SSO Applications in the Enterprise Portal (Preview)
JumpCloud’s Enterprise Portal (EP) centralizes the control and management of Organizations from one dashboard. This enables admins to control all of their organizations efficiently, from a single, browser-based portal. EP Admins can view top-level data for all of their managed orgs at-a-glance. They can also securely launch full management sessions from the EP for any org they administer.
Single Sign-On (SSO) gives your Organization's users convenient but secure access to all their web applications with a single set of credentials. In the EP, you can view SSO applications across the enterprise and its organizations, create enterprise-level or organization-level applications, share enterprise applications with organizations, and manage user group access.
Prerequisites
- A user account with Enterprise or Organization admin permissions
- JumpCloud SSO Package or higher or SSO à la carte option
- A user account with appropriate permissions in the SP
- Any SP specific information, like an org ID
Terminology:
- Enterprise Portal: Portal where Enterprise Admins manage settings for multiple organizations under one Enterprise Configuration. Differs from the JumpCloud Admin Portal, which is for one organization
- Enterprise (formerly Enterprise Configuration): Centralized hub for all the organizations' objects in the Enterprise Portal. Items can be created and shared for organizations in the Enterprise Portal from this hub
- Organizations: A division of the enterprise (for example a region or a country) that maintains its own users, devices, and resources
- Enterprise Administrator: Admin who has full access to all orgs and enterprise resources
- Organization Administrator: Admin whose access is limited to explicitly granted orgs
Considerations
- Organization-level applications cannot be shared with other organizations
- Deleting an enterprise application requires removing all organization associations first
- The Organizations tab is hidden for Enterprise applications viewed at the Organization level
Creating SSO Applications
Admins without permission to create or update SSO applications do not see the Add button.
To create an SSO application (Enterprise Administrator)
-
Log in to your EP.
-
Go to Access > SSO Applications.
-
Click + Add New Application (or Get Started if this is your first application).
-
Creation depends on your Global Selector:
| Global Selector | Flow |
|---|---|
| Enterprise | Choose Enterprise or Organization. If Organization, select the target organization, then continue |
| Specific organization | Starts the organization-level creation flow for that organization |
- Select one of the following:
- Prebuilt application:
- Type <
Your Application Name> in the Search field and select it
- Type <
- Custom SAML application:
- Click Select on the Custom Application tile, OR
- Search for Custom SAML App and select it
- Select Manage Single Sign-On (SSO) > Configure SSO with SAML
- OIDC application:
- Click Select on the Custom Application tile, OR
- Search for OIDC and select it
- Select Manage Single Sign-On (SSO) > Configure SSO with OIDC
- Prebuilt application:
- Click Next.
- In the Display Label, type your name for the application.
- Optionally, customize the description and how the application displays:
- Description - add a description that users will see in their user portal
- User Portal Image - choose Logo or Color Indicator
- Show in User Portal - enable to show the application tile in your organization's user portal
- If needed, customize the IdP URL:
- Expand Advanced Settings and enter the name you want to use for the end of the SSO IdP URL,
https://sso.jumpcloud.com/saml2/<applicationname>
- Expand Advanced Settings and enter the name you want to use for the end of the SSO IdP URL,
The **SSO IdP URL** is not editable after the application is created. You will have to delete and recreate the connector if you need to edit this field at a later time.
- Click Save Application.
- If successful, click:
- Configure Application and go to the next section
- Close to configure your new application at a later time
Enterprise-level applications show Managed By: Enterprise. Organization-level applications show the organization name.
To create an SSO application (Organization Administrator)
Organization Administrators cannot create enterprise-level applications.
-
Log in to your EP.
-
Go to Access > SSO Applications.
-
Click + Add New Application (or Get Started if this is your first application).
-
If the filter is View All, select the target organization.
-
Continue through the SSO application setup for that organization (prebuilt, Custom SAML, or OIDC), then complete the display settings and save as described above.
To configure the SSO integration
SAML configuration guides for each of the application service providers supported by JumpCloud can be found in the Integrations & Applications section of the JumpCloud Help Center. Find a specific SSO configuration guide by searching for an application's name in the search bar at the top of the page.
Users must be added before any changes can be made to the SSO configuration, like attribute mappings.
Sharing Enterprise-Level Applications
Applications created at the organization level cannot be shared.
-
Log in to your EP.
-
Go to Access > SSO Applications.
-
Click on the name of the application and select the Organizations tab.
-
Select the Organization(s) you would like to share the application with.
-
Click Save.
Managing Access to SSO Applications
To manage organization access
Applications created at the organization level cannot be shared.
-
Log in to your EP.
-
Go to Access > SSO Applications.
-
Click on the name of the configuration and then select the Organizations tab.
-
There are two options:
- Select the box next to the organizations where you want the configuration to be available
- Deselect the box next to the organizations where the configuration should no longer be available
-
Click Save.
To manage organization group access
-
Log in to your EP and use the Global Selector to navigate to your organization.
-
Go to Access > SSO Applications.
-
Find and select your SSO Application.
-
Go to the User Groups tab.
-
There are two options:
- Select the checkbox next to the user groups you want to give access
- Deselect the checkbox next to the user groups you want to remove access
-
Click Save.
Previewing Attribute Mappings and Rules
- Enterprise-level applications: Enterprise Administrators can preview attribute mappings and rules against users they have permission to view
- Organization-level applications: Organization Administrators can run previews from the read-only application view. You do not need to enter edit mode to preview
Viewing SSO Applications
- Log in to your EP.
- Go to Access > SSO Applications.
The SSO Applications list is scoped by the Global Selector by default:
| Global Selector | Who sees it | What the list shows |
|---|---|---|
| Enterprise | Enterprise Admin | All SSO applications |
| Specific organization | Enterprise Admin and Org Admin (only for orgs they can access) | Scopes to a single organization. Shows that org's local resources plus the enterprise resources shared to it. |
| View All | Org Admin (only for orgs they can access) | View only. Shows the local resources of the orgs they can access plus the enterprise resources shared to those orgs. |
Page filter (when Global Selector is View All)
When the Global Selector is set to View All, you can use the page filter on SSO Applications to temporarily narrow the list to View All, Enterprise, or a specific organization.
The page filter overrides the Global Selector for this page only. It is not saved. If you leave the page and return, the Global Selector scope applies again.
List columns
The SSO Applications list includes:
- Managed By — Enterprise or the organization name. Sortable, searchable, and filterable
- Organizations — Count of organizations associated with an enterprise-level application. Sortable
Editing and Deleting Enterprise-Level SSO Applications
To edit an enterprise-level application
-
Log in to your EP.
-
Go to Access > SSO Applications.
-
Open the enterprise-level SSO application.
-
Make your changes and save.
-
Review the confirmation modal. It shows how many organizations are affected by the change.
-
Confirm to apply the changes.
To delete an enterprise-level application
You cannot delete an enterprise-level SSO application while it is still associated with any organizations.
-
Log in to your EP.
-
Go to Access > SSO Applications.
-
Open the application and go to the Organizations tab.
-
Remove all organization associations and click Save.
-
Delete the application.
Audit Logging
Creating, updating, deleting, and changing organization associations for SSO applications generate Directory Insights (DI) events.
- From an Enterprise or View All scope, you can review integration DI events across organizations
- From a specific organization scope, you see events for that organization
See JumpCloud Directory Insights to learn more.
Was this information helpful?