Skip to content

JumpCloud identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On JumpCloud, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the JumpCloud connector needs.

Checks (6)

severity: high User Without MFA fix difficulty: medium #

Enroll JumpCloud users in multi-factor authentication

  1. Open JumpCloud Admin Console > Security Management > MFA/2FA and require TOTP/WebAuthn
  2. Set the org MFA policy to require enrollment for all users
  3. Notify affected users to complete enrollment

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Password Never Expires fix difficulty: easy #

Apply a password-expiration policy to JumpCloud users

  1. Open JumpCloud Admin Console > Settings > Password Settings
  2. Enable password expiration and set a rotation interval
  3. Disable per-user "Password never expires" overrides

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Locally Managed Account Outside SSO fix difficulty: medium #

Bring locally managed accounts under directory/SCIM lifecycle

  1. Identify users with externally_managed=false that should be HR/SCIM-sourced
  2. Connect the user to the authoritative source (HR import / SCIM) for lifecycle
  3. Confirm joiner-mover-leaver automation governs the account

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: medium System MFA Not Required At Login fix difficulty: medium #

Require MFA at system (device) login

  1. Open JumpCloud Admin Console > Devices and select the flagged system
  2. Enable "Require multi-factor authentication"
  3. Verify enrolled users can satisfy MFA at the login window

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: low System Agent Inactive fix difficulty: medium #

Investigate systems whose agent is no longer active

  1. Open JumpCloud Admin Console > Devices and locate inactive systems
  2. Reinstall or reconnect the JumpCloud agent, or decommission the device
  3. Remove stale device records to keep the inventory clean

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

severity: low SSO Application Without SSO Configured fix difficulty: medium #

Confirm published applications enforce SSO

  1. Open JumpCloud Admin Console > SSO and review the application
  2. Configure SAML/OIDC SSO and remove unused application connectors

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

More JumpCloud checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial