To access PureDome applications, users have the option to verify their identity using JumpCloud Single Sign-On (SSO).
How to enable JumpCloud SSO?
Below are the steps to configure JumpCloud SSO integration:
Step 1 - Setting up SSO Application on JumpCloud
- Log in to the JumpCloud Admin console, and go to SSO Applications > Get Started.
- Select Custom Application, and click Next.
- Enter a name for your application, and click Next.
- Select Manage Single Sign-On (SSO) > Configure SSO with OIDC, and click Next.
- Enter Display Label, a Description (if you wish), and click Next.
- Click Configure Application.
Step 2 - Configuring the Client ID and Client Secret
- Go to the SSO page of the application that you've just created. Under Redirect URIs, enter the provided URL, make sure Client Secret Basic is checked, and under Login URL, enter the following URL:
Redirect URIs: https://login.puredome.com/oauth2/callback
Login URL: https://login.puredome.com/
- Scroll down to Attribute Mapping (optional). Make sure to check Email and Profile from Standard Scopes, and click activate.
- Copy Client ID and Client Secret values for later use.
Step 3 - Configuring the Issuer URL
- Copy the following URL (to be used as issuer URL for later use):
https://oauth.id.jumpcloud.com/
Step 4 - Managing user access
- Go to User Groups, and click + to add a new user group for the PureDome OIDC application.
- After creating the user group, proceed to add users to that specific group.
- Following that, go back to the PureDome OIDC application just created. Go to User Groups, and assign the application to the user group created in the previous step, and click save.
Step 5 - Adding a new identity provider
- Head over to the PureDome console on your browser, navigate to Preferences and Single Sign-On. By choosing JumpCloud you will be asked to enter four values as follows:
IDP Name: Any name you want
Client ID: Value copied from JumpCloud Admin dashboard
IDP Client Secret: Value copied from JumpCloud Admin dashboard
Issuer URL: Created in step 3.
- After completing all the steps above, you have successfully set up an OIDC application on your JumpCloud Admin workspace with SSO enabled for PureDome.
How to enable JumpCloud SCIM?
Step 1 - Setting Up SCIM in the PureDome Console
- After enabling SCIM, you will find the SCIM Base URL and OAuth Bearer Token values in their respective tabs. Be sure to copy these values for future use.
- In the SCIM section, you’ll also see options for auto-assigning and auto-purchasing licenses. If you’d like, go ahead and enable those features!
Step 2 - Setting up Secure Web Authentication (SWA) Application on JumpCloud
- Log in to the JumpCloud Admin console, and go to SSO Applications > Get Started.
- Select Custom Application, and click Next.
- Enter a name for your application, and click Next.
- Select Export users to this app (Identity Management), and click Next.
- Enter Display Label, a Description (if you wish), and click Save Application > Configure Application.
Step 3 - SCIM Integration Setup Process
- Enter Base URL and Token Key (You'll find this in the PureDome console under the SCIM > SCIM Base URL tab and OAuth Bearer Token tab after you create the SSO integration and enable SCIM)
- In the Group Management section, turn on the Enable management of User Groups and Group Membership option in this application.
- Scroll down and click Test Connection.
- If everything in the app is configured correctly, you will receive a successful notification.
- Click Activate, then Save.
Step 4 - Managing user access
- Head to the User Groups section of your SCIM application. If you need to assign the application to a specific group, do so, and then click Save. Once you've linked the application from JumpCloud to either specific users or groups, return to the PureDome console. You'll see a list of users with the status "Inactive." Choose the users you want to give licenses to. Then, click Assign License to apply the licenses.
- Or if you aim to sync an entire JumpCloud group to PureDome as a team, remember to add it under the Users Groups tab as well.
Note:
- Single-Sign-On (SSO) will be enabled for the PureDome console and apps.
- Only users/groups assigned in your organization to this application will be able to log in subject to being invited to the PureDome console via their registered email address on their JumpCloud workspace account.
Note:
Supported app versions for SSO:
Windows: v2.1.6.8 and above
macOS: v2.1.3 and above
iOS: v2.1.2 and above
Android: v2.4.34 and above
If you have any questions or are experiencing any issues, please don't hesitate to contact our 24/7 customer support team via live chat or email at support@puredome.com. We're always happy to help!