> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://docs.brainframe.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# SAML SSO JumpCloud

# 🔑 **SAML SSO J**umpCloud 
> **"Enable secure single sign-on with JumpCloud and Brainframe** **GRC."**  
> *Follow these steps to configure SAML authentication between your JumpCloud tenant and Brainframe GRC.*  

---

## 1️⃣ Create the Application  

1. Go to the **JumpCloud admin console **→ User Authentication → SSO Applications and click **Add New Application**.  

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_10ob3v3.png)




2. Click "Select" on **Custom Application**, and click **Next on the following screen**

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_hf1vva.png)
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1kr9iwz.png)
3. Select **Manage Single Sign-On (SSO)** and **Configure SSO with SAML**

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_4c54hs.png)

4. Enter the application name "Brainframe GRC", and enter a description for the users. Upload a logo or keep a color (keep all other settings default), then click on **Save application **and on the next screen click **Configure Application**

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1kmwjxg.png)
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_gazg7x.png)



---

## 2️⃣ Configure the JumpCloud SAML Settings  

1. Go into Brainframe Workspace Settings > Authentication, and enable the In the SSO login to receive the different SAML settings![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_oppdis.png)

1. Inside the newly created JumpCloud SSO Application, select the SSO tab, and copy the "SP Entity ID" and "Default ACL URL" from the Brainframe setting![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_rikso5.png)
2. Make sure to configure "Assertion" as sign method![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_v9z0mw.png)
3. Now configure in Jumpcloud the firstname and lastname User attributes, as well as the Constant attribute "WorkspaceId" (note that this is case sensitive). You find the valid Workspace ID inside Brainframe![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_gk6izi.png)
4. On JumpCloud, click SAVE to finalize the SSO settings.




---

## 3️⃣ Brainframe Configuration  

Once JumpCloud is ready, we'll finalize the Brainframe GRC side in **Workspace Settings → Authentication**.  

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/brainframe-grc-07-13-20261217p_hnqsqp.png =756xauto)
1. Copy the "IdP URL" from JumpCloud to the Brainframe SSO "IdP Single sign on (SSO) Login URL"![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_7pq4tm.png)![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_xrtjrw.png)
2. Download the Certificate of the application (Open the certificate and copy everything WITHOUT the **BEGIN/END CERTIFICATE** lines) → Paste into **IdP application certificate** in Brainframe.  ![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_irqxcb.png)[](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1azgin6.png)
3. Now click **SAVE** inside Brainframe to store and enable SSO for this workspace.

| When a user enters their email during login, they will now see the SSO login button for your workspace. You can optionally check that users are automatically redirected to the IdP SSO page after the email was entered (only works if this email is linked to a single workspace with SSO enabled)
---

## 4️⃣ Assign groups & test 

1. Check the groups that should get access in the JumpCloud application and click SAVE.  ![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_ltd5q5.png)

2. Now you can test the application via JumpCloud SSO page ![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_15fq1ij.png)


3. 
---

## 5️⃣ Common Errors & Fixes  

||| ❌ Failed to read asymmetric key: you should update the “IdP application certificate “in Brainframe GRC settings with the IdP BASE64 certificate (without the BEGIN/END Certificate line)


||| ❌ Attributes mismatch → All attributes are case sensitive (e.g WorkspaceId must be exact).  
