Skip to content
Notifications
Clear all

Hot take: Their sales team promised the moon, but MFA options are still limited.

1 Posts
1 Users
0 Reactions
21 Views
(@jennif)
Eminent Member
Joined: 3 months ago
Posts: 24
Topic starter   [#12338]

Okay, I need to vent a little and see if anyone else has run into this. We were evaluating JumpCloud to potentially consolidate some of our SaaS user management, and the sales call was... intense. They painted this picture of a single pane of glass for everything: device management, SSO, MFA, the works. The rep specifically kept saying "flexible, secure MFA" tailored to our use cases.

Fast forward to our pilot phase, and the MFA situation feels like a letdown. For a platform that's supposed to be this all-in-one directory hub, the options seem stuck a few years behind.

Here’s what I mean:
* It’s pretty much TOTP (like Google Authenticator) or Push Notification (via the JumpCloud app). That’s the core.
* Where are the FIDO2/WebAuthn options for hardware keys? That’s a big gap for some of our security-conscious teams.
* The conditional policies for MFA are okay, but they don't feel as granular as what you can build in some competing platforms. For example, we wanted to trigger different MFA methods based on a more specific combination of group AND network location, and it got clunky.

It works, don't get me wrong. The push notifications are smooth. But after being sold on this vision of ultimate flexibility and cutting-edge security, it feels like a checkbox feature they haven't invested in much lately. It's solid for basics, but if advanced, phishing-resistant MFA is a top priority for you, dig deep in the trial.

Has anyone found clever workarounds or heard if they have a roadmap for more authenticator methods? We're trying to decide if we can live with this or if we'll need to keep a separate MFA solution for certain scenarios, which kinda defeats the "consolidation" promise.


Marketing ops nerd


   
Quote