The 13 JumpCloud security checks Black Cat runs
Black Cat SSPM evaluates 13 security policies against your JumpCloud configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect JumpCloud — what access Black Cat needs, and why.
Identity, MFA & sign-in
6 checks · highest severity: high
Configuration hardening
3 checks · highest severity: high
Identity, MFA & sign-in (6)
- User Without MFA severity: high
- Password Never Expires severity: medium
- Locally Managed Account Outside SSO severity: medium
- System MFA Not Required At Login severity: medium
- System Agent Inactive severity: low
- SSO Application Without SSO Configured severity: low
Configuration hardening (3)
- System SSH Password Authentication Enabled severity: high
- System SSH Root Login Enabled severity: high
- Dynamic User Group Without Restriction severity: medium
Other checks (4)
severity: critical Sudo User Without MFA fix difficulty: medium #
Require MFA for users with sudo/administrative rights
- Open JumpCloud Admin Console > Users and select the flagged user
- Either remove the Global Administrator / sudo grant or enforce MFA on the account
- Confirm the user completes MFA enrollment before re-granting elevation
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3
severity: critical Passwordless Sudo Enabled fix difficulty: easy #
Disable passwordless sudo on JumpCloud users
- Open JumpCloud Admin Console > Users and select the flagged user
- Disable "Enable as Global Administrator sudo without password"
- Re-bind the user to systems with standard sudo requiring a password
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3
severity: high System Full Disk Encryption Disabled fix difficulty: medium #
Enforce full disk encryption (FileVault/BitLocker) on managed systems
- Open JumpCloud Admin Console > Policies and apply an FDE policy to the device group
- Escrow the recovery key in JumpCloud
- Confirm fde.active reports true after enforcement
Satisfies: NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: low No Recent Directory Insights Events fix difficulty: easy #
Confirm Directory Insights is producing audit events
- Open JumpCloud Admin Console > Insights > Directory Insights
- Confirm events are present and the API key has Directory Insights access
- Configure log streaming/retention if required
Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1