The JumpCloud agent lets you set user access controls to elevate the standard permissions on a user to Admin\/Sudo or Passwordless Sudo. Specific, privileged permissions on devices ensure that your company’s devices are secure and protected. <\/p>\n\n\n\n
There are two ways to manage access levels of users:<\/p>\n\n\n\n
<\/p><\/div>
Windows users need to log out and log back in for permissions changes to take effect. <\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
Setting permissions at the user group level centralizes management of elevated device permissions in a single place. Permissions set at the user group level will be applied to associated device groups. Group members will inherit permissions to devices that are associated with those device groups. <\/p>\n\n\n\n
Considerations<\/strong>:<\/p>\n\n\n\n
There are two ways to provide Admin\/Sudo access through user groups:<\/p>\n\n\n\n
To give users within a user group Admin\/Sudo access to devices via the Device Groups tab<\/strong>:<\/p>\n\n\n\n
<\/p><\/div>
To give users within a user group Global Admin\/Sudo access via the Details tab<\/strong>:<\/p>\n\n\n\n
Users that aren’t admins on all of their devices can be given elevated permissions on a per-device basis. <\/p>\n\n\n\n
Considerations<\/strong>:<\/p>\n\n\n\n
To set a user as an Admin\/Sudo on a connected device<\/strong>: <\/p>\n\n\n\n
You can also assign a user that’s not admin on all of their devices temporary elevated privileges<\/strong>. A user can perform needed administrative actions on their device for a fixed period of time, and then their permissions are automatically revoked.\u00a0<\/p>\n\n\n\n
Considerations<\/strong>:<\/p>\n\n\n\n
<\/p><\/div>
Here’s a guided simulation: Temporary User Permissions per Device<\/a>.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
To assign temporary Admin\/Sudo access to a user\u2019s device<\/strong>: <\/p>\n\n\n\n
You can remove a user\u2019s temporary elevated privileges ahead of the expiration time set in the previous step.<\/p>\n\n\n\n
To modify existing temporary Admin\/Sudo permissions<\/strong>:<\/p>\n\n\n\n
Admins can assign global Admin\/Sudo permissions on a user to apply to all devices associated with that user.<\/p>\n\n\n\n
Considerations<\/strong>:<\/p>\n\n\n\n
To set a user as a global Admin\/Sudo on all associated devices<\/strong>:<\/p>\n\n\n\n
If you\u2019ve enabled Self-Service Account Provisioning, you can set Admin\/Sudo permissions for newly joined accounts from the Device Settings menu. See Provision New Users on Device Login<\/a>.<\/p>\n\n\n\n
A user\u2019s permission level can be adjusted after provisioning by Setting Permissions on a User per Device Bind<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"