Skip to main content

Admin Portal Roles

Admin roles restrict Admin Portal access to the areas each person needs for their job. JumpCloud provides default roles that you assign in Settings.

To assign these roles, go to Settings in the JumpCloud Admin Portal. See Settings in the JumpCloud Admin Portal.

note
  • Role-based permissions apply to administrator actions in the product and to the API key of each administrator.
  • When you apply a role with limited permissions, a banner in the Admin Portal explains the permission level for that account.

Administrator with Billing​

warning

This role has the highest level of Admin Portal access. Carefully consider who you give this level of access.

Accounts with this role have all privileges and can:

  • Perform all User Management tasks: create, modify, and delete user and administrator accounts.
  • Perform all group management tasks: create, modify, and delete user and device groups.
  • Perform all device management tasks: create, modify, delete, and grant access to devices; configure and run commands; configure and run device configurations and policies; configure and manage Mobile Device Management (MDM) settings and policies.
  • Perform all user authentication tasks: configure, grant access to, and require authentication resources such as Lightweight Directory Access Protocol (LDAP), Remote Authentication Dial-In User Service (RADIUS), Single Sign-On (SSO), and System for Cross-domain Identity Management (SCIM) applications.
  • Perform all directory integration tasks: configure and manage directory integrations; provision and deprovision users in integrated directories.
  • Perform all security management tasks: configure and require Multi-factor Authentication (MFA) factors; configure Password Settings.
  • Perform all account management tasks: configure all JumpCloud settings.
  • Perform billing management tasks: update the account payment method. Only roles with billing privileges can manage payment methods for JumpCloud accounts. Learn about Billing roles.
  • Perform all administration tasks for the Multi-Tenant Portal (MTP): all previously mentioned administration tasks for organizations in an MTP.
  • Perform all Privileged Access Management (PAM) tasks, including Manage all Privileged Resources and Backup.

Administrator​

warning

Carefully consider who you give this level of access.

This role has all of the privileges of Administrator with Billing except privileges to manage payments (Billing), administrators, the Multi-Tenant Portal, and Manage all Privileged Resources in Privileged Access Management (PAM).

Administrator has PAM Edit access for PAM areas. That includes create, update, delete, and view for PAM resources, Resource Managers, Blocking Rules, Jump Servers, and User Groups, plus Overview, Session History, and Backup. It does not include Manage all Privileged Resources.

Manager​

Accounts with this role can manage users, devices, and groups.

In Privileged Access Management (PAM), Manager can create, update, delete, and view Privileged Websites, Servers, Databases, Privileged Credentials, and Resource Managers.

Command Runner with Billing​

Accounts with this role can manage account payment methods.

Command Runner​

Accounts with this role can only run commands they are given access to.

Help Desk​

Accounts with this role can access and view JumpCloud resources, submit support requests, and manage users in the following ways:

  • Create and delete users
  • Reset account passwords
  • Unlock users
  • Set Admin/Sudo permissions on a user's device from the User > Devices tab

Billing Only​

Accounts with this role can access the Account tab in the MTP, with Read Only permissions everywhere else. From the Account tab, Admins can review the Account Overview, review payment history, update mailing and billing information, and view the usage associated with the account.

Read Only​

Accounts with this role have read-only permissions. They can access and view users and other JumpCloud resources, but cannot perform management tasks.

Read Only includes view-only Privileged Access Management (PAM), including Overview and Session History. Read Only cannot create, update, or delete PAM resources, cannot use Settings, and cannot enable PAM if the organization is not enabled yet.

Asset Manager​

Accounts with this role can only access Asset Management in the Admin Portal and the API.

Admin Portal Roles​

The following table outlines role permission scope for default roles.

ScopeAdministrator with BillingAdministratorManagerCommand Runner with BillingCommand RunnerHelp DeskRead OnlyBilling OnlyAsset Manager
Administrators: creating, editing, assigning roles, deletingEditRead OnlyRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Billing: Billing payment information, including adding, removing, managingEditNo AccessNo AccessEditNo AccessNo AccessNo AccessEditNo Access
Multi-Tenant Portal: organization and administrator managementEditRead OnlyRead OnlyN/AN/ARead OnlyRead OnlyNo AccessNo Access
Organization and User Portal: organization details, email configurations, User Portal session managementEditEditRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Authentication: authentication policies, organization-level MFA configurationsEditEditRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Users: creating, viewing, managing attributes, deleting, passwords, MFA requirements and enrollments, lockouts, direct assignments to resourcesEditEditEditNo AccessNo AccessEdit*Read OnlyNo AccessNo Access
Groups: creating, viewing, deleting, configuring, managing attributes, membership and assignment of resources to groupsEditEditEditNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Devices: installing agent, managing attributes, viewing, deleting, applying policies, MDM managementEditEditEditNo AccessNo AccessRead Only**Read OnlyNo AccessNo Access
Directory and App User Management: directory integrations and application (SCIM Identity Management), user exportsEditEditRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Notifications in the Admin Portal: viewing, dismissingEditEditRead OnlyRead OnlyRead OnlyRead OnlyRead OnlyRead OnlyNo Access
Insights: Actions in Directory Insights and System Insights, including viewing, queryingEditEditEditNo AccessNo AccessEditEditNo AccessNo Access
Commands: creating, viewing, scheduling, running, assigningEditEditEditRunning and Scheduling access to Commands for assigned CommandsRunning and Scheduling access to Commands for assigned CommandsRead OnlyRead OnlyNo AccessNo Access
Bulk User Imports: bulk imports of users leveraging the JumpCloud job serviceEditEditEditNo AccessNo AccessEditRead OnlyNo AccessNo Access
SSO Applications: configuring of SAML SSO for applicationsEditEditRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
RADIUS servers: creating, editing, viewing, deletingEditEditRead OnlyNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Remote Assist: launching remote sessions, viewing and controlling end-user devicesEditEditEditNo AccessNo AccessLaunch Remote Assist (if Remote Assist is enabled in Settings)No AccessNo AccessNo Access
AI and SaaS Management: settings, reviewing applicationsEditEditEditNo AccessNo AccessRead OnlyRead OnlyNo AccessNo Access
Asset Management: settings, viewing, editing, and creating assetsEditEditEditNo AccessNo AccessRead OnlyRead OnlyNo AccessEdit
JumpCloud AI Search: settings, searching, queryingFull Access (Enable, Disable, and Search)Full Access (Enable, Disable, and Search)Search OnlyNo AccessNo AccessSearch OnlySearch OnlyNo AccessNo Access
Privileged Access Management (PAM): managing privileged resources, jump servers, session history, related PAM Admin Portal areasFull AccessEdit***Edit****No AccessNo AccessNo AccessRead OnlyNo AccessNo Access

* Help Desk has Edit for Users, with Read Only for direct assignments to resources. This does not grant access to view, retrieve, or export user passwords.

** Help Desk has Read Only for Devices. You can download and install both the .pkg and MDM mobile configuration. This does not create a new device record.

*** Administrator Edit access for PAM includes create, update, delete, and view for PAM resources, Resource Managers, Blocking Rules, Jump Servers, and User Groups, plus Overview, Session History, and Backup. It does not include Manage all Privileged Resources.

**** Manager Edit access for PAM is limited to Privileged Websites, Servers, Databases, Privileged Credentials, and Resource Managers. Manager cannot use Overview, Session History, Blocking Rules, Jump Servers, User Groups, or Settings (Manage all Privileged Resources / Backup).

Case Portal Access and Permissions​

All JumpCloud Administrator roles are granted full access to the JumpCloud Case Portal. Every administrator in your organization can manage support interactions and provide product feedback. With this access, administrators can:

  • Create new support cases.
  • View, search, and filter a complete history of current and past cases.
  • Submit Feature Requests to JumpCloud.

Learn More​

Was this information helpful?