JumpCloud's Directory-as-a-Service® (DaaS) is the single point of authority to authenticate, authorize, and manage the identities of a business’s employees and the systems and IT resources they need access to. DaaS securely connects employees with systems, applications, and other resources through a single unified cloud-based directory, replacing the need for on premise solutions such as Active Directory® and LDAP. JumpCloud supports all major OS platforms and is designed to control and manage user access to both internal and external IT resources such as servers and applications.
JumpCloud's Directory-as-a-Service® (DaaS) is the single point of authority to authenticate, authorize, and manage the identities of a business’s employees and the systems and the IT resources they need access to. DaaS securely connects employees with systems, applications, and other resources through a single unified cloud-based directory, replacing the need for on premise solutions such as Active Directory® and LDAP. JumpCloud supports all major OS platforms and is designed to control and manage user access to both internal and external IT resources such as servers and applications.
At a glance:
-Centralized Employee Identity Access Management and Directory Services
-Google Apps Integration
-System and Server Management
-App SSO & MFA
-Auditing and Compliance Logging
-Active Directory Integration
CENTRALIZED EMPLOYEE IDENTITY ACCESS MANAGEMENT AND DIRECTORY SERVICES
The core of JumpCloud's Directory-as-a-Service® is the secure identity database that maps your users to the applications, devices, and networks that they need. JumpCloud is a cloud-based directory service that is highly scalable, always-on, and requiring no installation or on-going management, DaaS provides IT admins with an easy-to-use interface and standards-based protocols to integrate with your infrastructure.
GOOGLE APPS INTEGRATION
A tightly integrated cloud-based directory for organizations using Google Apps, extending Google Apps identities to devices, applications, and networks whether on-premises or in the cloud. JumpCloud adds one of the most significant missing components for Google Apps organizations – cloud-based directory services.
-Provision, deprovision, and manage Google Apps users from JumpCloud
-Import Google Apps users into JumpCloud
-Extend Google Apps identities to devices and other IT resources
MAC WINDOWS AND LINUX AUTHENTICATION AND DEVICE MANAGEMENT
JumpCloud's system management capabilities enable IT admins to regain control across Mac, Linux, and Windows systems, all centrally managed through policies.
-Local user account and SSH key management
-Centralized execution of scripts or commands across groups of devices (Windows, Mac, and Linux)
-Scripts can be written in bash, Perl, Python, Ruby, Go, Node.js or any language for which there’s an interpreter or compiler on the host
-Results available in a web-based UI or via API
-Audit logging of all scripts and commands executed
-JSON-based REST API
APPLICATION SINGLE SIGN-ON
Provide your users single sign-on access to the applications they need most. Leading SaaS vendors, LDAP, RESTful APIs and single-sign on support for internal applications enable admins to provision and manage user access to both on-premise or hosted applications.
-SAML 2.0 support for Google Apps, AWS, Salesforce, and hundreds more
-End user portal with single click access to various applications
-Easy administrative configuration for SAML-based applications
-Simple provisioning and de-provisioning
No longer do IT admins need to spin up their own RADIUS server, hook it up to their wireless infrastructure, and then go user by user to setup deeper network control. IT admins simply point their WiFi network to JumpCloud and enable users via the JumpCloud web console.
-Authenticates to your JumpCloud account to keep user management centralized
-Provision, deprovision, and configure RADIUS servers with MFA in seconds
-EAP TTLS PAP — fully TLS-encrypted authentication path, from client to JumpCloud and back: none of your credentials ever go unprotected
-TCP and UDP client support — choose TCP for reliability and UDP for compatibility, even with older clients
-Temporary access controls — vendors, clients, and traveling employees get the access they need, each with their own username and password.
-Supports multiple clients — including, but not limited to, Linux, OS X, Windows, Android, iOS, and Windows Phone.
JumpCloud runs LDAP servers in the cloud to maintain everything, and has created standard mechanisms to connect IT resources to LDAP.
-Highly available, global LDAP servers
-RFC 2307-compliant schema
-Standard LDAP configurations to enable connections with virtually all LDAP clients
-LDAP and LDAPS available (ports 389 in clear text or STARTTLS, and 636 with SSL)
-Support for inetOrgPerson, groupOfNames, posixGroup objects
-Users can be bind-only, or can both bind and search with a single mouse-click
-Support for memberOf overlay (identify group membership from the user)
-Support for group member search (identify group membership from the group)
-Easy to use SaaS interface
-End User/Employee Self Service
-Control your whole directory via a simple REST API
AUDITING & COMPLIANCE EVENT LOGGING
The ability to review the activities of users who have accessed and performed operations against resources within your internal network has become an absolute requirement for organizations of any size. The Events API provides JumpCloud administrators the ability to query event data on demand or via scheduled jobs into readable JSON, perfect for integrating with larger auditing needs.
-Captures a wide range of events from user account changes, system changes, script executions and more
-API-driven for simple access and integration needs
-JSON output to ensure seamless integration with wider logging requirements, procedures, and tools
MICROSOFT® ACTIVE DIRECTORY® INTEGRATION
JumpCloud extends Microsoft Active Directory to non-AD supported applications, networks, and systems. JumpCloud's Active Directory Bridge and Sync features are easy to set up. By deploying a small agent on your Domain Controller, users are extended to all of the IT resources they need.
-Extend Microsoft Active Directory to cloud infrastructure (AWS, GCP, etc.)
-Authenticate and manage Macs and Linux devices using Microsoft AD credentials
-Users and credentials are always consistent with Active Directory
-Choose which users are extended to cloud-based and other resources Active Directory makes it hard to reach