thejumpcloud/jumpcloud-admin
Manage your JumpCloud directory from any AI agent. Connects to the JumpCloud remote MCP server and ships skills for directory search, user lifecycle, device fleet, access reviews, SaaS spend, and Directory Insights audit events.
Trace JumpCloud entitlements — who can reach which SSO app or resource and through which groups, plus admin privilege and access-request posture for access reviews (SOC 2 / ISO 27001 style). Use when the user asks who has access to something, why someone has an app, or wants an entitlement report. For shadow IT / license waste use jumpcloud-saas-spend; for raw Directory Insights timelines use jumpcloud-audit-events; for alerts and health-rule triage use this skill’s alerts/health tools after entitlement scope is clear.
Orientation and router for JumpCloud Admin MCP — resource model, tool families, safety tiers, and which specialized skill to use. Prefer jumpcloud-directory-search for counts/aggregations, jumpcloud-user-lifecycle for onboard/offboard/MFA/password, jumpcloud-device-fleet for devices/commands/patch, jumpcloud-access-audit for entitlement paths, jumpcloud-saas-spend for licenses/shadow IT, and jumpcloud-audit-events for Directory Insights timelines. Use this skill when the task spans domains or no specialized skill fits (policies, assets, general tool choice).
Query JumpCloud Directory Insights audit events to reconstruct what happened — logins and login failures, admin actions, directory and MDM changes, SSO activity, and RADIUS or LDAP authentication. Use when investigating an incident, a lockout, suspicious activity, or a change nobody claims to have made, or when the user asks who did something, when it happened, or for an audit trail or evidence.
Inventory and operate a JumpCloud-managed device fleet — list and filter devices, check OS and agent versions, review patch and vulnerability posture, run remote commands, manage device groups, and lock, restart, or erase a machine. Use when the user asks about their laptops, endpoints, machines, MDM, patching, a lost or stolen device, or running a script across the fleet.
Answer aggregate, counting, and cross-resource questions about a JumpCloud organization in a single call using search_api_execute — how many users per group, devices by OS, accounts created in a date range, anything needing a group-by or a filter no list endpoint offers. Use whenever a JumpCloud question contains how many, count, per, by, average, oldest, newest, without, or missing, or when answering it would otherwise mean listing a resource and looping over the results.
Manage JumpCloud SaaS Management — review newly discovered shadow IT, approve or restrict applications, find unassigned and wasted licenses, calculate reclaimable spend, resolve app owners, and audit who actually logs into which SaaS app. Use when the user asks about SaaS spend, license waste, renewals, shadow IT, unapproved or newly discovered apps, app owners, or wants to cut software cost.
Onboard, modify, secure, and offboard JumpCloud users — create accounts, send activation, reset passwords and MFA, unlock accounts, grant and revoke group-based access, and run a complete offboarding. Use when the user mentions onboarding, offboarding, a new hire, a departure, a termination, suspending or deleting a user, or resetting someone's password or MFA.