Admin Portal Roles
Admin roles restrict Admin Portal access to the areas each person needs for their job. JumpCloud provides default roles that you assign in Settings.
To assign these roles, go to Settings in the JumpCloud Admin Portal. See Settings in the JumpCloud Admin Portal.
- Role-based permissions apply to administrator actions in the product and to the API key of each administrator.
- When you apply a role with limited permissions, a banner in the Admin Portal explains the permission level for that account.
Administrator with Billing
This role has the highest level of Admin Portal access. Carefully consider who you give this level of access.
Accounts with this role have all privileges and can:
- Perform all User Management tasks: create, modify, and delete user and administrator accounts.
- Perform all group management tasks: create, modify, and delete user and device groups.
- Perform all device management tasks: create, modify, delete, and grant access to devices; configure and run commands; configure and run device configurations and policies; configure and manage Mobile Device Management (MDM) settings and policies.
- Perform all user authentication tasks: configure, grant access to, and require authentication resources such as Lightweight Directory Access Protocol (LDAP), Remote Authentication Dial-In User Service (RADIUS), Single Sign-On (SSO), and System for Cross-domain Identity Management (SCIM) applications.
- Perform all directory integration tasks: configure and manage directory integrations; provision and deprovision users in integrated directories.
- Perform all security management tasks: configure and require Multi-factor Authentication (MFA) factors; configure Password Settings.
- Perform all account management tasks: configure all JumpCloud settings.
- Perform billing management tasks: update the account payment method. Only roles with billing privileges can manage payment methods for JumpCloud accounts. Learn about Billing roles.
- Perform all administration tasks for the Multi-Tenant Portal (MTP): all previously mentioned administration tasks for organizations in an MTP.
- Perform all Privileged Access Management (PAM) tasks, including Manage all Privileged Resources and Backup.
Administrator
Carefully consider who you give this level of access.
This role has all of the privileges of Administrator with Billing except privileges to manage payments (Billing), administrators, the Multi-Tenant Portal, and Manage all Privileged Resources in Privileged Access Management (PAM).
Administrator has PAM Edit access for PAM areas. That includes create, update, delete, and view for PAM resources, Resource Managers, Blocking Rules, Jump Servers, and User Groups, plus Overview, Session History, and Backup. It does not include Manage all Privileged Resources.
Manager
Accounts with this role can manage users, devices, and groups.
In Privileged Access Management (PAM), Manager can create, update, delete, and view Privileged Websites, Servers, Databases, Privileged Credentials, and Resource Managers.
Command Runner with Billing
Accounts with this role can manage account payment methods.
Command Runner
Accounts with this role can only run commands they are given access to.
Help Desk
Accounts with this role can access and view JumpCloud resources, submit support requests, and manage users in the following ways:
- Create and delete users
- Reset account passwords
- Unlock users
- Set Admin/Sudo permissions on a user's device from the User > Devices tab
Billing Only
Accounts with this role can access the Account tab in the MTP, with Read Only permissions everywhere else. From the Account tab, Admins can review the Account Overview, review payment history, update mailing and billing information, and view the usage associated with the account.
Read Only
Accounts with this role have read-only permissions. They can access and view users and other JumpCloud resources, but cannot perform management tasks.
Read Only includes view-only Privileged Access Management (PAM), including Overview and Session History. Read Only cannot create, update, or delete PAM resources, cannot use Settings, and cannot enable PAM if the organization is not enabled yet.
Asset Manager
Accounts with this role can only access Asset Management in the Admin Portal and the API.
Admin Portal Roles
The following table outlines role permission scope for default roles.
| Scope | Administrator with Billing | Administrator | Manager | Command Runner with Billing | Command Runner | Help Desk | Read Only | Billing Only | Asset Manager |
|---|---|---|---|---|---|---|---|---|---|
| Administrators: creating, editing, assigning roles, deleting | Edit | Read Only | Read Only | No Access | No Access | Read Only | Read Only | No Access | No Access |
| Billing: Billing payment information, including adding, removing, managing | Edit | No Access | No Access | Edit | No Access | No Access | No Access | Edit | No Access |
| Multi-Tenant Portal: organization and administrator management | Edit | Read Only | Read Only | N/A | N/A | Read Only | Read Only | No Access | No Access |
| Organization and User Portal: organization details, email configurations, User Portal session management | Edit | Edit | Read Only | No Access | No Access | Read Only | Read Only | No Access | No Access |
| Authentication: authentication policies, organization-level MFA configurations | Edit | Edit | Read Only | No Access | No Access | Read Only | Read Only | No Access | No Access |
| Users: creating, viewing, managing attributes, deleting, passwords, MFA requirements and enrollments, lockouts, direct assignments to resources | Edit | Edit | Edit | No Access | No Access | Edit* | Read Only | No Access | No Access |
| Groups: creating, viewing, deleting, configuring, managing attributes, membership and assignment of resources to groups | Edit | Edit | Edit | No Access | No Access | Read Only | Read Only | No Access | No Access |
| Devices: installing agent, managing attributes, viewing, deleting, applying policies, MDM management | Edit | Edit | Edit | No Access | No Access | Read Only** | Read Only | No Access | No Access |
| Directory and App User Management: directory integrations and application (SCIM Identity Management), user exports | Edit | Edit | Read Only | No Access | No Access | Read Only | Read Only | No Access | No Access |
| Notifications in the Admin Portal: viewing, dismissing | Edit | Edit | Read Only | Read Only | Read Only | Read Only | Read Only | Read Only | No Access |
| Insights: Actions in Directory Insights and System Insights, including viewing, querying | Edit | Edit | Edit | No Access | No Access | Edit | Edit | No Access | No Access |
| Commands: creating, viewing, scheduling, running, assigning | Edit | Edit | Edit | Running and Scheduling access to Commands for assigned Commands | Running and Scheduling access to Commands for assigned Commands | Read Only | Read Only | No Access | No Access |
| Bulk User Imports: bulk imports of users leveraging the JumpCloud job service | Edit | Edit | Edit | No Access | No Access | Edit | Read Only | No Access | No Access |
| SSO Applications: configuring of SAML SSO for applications | Edit | Edit | Read Only | No Access | No Access | Read Only | Read Only | No Access | No Access |
| RADIUS servers: creating, editing, viewing, deleting | Edit | Edit | Read Only | No Access | No Access | Read Only | Read Only | No Access | No Access |
| Remote Assist: launching remote sessions, viewing and controlling end-user devices | Edit | Edit | Edit | No Access | No Access | Launch Remote Assist (if Remote Assist is enabled in Settings) | No Access | No Access | No Access |
| AI and SaaS Management: settings, reviewing applications | Edit | Edit | Edit | No Access | No Access | Read Only | Read Only | No Access | No Access |
| Asset Management: settings, viewing, editing, and creating assets | Edit | Edit | Edit | No Access | No Access | Read Only | Read Only | No Access | Edit |
| JumpCloud AI Search: settings, searching, querying | Full Access (Enable, Disable, and Search) | Full Access (Enable, Disable, and Search) | Search Only | No Access | No Access | Search Only | Search Only | No Access | No Access |
| Privileged Access Management (PAM): managing privileged resources, jump servers, session history, related PAM Admin Portal areas | Full Access | Edit*** | Edit**** | No Access | No Access | No Access | Read Only | No Access | No Access |
* Help Desk has Edit for Users, with Read Only for direct assignments to resources. This does not grant access to view, retrieve, or export user passwords.
** Help Desk has Read Only for Devices. You can download and install both the .pkg and MDM mobile configuration. This does not create a new device record.
*** Administrator Edit access for PAM includes create, update, delete, and view for PAM resources, Resource Managers, Blocking Rules, Jump Servers, and User Groups, plus Overview, Session History, and Backup. It does not include Manage all Privileged Resources.
**** Manager Edit access for PAM is limited to Privileged Websites, Servers, Databases, Privileged Credentials, and Resource Managers. Manager cannot use Overview, Session History, Blocking Rules, Jump Servers, User Groups, or Settings (Manage all Privileged Resources / Backup).
Case Portal Access and Permissions
All JumpCloud Administrator roles are granted full access to the JumpCloud Case Portal. Every administrator in your organization can manage support interactions and provide product feedback. With this access, administrators can:
- Create new support cases.
- View, search, and filter a complete history of current and past cases.
- Submit Feature Requests to JumpCloud.
Learn More
Was this information helpful?