JumpCloud is single sign-on and cloud directory software for IT teams that manage identities, devices and app access across Windows, Mac and Linux.
JumpCloud gives an IT admin one console where a person is created once and then signed in to devices and applications from that record. JumpCloud Inc., an independent company based in Louisville, Colorado, makes the platform. It brings identity, device and access management into one product, and it is built for organizations that run Windows, macOS and Linux machines side by side. The identity side starts with Cloud Directory and Identity Lifecycle Management for onboarding and offboarding. Single Sign-On connects applications over SAML 2.0 and OpenID Connect, with a catalog of pre-configured connectors and a User Portal where people open their apps. Multi-Factor Authentication, Cloud LDAP, Cloud RADIUS and Privileged Access Management sit beside it. Access Request routes approvals, and Directory Insights records SSO sign-in events. On the device side, Unified Endpoint Management covers Windows Management, Apple MDM, Linux Management and Android EMM, with Patch Management, Remote Access, Asset Management and System Insights. Agentic IAM lets AI agents use SSO applications assigned through agent groups. JumpCloud suits IT admins and security teams at growing companies, and managed service providers that run IT for many clients through the Multi-Tenant Portal. It fits organizations moving off on-premises Active Directory, and companies on Google Workspace or Microsoft 365 that want a directory alongside them. The platform is sold as packages priced by user (Device Management, SSO and Device Identity Management), quote-based Platform tiers, and a la carte products bought one at a time. Administrators work in the admin portal, while employees see application tiles and their assigned devices in the User Portal. Approvers handle requests in Tasks and Access Requests. The directory can take sign-ins from Google Workspace, Entra ID or Okta as the upstream identity provider, and Google, AWS and CrowdStrike are listed as technology partners. Security teams export SSO sign-in events from Directory Insights or pull them through the API for audit work.
Features
- Included: SAML 2.0 identity provider
- Included: OpenID Connect identity provider
- Included: Pre-configured SSO connectors for popular apps
- Included: Password vaulting for apps without federation
- Included: End-user app launcher portal
- Included: Desktop SSO from a domain-joined device
- Not included: Mobile SSO for native apps
- Included: Group-based app assignment
- Included: IdP-initiated and SP-initiated flows
- Not included: Custom attribute mapping and claims
- Included: Federation with external identity providers
- Not included: Per-app sign-on policies
- Not included: Session timeout and global sign-out
- Not included: Custom-branded employee sign-in page
- Included: Sign-in activity reports
- Included: Just-in-time user creation on first login
- Not included: Free tier for small teams
- Not included: Uptime SLA published
Additional Features
- SAML 2.0 and OpenID Connect single sign-on
- Catalog of pre-configured application connectors
- Cloud Directory
- Identity Lifecycle Management
- Multi-Factor Authentication
- Cloud LDAP
- Cloud RADIUS
- Privileged Access Management
Best for
- IT teams running Mac, Windows and Linux fleets from one console
- Organizations replacing on-premises Active Directory with a cloud directory
- Managed service providers running many client organizations
- Google Workspace or Microsoft 365 companies adding a directory beside them
- Organizations of up to 300 users buying Platform Essentials
- IT teams automating employee onboarding and offboarding
- Security teams working toward Zero Trust and compliance evidence
Use cases
- Signing employees in to SaaS apps over SAML or OIDC
- Replacing on-premises Active Directory with a cloud directory
- Enrolling and managing Mac, Windows, Linux and Android devices
- Automating onboarding and offboarding
- Going passwordless
- Approving access requests through set approval flows
- Auditing SSO sign-in events in Directory Insights
- Assigning applications to user groups
- Federating with Google Workspace, Entra ID or Okta as the upstream identity provider
- Tracking device inventory and asset status
- Connecting AI agents to assigned SSO applications through an AI gateway
- Reviewing shadow IT and SaaS usage
Screenshots & Videos
Explore JumpCloud in action