The JumpCloud integration enables your security and compliance teams to sync personnel identities into Drata and provision user accounts. This connection is typically established early in the onboarding process to help automate access-related compliance controls and build your source of truth for identity in Drata.
Key Capabilities
This integration enables the following functionality for visibility and compliance:
Automated personnel sync: Continuously imports users and groups into Drata, populating the Personnel page with identity source-of-truth data.
Enables access-based controls: Supports identity-related compliance tests (e.g., MFA enforcement, unique accounts).
Foundation for SSO: Required to enable Single Sign-On (SSO) through JumpCloud.
This integration supports compliance monitoring tests like:
Test 86: MFA on Identity Provider
Test 96: Employees Have Unique Email Accounts
Prerequisites & Data Access
JumpCloud Admin access: You must be able to generate an API key.
Drata Role Required: Admin, Workspace Manager, or DevOps Engineer. Access Reviewers can only view the connection page
Domain Matching: If your organization uses multiple email domains and hasn’t enabled multi-domain sync, contact Drata Support to activate this capability.
Permissions & Required Fields
Permission / Field | Why It’s Needed |
API Key (read-only) | Retrieves personnel and group data from JumpCloud |
Group ID (optional) | Allows limiting the sync to a specific group |
Step-by-Step Setup
Step 1: Generate Your JumpCloud API Key
Log in to your JumpCloud Admin Console.
Click your profile icon → My API Key.
Click Generate New API Key if you don’t have one.
Copy the generated key.
Expected outcome: You have your API key ready to authorize Drata’s connection.
Step 2: Connect JumpCloud in Drata
In Drata, go to the Connections page.
Search for JumpCloud.
Start the connection process.
Paste your API key when prompted.
Expected outcome: Drata authenticates your API key and begins syncing personnel from JumpCloud. Initial sync may take up to one hour depending on your organization size.
Step 3: Limit Sync Scope by Group
You can restrict which users sync into Drata by specifying a JumpCloud group.
Go to your JumpCloud IdP connection in Drata.
Select the edit icon next to Setup details.
Enter the exact name of the JumpCloud group you want to sync. You can find available groups at JumpCloud Groups.
Ensure the group includes your Drata administrator.
Save your changes.
Expected outcome: Drata limits personnel sync to the specified role.
Next Steps
You may enable Single Sign-On (SSO) to allow personnel to log in to Drata using JumpCloud credentials.
