Jumpcloud Integration
JumpCloud directory and device event ingestion for cloud-first identity security.
What this integration does
JumpCloud meets agentic SOC
JumpCloud's open directory platform generates user directory events, SSO authentication logs, RADIUS events, and device management commands. ManySignal ingests JumpCloud events via the JumpCloud Directory Insights API, providing identity and device security visibility for organisations using JumpCloud as their primary directory service.
JumpCloud Directory Insights API integration
SSO authentication event collection
LDAP and RADIUS authentication log ingestion
Data collected
- Directory Insights events (authentication, user changes, admin actions)
- SSO session events for connected applications
- RADIUS authentication events for VPN and Wi-Fi
- MDM device lock, wipe, and policy compliance events
- Admin user action events
Actions supported
- Suspend JumpCloud user account via API on verdict
- Force user password reset via JumpCloud API
- Remove user from a JumpCloud group
- Lock device via MDM command
Getting started
Set up in minutes
- 1
Generate a JumpCloud API key
- 2
Add the connector in ManySignal
- 3
Configure response actions
- 4
Enable device monitoring
Jumpcloud Integration: frequently asked questions
What is the JumpCloud Directory Insights event retention period?
JumpCloud retains Directory Insights events for 15 days on standard plans and up to 90 days on enterprise plans. ManySignal backfills within the available retention window.
Can ManySignal detect JumpCloud account takeover?
Yes. Anomalous sign-in events (new country, new device, unusual time) and impossible travel detections work across JumpCloud SSO authentication events.
Does ManySignal support JumpCloud RADIUS for VPN monitoring?
Yes. JumpCloud RADIUS authentication events for VPN and Wi-Fi are ingested and correlated with other identity events for the same user.
How does JumpCloud integrate with device context?
JumpCloud MDM-managed devices are identified by device ID in authentication events. ManySignal correlates these with endpoint telemetry if a complementary EDR connector (CrowdStrike, SentinelOne) is also active.
Can ManySignal detect when a JumpCloud admin adds or removes a user from a privileged group?
Yes. Group membership change events appear in Directory Insights. ManySignal alerts on changes to groups associated with privileged system access or high-value SaaS applications.
Does ManySignal support JumpCloud's Zero Trust Network Access (ZTNA)?
JumpCloud ZTNA access events are captured in Directory Insights. ManySignal treats ZTNA policy violations as high-priority events.
What response actions can ManySignal take?
User account suspension, password reset, group removal, and device lock are supported via the JumpCloud API. All actions are logged with the triggering alert evidence in ManySignal.
Does this work with JumpCloud's Google Workspace and Microsoft 365 integrations?
JumpCloud's integrations with Google Workspace and Microsoft 365 generate events in Directory Insights. ManySignal ingests these alongside direct Google Workspace and Microsoft 365 connectors.
How quickly do JumpCloud events appear in ManySignal?
ManySignal polls the Directory Insights API every 60 seconds, providing approximately 1-minute event latency for high-priority security events.
Is there support for JumpCloud's SCIM provisioning events?
SCIM provisioning and deprovisioning events appear in Directory Insights as user creation and deletion events, tagged with the SCIM source application.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.