Skip to main content

SSO Applications in the Enterprise Portal (Preview)

JumpCloud’s Enterprise Portal (EP) centralizes the control and management of Organizations from one dashboard. This enables admins to control all of their organizations efficiently, from a single, browser-based portal. EP Admins can view top-level data for all of their managed orgs at-a-glance. They can also securely launch full management sessions from the EP for any org they administer.

Single Sign-On (SSO) gives your Organization's users convenient but secure access to all their web applications with a single set of credentials. In the EP, you can view SSO applications across the enterprise and its organizations, create enterprise-level or organization-level applications, share enterprise applications with organizations, and manage user group access.

Prerequisites

  • A user account with Enterprise or Organization admin permissions
  • JumpCloud SSO Package or higher or SSO à la carte option
  • A user account with appropriate permissions in the SP
  • Any SP specific information, like an org ID

Terminology:

  • Enterprise Portal: Portal where Enterprise Admins manage settings for multiple organizations under one Enterprise Configuration. Differs from the JumpCloud Admin Portal, which is for one organization
    • Enterprise (formerly Enterprise Configuration): Centralized hub for all the organizations' objects in the Enterprise Portal. Items can be created and shared for organizations in the Enterprise Portal from this hub
  • Organizations: A division of the enterprise (for example a region or a country) that maintains its own users, devices, and resources
  • Enterprise Administrator: Admin who has full access to all orgs and enterprise resources
  • Organization Administrator: Admin whose access is limited to explicitly granted orgs

Considerations

  • Organization-level applications cannot be shared with other organizations
  • Deleting an enterprise application requires removing all organization associations first
  • The Organizations tab is hidden for Enterprise applications viewed at the Organization level

Creating SSO Applications​

note

Admins without permission to create or update SSO applications do not see the Add button.

To create an SSO application (Enterprise Administrator)​

  1. Log in to your EP.

  2. Go to Access > SSO Applications.

  3. Click + Add New Application (or Get Started if this is your first application).

  4. Creation depends on your Global Selector:

Global SelectorFlow
EnterpriseChoose Enterprise or Organization. If Organization, select the target organization, then continue
Specific organizationStarts the organization-level creation flow for that organization
  1. Select one of the following:
    • Prebuilt application:
      • Type <Your Application Name> in the Search field and select it
    • Custom SAML application:
      • Click Select on the Custom Application tile, OR
      • Search for Custom SAML App and select it
      • Select Manage Single Sign-On (SSO) > Configure SSO with SAML
    • OIDC application:
      • Click Select on the Custom Application tile, OR
      • Search for OIDC and select it
      • Select Manage Single Sign-On (SSO) > Configure SSO with OIDC
  2. Click Next.
  3. In the Display Label, type your name for the application.
  4. Optionally, customize the description and how the application displays:
    • Description - add a description that users will see in their user portal
    • User Portal Image - choose Logo or Color Indicator
    • Show in User Portal - enable to show the application tile in your organization's user portal
  5. If needed, customize the IdP URL:
    • Expand Advanced Settings and enter the name you want to use for the end of the SSO IdP URL, https://sso.jumpcloud.com/saml2/&lt;applicationname>
warning

The **SSO IdP URL** is not editable after the application is created. You will have to delete and recreate the connector if you need to edit this field at a later time.

  1. Click Save Application.
  2. If successful, click:
    • Configure Application and go to the next section
    • Close to configure your new application at a later time

Enterprise-level applications show Managed By: Enterprise. Organization-level applications show the organization name.

To create an SSO application (Organization Administrator)​

Organization Administrators cannot create enterprise-level applications.

  1. Log in to your EP.

  2. Go to Access > SSO Applications.

  3. Click + Add New Application (or Get Started if this is your first application).

  4. If the filter is View All, select the target organization.

  5. Continue through the SSO application setup for that organization (prebuilt, Custom SAML, or OIDC), then complete the display settings and save as described above.

To configure the SSO integration​

SAML configuration guides for each of the application service providers supported by JumpCloud can be found in the Integrations & Applications section of the JumpCloud Help Center. Find a specific SSO configuration guide by searching for an application's name in the search bar at the top of the page.

note

Users must be added before any changes can be made to the SSO configuration, like attribute mappings.

Sharing Enterprise-Level Applications​

note

Applications created at the organization level cannot be shared.

  1. Log in to your EP.

  2. Go to Access > SSO Applications.

  3. Click on the name of the application and select the Organizations tab.

  4. Select the Organization(s) you would like to share the application with.

  5. Click Save.

Managing Access to SSO Applications​

To manage organization access​

note

Applications created at the organization level cannot be shared.

  1. Log in to your EP.

  2. Go to Access > SSO Applications.

  3. Click on the name of the configuration and then select the Organizations tab.

  4. There are two options:

    • Select the box next to the organizations where you want the configuration to be available
    • Deselect the box next to the organizations where the configuration should no longer be available
  5. Click Save.

To manage organization group access​

  1. Log in to your EP and use the Global Selector to navigate to your organization.

  2. Go to Access > SSO Applications.

  3. Find and select your SSO Application.

  4. Go to the User Groups tab.

  5. There are two options:

    • Select the checkbox next to the user groups you want to give access
    • Deselect the checkbox next to the user groups you want to remove access
  6. Click Save.

Previewing Attribute Mappings and Rules​

  • Enterprise-level applications: Enterprise Administrators can preview attribute mappings and rules against users they have permission to view
  • Organization-level applications: Organization Administrators can run previews from the read-only application view. You do not need to enter edit mode to preview

Viewing SSO Applications​

  1. Log in to your EP.
  2. Go to Access > SSO Applications.

The SSO Applications list is scoped by the Global Selector by default:

Global SelectorWho sees itWhat the list shows
EnterpriseEnterprise AdminAll SSO applications
Specific organizationEnterprise Admin and Org Admin (only for orgs they can access)Scopes to a single organization. Shows that org's local resources plus the enterprise resources shared to it.
View AllOrg Admin (only for orgs they can access)View only. Shows the local resources of the orgs they can access plus the enterprise resources shared to those orgs.

Page filter (when Global Selector is View All)​

When the Global Selector is set to View All, you can use the page filter on SSO Applications to temporarily narrow the list to View All, Enterprise, or a specific organization.

note

The page filter overrides the Global Selector for this page only. It is not saved. If you leave the page and return, the Global Selector scope applies again.

List columns​

The SSO Applications list includes:

  • Managed By — Enterprise or the organization name. Sortable, searchable, and filterable
  • Organizations — Count of organizations associated with an enterprise-level application. Sortable

Editing and Deleting Enterprise-Level SSO Applications​

To edit an enterprise-level application​

  1. Log in to your EP.

  2. Go to Access > SSO Applications.

  3. Open the enterprise-level SSO application.

  4. Make your changes and save.

  5. Review the confirmation modal. It shows how many organizations are affected by the change.

  6. Confirm to apply the changes.

To delete an enterprise-level application​

You cannot delete an enterprise-level SSO application while it is still associated with any organizations.

  1. Log in to your EP.

  2. Go to Access > SSO Applications.

  3. Open the application and go to the Organizations tab.

  4. Remove all organization associations and click Save.

  5. Delete the application.

Audit Logging​

Creating, updating, deleting, and changing organization associations for SSO applications generate Directory Insights (DI) events.

  • From an Enterprise or View All scope, you can review integration DI events across organizations
  • From a specific organization scope, you see events for that organization

See JumpCloud Directory Insights to learn more.

Was this information helpful?