Skip to main content

JumpCloud

Visualize JumpCloud users, groups, and applications, map JumpCloud users to employees, and monitor changes through queries and alerts.

Installation​

info

JupiterOne requires a Read Only Admin API key used to authenticate with the JumpCloud account.

Each JupiterOne integration instance ingests a single JumpCloud organization. If your API key is a multi-tenant (MTP) admin key that can see more than one organization, you must also provide an Organization ID, and you need one integration instance per organization.

warning

JumpCloud Service Account keys are not supported. They cannot reach the multi-tenant endpoints this integration uses, and JumpCloud rejects them with 403 Forbidden. Use an Admin API key instead.

Configuration in JumpCloud​

  1. Log into the Admin portal
  2. Create a new Administrator user with the Read Only role:
    • Press the profile circle in the top right
    • Press Administrators
    • Press Add Administrator
    • Press Create New Admin
    • Enter required fields
    • Set role to Read Only
    • Check Enable API access
    • Press Save
  3. Log into the Admin portal with new Read Only Admin
  4. Once logged in, press the profile circle
    • Press My API Key
    • Copy API Key for use in the next section

Finding your Organization ID​

Only required if your API key is a multi-tenant (MTP) admin key that can see more than one JumpCloud organization. Single-tenant admin keys can skip this section.

  1. Log into the Admin portal
  2. Select the organization you want this integration instance to ingest
  3. Press the profile circle in the top right, then press Settings
  4. Copy the value of the Organization ID field for use in the next section

Repeat for each organization you want to ingest. Each one needs its own JupiterOne integration instance.

Configuration in JupiterOne​

To install the JumpCloud integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select JumpCloud. Click New Instance to begin configuring your integration, providing the following:

  • Account Name used to identify the JumpCloud account in JupiterOne. Ingested entities will have this value stored in tag.AccountName when the AccountName option is enabled.

  • Description to assist in identifying the integration instance, if desired.

  • Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as DISABLED and manually execute the integration.

  • API Key from an Admin with the Read Only role.

  • Organization ID of the single JumpCloud organization this instance ingests. Required if your API key is a multi-tenant (MTP) admin key, which JumpCloud rejects with 401 Unauthorized unless the organization is named. Leave blank for single-tenant admin keys, where JumpCloud resolves the organization automatically.

Click Create once all values are provided to finalize the integration.

Next steps​

Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.