Skip to content

The 13 JumpCloud security checks Black Cat runs

Black Cat SSPM evaluates 13 security policies against your JumpCloud configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect JumpCloud — what access Black Cat needs, and why.

Identity, MFA & sign-in (6)

Configuration hardening (3)

Other checks (4)

severity: critical Sudo User Without MFA fix difficulty: medium #

Require MFA for users with sudo/administrative rights

  1. Open JumpCloud Admin Console > Users and select the flagged user
  2. Either remove the Global Administrator / sudo grant or enforce MFA on the account
  3. Confirm the user completes MFA enrollment before re-granting elevation

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: critical Passwordless Sudo Enabled fix difficulty: easy #

Disable passwordless sudo on JumpCloud users

  1. Open JumpCloud Admin Console > Users and select the flagged user
  2. Disable "Enable as Global Administrator sudo without password"
  3. Re-bind the user to systems with standard sudo requiring a password

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: high System Full Disk Encryption Disabled fix difficulty: medium #

Enforce full disk encryption (FileVault/BitLocker) on managed systems

  1. Open JumpCloud Admin Console > Policies and apply an FDE policy to the device group
  2. Escrow the recovery key in JumpCloud
  3. Confirm fde.active reports true after enforcement

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: low No Recent Directory Insights Events fix difficulty: easy #

Confirm Directory Insights is producing audit events

  1. Open JumpCloud Admin Console > Insights > Directory Insights
  2. Confirm events are present and the API key has Directory Insights access
  3. Configure log streaming/retention if required

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial