Back to main siteBack Contact us
Open Directory

JumpCloud

Identity and Access

One directory for people, devices and the things they sign in to

JumpCloud combines the directory, single sign-on, multi-factor authentication and device management into one cloud service covering Windows, macOS and Linux. It is aimed squarely at organizations that never had a domain controller, or would like to stop having one.


The shape of the problem

Identity ended up split across three or four products

Very few organizations chose this arrangement. It accumulated, one reasonable decision at a time.

The directory stayed where it was

And the rest of the estate left

Many businesses still run a directory built for an office full of Windows desktops on one network, while the actual estate is laptops on home broadband, Macs in the design team, and thirty cloud applications that never joined a domain at all. The directory is still authoritative for some of it, which is the awkward part: it cannot be switched off, and it no longer describes reality.

What usually happens next is a patch. Single sign-on is bought for the cloud applications, a device management product is bought for the Macs, and something is put in place to synchronise identities between them. Each purchase is sensible. The result is an identity system with three sources of truth and a synchronisation job nobody wants to touch.

Leaving becomes a checklist

The moment the split shows

The test of an identity arrangement is what happens when somebody leaves on a Friday. In a single directory, one disable removes access everywhere. In a split arrangement, it removes access in some places, leaves a laptop still logged in, and depends on a person remembering the applications that were never connected.

That gap is not theoretical. Former employees retaining access to a file store or a finance system is among the more common findings in a security review, and it is almost always caused by the arrangement rather than by carelessness.

Ask how long it takes to remove somebody completely today, and how you would prove it was done. The answer sizes this problem exactly.

Where it sits

One authority, connected outward to everything else

The idea is not new. What is different is that the directory itself is a cloud service, so the devices it governs never need to be on your network.

One directory people, groups, policy delivered as a service DEVICES Windows laptops Macs Linux workstations Phones and tablets RESOURCES Microsoft 365 Cloud applications File shares Servers and networks Disable a person once, and every line above goes with them
The arrangement being argued for. Whether it is worth changing to depends almost entirely on how much of the left-hand column you currently manage separately.
What the platform covers

The functions, and what each typically replaces

The commercial case rests on the bundle. It is worth listing what you pay for separately today before accepting that case.

Cloud directory
The authoritative record of people and groups, running as a service rather than on a server you patch. This is the part that replaces or sits beside a traditional domain.
Single sign-on
One set of credentials across cloud applications, so joiners and leavers are handled in one place rather than in each vendor's admin console.
Multi-factor authentication
Enforced at the directory, which means it also covers signing in to the laptop itself rather than only to web applications.
Device management
Configuration, policy and patching across Windows, macOS and Linux from one console. Cross-platform coverage is the specific reason many organizations look at this product at all.
Privileged access and password management
Control of administrative rights and a credential store, included rather than bought separately. Verify the depth of each against your requirements, since a bundled component is rarely as deep as a specialist one.
List what you currently pay for separately →
An honest read

Who this is for, and who already owns something better

The comparison that usually decides this, stated plainly.
If your situation isThe likely right answer
Mixed Windows, Mac and Linux, no domain controllerThis is the case JumpCloud is built for
Entirely Microsoft, on a Business Premium or E3 licenceCheck Entra ID and Intune first; you may already own it
Large enterprise with complex federation and governanceA specialist identity platform will go deeper
An ageing domain controller nobody wants to replaceWorth a serious look, and plan the migration carefully
Twenty staff, all on Google WorkspaceProbably more directory than you need today

What to check before committing

Three specifics that change the maths

Pricing is tiered by function, so the useful exercise is to establish which tier actually covers your requirements and compare that figure with the sum of what you pay now. Ask about the migration path from whatever holds your identities today, because that project, not the licence, is the real cost. And confirm which components meet any regulatory obligation you carry, rather than assuming a bundled feature satisfies a requirement written for a specialist product.

In short

Start with the leaver test

Pick the last person who left. List everywhere they had access, and how each one was removed. If that list took longer than a minute to assemble, the arrangement is the problem rather than the process.

Review Your Identity Setup

Get in touch with Your Company

Questions about this solution? Reach us directly.