JumpCloud
One directory for people, devices and the things they sign in to
JumpCloud combines the directory, single sign-on, multi-factor authentication and device management into one cloud service covering Windows, macOS and Linux. It is aimed squarely at organizations that never had a domain controller, or would like to stop having one.
Identity ended up split across three or four products
Very few organizations chose this arrangement. It accumulated, one reasonable decision at a time.
The directory stayed where it was
And the rest of the estate leftMany businesses still run a directory built for an office full of Windows desktops on one network, while the actual estate is laptops on home broadband, Macs in the design team, and thirty cloud applications that never joined a domain at all. The directory is still authoritative for some of it, which is the awkward part: it cannot be switched off, and it no longer describes reality.
What usually happens next is a patch. Single sign-on is bought for the cloud applications, a device management product is bought for the Macs, and something is put in place to synchronise identities between them. Each purchase is sensible. The result is an identity system with three sources of truth and a synchronisation job nobody wants to touch.
Leaving becomes a checklist
The moment the split showsThe test of an identity arrangement is what happens when somebody leaves on a Friday. In a single directory, one disable removes access everywhere. In a split arrangement, it removes access in some places, leaves a laptop still logged in, and depends on a person remembering the applications that were never connected.
That gap is not theoretical. Former employees retaining access to a file store or a finance system is among the more common findings in a security review, and it is almost always caused by the arrangement rather than by carelessness.
Ask how long it takes to remove somebody completely today, and how you would prove it was done. The answer sizes this problem exactly.
One authority, connected outward to everything else
The idea is not new. What is different is that the directory itself is a cloud service, so the devices it governs never need to be on your network.
The functions, and what each typically replaces
The commercial case rests on the bundle. It is worth listing what you pay for separately today before accepting that case.
- Cloud directory
- The authoritative record of people and groups, running as a service rather than on a server you patch. This is the part that replaces or sits beside a traditional domain.
- Single sign-on
- One set of credentials across cloud applications, so joiners and leavers are handled in one place rather than in each vendor's admin console.
- Multi-factor authentication
- Enforced at the directory, which means it also covers signing in to the laptop itself rather than only to web applications.
- Device management
- Configuration, policy and patching across Windows, macOS and Linux from one console. Cross-platform coverage is the specific reason many organizations look at this product at all.
- Privileged access and password management
- Control of administrative rights and a credential store, included rather than bought separately. Verify the depth of each against your requirements, since a bundled component is rarely as deep as a specialist one.
Who this is for, and who already owns something better
| If your situation is | The likely right answer |
|---|---|
| Mixed Windows, Mac and Linux, no domain controller | This is the case JumpCloud is built for |
| Entirely Microsoft, on a Business Premium or E3 licence | Check Entra ID and Intune first; you may already own it |
| Large enterprise with complex federation and governance | A specialist identity platform will go deeper |
| An ageing domain controller nobody wants to replace | Worth a serious look, and plan the migration carefully |
| Twenty staff, all on Google Workspace | Probably more directory than you need today |
What to check before committing
Three specifics that change the mathsPricing is tiered by function, so the useful exercise is to establish which tier actually covers your requirements and compare that figure with the sum of what you pay now. Ask about the migration path from whatever holds your identities today, because that project, not the licence, is the real cost. And confirm which components meet any regulatory obligation you carry, rather than assuming a bundled feature satisfies a requirement written for a specialist product.
Start with the leaver test
Pick the last person who left. List everywhere they had access, and how each one was removed. If that list took longer than a minute to assemble, the arrangement is the problem rather than the process.
Review Your Identity SetupGet in touch with Your Company
Questions about this solution? Reach us directly.