JumpCloud identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On JumpCloud, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the JumpCloud connector needs.
Checks (6)
severity: high User Without MFA fix difficulty: medium #
Enroll JumpCloud users in multi-factor authentication
- Open JumpCloud Admin Console > Security Management > MFA/2FA and require TOTP/WebAuthn
- Set the org MFA policy to require enrollment for all users
- Notify affected users to complete enrollment
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Password Never Expires fix difficulty: easy #
Apply a password-expiration policy to JumpCloud users
- Open JumpCloud Admin Console > Settings > Password Settings
- Enable password expiration and set a rotation interval
- Disable per-user "Password never expires" overrides
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Locally Managed Account Outside SSO fix difficulty: medium #
Bring locally managed accounts under directory/SCIM lifecycle
- Identify users with externally_managed=false that should be HR/SCIM-sourced
- Connect the user to the authoritative source (HR import / SCIM) for lifecycle
- Confirm joiner-mover-leaver automation governs the account
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium System MFA Not Required At Login fix difficulty: medium #
Require MFA at system (device) login
- Open JumpCloud Admin Console > Devices and select the flagged system
- Enable "Require multi-factor authentication"
- Verify enrolled users can satisfy MFA at the login window
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: low System Agent Inactive fix difficulty: medium #
Investigate systems whose agent is no longer active
- Open JumpCloud Admin Console > Devices and locate inactive systems
- Reinstall or reconnect the JumpCloud agent, or decommission the device
- Remove stale device records to keep the inventory clean
Satisfies: NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: low SSO Application Without SSO Configured fix difficulty: medium #
Confirm published applications enforce SSO
- Open JumpCloud Admin Console > SSO and review the application
- Configure SAML/OIDC SSO and remove unused application connectors
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4