{"id":74830,"date":"2023-05-19T14:04:58","date_gmt":"2023-05-19T18:04:58","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=74830"},"modified":"2024-03-25T16:51:27","modified_gmt":"2024-03-25T20:51:27","slug":"bind-users-to-devices","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/bind-users-to-devices","title":{"rendered":"Bind Users to Devices"},"content":{"rendered":"\n
After you\u2019ve created or imported your users and devices to your JumpCloud organization, you must bind those users to their devices. Once bound, the user can access the device by logging in with their JumpCloud username and password. If a user isn\u2019t bound to a device, they\u2019re unable to log in.<\/p>\n\n\n\n
When you bind a user to a device, you are either provisioning a new local account to a macOS, Windows, or Linux device if one doesn\u2019t already exist, or allowing JumpCloud to manage an existing local account on the device. <\/p>\n\n\n\n
You can bind a single user to a single device or a group <\/a>of users<\/a> to a group of devices:<\/p>\n\n\n\n <\/p><\/div> You can also let new users bind their account to macOS and Windows devices directly from the login window. See Provision New Users on Device Login<\/a>. <\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Considerations<\/strong>:<\/p>\n\n\n\n If you are binding a new user account to the device, whether it\u2019s the first account on the device or an additional account, you perform the following steps:<\/p>\n\n\n\n After the user is bound to the device, the user can utilize their JumpCloud credentials to log in. If your user or device needs to use multi-factor authentication (MFA), JumpCloud will prompt the user when they log in to configure MFA. You can bind a user group to a device group to grant a group of users access to each device in the group.<\/p>\n\n\n\n <\/p><\/div> Binding a user group to a device group will create a local user account for each user in the user group on each device in the device group. Adding a large number of user accounts to a device may prevent it from operating correctly. Proceed with caution.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n To bind a user group to a device group<\/strong>:<\/p>\n\n\n\n If your device already has a local user account, JumpCloud can manage, or take over, that account. If the JumpCloud user name and the existing account\u2019s username match exactly, JumpCloud will take over that existing account. If they do not, you can specify the account for JumpCloud to manage. For more information, Take Over an Existing User Account with JumpCloud<\/a>.<\/p>\n\n\n\n <\/p><\/div> As this process is writing the user\u2019s password through Mac Keychain and the Windows Data Protection APIs, users will be logged out of all resources after account takeover. This is expected behavior. Some examples of these resources include 1Password, Dropbox, Google Drive, Slack, Microsoft Office, Google Workspace, Microsoft Teams, Chrome, Firefox, Edge browsers, etc.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n <\/p><\/div> For macOS takeovers, users must log out and log back in to their system after they are connected to the system via JumpCloud. See MacOS Account Takeover Considerations<\/a>.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n If you no longer want a user to have access to a device, you can unbind that user from the device. For more information, see Unbind Users from a Resource<\/a>. <\/p><\/div> Use caution when unbinding users from devices. If the device has no user accounts on it, the device can become locked and will no longer be able to be accessed by JumpCloud. <\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n\n
\n
Bind a User to a Device<\/h2>\n\n\n\n
\n
<\/li>\n\n\n\n
User accounts aren’t provisioned to the device until the JumpCloud agent polls with your organization\u2019s Admin Portal, which happens every few minutes.
You can connect the user to any resource in JumpCloud (devices, applications, networks, etc.). If the user is created in a Staged user state, they won’t gain access to their assigned resources until they are activated. See Manage User States<\/a> for specific information about when a user gains access.<\/p>\n\n\n\nBind a User Group to a Device Group<\/h2>\n\n\n\n
\n
<\/li>\n\n\n\nTake Over an Existing Account<\/h2>\n\n\n\n
Unbind a User from a Device<\/h2>\n\n\n\n
Considerations<\/strong>: <\/p>\n\n\n\n\n