello. JumpCloud Go authentication also satisfies User Portal MFA requirements.

To configure MFA factors, browser extension deployment, and related settings, click Manage MFA Configurations.

To learn more about JumpCloud Go:

Directory Insights​

Directory Insights logs directory events for audit and compliance. You can investigate Admin changes, authentications, and activity across users, devices, and resources in JumpCloud.

Use the JumpCloud REST API, the PowerShell Module, or the Admin Portal to access event logs and monitor user authentications to the User Portal, SAML SSO applications, RADIUS, and LDAP.

Prerequisites:

To view your current Directory Insights status:

  1. Go to Settings > Features > Insights.
  2. Check the Directory Insights toggle to see whether the feature is on for your organization.

Learn more about Directory Insights:

System Insights​

System Insights collects device data across your fleet for inventory, security, and configuration reporting on macOS, Windows, and Linux. You can gather information from JumpCloud managed devices with the JumpCloud REST API and the PowerShell Module.

You can use the System Insights feature to:

  • Easily take stock of your suite of devices and the state of the machines in your org.
  • See inventory information like vendor, model, serial number etc.
  • Query system endpoints to resolve issues proactively without having to interrupt employees.
  • Provide info to auditors to prove that systems in your org are compliant.
  • Gather info about device uptime to leverage when diagnosing issues.
  • Allow security and DevOps teams to interrogate machines to look for security vulnerabilities.
  • See which devices are protected by disk encryption and which need to be updated with it.

Prerequisites:

  • System Insights is included in some of our package plans. See JumpCloud Pricing for information on our package plans.
  • To enable System Insights for your account, customers with free accounts can contact us at systeminsights@jumpcloud.com, and customers with paid accounts can contact their Account Manager. New customers can contact us at sales@jumpcloud.com.
  • System Insights only supports 64-bit operating systems.

To enable System Insights:

  1. Go to Settings > Features > Insights.
  2. Toggle on System Insights.
  3. Under Auto-Enable System Insights on New Devices, select the macOS, Windows, or Linux checkbox for each operating system you want to include.
  4. Click Save changes.

New devices automatically enroll in System Insights for the operating systems you select. Existing devices must be enabled individually.

Learn more about System Insights:

Remote Access​

Use Remote Access to manage Remote Assist Service, Silent Assist, Background Tools Service, Session Timeout, and Experience Survey. See Get Started: Remote Assist for requirements and procedures.

Under Session Timeout, set the maximum length for Remote Assist sessions. The session ends when the selected duration is reached.

To set the session timeout:

  1. Go to Settings > Features > Remote Access.
  2. Under Session Timeout, select a duration from the drop-down.
  3. Click Save changes.

Learn more about Remote Assist:

Was this information helpful?