This guide is for businesses that get JumpCloud Platform Prime through Olimar, a JumpCloud partner and JumpCloud managed service provider. It follows the order of a project: order, manage your users, deploy, then use it day to day.
Who does what. Olimar is the sole administrator of your company’s JumpCloud organization: you do not have access to the JumpCloud administration console.
- You manage your users and your number of licenses in your JumpCloud area of the Olimar client portal.
- Olimar handles configuration: user import, SSO, MFA, device policies, MDM, Microsoft 365 and Google Workspace integrations. It does this on request to support, or as part of a deployment package.
- Your employees use JumpCloud’s User Portal: activating their account, MFA, applications, installing the agent, enrolling their devices.
Technical procedures summarize JumpCloud’s official documentation, read on September 24, 2026; each one links to its source article. If anything differs, the official article prevails. Recommendations marked “Olimar” are ours, not JumpCloud’s.
Getting started with Olimar
Ordering on the portal
- Go to the Olimar client portal, then sign in or create your company’s account.
- Choose JumpCloud Platform Prime and enter your number of licenses, between 5 and 50. Above 50, submit a guided deployment request: Olimar sends you a quote.
- Pay when you order. There is no free trial and no Founder Offer for JumpCloud. See Billing and account.
Prices are on the Pricing page.
Declaring a business purchase
JumpCloud is for businesses only. When you order, you check the following declaration; without it, the order is refused:
I am buying on behalf of a business, for professional use.
The order also reminds you that the service is hosted in the United States.
Your JumpCloud area in the Olimar portal
Once payment is confirmed, Olimar creates your company’s JumpCloud organization. You then manage it from your JumpCloud area of the Olimar portal, without a JumpCloud console:
- add, remove or suspend a user;
- reset a user’s password;
- adjust your number of licenses, between 5 and 50 (see Billing and account).
For any other configuration (SSO, policies, MDM, integrations), write to Olimar support.
What your employees receive
When a user is created, JumpCloud sends them a welcome email. If no password was set for them, this email contains a link to set their own password and activate their account. Source: Best Practices for Creating Users.
The employee then signs in to JumpCloud’s User Portal at https://console.jumpcloud.com/userconsole: they enter their work email, click Continue, then enter their password. Source: Get Started: User Portal.
The User Portal is not an administration console: employees only see their own applications, devices and security settings.
Setting up MFA (employees)
When MFA is required, the User Portal asks for it at sign-in (Verify Your Identity):
- click Continue;
- install an authenticator app — JumpCloud recommends JumpCloud Protect —, then click I Have the App;
- scan the QR code and enter the 6-digit code shown by the app;
- keep the key shown under the QR code in a safe place: it is used if the phone is lost.
If enrollment is not completed before the enrollment period ends, the account is locked and must be unlocked by the administrator, that is, Olimar. Source: Users: Set up Authenticator App. To sign in afterwards: Users: Log in to User Portal with MFA.
Installation
Installation happens at two levels: Olimar prepares the organization and the enrollment methods; your employees (or your IT team) install the agent and enroll their devices.
What Olimar sets up
Depending on your fleet and package, Olimar configures:
- Apple MDM, with an Apple Push (APNs) certificate renewed every year. Renewal requires the same Apple ID: Olimar creates it with you, in the company’s name. Source: Set Up Apple MDM;
- Automated Device Enrollment (ADE) of Apple devices bought by the company, if you have an Apple Business Manager account. The token is renewed every year. Source: Configure ADE;
- Android Enterprise, connected to a Google administrator account of your company. Source: Set Up Android EMM;
- agent installation from the User Portal, or through a mass deployment (see below). Source: Install the Agent.
Network requirements (your IT team)
The JumpCloud agent accepts no inbound connections: it connects out to JumpCloud’s services. Downloading it requires TLS 1.2 or later. If your firewall filters outbound traffic, allow the following domains — the article’s “Everywhere Else” list, which applies to organizations outside the European Union and India. Source: Agent Networking and Port Requirements.
| Domain | Port | Note |
|---|---|---|
agent.jumpcloud.com | 443 | |
kickstart.jumpcloud.com, private-kickstart.jumpcloud.com | 443 | |
console.jumpcloud.com | 443 | |
cdn02.jumpcloud.com, cdn03.jumpcloud.com | 443 | |
thirdparty.jumpcloud.com | 443 | |
a1hrq03pdcca60-ats.iot.us-east-1.amazonaws.com | 443 | |
s3.amazonaws.com | 443 | |
assist.jumpcloud.com | 443 | Remote Assist |
*.pwm.jumpcloud.com (including cdn.pwm.jumpcloud.com, devices.pwm.jumpcloud.com) | 443 | Password vault |
chocolatey.org | 443 | Windows software management; packages may download files from their vendors |
pool.ntp.org | 123/UDP | Time sync, optional if your internal network provides it |
If you use LDAP or RADIUS: ldap.jumpcloud.com on ports 636 (LDAPS) and 389 (StartTLS), and radius.jumpcloud.com on port 1812. Sources: Create an Allow List for JumpCloud Services and JumpCloud Data Centers.
Apple and Android devices managed by MDM also talk to Apple’s and Google’s services: check their own network requirements.
Installing the agent on your computer (employees)
Once remote install is enabled for your organization, each employee installs the agent on their work computer — never on a personal computer without the company’s approval:
- sign in to the User Portal;
- go to Security, Device Enrollment tab;
- choose your system (Windows, Mac or Linux), download the agent, then install it.
Source: Install the JumpCloud Agent from the User Portal.
Supported systems: Windows 11 and 10 (64-bit), Windows Server 2016 to 2025, recent macOS releases (Intel and Apple processors), and the main Linux distributions (Ubuntu, Debian, Red Hat Enterprise Linux, Rocky Linux, Fedora, Amazon Linux, Linux Mint). Source: Agent Compatibility, System Requirements, and Impacts.
On Mac, JumpCloud recommends MDM enrollment rather than a command-line install: the enrollment profile also installs the agent. Source: Add Company-Owned Apple Devices to MDM.
Mass deployment (with Olimar)
For a large fleet, Olimar gives you the install command, which contains your organization’s connect key, for your IT team to run. Treat this key as a secret: it lets anyone enroll devices in your organization.
- Windows: silent install of the MSI package, for example through GPO. Source: JumpCloud Agent Windows Installation Walkthrough.
- Linux: an install script run with
sudo; then check the service withsystemctl status jcagent. Source: Install the Linux Agent.
Enrolling a mobile device (employees)
- Company device: Olimar gives you a QR code or an enrollment link. On iPhone and iPad, the enrollment profile expires after one hour. Source: Add Company-Owned Apple Devices to MDM. On Android, a new or factory-reset device enrolls by scanning a QR code. Source: Add and Manage Android Devices.
- Personal device, if your company allows it: on iPhone and iPad, once Olimar enables the option, the employee enrolls the device from the User Portal (Enroll your iOS Device); a Managed Apple ID must be associated with their account. Source: Add Personal Apple Devices to MDM with User Enrollment. On Android (5.1 or later), a Work Profile keeps personal data separate from company data; Olimar tells you how to proceed. Source: Add and Manage Android Devices.
Before allowing personal devices, read Personal information.
Deployment
Deployment is carried out by Olimar, with you: you decide the rules, Olimar applies them. In guided mode, it is part of your package; with online ordering, it is ordered from support, by the hour or with a block of hours.
1. Plan and take inventory (you)
Olimar recommendations. Prepare the inventory we will use:
- users: who, with which work email, in which team;
- devices: how many, on which system (Windows, macOS, Linux, iOS, Android), who owns them (company or personal);
- the applications in use, and which already support SAML or OIDC;
- your current directory: Microsoft 365 / Entra ID, Google Workspace, Active Directory, or none.
Count your users before ordering: every account in the organization uses a license (see Billing and account).
2. Import users (Olimar)
Olimar creates your users from the source that suits you. Source: Add Users to the Admin Portal.
- CSV file: first name, last name, username, email address (unique for each user).
- Microsoft 365 / Entra ID: import of existing users, then account creation, attribute sync and security group management in Microsoft 365. Source: M365 Directory Integration.
- Google Workspace: manual import, or automatic every hour. Once a user signs in to their JumpCloud portal, JumpCloud becomes authoritative for their password and pushes it to Google. Source: Google Workspace Directory Integration.
- Active Directory: import from AD into JumpCloud, two-way sync, or a gradual move to JumpCloud. Source: Get Started: Active Directory Integration.
3. Organize groups (Olimar)
In JumpCloud, nothing is accessible by default: connecting a user or group to a resource is what grants access to it. Source: Get Started: User Groups.
Olimar recommendation: one group per team, a “Pilot” group for step 9, and one device group per operating system.
4. Link existing computer accounts (Olimar, with your employees)
Olimar binds each user to their computer. If the JumpCloud username exactly matches the existing local account, JumpCloud takes over that account instead of creating a second one. Sources: Bind Users to Devices and Take Over an Existing User Account with JumpCloud.
What your employees need to know, from these articles:
- after takeover, they are logged out of their applications and browsers: warn them;
- Windows: their local password and JumpCloud password must be identical before binding, or passwords saved in Windows Credential Manager are lost;
- macOS: they must log out and back in, entering the old and new passwords, to update the keychain and FileVault.
5. Connect SSO to applications (Olimar)
Olimar connects your applications through SAML or OIDC, from JumpCloud’s pre-built connectors, and opens them to the relevant groups. Your employees then launch them from their User Portal. Source: Get Started: Applications.
- Microsoft 365: first requires the Microsoft 365 directory integration. Source: SSO with Microsoft 365.
- Google Workspace: requires a Business, Enterprise or Education edition. Source: SSO with Google Workspace.
- Slack: requires a Slack Business+ or Enterprise Grid plan. Source: Integrate with Slack.
6. Require MFA (Olimar)
Olimar requires MFA for the User Portal, with an enrollment period of 1 to 365 days, or through a conditional access policy. Source: Require MFA for Users. MFA can also protect computer sign-in. Source: Enable TOTP MFA for Devices.
Olimar recommendation: ask your employees to enroll their factor (see Setting up MFA) before it is enforced, as JumpCloud advises.
7. Apply device policies (Olimar)
Baseline recommended by Olimar, to be confirmed with you:
- Windows encryption (BitLocker): requires Windows 10 or 11 Pro or Enterprise and a TPM 2.0 chip; the recovery key is kept by JumpCloud. Source: BitLocker Policy;
- macOS encryption (FileVault): requires MDM enrollment. Source: Create a Mac FileVault 2 Policy;
- screen lock, one policy per system: Windows, macOS, Linux;
- OS patches for macOS, iOS, Windows and Linux (Ubuntu), and browsers. Source: Get Started: Patch Management.
8. Configure conditional access (Olimar)
Access to the User Portal and applications can be denied, allowed with MFA or allowed, depending on whether the device is managed, whether its disk is encrypted, its IP address, its country or its operating system. Sources: Get Started: Conditional Access Policies and Configure a Conditional Access Policy.
Olimar recommendation: start with “allow with MFA” for everyone, then require a managed device for sensitive applications once your devices are enrolled.
9. Pilot, then roll out
Olimar recommendations:
- Pilot: 3 to 5 volunteer employees, with at least one device per system in your fleet, for one to two weeks.
- Review: we adjust the policies that get in the way, and you prepare a one-page guide for your employees.
- Rollout: team by team, computers first, then mobile devices.
10. When an employee leaves
Olimar checklist:
- On the day of departure, suspend the user in your area of the Olimar portal. Suspension revokes all their access and logs them out of their computer; on Windows Home, it only takes effect at the next logout or restart. Source: Suspend and Reactivate Users.
- Recover their devices. If needed, ask Olimar support to lock or erase them remotely. Erasing is irreversible. Sources: Use Windows and Linux Security Commands and MDM Commands.
- Transfer their files and shared mailboxes in your other tools, following your own procedures.
- Remove the user once the transition is done: a suspended user still uses a license; only removal frees it. Source: Manage User States.
Day-to-day use
In your area of the Olimar portal
- Add a user: they receive their welcome and activation email. First check that you have a free license.
- Suspend, then remove a departing user (see when an employee leaves).
- Reset a password for a locked-out employee.
- Adjust your number of licenses (see Billing and account).
What your employees do themselves
In the User Portal, Security section, employees can reset their password, manage their MFA and enroll their devices. They also launch their applications and open the password vault there. If they forgot their password, the Reset User Password link on the sign-in page lets them reset it. Source: Get Started: User Portal.
New phone? The employee resets their MFA by following Users: Reset MFA in User Portal.
Reports
JumpCloud produces reports: users to devices, SSO applications, patches, OS versions, software inventory, device security and more. Source: JumpCloud Reports. The event log is kept 90 days. Source: Directory Insights. Ask Olimar support for them.
Remote control (Remote Assist)
To help you, Olimar support can take control of a Windows, macOS or Linux computer with Remote Assist, installed automatically with the agent. Depending on the mode, the employee accepts the session or shares a one-time code. On macOS, they must grant the Screen Recording and Accessibility permissions. Source: Get Started: Remote Assist.
Olimar’s commitment: we only take control of a computer in use with the employee’s consent.
Billing and account
Pricing
| Item | Price, before tax |
|---|---|
| JumpCloud Platform Prime subscription | $30 per license (one user) per month |
| Minimum | 5 licenses, i.e. $150 per month |
| Essential deployment (one-time) | $720, 6 hours |
| Standard deployment (one-time) | $1,440, 16 hours |
| Custom deployment | by quote |
| Hourly support | $120 per hour |
| Support block | $500 for 5 hours |
Prices in Canadian dollars, taxes extra. If anything differs, the Pricing page prevails.
Licenses
- One license = one user in your JumpCloud organization, whether active or suspended: only removing a user frees their license. Source: Billing FAQ.
- You manage your number of licenses yourself in your area of the Olimar portal, between 5 and 50.
- Above 50 licenses, it is by quote. Exception: after at least 3 consecutive months paid with no missed payment, you can go above 50 licenses yourself, from the portal.
Charges
- On the last day of each month, the number of licenses configured at that time is charged for the following month.
- No proration: a license added during the month is billed as a full month, paid immediately.
- A decrease is never refunded: it applies to the end-of-month charge.
- No commitment, no free trial, no Founder Offer.
Payment by invoice
On request, and from 50 licenses only, Olimar may accept payment by invoice, due in 30 days. Write to us to ask.
Failed payment and deactivation
- If a charge fails, you are notified by email.
- If the invoice is still unpaid on the 1st of the month, all accounts in your JumpCloud organization are deactivated: your employees can no longer sign in.
- Reactivation: as soon as payment is received, the accounts deactivated by Olimar are reactivated. Users you had suspended yourself stay suspended.
Update your payment method from your Olimar client portal.
Cancellation
The subscription has no commitment. To cancel, write to info@olimar.ca or use your client portal. Olimar then asks JumpCloud to remove your organization. Before cancelling, ask us for the reports and logs you want to keep, and plan how your devices and accounts will be managed afterwards. The full terms are in the terms and conditions of sale.
Personal information
JumpCloud holds information about your employees: names, email addresses, devices, sign-in logs. It is hosted in the United States by JumpCloud Inc. As the administrator of your organization, Olimar has access to it to provide the service and support. Your company remains responsible for its employees’ personal information: these recommendations help, but they are not legal advice.
Olimar recommendations:
- Prefer professional information: work email, title, team. Don’t store personal addresses or phone numbers, or information with no use for access management.
- Avoid BYOD, or limit it. If you allow personal devices, use the modes designed for them — Apple User Enrollment, Android Work Profile — rather than full enrollment, and apply only the policies you need.
- Tell your employees what the company sees and does: device inventory, sign-in logs, remote control, possible locking or erasing of a device.
- Do your own assessment. Your employees are concerned, and their information is communicated outside Québec: Québec’s Law 25 may require a privacy impact assessment before that communication. Carry it out, or have your advisor do it.
- Limit retention: remove former employees’ users once the transition is done.
JumpCloud’s security commitments (SOC 2 Type 2, ISO 27001) are presented at jumpcloud.com/security.
Support
Olimar, your first level
Olimar is your only contact for JumpCloud. JumpCloud provides second-level support to Olimar only: do not contact JumpCloud directly.
- By email: info@olimar.ca, or through the contact form.
- Online ordering: on-demand support, by the hour or with a block of hours, ordered from your client portal. Prices are on the Pricing page.
- Guided mode: your deployment package includes the support set out in your quote.
To speed things up, include your company’s name, the user or device concerned, and what you have already tried.
JumpCloud resources for your employees
- Get Started: User Portal — the User Portal;
- Users: JumpCloud Protect App Overview — the MFA app;
- JumpCloud Status — if a service seems down.