
Connect JumpCloud to Lutril
Lutril connects to JumpCloud with an administrator API key and governs the people in your JumpCloud organization: it reads every user with whether they hold sudo on their devices, whether multi factor is enrolled, and which user groups they belong to. It time boxes access two ways. Somebody with no account gets one created without a password, so JumpCloud sends its own activation mail and Lutril never holds a credential; the deadline suspends that account. Somebody who already has an account is added to one user group for the life of the grant, and the deadline removes that membership and nothing else. Lutril governs JumpCloud as an application here, not as the identity provider your access reviews are reconciled against.
Access requested
- An API key created by an administrator who can manage users and groups. The key inherits that administrator's rights.
- If your organization uses scoped API keys: users, users.create (to provision) and groups.
Setup steps
- 1
Sign in to the JumpCloud Admin Portal as an administrator who can manage users and user groups, open your account menu at the top right, and copy the API key. The key carries that administrator's rights, so create it from an account that really can manage people.
JumpCloud APIs overview - 2
Note the region your organization lives in. It is in the address you sign in to: console.jumpcloud.com for the United States, console.eu.jumpcloud.com for the European Union, console.in.jumpcloud.com for India. A key created in one region is not accepted by another.
- 3
In Lutril, connect JumpCloud, paste the API key and pick the matching region. Leave the Organization ID empty unless you are on a Managed Service Provider portal where one key reaches several organizations.
- 4
To time box JumpCloud access, set the access levels on the JumpCloud app in your catalogue to your own user groups. A group is what opens SSO applications, LDAP, RADIUS and machines, so it is the unit a grant can genuinely hand back at a deadline.
Get started with user groups - 5
Lutril NEVER deletes a JumpCloud account, by any path. A deadline suspends it, and so does offboarding and an access review decision, because all three go through the same route. Deleting a user would destroy its identifier, its SSH keys, its group memberships and the link to the machines it owns; suspension keeps all of it and is undone in one call.
Suspend and reactivate users - 6
A grant only ever adds. Anyone already in the group they asked for is left exactly as they were, so a deadline can never take away a membership that Lutril did not grant.
- 7
Lutril does not detect JumpCloud console administrators. The only endpoint that lists them is scoped to Managed Service Provider portals and returns identifiers without addresses, so there is no reliable way to tie one to a person. What Lutril does report is sudo, which is local administration on every device a person is bound to, and that is the standing privilege worth reviewing.
Where to create it
Official docs
Sign in to Lutril to connect JumpCloud, or book a demo and we set it up with you. No slides.