01-06-2025 01:51 PM - edited 01-06-2025 01:53 PM
Hello All,
I am pleased to announce the GA release of “Secure Admin Portal Login with Advanced MFA methods”. This feature aims to empower the admins to have a secure access experience with higher authentication assurance to the JumpCloud Admin Portal with key benefits that facilitate:
The Admin Experience
Giving an admin role to a user account allows privileged users in your organization to switch between their admin and user roles with a single set of credentials. Whichever MFA factors are applied to the user account are enforced when the user logs in to the Admin Portal. If the admin role is ever revoked, the user identity is preserved.
“Administrators with Billing” are enabled with the below key features:
Note ⭐ : The existing admins are not automatically converted into a single identity to matching users. Instead an in-product experience is provided to identify admin accounts who have matching users and a simple edit to transform them into a single identity.
👉 It is recommended that “Administrators with Billing” create new admins from existing users or transform their current existing admins to matching users, to take advantage of the advanced Phishing resistant MFA methods like JumpCloud Go, YubiKeys or Device Authenticators (WebAuthn) and strengthen the security of their Admin Portal.
Getting Started
As an “Administrator with Billing” access the Administrators page left navigation menu under “Settings -> Administrators”
Configuration Experience :
Once you land into the administrators page, there are a couple of mainstream configuration experience changes presented to the administrators.
There are 2 options now when you add new administrators
Existing customers who may have already created administrators before this feature was released, now can see visual and verbal cues to know if there are admin accounts that exist with matching users that can be transformed into a single identity to leverage Advanced MFA methods.
Once the configuration is complete, an email is sent to the new administrators with their role and that they can access the admin portal with their User Credentials and MFA
Secure Access Experience :
Once admins are created from existing users, if the users have MFA configured, they extend to the admins during access as a step-up MFA before gaining access to the Admin Portal.
There are a couple of ways the admins access the Admin Portal today.
The “Administrators with Billing” can now configure higher authentication assurance MFA factors like the Phishing resistant JumpCloud Go, WebAuthn or JumpCloud Protect Push and have the users with administrator role, enrol to them. This ensures that privileged user identities have a secure way to log into the Admin Portal with advanced MFA factors to strengthen their access security.
Scenario 1 - Admin Portal is launched within an authenticated User Portal by a User with Admin Role and has MFA configured and enrolled
Scenario 2 - Admin Portal is launched directly via console.jumpcloud.com/login and clicking on Admin Portal link, by a User with Admin Role who has MFA configured and enrolled
Access Removal or Auto Admin Deletion on User Deprovisioning Experience
By managing admins from existing users, account management is much more streamlined and simplified. Admin accounts are removed instantly when users leave the organization or admin roles can be removed from users based on need, when they move into different units within the organization. This reduces the attack surface, preventing unauthorized access to adversaries
Documentation - https://jumpcloud.com/support/secure-admin-portal-logins
FAQ - https://jumpcloud.com/support/faq-give-user-an-admin-role
New to the site? Take a look at these additional resources:
Ready to join us? You can register here.