Skip to content

JumpCloud configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On JumpCloud, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the JumpCloud connector needs.

Checks (3)

severity: high System SSH Password Authentication Enabled fix difficulty: medium #

Disable SSH password authentication on managed systems

  1. Open JumpCloud Admin Console > Devices and select the flagged system
  2. Disable "Allow SSH password authentication" and require public-key auth
  3. Verify users have SSH keys provisioned before enforcing

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high System SSH Root Login Enabled fix difficulty: easy #

Disable SSH root login on managed systems

  1. Open JumpCloud Admin Console > Devices and select the flagged system
  2. Disable "Allow SSH root login"
  3. Use sudo-based elevation for administrative tasks instead

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Dynamic User Group Without Restriction fix difficulty: medium #

Review dynamic user groups that auto-add members by query

  1. Open JumpCloud Admin Console > User Groups and select the dynamic group
  2. Confirm the membership query is scoped and intended
  3. Restrict over-broad queries that could auto-grant access

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More JumpCloud checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial