Use JumpCloud to Restrict Access to Apps Outside of Venn’s Blue Border

JumpCloud’s conditional access policies can be used to restrict access to any SSO application that uses JumpCloud as the Identity Provider so that they can only be used securely in Blue Border. 

For example, if your users log in to Zoom with their JumpCloud credentials, you can restrict access to Zoom with a conditional access policy scoped to that application. 

Access for SSO apps is evaluated on sign-in.

Requirements

Adding a condition to a JumpCloud access policy — including the IP Address condition used in this article — turns it into a conditional access policy. This is a Premium feature available as part of JumpCloud’s Platform Prime plan. Visit this JumpCloud resource to learn more about Conditional Access Policies.

JumpCloud Resources

JumpCloud doesn’t have a dedicated “report-only” or “monitor” mode like Entra ID or Google Workspace. The closest equivalent is to enable the policy in a non-blocking state first and confirm it’s matching the right sign-ins in Directory Insights before you switch it to deny access, as shown in the Approach below. Directory Insights is a separate add-on that isn’t included in every JumpCloud plan — contact your JumpCloud account manager if you don’t already have it enabled.

Approach

  1. Gather your PCG IP addresses.
  2. Create an IP list in JumpCloud for your PCG IP addresses (instructions here).
  3. Create a Conditional Access Policy for the SSO Applications resource (instructions here).
    • Under Assignments, select the specific application(s) you want to restrict and the user group(s) you want the policy to apply to.
    • Under Conditions, add an IP Address condition, set the Operator to Is Not On List, and select the IP list you created in step 1 as the Value.
    • Under Action, set Access to Allowed (not Denied) for now, so you can test the policy without blocking anyone.
    • Enable the policy in this non-blocking state.
  4. If you have Directory Insights enabled, go to Insights Directory and review conditional access policy events over a few days to confirm the policy is correctly matching sign-ins from outside your PCG IP addresses for the application(s) and user group(s) you assigned it to (instructions here).
  5. Once you’ve confirmed the policy identifies the correct sign-ins, edit the policy and change Action to Denied to start blocking access from outside your PCG IP addresses.

Warnings

  • Do not apply this policy — or any policy that denies access from outside your PCG IP addresses — to the Admin Portal or the User Portal in order to avoid locking out administrators.
  • If JumpCloud is your Venn identity provider, do not add this policy to the SSO application entry Venn uses to authenticate users, in order to avoid blocking users from being able to log in to Venn’s Workplace app.
  • If you are not using Venn’s MDM solution, only apply this restriction to the device types users will be using Venn on (Windows and/or Mac). Add an Operating System condition set to Is with Windows and/or macOS selected, and set the policy to All of the following conditions must match for this policy to apply so that both the Operating System and IP Address conditions must be true before access is denied.
  • A policy set to deny access always takes precedence over a policy that allows access, even with MFA. Double-check the users and applications assigned to a denial policy before enabling it so you don’t accidentally lock out users who need access.
  • Keep in mind that there may be use cases and exceptions that you are not aware of or there may be individuals at your organization who were not fully onboarded to Venn.
    • If possible, set the access to Allowed and review conditional access policy events over a few days before changing the action to Denied as outlined above to test the restriction before blocking access.
    • Always notify users before enabling restrictions in order to avoid disruption of business. Leverage the Access Lockdown email template in the Venn Rollout Toolkit to inform your users.

Tips

  • If JumpCloud is set up as your Venn identity provider, consider assigning this policy to the same user group(s) that you use to assign access to Venn’s Workplace app.
  • Conditional Access Policies can be used to restrict access to any SSO application configured in JumpCloud. Consider setting up JumpCloud SSO for key business applications so that you can improve ease of access for your users and restrict access outside of Venn’s Blue Border (instructions here).

Was this article helpful?